File: //usr/local/apache/error_log
[Mon Jul 20 06:02:04.744003 2026] [lsapi:notice] [pid 943696:tid 943696] mod_lsapi: version 1.1-92
[Mon Jul 20 06:02:04.748579 2026] [:notice] [pid 796543:tid 796543] [host root@box5936.bluehost.com] mod_lsapi: Selfstarter 796543 started
[Mon Jul 20 06:02:04.765022 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: omrobuildingcenter.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.788446 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: entraalnuevomundo.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.807349 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-ea73e5c1.vnl.uel.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.809785 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thepauze.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.810504 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundbathmiami.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.811399 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sardimacmillan.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.812072 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sarahmusica.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.812737 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: membresiabeyou.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.813432 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: representgrace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.822309 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.828929 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: beforeracism.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.833718 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-3568b81f.zbj.ahr.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.844959 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: dnsplumbing.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.845793 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lakebreezegolf.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.846577 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lakebreezegolfclub.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.893638 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-555c397c.thestudioatfruitland.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.921280 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: boutrosinc.tempo-domain.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.922070 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: boutiquereinc.tempo-domain.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.925938 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: arunavabanerjee.stiqstudio.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.929315 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sitelca-com-co.sitac.com.co:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.939451 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: panova.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.945176 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nextbit-mx.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.946554 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: queridavida.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.947191 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: digi-access.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.948578 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: brisaslapunta.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.952970 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: eco-toner-com-mx.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.955111 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: elespecialista-mx.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.964069 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fkconstructionfunding-info.fkconstructionfunding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.966164 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-a61ebc8c.primefocusfm.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.967867 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: outlookturf.lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.968715 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-991472ff.lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.969582 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hilltopnurseryinc.lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.975240 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: qualitycoatingsinspection.northernstatemedia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.978963 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mail.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.980075 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: link.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.984406 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: silkbyblair.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.985253 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oldracelimited.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.985980 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: learnthissecret.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.025018 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: kingsafety.ca.ksands.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.034069 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: misralrakamia.itdynamix.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.035012 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: dev.sixpackminer.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.036549 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: panel.sixpackminer.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.038656 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: 6packminer.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.039384 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.040006 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: 6packminer-org.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.040679 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: 6packminer-net.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.041385 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer-io.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.042228 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-1f18706a.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.043034 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer-org.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.043787 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer-net.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.044697 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: abilite-uk.finding-funding.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.055704 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: webhubpro.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.058698 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mnvk-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.060361 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ukstudyagent.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.061159 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nvkart-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.061908 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bacg-finance.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.064516 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-fe5f3c9f.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.065338 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-f881ee98.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.066117 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-f6f4e776.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.066973 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-f3475bc5.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.067772 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-da985395.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.068739 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-b20dbffc.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.069924 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-8515b3f7.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.070604 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-701c1737.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.071454 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-0f976ec9.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.072307 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: uktouragency-com.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.073227 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bacginvest-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.075150 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: estateagentuk.com.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.075842 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: registerbusinessuk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.078131 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: exportsolution-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.079036 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: accountingco.finance.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.079799 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: technicalseohouse.com.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.080784 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: gua-yhh-mybluehost-me.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.081667 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: companyregistrationuk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.122735 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mtredistricting-gov.mtlegnews.gov:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.125894 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-201b05a6.drtoddreiter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.126826 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: longevityperformanceclinic.drtoddreiter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.127627 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: c-control.dexmanager.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.128330 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sauronsoftware.dexmanager.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.141785 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-a3818cc7.curlsnpearlsss.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.144461 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: wildlifeart-net.creekcombatveterans.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.145505 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: tellthetruthtravel.creekcombatveterans.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.146260 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lowemissionsasia-org.creekcombatveterans.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.147158 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hamelrealestate.collectingrealestate.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.162534 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nevelow.bespokesaintlouis.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.171725 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: faidr.auddia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.195417 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: yungmedusa.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.207365 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: willockhall.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.209730 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: karmaminds.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.236254 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: totheyoungerme.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.242008 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: threethirds.co:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.244331 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thexo.blog:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.246703 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thepostalshoppe1.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.268590 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sunsetwaters.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.269463 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sulfure.ch:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.274659 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: s-o-solutions.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.277608 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sodacitypeaceofmind.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.280618 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sitac.com.co:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.282713 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sheliastransportation.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.289197 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: scottdudekphotography.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.297642 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: saintrhum.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.300733 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sacredpathway.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.306765 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rose-treks.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.308956 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rhs.tev.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.318519 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: qoe.tdd.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.321297 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: qcms.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.327167 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: primefocusfm.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.328205 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.330935 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: peycosoluciones.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.332904 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: passportsnpinot.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.340265 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: northernstatemedia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.344289 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.346034 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ohq.ryb.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.353758 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nowetsheets.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.358624 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ninilchik.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.361158 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nextlevellifts.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.367491 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mvg.rfs.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.369041 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mswsupply.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.394195 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lindakingart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.399845 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: launchrolesville.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.403439 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ksd.oas.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.405219 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: krissywiedenhoff.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.406386 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: saphansiam.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.410957 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jxk.wid.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.415904 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jmfinnfilms.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.421170 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: livingwithhiddenpain.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.430945 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: holistica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.432841 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hoggdavis.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.433694 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: heidimortenson.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.434346 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hcresthomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.437577 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.454799 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: freestoreministry.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.455847 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fpn.adr.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.457486 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fol.ehn.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.461546 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ffl.tdd.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.466305 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: eym.rfn.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.479213 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: heatherbowman.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.480039 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: drtoddreiter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.487776 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: curlsnpearlsss.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.496241 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: cleansparkly.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.509726 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bridgetforcongress.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.524900 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: auddia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.526338 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: matthewkilthaumd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.539434 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: airportsec.com.ec:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.546765 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bog.vvo.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.570370 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oneoilaway.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.571136 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: loveteresa.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.571807 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: teresaharding.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.572448 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: dadviceonline.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.573076 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mlmgamechangers.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.573734 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: myoilsuccesssystem.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.574424 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: joinmlmgamechangers.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.575182 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: frankincenseoils-net.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.575831 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mlmgamechangersecrets.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.576491 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: operationcoursecreation.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.577150 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: teresahardingmasterclass.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.577834 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: marketinggamechangersonline.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.578608 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: marketinggamechangersecrets.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.580071 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: besoundful.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.580743 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: alimentamor.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.581400 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rodrigosardi.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.582147 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fansarogroup.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.583737 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: theupgradables.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.584427 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thegpsapproach.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.585890 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: meditacionmiami.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.586682 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bgenerationlove.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.587406 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-dad43c4c.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.588339 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-4fba7881.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.589319 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: miamimeditations.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.590898 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: iamsarahmacmillan.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.591835 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: familiaconsciente.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.592649 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: aprendeameditar-co.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.593413 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sarahmacmillan-life.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.594228 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: familiasconscientes.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.594998 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundmeditationmiami.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.595908 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: generationloveproject.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.597164 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: espiritualidadmoderna.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.597941 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundhealingsouthflorida.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.598731 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundmeditationsouthflorida.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.599463 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sergnotes.raya31.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.600470 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jennylouraya.raya31.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.601299 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: locketsandcharms.raya31.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.604330 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oohlovely.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.605358 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jenfarley.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.606190 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: cathybuffini.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.607004 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: drawingthedog.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.607884 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hedgerow-crafts.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.608739 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-a6fcc47f.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.611185 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thescarystory.lakelopezonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.612082 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thewritinglair.lakelopezonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.626592 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.627965 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.633900 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lvcinc.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.635316 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.649900 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-7a50eaec.querenciapartners.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.650919 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rootsofwisdom.ca.querenciapartners.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.651761 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thailandtire.greatroadtire.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.705933 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: elementfix.elementconstruction.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.727439 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: boracayhaven.com.ph:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.742930 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: globalglow.ca:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.751880 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: callourplace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.793106 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: demnetworks.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.795901 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.808718 2026] [qos:notice] [pid 943696:tid 943696] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Mon Jul 20 06:02:06.016631 2026] [http2:info] [pid 943696:tid 943696] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Mon Jul 20 06:02:06.021182 2026] [mpm_event:notice] [pid 943696:tid 943696] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Mon Jul 20 06:02:06.021197 2026] [core:notice] [pid 943696:tid 943696] AH00094: Command line: '/usr/sbin/httpd'
[Mon Jul 20 06:02:07.070332 2026] [http2:info] [pid 796567:tid 796567] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:02:07.090795 2026] [security2:error] [pid 796567:tid 796734] [client 51.68.111.205:17401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pscmedicalbilling.com"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVoQAAAjk"]
[Mon Jul 20 06:02:07.090961 2026] [security2:error] [pid 796567:tid 796734] [client 51.68.111.205:17401] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pscmedicalbilling.com"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVoQAAAjk"]
[Mon Jul 20 06:02:07.092170 2026] [security2:error] [pid 796567:tid 796730] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socalledsam.com"] [uri "/.well-known/about.php"] [unique_id "al4OP7LfyzVz2SrjZpiVnwAAAjU"]
[Mon Jul 20 06:02:07.092801 2026] [security2:error] [pid 796567:tid 796701] [client 185.132.186.67:24237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/cc.php"] [unique_id "al4OP7LfyzVz2SrjZpiVkAAAAhg"]
[Mon Jul 20 06:02:07.093316 2026] [security2:error] [pid 796567:tid 796730] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "socalledsam.com"] [uri "/.well-known/about.php"] [unique_id "al4OP7LfyzVz2SrjZpiVnwAAAjU"]
[Mon Jul 20 06:02:07.099073 2026] [security2:error] [pid 796567:tid 796733] [client 14.224.227.113:50718] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVoAAAAjg"]
[Mon Jul 20 06:02:07.099237 2026] [security2:error] [pid 796567:tid 796709] [client 14.251.3.155:50715] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVlgAAAiA"]
[Mon Jul 20 06:02:07.099217 2026] [security2:error] [pid 796567:tid 796716] [client 14.251.3.155:50707] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVmQAAAic"]
[Mon Jul 20 06:02:07.099333 2026] [security2:error] [pid 796567:tid 796704] [client 46.110.96.34:41500] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVkwAAAhs"]
[Mon Jul 20 06:02:07.099684 2026] [security2:error] [pid 796567:tid 796698] [client 14.251.3.155:50709] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVkQAAAhU"]
[Mon Jul 20 06:02:07.099839 2026] [security2:error] [pid 796567:tid 796737] [client 14.251.3.155:50724] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVogAAAjw"]
[Mon Jul 20 06:02:07.100321 2026] [security2:error] [pid 796567:tid 796748] [client 14.224.227.113:50728] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVqAAAAkc"]
[Mon Jul 20 06:02:07.100408 2026] [security2:error] [pid 796567:tid 796729] [client 14.224.227.113:50710] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVngAAAjQ"]
[Mon Jul 20 06:02:07.100413 2026] [security2:error] [pid 796567:tid 796725] [client 14.251.3.155:50719] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVnAAAAjA"]
[Mon Jul 20 06:02:07.100696 2026] [security2:error] [pid 796567:tid 796713] [client 14.251.3.155:50717] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVmAAAAiQ"]
[Mon Jul 20 06:02:07.100697 2026] [security2:error] [pid 796567:tid 796741] [client 14.224.227.113:50721] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVpAAAAkA"]
[Mon Jul 20 06:02:07.102214 2026] [security2:error] [pid 796567:tid 796745] [client 14.224.227.113:50725] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVpgAAAkQ"]
[Mon Jul 20 06:02:07.102097 2026] [security2:error] [pid 796567:tid 796721] [client 14.251.3.155:50711] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVmgAAAiw"]
[Mon Jul 20 06:02:07.102340 2026] [security2:error] [pid 796567:tid 796706] [client 14.251.3.155:50713] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVlAAAAh0"]
[Mon Jul 20 06:02:07.102919 2026] [security2:error] [pid 796567:tid 796751] [client 14.224.227.113:50712] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVpwAAAko"]
[Mon Jul 20 06:02:07.107474 2026] [core:error] [pid 796567:tid 796738] [client 14.225.17.146:61507] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:07.107495 2026] [core:error] [pid 796567:tid 796738] [client 14.225.17.146:61507] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:07.118645 2026] [security2:error] [pid 796567:tid 796575] [remote 176.31.139.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "tiokubito.cl"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVswACigc"]
[Mon Jul 20 06:02:07.118775 2026] [security2:error] [pid 796567:tid 796815] [client 176.31.139.25:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tiokubito.cl"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVswACigc"]
[Mon Jul 20 06:02:07.141663 2026] [security2:error] [pid 796567:tid 796581] [remote 57.141.18.104:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4OP7LfyzVz2SrjZpiVvAACRA0"]
[Mon Jul 20 06:02:07.151146 2026] [security2:error] [pid 796567:tid 796608] [remote 57.141.18.27:20034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4OP7LfyzVz2SrjZpiV2QACLCg"]
[Mon Jul 20 06:02:07.182327 2026] [security2:error] [pid 796567:tid 796631] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWBgACjD8"]
[Mon Jul 20 06:02:07.182569 2026] [security2:error] [pid 796567:tid 796817] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWBgACjD8"]
[Mon Jul 20 06:02:07.259771 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:61290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIQAAAh4"]
[Mon Jul 20 06:02:07.259941 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:61290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIQAAAh4"]
[Mon Jul 20 06:02:07.261290 2026] [security2:error] [pid 796567:tid 796640] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIAACM0g"]
[Mon Jul 20 06:02:07.261576 2026] [security2:error] [pid 796567:tid 796728] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIAACM0g"]
[Mon Jul 20 06:02:07.293331 2026] [security2:error] [pid 796567:tid 796729] [client 179.0.122.163:22306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.122.0.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWMgAAAjQ"]
[Mon Jul 20 06:02:07.293513 2026] [security2:error] [pid 796567:tid 796729] [client 179.0.122.163:22306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWMgAAAjQ"]
[Mon Jul 20 06:02:07.302299 2026] [security2:error] [pid 796567:tid 796720] [client 114.119.136.5:39273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/category/magical-realism"] [unique_id "al4OP7LfyzVz2SrjZpiWMQAAAis"], referer: https://omenana.com/category/magical-realism/page/2?filter_by=review_high
[Mon Jul 20 06:02:07.354746 2026] [security2:error] [pid 796567:tid 796803] [client 65.1.132.125:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWQgAAAn4"]
[Mon Jul 20 06:02:07.354903 2026] [security2:error] [pid 796567:tid 796803] [client 65.1.132.125:47428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWQgAAAn4"]
[Mon Jul 20 06:02:07.366289 2026] [security2:error] [pid 796567:tid 796814] [client 193.19.109.245:58671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWRwAAAok"]
[Mon Jul 20 06:02:07.388176 2026] [security2:error] [pid 796567:tid 796812] [client 193.19.109.238:29531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWRgAAAoc"]
[Mon Jul 20 06:02:07.404355 2026] [security2:error] [pid 796567:tid 796749] [client 41.173.37.102:5975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWUQAAAkg"]
[Mon Jul 20 06:02:07.404537 2026] [security2:error] [pid 796567:tid 796749] [client 41.173.37.102:5975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWUQAAAkg"]
[Mon Jul 20 06:02:07.413543 2026] [security2:error] [pid 796567:tid 796718] [client 164.100.212.184:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWVQAAAik"]
[Mon Jul 20 06:02:07.413664 2026] [security2:error] [pid 796567:tid 796718] [client 164.100.212.184:50819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWVQAAAik"]
[Mon Jul 20 06:02:07.439976 2026] [security2:error] [pid 796567:tid 796800] [client 178.152.178.232:36324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWYQAAAns"]
[Mon Jul 20 06:02:07.440111 2026] [security2:error] [pid 796567:tid 796800] [client 178.152.178.232:36324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWYQAAAns"]
[Mon Jul 20 06:02:07.451413 2026] [security2:error] [pid 796567:tid 796713] [client 181.224.94.124:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWZQAAAiQ"]
[Mon Jul 20 06:02:07.451561 2026] [security2:error] [pid 796567:tid 796713] [client 181.224.94.124:12181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWZQAAAiQ"]
[Mon Jul 20 06:02:07.467446 2026] [security2:error] [pid 796567:tid 796650] [remote 188.166.241.141:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWaQAChVI"]
[Mon Jul 20 06:02:07.568834 2026] [security2:error] [pid 796567:tid 796808] [client 114.119.158.83:30723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.safe-systems.net"] [uri "/nextbit.mx/portafolio/aviato/product-single.html"] [unique_id "al4OP7LfyzVz2SrjZpiWdQAAAoM"], referer: http://www.safe-systems.net/nextbit.mx/portafolio/aviato/checkout.html
[Mon Jul 20 06:02:07.573725 2026] [security2:error] [pid 796567:tid 796819] [client 103.149.16.77:58315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWdgAAAo4"]
[Mon Jul 20 06:02:07.573891 2026] [security2:error] [pid 796567:tid 796819] [client 103.149.16.77:58315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWdgAAAo4"]
[Mon Jul 20 06:02:07.650119 2026] [security2:error] [pid 796567:tid 796822] [client 210.212.97.243:10424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWegAAApE"]
[Mon Jul 20 06:02:07.650289 2026] [security2:error] [pid 796567:tid 796822] [client 210.212.97.243:10424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWegAAApE"]
[Mon Jul 20 06:02:07.654316 2026] [autoindex:error] [pid 796567:tid 796816] [client 194.233.91.21:52295] AH01276: Cannot serve directory /home4/jvcmotor/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:02:07.733402 2026] [security2:error] [pid 796567:tid 796661] [remote 8.217.108.67:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circafabrication.com"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWhgACWl0"]
[Mon Jul 20 06:02:07.765186 2026] [security2:error] [pid 796567:tid 796767] [client 50.116.65.227:12512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OP7LfyzVz2SrjZpiWjQAAAlo"]
[Mon Jul 20 06:02:07.769446 2026] [security2:error] [pid 796567:tid 796820] [client 34.44.142.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWfwAAAo8"]
[Mon Jul 20 06:02:07.783386 2026] [security2:error] [pid 796567:tid 796704] [client 129.222.187.209:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWkQAAAhs"]
[Mon Jul 20 06:02:07.784415 2026] [security2:error] [pid 796567:tid 796782] [client 50.116.65.227:12538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OP7LfyzVz2SrjZpiWkAAAAmk"]
[Mon Jul 20 06:02:07.791142 2026] [security2:error] [pid 796567:tid 796704] [client 129.222.187.209:4505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWkQAAAhs"]
[Mon Jul 20 06:02:07.827408 2026] [security2:error] [pid 796567:tid 796664] [remote 148.113.128.53:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "tiokubito.cl"] [uri "/wp-content/uploads/2024/06/1000173187.jpg"] [unique_id "al4OP7LfyzVz2SrjZpiWlQACKWA"]
[Mon Jul 20 06:02:07.827685 2026] [security2:error] [pid 796567:tid 796718] [client 148.113.128.53:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tiokubito.cl"] [uri "/wp-content/uploads/2024/06/1000173187.jpg"] [unique_id "al4OP7LfyzVz2SrjZpiWlQACKWA"]
[Mon Jul 20 06:02:07.853914 2026] [security2:error] [pid 796567:tid 796665] [remote 188.166.241.141:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWlwACIWE"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:02:07.865112 2026] [security2:error] [pid 796567:tid 796787] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWawAAAm4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:08.111558 2026] [http2:info] [pid 796928:tid 796928] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:02:08.299973 2026] [security2:error] [pid 796567:tid 796801] [client 173.239.240.10:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bnb-engineering.com"] [uri "/wp-login.php"] [unique_id "al4OQLLfyzVz2SrjZpiWrgAAAnw"]
[Mon Jul 20 06:02:08.588929 2026] [security2:error] [pid 796567:tid 796710] [client 72.255.10.154:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiWyAAAAiE"]
[Mon Jul 20 06:02:08.589050 2026] [security2:error] [pid 796567:tid 796710] [client 72.255.10.154:1045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiWyAAAAiE"]
[Mon Jul 20 06:02:08.666121 2026] [security2:error] [pid 796928:tid 797081] [client 35.90.38.209:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4OQOsTy9vX-htKvPn4uQAAArA"]
[Mon Jul 20 06:02:08.769313 2026] [security2:error] [pid 796928:tid 797060] [client 112.213.160.112:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OQOsTy9vX-htKvPn4vQAAAps"]
[Mon Jul 20 06:02:08.769447 2026] [security2:error] [pid 796928:tid 797060] [client 112.213.160.112:8215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OQOsTy9vX-htKvPn4vQAAAps"]
[Mon Jul 20 06:02:08.790680 2026] [security2:error] [pid 796567:tid 796688] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiW0gACJXg"]
[Mon Jul 20 06:02:08.790912 2026] [security2:error] [pid 796567:tid 796714] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiW0gACJXg"]
[Mon Jul 20 06:02:08.876803 2026] [security2:error] [pid 796567:tid 796691] [remote 57.141.18.57:22890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2950356"] [unique_id "al4OQLLfyzVz2SrjZpiW2AACUHs"]
[Mon Jul 20 06:02:09.046529 2026] [security2:error] [pid 796928:tid 797107] [client 185.132.186.102:54545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/index.php"] [unique_id "al4OQesTy9vX-htKvPn4xgAAAso"]
[Mon Jul 20 06:02:09.072484 2026] [security2:error] [pid 796567:tid 796725] [client 14.225.17.146:61251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWngAAAjA"], referer: http://walkingandtalking.net/wordpress
[Mon Jul 20 06:02:09.370813 2026] [security2:error] [pid 796567:tid 796798] [client 98.159.234.160:30539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OQbLfyzVz2SrjZpiW8gAAAnk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:09.765854 2026] [security2:error] [pid 796567:tid 796823] [client 150.228.148.150:12650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OQbLfyzVz2SrjZpiXBgAAApI"]
[Mon Jul 20 06:02:09.766031 2026] [security2:error] [pid 796567:tid 796823] [client 150.228.148.150:12650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OQbLfyzVz2SrjZpiXBgAAApI"]
[Mon Jul 20 06:02:09.771763 2026] [security2:error] [pid 796567:tid 796794] [client 14.225.17.146:54629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4OQLLfyzVz2SrjZpiWtQAAAnU"], referer: http://iagdevelopments.com/wordpress
[Mon Jul 20 06:02:09.954479 2026] [security2:error] [pid 796928:tid 797138] [client 14.225.17.146:62339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4OQesTy9vX-htKvPn44AAAAuk"], referer: https://walkingandtalking.net/wordpress
[Mon Jul 20 06:02:10.009674 2026] [security2:error] [pid 796567:tid 796816] [client 173.239.254.41:21321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXEwAAAos"]
[Mon Jul 20 06:02:10.052928 2026] [security2:error] [pid 796928:tid 797134] [client 103.95.123.246:18820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn45wAAAuU"]
[Mon Jul 20 06:02:10.053065 2026] [security2:error] [pid 796928:tid 797134] [client 103.95.123.246:18820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn45wAAAuU"]
[Mon Jul 20 06:02:10.085130 2026] [security2:error] [pid 796567:tid 796641] [remote 217.61.143.92:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXGgACdEk"]
[Mon Jul 20 06:02:10.191142 2026] [security2:error] [pid 796567:tid 796734] [client 14.225.17.146:61254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWpAAAAjk"], referer: http://windowtx.com/wordpress
[Mon Jul 20 06:02:10.290829 2026] [security2:error] [pid 796567:tid 796810] [client 52.183.195.200:21699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4OQrLfyzVz2SrjZpiXJQAAAoU"]
[Mon Jul 20 06:02:10.314354 2026] [security2:error] [pid 796567:tid 796645] [remote 217.61.143.92:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXKQACH00"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:02:10.322253 2026] [security2:error] [pid 796567:tid 796819] [client 52.183.195.200:21699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OQrLfyzVz2SrjZpiXKwAAAo4"]
[Mon Jul 20 06:02:10.610473 2026] [security2:error] [pid 796567:tid 796649] [remote 45.90.123.233:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXOwACJ1E"]
[Mon Jul 20 06:02:10.734654 2026] [security2:error] [pid 796567:tid 796819] [client 77.110.127.138:54511] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4OQrLfyzVz2SrjZpiXRAAAAo4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:10.820962 2026] [security2:error] [pid 796567:tid 796710] [client 193.19.109.243:22235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXSwAAAiE"]
[Mon Jul 20 06:02:10.822386 2026] [security2:error] [pid 796567:tid 796713] [client 193.19.109.222:50699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXSgAAAiQ"]
[Mon Jul 20 06:02:10.886793 2026] [security2:error] [pid 796567:tid 796706] [client 14.225.17.146:50347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4OQrLfyzVz2SrjZpiXTAAAAh0"], referer: https://iagdevelopments.com/wordpress
[Mon Jul 20 06:02:10.901215 2026] [security2:error] [pid 796567:tid 796611] [remote 45.90.123.233:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXTwACdSs"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:02:10.915080 2026] [security2:error] [pid 796928:tid 797169] [client 106.192.104.4:52500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn4-gAAAwg"]
[Mon Jul 20 06:02:10.915211 2026] [security2:error] [pid 796928:tid 797169] [client 106.192.104.4:52500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn4-gAAAwg"]
[Mon Jul 20 06:02:10.998628 2026] [security2:error] [pid 796567:tid 796822] [client 185.132.186.98:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ab.php"] [unique_id "al4OQrLfyzVz2SrjZpiXWAAAApE"]
[Mon Jul 20 06:02:11.288590 2026] [security2:error] [pid 796928:tid 797086] [client 172.200.24.58:3011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4OQ-sTy9vX-htKvPn5BAAAArU"]
[Mon Jul 20 06:02:11.350207 2026] [security2:error] [pid 796928:tid 797102] [client 172.200.24.58:3011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OQ-sTy9vX-htKvPn5CQAAAsU"]
[Mon Jul 20 06:02:11.400533 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.64:47706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiV0AACYyI"]
[Mon Jul 20 06:02:11.465094 2026] [security2:error] [pid 796567:tid 796762] [client 57.141.18.32:20832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiV0gACVRk"]
[Mon Jul 20 06:02:11.638010 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.72:39798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWPgACNU8"]
[Mon Jul 20 06:02:11.830948 2026] [security2:error] [pid 796567:tid 796634] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ7LfyzVz2SrjZpiXggACjkI"]
[Mon Jul 20 06:02:11.831146 2026] [security2:error] [pid 796567:tid 796819] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ7LfyzVz2SrjZpiXggACjkI"]
[Mon Jul 20 06:02:11.937023 2026] [security2:error] [pid 796928:tid 797139] [client 18.228.171.129:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ-sTy9vX-htKvPn5GAAAAuo"]
[Mon Jul 20 06:02:11.937208 2026] [security2:error] [pid 796928:tid 797139] [client 18.228.171.129:33790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ-sTy9vX-htKvPn5GAAAAuo"]
[Mon Jul 20 06:02:12.224572 2026] [security2:error] [pid 796567:tid 796797] [client 115.246.21.170:20945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXjwAAAng"]
[Mon Jul 20 06:02:12.224737 2026] [security2:error] [pid 796567:tid 796797] [client 115.246.21.170:20945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXjwAAAng"]
[Mon Jul 20 06:02:12.318594 2026] [security2:error] [pid 796928:tid 797153] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OROsTy9vX-htKvPn5GwAAAvg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:12.713255 2026] [security2:error] [pid 796567:tid 796791] [client 47.31.86.100:53911] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXngAAAnI"]
[Mon Jul 20 06:02:12.713376 2026] [security2:error] [pid 796567:tid 796791] [client 47.31.86.100:53911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXngAAAnI"]
[Mon Jul 20 06:02:12.775746 2026] [security2:error] [pid 796567:tid 796797] [client 173.239.240.20:45031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bnb-engineering.com"] [uri "/wp-login.php"] [unique_id "al4ORLLfyzVz2SrjZpiXowAAAng"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:02:12.939898 2026] [security2:error] [pid 796567:tid 796706] [client 185.132.186.75:25211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/about.php"] [unique_id "al4ORLLfyzVz2SrjZpiXswAAAh0"]
[Mon Jul 20 06:02:13.361099 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:31345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OResTy9vX-htKvPn5NgAAAp4"]
[Mon Jul 20 06:02:13.382523 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:31345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OResTy9vX-htKvPn5NgAAAp4"]
[Mon Jul 20 06:02:13.932111 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:56981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4OROsTy9vX-htKvPn5HwAAAvU"], referer: http://xp-design.co/wordpress
[Mon Jul 20 06:02:14.079868 2026] [security2:error] [pid 796567:tid 796814] [client 77.110.127.138:54511] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4ORrLfyzVz2SrjZpiX5QAAAok"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:14.214691 2026] [security2:error] [pid 796928:tid 797148] [client 178.152.178.232:36415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5VgAAAvM"]
[Mon Jul 20 06:02:14.214893 2026] [security2:error] [pid 796928:tid 797148] [client 178.152.178.232:36415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5VgAAAvM"]
[Mon Jul 20 06:02:14.463083 2026] [security2:error] [pid 796928:tid 797141] [client 41.173.37.102:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5XAAAAuw"]
[Mon Jul 20 06:02:14.463251 2026] [security2:error] [pid 796928:tid 797141] [client 41.173.37.102:6584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5XAAAAuw"]
[Mon Jul 20 06:02:14.603345 2026] [security2:error] [pid 796567:tid 796744] [client 57.141.18.72:39810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OQrLfyzVz2SrjZpiXKgACQ04"]
[Mon Jul 20 06:02:14.822401 2026] [security2:error] [pid 796928:tid 797065] [client 3.109.4.218:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5awAAAqA"]
[Mon Jul 20 06:02:14.822559 2026] [security2:error] [pid 796928:tid 797065] [client 3.109.4.218:36408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5awAAAqA"]
[Mon Jul 20 06:02:14.849795 2026] [security2:error] [pid 796928:tid 796948] [remote 209.42.18.223:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4ORusTy9vX-htKvPn5bAACvBM"]
[Mon Jul 20 06:02:14.889907 2026] [security2:error] [pid 796928:tid 797115] [client 185.132.186.91:34147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "al4ORusTy9vX-htKvPn5bwAAAtI"]
[Mon Jul 20 06:02:15.050207 2026] [security2:error] [pid 796928:tid 796949] [remote 209.42.18.223:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OR-sTy9vX-htKvPn5dgAC6BQ"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:02:15.283685 2026] [security2:error] [pid 796567:tid 796759] [client 14.225.17.146:49759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OR7LfyzVz2SrjZpiYDgAAAlI"], referer: http://fkconstructionfunding.com/wordpress
[Mon Jul 20 06:02:15.346683 2026] [security2:error] [pid 796928:tid 797136] [client 14.224.227.113:50714] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5fgAAAuc"]
[Mon Jul 20 06:02:15.372907 2026] [security2:error] [pid 796567:tid 796639] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYGAACIUc"]
[Mon Jul 20 06:02:15.373121 2026] [security2:error] [pid 796567:tid 796710] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYGAACIUc"]
[Mon Jul 20 06:02:15.394743 2026] [security2:error] [pid 796567:tid 796794] [client 14.224.227.113:50708] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYGwAAAnU"]
[Mon Jul 20 06:02:15.395834 2026] [security2:error] [pid 796928:tid 797174] [client 14.224.227.113:50716] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5gQAAAw0"]
[Mon Jul 20 06:02:15.401004 2026] [security2:error] [pid 796928:tid 797144] [client 14.224.227.113:50723] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5ggAAAu8"]
[Mon Jul 20 06:02:15.563389 2026] [security2:error] [pid 796928:tid 797148] [client 14.251.3.155:50753] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5iQAAAvM"]
[Mon Jul 20 06:02:15.576898 2026] [security2:error] [pid 796928:tid 797058] [client 14.251.3.155:50755] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5igAAApk"]
[Mon Jul 20 06:02:15.586844 2026] [security2:error] [pid 796567:tid 796762] [client 14.251.3.155:50751] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYJwAAAlU"]
[Mon Jul 20 06:02:15.599974 2026] [security2:error] [pid 796567:tid 796823] [client 14.251.3.155:50757] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYKgAAApI"]
[Mon Jul 20 06:02:15.621780 2026] [security2:error] [pid 796928:tid 797163] [client 14.224.227.113:50752] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5jgAAAwI"]
[Mon Jul 20 06:02:15.628357 2026] [security2:error] [pid 796928:tid 797073] [client 14.224.227.113:50754] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5jwAAAqg"]
[Mon Jul 20 06:02:15.772644 2026] [security2:error] [pid 796567:tid 796795] [client 14.225.17.146:58571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4ORrLfyzVz2SrjZpiX-QAAAnY"], referer: http://entuvy.com/wordpress
[Mon Jul 20 06:02:15.850157 2026] [security2:error] [pid 796567:tid 796800] [client 14.251.3.155:50761] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYMQAAAns"]
[Mon Jul 20 06:02:15.896722 2026] [security2:error] [pid 796567:tid 796798] [client 103.149.16.77:58802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYNAAAAnk"]
[Mon Jul 20 06:02:15.896856 2026] [security2:error] [pid 796567:tid 796798] [client 103.149.16.77:58802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYNAAAAnk"]
[Mon Jul 20 06:02:16.075048 2026] [security2:error] [pid 796567:tid 796706] [client 210.212.97.243:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYQwAAAh0"]
[Mon Jul 20 06:02:16.075241 2026] [security2:error] [pid 796567:tid 796706] [client 210.212.97.243:10425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYQwAAAh0"]
[Mon Jul 20 06:02:16.153758 2026] [security2:error] [pid 796567:tid 796811] [client 14.251.3.155:50726] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OSLLfyzVz2SrjZpiYRwAAAoY"]
[Mon Jul 20 06:02:16.155168 2026] [security2:error] [pid 796567:tid 796748] [client 14.251.3.155:50722] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OSLLfyzVz2SrjZpiYSAAAAkc"]
[Mon Jul 20 06:02:16.459850 2026] [security2:error] [pid 796567:tid 796747] [client 14.225.17.146:58803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4OSLLfyzVz2SrjZpiYSgAAAkY"], referer: http://alrowad-hub.net/wordpress
[Mon Jul 20 06:02:16.464142 2026] [security2:error] [pid 796567:tid 796784] [client 14.225.17.146:58804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OSLLfyzVz2SrjZpiYSwAAAms"], referer: https://fkconstructionfunding.com/wordpress
[Mon Jul 20 06:02:16.485260 2026] [security2:error] [pid 796567:tid 796807] [client 14.225.17.146:60501] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4OR7LfyzVz2SrjZpiYLgAAAoI"], referer: http://uritems.net/wordpress
[Mon Jul 20 06:02:16.530541 2026] [security2:error] [pid 796928:tid 797060] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSOsTy9vX-htKvPn5oAAAAps"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:16.549704 2026] [security2:error] [pid 796928:tid 797165] [client 50.116.65.227:55244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OSOsTy9vX-htKvPn5sAAAAwQ"]
[Mon Jul 20 06:02:16.564494 2026] [security2:error] [pid 796928:tid 797144] [client 50.116.65.227:55252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OSOsTy9vX-htKvPn5sgAAAu8"]
[Mon Jul 20 06:02:16.749533 2026] [security2:error] [pid 796567:tid 796737] [client 57.141.18.6:48804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ORLLfyzVz2SrjZpiXlAACPGw"]
[Mon Jul 20 06:02:16.830569 2026] [security2:error] [pid 796928:tid 797088] [client 185.132.186.104:61567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/doc.php"] [unique_id "al4OSOsTy9vX-htKvPn5uAAAArc"]
[Mon Jul 20 06:02:16.841996 2026] [security2:error] [pid 796567:tid 796703] [client 164.100.212.184:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYbQAAAho"]
[Mon Jul 20 06:02:16.842162 2026] [security2:error] [pid 796567:tid 796703] [client 164.100.212.184:51380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYbQAAAho"]
[Mon Jul 20 06:02:17.215465 2026] [security2:error] [pid 796928:tid 797111] [client 14.225.17.146:60447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4OR-sTy9vX-htKvPn5hwAAAs4"], referer: http://detroitcsc.com/wordpress
[Mon Jul 20 06:02:17.284785 2026] [security2:error] [pid 796928:tid 797146] [client 45.146.54.115:45185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "travelbyfire.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4OSesTy9vX-htKvPn5ygAAAvE"]
[Mon Jul 20 06:02:17.345904 2026] [security2:error] [pid 796928:tid 797107] [client 181.224.94.124:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSesTy9vX-htKvPn50AAAAso"]
[Mon Jul 20 06:02:17.346046 2026] [security2:error] [pid 796928:tid 797107] [client 181.224.94.124:6659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSesTy9vX-htKvPn50AAAAso"]
[Mon Jul 20 06:02:17.495040 2026] [security2:error] [pid 796567:tid 796814] [client 129.222.187.209:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSbLfyzVz2SrjZpiYjAAAAok"]
[Mon Jul 20 06:02:17.495193 2026] [security2:error] [pid 796567:tid 796814] [client 129.222.187.209:21099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSbLfyzVz2SrjZpiYjAAAAok"]
[Mon Jul 20 06:02:17.531180 2026] [security2:error] [pid 796928:tid 797146] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSesTy9vX-htKvPn5ywAAAvE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:17.800945 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:54510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4OSbLfyzVz2SrjZpiYnQAAAmY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:17.978599 2026] [security2:error] [pid 796567:tid 796725] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSbLfyzVz2SrjZpiYmAAAAjA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:18.010704 2026] [security2:error] [pid 796928:tid 797116] [client 82.102.18.116:60000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "al4OSusTy9vX-htKvPn55wAAAtM"]
[Mon Jul 20 06:02:18.587417 2026] [security2:error] [pid 796928:tid 797102] [client 14.225.17.146:57095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4OSOsTy9vX-htKvPn5qAAAAsU"], referer: http://outlookturf.com/wordpress
[Mon Jul 20 06:02:18.771818 2026] [security2:error] [pid 796567:tid 796766] [client 185.132.186.59:34527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al4OSrLfyzVz2SrjZpiYyQAAAlk"]
[Mon Jul 20 06:02:18.781563 2026] [security2:error] [pid 796928:tid 797088] [client 103.118.29.185:47844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4OSusTy9vX-htKvPn6AQACtyE"], referer: https://blaizeaccountingservices.com/wp-login.php
[Mon Jul 20 06:02:18.904549 2026] [security2:error] [pid 796567:tid 796759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSrLfyzVz2SrjZpiYxAAAAlI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:19.226987 2026] [security2:error] [pid 796567:tid 796822] [client 72.255.10.154:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY5AAAApE"]
[Mon Jul 20 06:02:19.227173 2026] [security2:error] [pid 796567:tid 796822] [client 72.255.10.154:2339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY5AAAApE"]
[Mon Jul 20 06:02:19.256345 2026] [security2:error] [pid 796928:tid 797097] [client 45.157.112.60:39489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OS-sTy9vX-htKvPn6GQAAAsA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:19.258383 2026] [security2:error] [pid 796567:tid 796747] [client 47.128.120.29:26644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tejasenvironmental.com"] [uri "/robots.txt"] [unique_id "al4OS7LfyzVz2SrjZpiY5wAAAkY"]
[Mon Jul 20 06:02:19.304781 2026] [security2:error] [pid 796928:tid 797167] [client 14.224.227.113:50767] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OS-sTy9vX-htKvPn6HAAAAwY"]
[Mon Jul 20 06:02:19.352152 2026] [security2:error] [pid 796928:tid 797108] [client 82.102.18.116:58758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4OS-sTy9vX-htKvPn6HwAAAss"]
[Mon Jul 20 06:02:19.369915 2026] [security2:error] [pid 796928:tid 797173] [client 158.173.89.95:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OS-sTy9vX-htKvPn6IAAAAww"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:19.395323 2026] [security2:error] [pid 796928:tid 797096] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6EQAAAr8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:19.402937 2026] [security2:error] [pid 796567:tid 796590] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY6wACaxY"]
[Mon Jul 20 06:02:19.403103 2026] [security2:error] [pid 796567:tid 796784] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY6wACaxY"]
[Mon Jul 20 06:02:19.467767 2026] [security2:error] [pid 796928:tid 796968] [remote 173.249.4.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4OS-sTy9vX-htKvPn6JAACnic"]
[Mon Jul 20 06:02:19.483238 2026] [security2:error] [pid 796928:tid 797084] [client 74.7.227.179:39166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6GwACsyU"], referer: https://tejasenvironmental.com/p=474663
[Mon Jul 20 06:02:19.523241 2026] [security2:error] [pid 796567:tid 796804] [client 112.213.160.112:30732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY8wAAAn8"]
[Mon Jul 20 06:02:19.523384 2026] [security2:error] [pid 796567:tid 796804] [client 112.213.160.112:30732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY8wAAAn8"]
[Mon Jul 20 06:02:19.780949 2026] [security2:error] [pid 796928:tid 797081] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6KwAAArA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:19.880255 2026] [security2:error] [pid 796928:tid 796972] [remote 173.249.4.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4OS-sTy9vX-htKvPn6PAACvSs"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 06:02:20.019029 2026] [security2:error] [pid 796567:tid 796808] [client 82.102.18.116:58772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4OTLLfyzVz2SrjZpiZDAAAAoM"]
[Mon Jul 20 06:02:20.313114 2026] [security2:error] [pid 796928:tid 797097] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6PgAAAsA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:20.414843 2026] [security2:error] [pid 796567:tid 796701] [client 150.228.148.150:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OTLLfyzVz2SrjZpiZJwAAAhg"]
[Mon Jul 20 06:02:20.429152 2026] [security2:error] [pid 796567:tid 796701] [client 150.228.148.150:19279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OTLLfyzVz2SrjZpiZJwAAAhg"]
[Mon Jul 20 06:02:20.464367 2026] [security2:error] [pid 796928:tid 796973] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ardhalwafa.com"] [uri "/.well-known/about.php"] [unique_id "al4OTOsTy9vX-htKvPn6WgADCSw"]
[Mon Jul 20 06:02:20.464782 2026] [security2:error] [pid 796928:tid 797170] [client 20.220.225.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ardhalwafa.com"] [uri "/.well-known/about.php"] [unique_id "al4OTOsTy9vX-htKvPn6WgADCSw"]
[Mon Jul 20 06:02:20.579077 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.43:30868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OR7LfyzVz2SrjZpiYJAACNTM"]
[Mon Jul 20 06:02:20.660966 2026] [security2:error] [pid 796928:tid 797126] [client 82.102.18.116:58776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "al4OTOsTy9vX-htKvPn6YQAAAt0"]
[Mon Jul 20 06:02:20.708742 2026] [security2:error] [pid 796928:tid 797093] [client 185.132.186.93:28971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "al4OTOsTy9vX-htKvPn6ZQAAArw"]
[Mon Jul 20 06:02:20.759039 2026] [security2:error] [pid 796928:tid 797111] [client 173.239.240.6:25001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bnb-engineering.com"] [uri "/wp-login.php"] [unique_id "al4OTOsTy9vX-htKvPn6ZgAAAs4"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:02:20.785878 2026] [security2:error] [pid 796567:tid 796813] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OTLLfyzVz2SrjZpiZMQAAAog"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:20.879520 2026] [security2:error] [pid 796567:tid 796656] [remote 124.55.178.99:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4OTLLfyzVz2SrjZpiZPQACMFg"]
[Mon Jul 20 06:02:20.896047 2026] [security2:error] [pid 796928:tid 797124] [client 103.95.123.246:19325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OTOsTy9vX-htKvPn6aAAAAts"]
[Mon Jul 20 06:02:20.896737 2026] [security2:error] [pid 796928:tid 797124] [client 103.95.123.246:19325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OTOsTy9vX-htKvPn6aAAAAts"]
[Mon Jul 20 06:02:20.982885 2026] [security2:error] [pid 796928:tid 797156] [client 14.225.17.146:58891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4OSesTy9vX-htKvPn5yAAAAvs"], referer: http://gearwaterproof.com/wordpress
[Mon Jul 20 06:02:21.329894 2026] [security2:error] [pid 796567:tid 796667] [remote 124.55.178.99:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4OTbLfyzVz2SrjZpiZUwACI2M"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:02:21.337648 2026] [security2:error] [pid 796567:tid 796732] [client 82.102.18.116:58790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4OTbLfyzVz2SrjZpiZVAAAAjc"]
[Mon Jul 20 06:02:21.378393 2026] [security2:error] [pid 796928:tid 797103] [client 106.192.104.4:52993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6fQAAAsY"]
[Mon Jul 20 06:02:21.387565 2026] [security2:error] [pid 796928:tid 797103] [client 106.192.104.4:52993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6fQAAAsY"]
[Mon Jul 20 06:02:21.443287 2026] [security2:error] [pid 796928:tid 796979] [remote 199.189.225.40:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OTesTy9vX-htKvPn6fwACwDI"]
[Mon Jul 20 06:02:21.494781 2026] [proxy:error] [pid 796928:tid 797069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:21.494843 2026] [proxy_http:error] [pid 796928:tid 797069] [client 198.235.24.28:60148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:21.496047 2026] [proxy:error] [pid 796928:tid 797069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:21.496103 2026] [proxy_http:error] [pid 796928:tid 797069] [client 198.235.24.28:60148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:21.837426 2026] [security2:error] [pid 796928:tid 797061] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reydelcalentador.com"] [uri "/wp-admin/install.php"] [unique_id "al4OTesTy9vX-htKvPn6lwAAApw"]
[Mon Jul 20 06:02:21.926232 2026] [security2:error] [pid 796928:tid 796982] [remote 199.189.225.40:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OTesTy9vX-htKvPn6nQADAjU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:02:21.991228 2026] [security2:error] [pid 796928:tid 796983] [remote 173.212.252.15:42070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6oAACwjY"]
[Mon Jul 20 06:02:21.991599 2026] [security2:error] [pid 796928:tid 797099] [client 173.212.252.15:42070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6oAACwjY"]
[Mon Jul 20 06:02:21.997405 2026] [security2:error] [pid 796928:tid 797140] [client 82.102.18.116:58794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "al4OTesTy9vX-htKvPn6oQAAAus"]
[Mon Jul 20 06:02:22.348721 2026] [security2:error] [pid 796928:tid 797113] [client 14.225.17.146:52955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4OTOsTy9vX-htKvPn6UwAAAtA"], referer: http://margaretspeckogawa.com/wordpress
[Mon Jul 20 06:02:22.353265 2026] [security2:error] [pid 796928:tid 797130] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylg.kng.mybluehost.me"] [uri "/wp-admin/install.php"] [unique_id "al4OTusTy9vX-htKvPn6sAAC4To"]
[Mon Jul 20 06:02:22.459583 2026] [security2:error] [pid 796928:tid 797146] [client 14.225.17.146:52935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4OTOsTy9vX-htKvPn6SQAAAvE"], referer: http://narv.co/wordpress
[Mon Jul 20 06:02:22.657362 2026] [security2:error] [pid 796928:tid 797071] [client 18.228.171.129:11954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6vgAAAqY"]
[Mon Jul 20 06:02:22.657471 2026] [security2:error] [pid 796928:tid 797071] [client 18.228.171.129:11954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6vgAAAqY"]
[Mon Jul 20 06:02:22.659187 2026] [security2:error] [pid 796567:tid 796730] [client 185.132.186.87:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/mar.php"] [unique_id "al4OTrLfyzVz2SrjZpiZlAAAAjU"]
[Mon Jul 20 06:02:22.686461 2026] [security2:error] [pid 796567:tid 796811] [client 82.102.18.116:58806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4OTrLfyzVz2SrjZpiZlQAAAoY"]
[Mon Jul 20 06:02:22.922576 2026] [security2:error] [pid 796928:tid 797179] [client 115.246.21.170:20601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ygAAAxI"]
[Mon Jul 20 06:02:22.922780 2026] [security2:error] [pid 796928:tid 797179] [client 115.246.21.170:20601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ygAAAxI"]
[Mon Jul 20 06:02:22.964643 2026] [security2:error] [pid 796928:tid 796993] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ywAC60A"]
[Mon Jul 20 06:02:22.964906 2026] [security2:error] [pid 796928:tid 797140] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ywAC60A"]
[Mon Jul 20 06:02:23.005112 2026] [security2:error] [pid 796567:tid 796764] [client 103.153.183.69:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//var/www/html/config.php"] [unique_id "al4OT7LfyzVz2SrjZpiZrwAAAlc"], referer: https://www.reddit.com/
[Mon Jul 20 06:02:23.037835 2026] [security2:error] [pid 796567:tid 796638] [remote 162.19.86.63:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OT7LfyzVz2SrjZpiZsQACR0Y"]
[Mon Jul 20 06:02:23.043337 2026] [security2:error] [pid 796928:tid 797062] [client 14.225.17.146:58405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4OTusTy9vX-htKvPn6wgAAAp0"], referer: http://sesamegreenbeans.com/wordpress
[Mon Jul 20 06:02:23.183629 2026] [security2:error] [pid 796567:tid 796732] [client 47.31.86.100:54339] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZuAAAAjc"]
[Mon Jul 20 06:02:23.183811 2026] [security2:error] [pid 796567:tid 796732] [client 47.31.86.100:54339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZuAAAAjc"]
[Mon Jul 20 06:02:23.247068 2026] [security2:error] [pid 796567:tid 796632] [remote 162.19.86.63:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OT7LfyzVz2SrjZpiZvAACOUA"], referer: https://narv.co/wp-login.php
[Mon Jul 20 06:02:23.321268 2026] [security2:error] [pid 796567:tid 796718] [client 82.102.18.116:58810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4OT7LfyzVz2SrjZpiZwgAAAik"]
[Mon Jul 20 06:02:23.391311 2026] [security2:error] [pid 796567:tid 796747] [client 74.208.214.194:41142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OT7LfyzVz2SrjZpiZzAAAAkY"]
[Mon Jul 20 06:02:23.465604 2026] [security2:error] [pid 796567:tid 796589] [remote 179.162.94.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.94.162.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZzwAChBU"]
[Mon Jul 20 06:02:23.465845 2026] [security2:error] [pid 796567:tid 796809] [client 179.162.94.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZzwAChBU"]
[Mon Jul 20 06:02:23.483286 2026] [security2:error] [pid 796928:tid 796996] [remote 124.55.178.99:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4OT-sTy9vX-htKvPn62gAC1kM"]
[Mon Jul 20 06:02:23.536058 2026] [security2:error] [pid 796928:tid 797123] [client 14.225.17.146:61689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4OT-sTy9vX-htKvPn61wAAAto"], referer: https://narv.co/wordpress
[Mon Jul 20 06:02:23.888366 2026] [security2:error] [pid 796928:tid 797000] [remote 124.55.178.99:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4OT-sTy9vX-htKvPn67QACpkc"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:02:23.952701 2026] [security2:error] [pid 796567:tid 796777] [client 77.110.127.138:54511] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/"] [unique_id "al4OT7LfyzVz2SrjZpiZ3QAAAmQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:23.954144 2026] [security2:error] [pid 796928:tid 797076] [client 82.102.18.116:58820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4OT-sTy9vX-htKvPn68gAAAqs"]
[Mon Jul 20 06:02:23.997034 2026] [security2:error] [pid 796567:tid 796813] [client 14.225.17.146:61449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4OT7LfyzVz2SrjZpiZywAAAog"]
[Mon Jul 20 06:02:24.004205 2026] [proxy:error] [pid 796928:tid 797092] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:24.004277 2026] [proxy_http:error] [pid 796928:tid 797092] [client 87.236.176.17:38139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:24.004993 2026] [proxy:error] [pid 796928:tid 797092] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:24.005025 2026] [proxy_http:error] [pid 796928:tid 797092] [client 87.236.176.17:38139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:24.156968 2026] [security2:error] [pid 796928:tid 797147] [client 14.225.17.146:54910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4OT-sTy9vX-htKvPn68AAAAvI"], referer: https://sesamegreenbeans.com/wordpress
[Mon Jul 20 06:02:24.372253 2026] [security2:error] [pid 796567:tid 796780] [client 129.222.187.209:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OULLfyzVz2SrjZpiZ8gAAAmc"]
[Mon Jul 20 06:02:24.372413 2026] [security2:error] [pid 796567:tid 796780] [client 129.222.187.209:62001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OULLfyzVz2SrjZpiZ8gAAAmc"]
[Mon Jul 20 06:02:24.387907 2026] [security2:error] [pid 796928:tid 797064] [client 45.61.188.240:49291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "learnthissecret.com"] [uri "/"] [unique_id "al4OUOsTy9vX-htKvPn7BgAAAp8"]
[Mon Jul 20 06:02:24.552410 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OUOsTy9vX-htKvPn7BAAAAtg"], referer: https://mezzacraft.com/crochet-meetups/
[Mon Jul 20 06:02:24.615577 2026] [security2:error] [pid 796928:tid 797151] [client 185.132.186.80:53039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "al4OUOsTy9vX-htKvPn7EwAAAvY"]
[Mon Jul 20 06:02:24.636884 2026] [security2:error] [pid 796928:tid 797060] [client 82.102.18.116:58828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4OUOsTy9vX-htKvPn7FAAAAps"]
[Mon Jul 20 06:02:24.652965 2026] [security2:error] [pid 796567:tid 796778] [client 45.61.188.240:49322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "learnthissecret.com"] [uri "/"] [unique_id "al4OULLfyzVz2SrjZpiaAgAAAmU"]
[Mon Jul 20 06:02:24.789279 2026] [core:error] [pid 796567:tid 796808] [client 144.217.135.187:39189] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:24.789301 2026] [core:error] [pid 796567:tid 796808] [client 144.217.135.187:39189] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:25.019216 2026] [security2:error] [pid 796928:tid 797007] [remote 160.187.68.132:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4OUesTy9vX-htKvPn7HwAC-U4"]
[Mon Jul 20 06:02:25.023673 2026] [security2:error] [pid 796928:tid 797006] [remote 47.86.33.52:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4OUOsTy9vX-htKvPn7HgAC_00"]
[Mon Jul 20 06:02:25.060313 2026] [security2:error] [pid 796567:tid 796713] [client 57.141.18.28:30214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OTLLfyzVz2SrjZpiZHAACJCI"]
[Mon Jul 20 06:02:25.196209 2026] [security2:error] [pid 796567:tid 796792] [client 41.173.37.102:7169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaHgAAAnM"]
[Mon Jul 20 06:02:25.196324 2026] [security2:error] [pid 796567:tid 796792] [client 41.173.37.102:7169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaHgAAAnM"]
[Mon Jul 20 06:02:25.208944 2026] [security2:error] [pid 796567:tid 796816] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OUbLfyzVz2SrjZpiaGgAAAos"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:25.316785 2026] [security2:error] [pid 796928:tid 797183] [client 82.102.18.116:58830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4OUesTy9vX-htKvPn7JQAAAxY"]
[Mon Jul 20 06:02:25.359453 2026] [security2:error] [pid 796567:tid 796703] [client 46.110.96.34:55645] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OUbLfyzVz2SrjZpiaJAAAAho"]
[Mon Jul 20 06:02:25.470834 2026] [security2:error] [pid 796928:tid 797010] [remote 160.187.68.132:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4OUesTy9vX-htKvPn7LQAC9FE"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:02:25.644689 2026] [security2:error] [pid 796928:tid 797158] [client 27.96.94.195:37644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6twAAAv0"]
[Mon Jul 20 06:02:25.645436 2026] [security2:error] [pid 796567:tid 796800] [client 50.116.65.227:40428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OUbLfyzVz2SrjZpiaNgAAAns"]
[Mon Jul 20 06:02:25.657417 2026] [security2:error] [pid 796928:tid 797103] [client 50.116.65.227:40444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OUesTy9vX-htKvPn7MgAAAsY"]
[Mon Jul 20 06:02:25.747074 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:30330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaPQAAAhw"]
[Mon Jul 20 06:02:25.747182 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:30330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaPQAAAhw"]
[Mon Jul 20 06:02:25.965235 2026] [security2:error] [pid 796567:tid 796669] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaRwACL2U"]
[Mon Jul 20 06:02:25.965447 2026] [security2:error] [pid 796567:tid 796724] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaRwACL2U"]
[Mon Jul 20 06:02:25.986075 2026] [security2:error] [pid 796928:tid 797098] [client 82.102.18.116:58840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "al4OUesTy9vX-htKvPn7PwAAAsE"]
[Mon Jul 20 06:02:26.329609 2026] [security2:error] [pid 796928:tid 797142] [client 146.75.146.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4OUesTy9vX-htKvPn7NQAAAu0"]
[Mon Jul 20 06:02:26.553603 2026] [security2:error] [pid 796567:tid 796784] [client 185.132.186.104:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al4OUrLfyzVz2SrjZpiaYAAAAms"]
[Mon Jul 20 06:02:26.576468 2026] [security2:error] [pid 796567:tid 796795] [client 210.212.97.243:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OUrLfyzVz2SrjZpiaYQAAAnY"]
[Mon Jul 20 06:02:26.576586 2026] [security2:error] [pid 796567:tid 796795] [client 210.212.97.243:10426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OUrLfyzVz2SrjZpiaYQAAAnY"]
[Mon Jul 20 06:02:26.663772 2026] [security2:error] [pid 796928:tid 797148] [client 82.102.18.116:58842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4OUusTy9vX-htKvPn7WAAAAvM"]
[Mon Jul 20 06:02:26.751642 2026] [security2:error] [pid 796928:tid 797093] [client 103.149.16.77:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OUusTy9vX-htKvPn7XgAAArw"]
[Mon Jul 20 06:02:26.751767 2026] [security2:error] [pid 796928:tid 797093] [client 103.149.16.77:59301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OUusTy9vX-htKvPn7XgAAArw"]
[Mon Jul 20 06:02:26.762226 2026] [security2:error] [pid 796928:tid 797019] [remote 8.217.108.67:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circafabrication.com"] [uri "/wp-login.php"] [unique_id "al4OUusTy9vX-htKvPn7XQAC6Fo"], referer: https://circafabrication.com/wp-login.php
[Mon Jul 20 06:02:26.874629 2026] [security2:error] [pid 796567:tid 796579] [remote 198.46.152.106:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4OUrLfyzVz2SrjZpiaawACMAs"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:02:27.040207 2026] [security2:error] [pid 796928:tid 797079] [client 57.141.18.119:48150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OTusTy9vX-htKvPn6vAACrj0"]
[Mon Jul 20 06:02:27.290205 2026] [security2:error] [pid 796928:tid 797074] [client 82.102.18.116:58848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4OU-sTy9vX-htKvPn7eAAAAqk"]
[Mon Jul 20 06:02:27.433818 2026] [security2:error] [pid 796928:tid 797124] [client 164.100.212.184:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OU-sTy9vX-htKvPn7ggAAAts"]
[Mon Jul 20 06:02:27.433930 2026] [security2:error] [pid 796928:tid 797124] [client 164.100.212.184:51981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OU-sTy9vX-htKvPn7ggAAAts"]
[Mon Jul 20 06:02:27.680012 2026] [security2:error] [pid 796928:tid 797026] [remote 212.95.34.85:13856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OU-sTy9vX-htKvPn7lAADD2E"]
[Mon Jul 20 06:02:27.868894 2026] [security2:error] [pid 796567:tid 796724] [client 181.224.94.124:20289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OU7LfyzVz2SrjZpiajwAAAi8"]
[Mon Jul 20 06:02:27.869027 2026] [security2:error] [pid 796567:tid 796724] [client 181.224.94.124:20289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OU7LfyzVz2SrjZpiajwAAAi8"]
[Mon Jul 20 06:02:27.876085 2026] [security2:error] [pid 796928:tid 797027] [remote 212.95.34.85:13856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OU-sTy9vX-htKvPn7mgAC02I"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:02:27.931973 2026] [security2:error] [pid 796567:tid 796719] [client 77.110.127.138:54508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/"] [unique_id "al4OU7LfyzVz2SrjZpiakQAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:27.965371 2026] [security2:error] [pid 796928:tid 797058] [client 82.102.18.116:58856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4OU-sTy9vX-htKvPn7nQAAApk"]
[Mon Jul 20 06:02:28.067345 2026] [security2:error] [pid 796928:tid 797028] [remote 91.142.222.105:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OVOsTy9vX-htKvPn7pAAC9GM"]
[Mon Jul 20 06:02:28.133056 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:55350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OVOsTy9vX-htKvPn7pgAAAuw"]
[Mon Jul 20 06:02:28.138027 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:55350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OVOsTy9vX-htKvPn7pgAAAuw"]
[Mon Jul 20 06:02:28.342627 2026] [security2:error] [pid 796928:tid 797032] [remote 91.142.222.105:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OVOsTy9vX-htKvPn7rQACuGc"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:02:28.373149 2026] [security2:error] [pid 796928:tid 797033] [remote 47.86.33.52:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4OVOsTy9vX-htKvPn7rgAC8mg"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:02:28.509580 2026] [security2:error] [pid 796928:tid 797122] [client 158.173.166.181:27809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OVOsTy9vX-htKvPn7tAAAAtk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:28.590183 2026] [security2:error] [pid 796928:tid 797100] [client 14.225.17.146:64042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4OUusTy9vX-htKvPn7RAAAAsM"], referer: http://aandarealtygroup.com/wordpress
[Mon Jul 20 06:02:28.603118 2026] [security2:error] [pid 796567:tid 796723] [client 82.102.18.116:53714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4OVLLfyzVz2SrjZpiatwAAAi4"]
[Mon Jul 20 06:02:28.909353 2026] [security2:error] [pid 796567:tid 796710] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OVLLfyzVz2SrjZpiavQAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:29.032322 2026] [security2:error] [pid 796567:tid 796803] [client 185.132.186.104:37423] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/1.php"] [unique_id "al4OVbLfyzVz2SrjZpiaywAAAn4"]
[Mon Jul 20 06:02:29.032446 2026] [security2:error] [pid 796567:tid 796803] [client 185.132.186.104:37423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/1.php"] [unique_id "al4OVbLfyzVz2SrjZpiaywAAAn4"]
[Mon Jul 20 06:02:29.096524 2026] [security2:error] [pid 796567:tid 796727] [client 14.225.17.146:53813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OU7LfyzVz2SrjZpiahwAAAjI"], referer: http://effingweirdmuseums.com/wordpress
[Mon Jul 20 06:02:29.256111 2026] [security2:error] [pid 796567:tid 796745] [client 144.124.196.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4OVLLfyzVz2SrjZpiaxgAAAkQ"]
[Mon Jul 20 06:02:29.701068 2026] [security2:error] [pid 796567:tid 796781] [client 114.119.142.207:62767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "verdunestate.com"] [uri "/lebanon-beirut/propertyDetail.asp"] [unique_id "al4OVbLfyzVz2SrjZpia6AAAAmg"], referer: http://verdunestate.com/lebanon-beirut/property.asp?p=15®ion&area&ListingtypeID&PropertytypeID
[Mon Jul 20 06:02:30.024729 2026] [security2:error] [pid 796567:tid 796728] [client 14.225.17.146:61500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OVbLfyzVz2SrjZpia7QAAAjM"], referer: https://effingweirdmuseums.com/wordpress
[Mon Jul 20 06:02:30.068058 2026] [security2:error] [pid 796928:tid 797041] [remote 5.161.225.162:53694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn79AACuXA"]
[Mon Jul 20 06:02:30.097902 2026] [security2:error] [pid 796928:tid 797152] [client 72.255.10.154:26256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn79wAAAvc"]
[Mon Jul 20 06:02:30.098018 2026] [security2:error] [pid 796928:tid 797152] [client 72.255.10.154:26256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn79wAAAvc"]
[Mon Jul 20 06:02:30.196223 2026] [security2:error] [pid 796567:tid 796704] [client 112.213.160.112:31163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OVrLfyzVz2SrjZpia_AAAAhs"]
[Mon Jul 20 06:02:30.196413 2026] [security2:error] [pid 796567:tid 796704] [client 112.213.160.112:31163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OVrLfyzVz2SrjZpia_AAAAhs"]
[Mon Jul 20 06:02:30.262319 2026] [security2:error] [pid 796928:tid 797042] [remote 5.161.225.162:53694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn7_AAC9HE"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:02:30.350891 2026] [security2:error] [pid 796928:tid 797077] [client 3.77.67.4:31894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4OVusTy9vX-htKvPn7-wAAAqw"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:02:30.723687 2026] [security2:error] [pid 796928:tid 797047] [remote 167.233.114.32:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn8DAAC_nY"]
[Mon Jul 20 06:02:30.905173 2026] [security2:error] [pid 796928:tid 797049] [remote 167.233.114.32:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn8FAACw3g"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:02:30.933095 2026] [security2:error] [pid 796928:tid 797110] [client 150.228.148.150:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn8FQAAAs0"]
[Mon Jul 20 06:02:30.933248 2026] [security2:error] [pid 796928:tid 797110] [client 150.228.148.150:14324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn8FQAAAs0"]
[Mon Jul 20 06:02:30.990876 2026] [security2:error] [pid 796928:tid 797072] [client 185.132.186.83:26041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Engine/index.php"] [unique_id "al4OVusTy9vX-htKvPn8FgAAAqc"]
[Mon Jul 20 06:02:31.265593 2026] [security2:error] [pid 796567:tid 796701] [client 179.0.122.163:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.122.0.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OV7LfyzVz2SrjZpibKgAAAhg"]
[Mon Jul 20 06:02:31.265772 2026] [security2:error] [pid 796567:tid 796701] [client 179.0.122.163:21813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OV7LfyzVz2SrjZpibKgAAAhg"]
[Mon Jul 20 06:02:31.451260 2026] [security2:error] [pid 796567:tid 796728] [client 77.110.127.138:54508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/"] [unique_id "al4OV7LfyzVz2SrjZpibLQAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:31.670659 2026] [security2:error] [pid 796928:tid 796936] [remote 95.217.78.234:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OV-sTy9vX-htKvPn8OwACmwc"]
[Mon Jul 20 06:02:31.674861 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:50492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4OV-sTy9vX-htKvPn8OAAAAvU"], referer: http://katsklar.com/wordpress
[Mon Jul 20 06:02:31.900508 2026] [security2:error] [pid 796928:tid 796939] [remote 95.217.78.234:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OV-sTy9vX-htKvPn8QwADFwo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:02:32.150686 2026] [security2:error] [pid 796928:tid 797157] [client 74.208.214.194:38550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OWOsTy9vX-htKvPn8TgAAAvw"]
[Mon Jul 20 06:02:32.160421 2026] [security2:error] [pid 796928:tid 797173] [client 27.96.94.195:37913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OWOsTy9vX-htKvPn8RgAAAww"]
[Mon Jul 20 06:02:32.225837 2026] [security2:error] [pid 796567:tid 796717] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OWLLfyzVz2SrjZpibRAAAAig"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:32.463520 2026] [security2:error] [pid 796567:tid 796735] [client 57.141.18.46:43338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OU7LfyzVz2SrjZpiakAACOnA"]
[Mon Jul 20 06:02:32.468194 2026] [security2:error] [pid 796567:tid 796581] [remote 45.90.123.233:44790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4OWLLfyzVz2SrjZpibXgACNA0"]
[Mon Jul 20 06:02:32.468348 2026] [security2:error] [pid 796567:tid 796729] [client 45.90.123.233:44790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4OWLLfyzVz2SrjZpibXgACNA0"]
[Mon Jul 20 06:02:32.567919 2026] [security2:error] [pid 796928:tid 797068] [client 103.95.123.246:19829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OWOsTy9vX-htKvPn8VQAAAqM"]
[Mon Jul 20 06:02:32.568116 2026] [security2:error] [pid 796928:tid 797068] [client 103.95.123.246:19829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OWOsTy9vX-htKvPn8VQAAAqM"]
[Mon Jul 20 06:02:32.733519 2026] [security2:error] [pid 796928:tid 797149] [client 13.219.54.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OWOsTy9vX-htKvPn8VgAC9A4"]
[Mon Jul 20 06:02:32.813265 2026] [security2:error] [pid 796928:tid 796948] [remote 45.90.123.233:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4OWOsTy9vX-htKvPn8YwADAxM"]
[Mon Jul 20 06:02:32.940444 2026] [security2:error] [pid 796928:tid 797063] [client 185.132.186.57:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/index.php"] [unique_id "al4OWOsTy9vX-htKvPn8agAAAp4"]
[Mon Jul 20 06:02:33.006849 2026] [security2:error] [pid 796928:tid 796947] [remote 45.90.123.233:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4OWesTy9vX-htKvPn8bQAC-RI"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:02:33.314221 2026] [security2:error] [pid 796567:tid 796686] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibgwACi3Y"]
[Mon Jul 20 06:02:33.314332 2026] [security2:error] [pid 796567:tid 796816] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibgwACi3Y"]
[Mon Jul 20 06:02:33.346206 2026] [security2:error] [pid 796928:tid 797067] [client 18.228.171.129:23322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8eAAAAqI"]
[Mon Jul 20 06:02:33.346327 2026] [security2:error] [pid 796928:tid 797067] [client 18.228.171.129:23322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8eAAAAqI"]
[Mon Jul 20 06:02:33.536302 2026] [security2:error] [pid 796567:tid 796692] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibjwACh3w"]
[Mon Jul 20 06:02:33.536478 2026] [security2:error] [pid 796567:tid 796812] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibjwACh3w"]
[Mon Jul 20 06:02:33.563744 2026] [security2:error] [pid 796928:tid 797147] [client 115.246.21.170:17041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fQAAAvI"]
[Mon Jul 20 06:02:33.563923 2026] [security2:error] [pid 796928:tid 797147] [client 115.246.21.170:17041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fQAAAvI"]
[Mon Jul 20 06:02:33.650444 2026] [security2:error] [pid 796567:tid 796608] [remote 57.141.18.42:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6065685"] [unique_id "al4OWbLfyzVz2SrjZpibkgACIig"]
[Mon Jul 20 06:02:33.671833 2026] [security2:error] [pid 796928:tid 797183] [client 106.192.104.4:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fgAAAxY"]
[Mon Jul 20 06:02:33.672008 2026] [security2:error] [pid 796928:tid 797183] [client 106.192.104.4:53541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fgAAAxY"]
[Mon Jul 20 06:02:33.727424 2026] [security2:error] [pid 796928:tid 797167] [client 47.31.86.100:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fwAAAwY"]
[Mon Jul 20 06:02:33.727564 2026] [security2:error] [pid 796928:tid 797167] [client 47.31.86.100:54769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fwAAAwY"]
[Mon Jul 20 06:02:33.885075 2026] [security2:error] [pid 796567:tid 796745] [client 193.19.109.222:40073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4OWbLfyzVz2SrjZpibowAAAkQ"]
[Mon Jul 20 06:02:34.063995 2026] [security2:error] [pid 796928:tid 796933] [remote 217.61.143.92:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4OWusTy9vX-htKvPn8igACowQ"]
[Mon Jul 20 06:02:34.289925 2026] [security2:error] [pid 796928:tid 796963] [remote 217.61.143.92:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4OWusTy9vX-htKvPn8lgAC0SI"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:02:34.463209 2026] [security2:error] [pid 796928:tid 796962] [remote 57.141.18.34:40496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3053148"] [unique_id "al4OWusTy9vX-htKvPn8mQADCCE"]
[Mon Jul 20 06:02:34.493825 2026] [security2:error] [pid 796928:tid 797153] [client 14.251.3.155:55567] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OWusTy9vX-htKvPn8nAAAAvg"]
[Mon Jul 20 06:02:34.599318 2026] [security2:error] [pid 796567:tid 796700] [client 50.116.65.227:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OWrLfyzVz2SrjZpibxwAAAhc"]
[Mon Jul 20 06:02:34.610605 2026] [security2:error] [pid 796567:tid 796816] [client 50.116.65.227:38092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OWrLfyzVz2SrjZpibyQAAAos"]
[Mon Jul 20 06:02:34.843202 2026] [security2:error] [pid 796928:tid 797067] [client 14.251.3.155:50771] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OWusTy9vX-htKvPn8ogAAAqI"]
[Mon Jul 20 06:02:34.999132 2026] [security2:error] [pid 796567:tid 796743] [client 129.222.187.209:34314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OWrLfyzVz2SrjZpib2AAAAkI"]
[Mon Jul 20 06:02:35.009376 2026] [security2:error] [pid 796567:tid 796743] [client 129.222.187.209:34314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OWrLfyzVz2SrjZpib2AAAAkI"]
[Mon Jul 20 06:02:35.285193 2026] [security2:error] [pid 796567:tid 796726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OWrLfyzVz2SrjZpib1gAAAjE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:35.456115 2026] [security2:error] [pid 796928:tid 797175] [client 185.132.186.81:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/fm.php"] [unique_id "al4OW-sTy9vX-htKvPn8ugAAAw4"]
[Mon Jul 20 06:02:35.483098 2026] [security2:error] [pid 796928:tid 797099] [client 193.19.109.218:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OW-sTy9vX-htKvPn8vQAAAsI"]
[Mon Jul 20 06:02:35.516735 2026] [security2:error] [pid 796928:tid 797149] [client 193.19.109.238:47319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OW-sTy9vX-htKvPn8wQAAAvQ"]
[Mon Jul 20 06:02:35.547453 2026] [security2:error] [pid 796928:tid 797087] [client 193.37.33.1:60817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OW-sTy9vX-htKvPn8xAAAArY"]
[Mon Jul 20 06:02:35.793449 2026] [security2:error] [pid 796928:tid 797131] [client 178.152.178.232:36053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zQAAAuI"]
[Mon Jul 20 06:02:35.793664 2026] [security2:error] [pid 796928:tid 797131] [client 178.152.178.232:36053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zQAAAuI"]
[Mon Jul 20 06:02:35.804323 2026] [autoindex:error] [pid 796928:tid 797124] [client 14.225.17.146:62179] AH01276: Cannot serve directory /home1/amaliaca/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://amalia-capital.com/wordpress
[Mon Jul 20 06:02:35.804689 2026] [security2:error] [pid 796928:tid 797142] [client 41.173.37.102:7615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zwAAAu0"]
[Mon Jul 20 06:02:35.804823 2026] [security2:error] [pid 796928:tid 797142] [client 41.173.37.102:7615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zwAAAu0"]
[Mon Jul 20 06:02:36.017507 2026] [security2:error] [pid 796928:tid 797139] [client 14.225.17.146:52807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4OWusTy9vX-htKvPn8kgAAAuo"], referer: http://nomorewetsheets.net/wordpress
[Mon Jul 20 06:02:36.111349 2026] [security2:error] [pid 796567:tid 796818] [client 14.225.17.146:57611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4OWrLfyzVz2SrjZpibwwAAAo0"], referer: http://chestermonty.com/wordpress
[Mon Jul 20 06:02:36.535614 2026] [security2:error] [pid 796928:tid 796971] [remote 124.55.178.99:36076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OXOsTy9vX-htKvPn88AAC-io"]
[Mon Jul 20 06:02:36.535819 2026] [security2:error] [pid 796928:tid 797155] [client 124.55.178.99:36076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OXOsTy9vX-htKvPn88AAC-io"]
[Mon Jul 20 06:02:36.551009 2026] [lsapi:warn] [pid 796928:tid 797150] [client 14.225.17.146:57495] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:36.551038 2026] [lsapi:warn] [pid 796928:tid 797150] [client 14.225.17.146:57495] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:36.553667 2026] [security2:error] [pid 796567:tid 796572] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicBwACbwQ"]
[Mon Jul 20 06:02:36.553874 2026] [security2:error] [pid 796567:tid 796788] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicBwACbwQ"]
[Mon Jul 20 06:02:36.751947 2026] [security2:error] [pid 796928:tid 796972] [remote 152.228.213.32:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4OXOsTy9vX-htKvPn89AACtis"]
[Mon Jul 20 06:02:36.765641 2026] [security2:error] [pid 796567:tid 796796] [client 65.1.132.125:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicCgAAAnc"]
[Mon Jul 20 06:02:36.765792 2026] [security2:error] [pid 796567:tid 796796] [client 65.1.132.125:19926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicCgAAAnc"]
[Mon Jul 20 06:02:36.894423 2026] [security2:error] [pid 796928:tid 797122] [client 57.141.18.47:44424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OV-sTy9vX-htKvPn8QgAC2QY"]
[Mon Jul 20 06:02:37.030353 2026] [security2:error] [pid 796567:tid 796712] [client 114.119.129.107:60877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hoomanr.com"] [uri "/web/handbook/handbook4.jpg"] [unique_id "al4OXbLfyzVz2SrjZpicGAAAAiM"], referer: http://hoomanr.com/web/handbook/handbook4.jpg
[Mon Jul 20 06:02:37.064420 2026] [security2:error] [pid 796567:tid 796661] [remote 124.55.178.99:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OXbLfyzVz2SrjZpicGgACHF0"]
[Mon Jul 20 06:02:37.092356 2026] [security2:error] [pid 796928:tid 797140] [client 210.212.97.243:10427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OXesTy9vX-htKvPn9AAAAAus"]
[Mon Jul 20 06:02:37.092541 2026] [security2:error] [pid 796928:tid 797140] [client 210.212.97.243:10427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OXesTy9vX-htKvPn9AAAAAus"]
[Mon Jul 20 06:02:37.110447 2026] [lsapi:warn] [pid 796567:tid 796707] [client 50.116.65.227:38136] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:02:37.110475 2026] [lsapi:warn] [pid 796567:tid 796707] [client 50.116.65.227:38136] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:02:37.124902 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:57495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4OXOsTy9vX-htKvPn82gAAAvU"], referer: http://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:37.127078 2026] [security2:error] [pid 796928:tid 797092] [client 14.225.17.146:64861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4OXesTy9vX-htKvPn8-gAAArs"], referer: https://chestermonty.com/wordpress
[Mon Jul 20 06:02:37.207579 2026] [security2:error] [pid 796928:tid 796974] [remote 152.228.213.32:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4OXesTy9vX-htKvPn9AQAC0i0"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:02:37.326363 2026] [security2:error] [pid 796567:tid 796766] [client 103.149.16.77:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OXbLfyzVz2SrjZpicIwAAAlk"]
[Mon Jul 20 06:02:37.326471 2026] [security2:error] [pid 796567:tid 796766] [client 103.149.16.77:59793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OXbLfyzVz2SrjZpicIwAAAlk"]
[Mon Jul 20 06:02:37.395292 2026] [security2:error] [pid 796928:tid 797132] [client 185.132.186.72:36773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/index.php"] [unique_id "al4OXesTy9vX-htKvPn9CwAAAuM"]
[Mon Jul 20 06:02:37.456666 2026] [security2:error] [pid 796928:tid 797069] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OXesTy9vX-htKvPn9BQAAAqQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:37.482009 2026] [security2:error] [pid 796567:tid 796634] [remote 124.55.178.99:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OXbLfyzVz2SrjZpicKgACOUI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:02:37.970439 2026] [security2:error] [pid 796928:tid 797159] [client 47.128.112.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.benbayly.co.nz"] [uri "/index.php"] [unique_id "al4OXOsTy9vX-htKvPn89QAC_gU"]
[Mon Jul 20 06:02:37.998919 2026] [security2:error] [pid 796928:tid 797156] [client 114.119.140.50:36465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villa-m-medjugorje.com"] [uri "/terms-conditions/"] [unique_id "al4OXesTy9vX-htKvPn9FAAAAvs"], referer: https://villa-m-medjugorje.com/booking-confirmation/booking-canceled/
[Mon Jul 20 06:02:38.017929 2026] [security2:error] [pid 796928:tid 797099] [client 164.100.212.184:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OXusTy9vX-htKvPn9GAAAAsI"]
[Mon Jul 20 06:02:38.018026 2026] [security2:error] [pid 796928:tid 797099] [client 164.100.212.184:61967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OXusTy9vX-htKvPn9GAAAAsI"]
[Mon Jul 20 06:02:38.039159 2026] [lsapi:warn] [pid 796567:tid 796817] [client 14.225.17.146:62782] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:38.039179 2026] [lsapi:warn] [pid 796567:tid 796817] [client 14.225.17.146:62782] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:38.090687 2026] [security2:error] [pid 796567:tid 796817] [client 14.225.17.146:62782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4OXrLfyzVz2SrjZpicQQAAAow"], referer: https://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:38.299419 2026] [security2:error] [pid 796567:tid 796716] [client 46.110.96.34:19965] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSgAAAic"]
[Mon Jul 20 06:02:38.299419 2026] [security2:error] [pid 796928:tid 797143] [client 46.110.96.34:6158] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9HQAAAu4"]
[Mon Jul 20 06:02:38.299506 2026] [security2:error] [pid 796567:tid 796716] [client 46.110.96.34:19965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSgAAAic"]
[Mon Jul 20 06:02:38.299512 2026] [security2:error] [pid 796928:tid 797143] [client 46.110.96.34:6158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9HQAAAu4"]
[Mon Jul 20 06:02:38.299598 2026] [security2:error] [pid 796567:tid 796821] [client 46.110.96.34:10348] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSwAAApA"]
[Mon Jul 20 06:02:38.299742 2026] [security2:error] [pid 796567:tid 796821] [client 46.110.96.34:10348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSwAAApA"]
[Mon Jul 20 06:02:38.300377 2026] [security2:error] [pid 796567:tid 796792] [client 46.110.96.34:38347] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicTAAAAnM"]
[Mon Jul 20 06:02:38.300458 2026] [security2:error] [pid 796567:tid 796792] [client 46.110.96.34:38347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicTAAAAnM"]
[Mon Jul 20 06:02:38.380203 2026] [security2:error] [pid 796567:tid 796719] [client 181.224.94.124:9899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicVAAAAio"]
[Mon Jul 20 06:02:38.380356 2026] [security2:error] [pid 796567:tid 796719] [client 181.224.94.124:9899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicVAAAAio"]
[Mon Jul 20 06:02:38.533774 2026] [security2:error] [pid 796928:tid 797131] [client 46.110.96.34:6158] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9JgAAAuI"]
[Mon Jul 20 06:02:38.533859 2026] [security2:error] [pid 796928:tid 797131] [client 46.110.96.34:6158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9JgAAAuI"]
[Mon Jul 20 06:02:38.535253 2026] [security2:error] [pid 796567:tid 796736] [client 46.110.96.34:10348] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXAAAAjs"]
[Mon Jul 20 06:02:38.535367 2026] [security2:error] [pid 796567:tid 796736] [client 46.110.96.34:10348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXAAAAjs"]
[Mon Jul 20 06:02:38.549140 2026] [security2:error] [pid 796928:tid 797146] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OXusTy9vX-htKvPn9IQAAAvE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:38.557648 2026] [security2:error] [pid 796567:tid 796710] [client 46.110.96.34:19965] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXgAAAiE"]
[Mon Jul 20 06:02:38.557724 2026] [security2:error] [pid 796567:tid 796710] [client 46.110.96.34:19965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXgAAAiE"]
[Mon Jul 20 06:02:38.664680 2026] [security2:error] [pid 796567:tid 796722] [client 46.110.96.34:38347] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicZQAAAi0"]
[Mon Jul 20 06:02:38.664817 2026] [security2:error] [pid 796567:tid 796722] [client 46.110.96.34:38347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicZQAAAi0"]
[Mon Jul 20 06:02:38.698247 2026] [security2:error] [pid 796567:tid 796795] [client 129.222.187.209:21031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZwAAAnY"]
[Mon Jul 20 06:02:38.699285 2026] [security2:error] [pid 796567:tid 796705] [client 44.245.170.32:24324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZgAAAhw"]
[Mon Jul 20 06:02:38.699381 2026] [security2:error] [pid 796567:tid 796705] [client 44.245.170.32:24324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZgAAAhw"]
[Mon Jul 20 06:02:38.708590 2026] [security2:error] [pid 796567:tid 796795] [client 129.222.187.209:21031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZwAAAnY"]
[Mon Jul 20 06:02:38.956517 2026] [security2:error] [pid 796567:tid 796745] [client 14.225.17.146:57312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4OXbLfyzVz2SrjZpicOAAAAkQ"], referer: http://retzkolonglogistics.com/wordpress
[Mon Jul 20 06:02:39.089893 2026] [security2:error] [pid 796928:tid 797133] [client 57.141.18.41:56944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OWusTy9vX-htKvPn8hwAC5B4"]
[Mon Jul 20 06:02:39.319594 2026] [security2:error] [pid 796567:tid 796740] [client 185.132.186.66:33487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/wp-conflg.php"] [unique_id "al4OX7LfyzVz2SrjZpicfAAAAj8"]
[Mon Jul 20 06:02:40.848061 2026] [security2:error] [pid 796567:tid 796714] [client 27.96.94.195:37899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OYLLfyzVz2SrjZpicuQAAAiU"]
[Mon Jul 20 06:02:40.864232 2026] [security2:error] [pid 796928:tid 797073] [client 112.213.160.112:30794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OYOsTy9vX-htKvPn9YgAAAqg"]
[Mon Jul 20 06:02:40.864379 2026] [security2:error] [pid 796928:tid 797073] [client 112.213.160.112:30794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OYOsTy9vX-htKvPn9YgAAAqg"]
[Mon Jul 20 06:02:40.916573 2026] [core:error] [pid 796928:tid 797106] [client 205.210.31.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:40.916592 2026] [core:error] [pid 796928:tid 797106] [client 205.210.31.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:41.085692 2026] [security2:error] [pid 796567:tid 796794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicwQAAAnU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:41.268208 2026] [security2:error] [pid 796567:tid 796768] [client 185.132.186.53:31127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/file.php"] [unique_id "al4OYbLfyzVz2SrjZpic1AAAAls"]
[Mon Jul 20 06:02:41.273937 2026] [security2:error] [pid 796567:tid 796746] [client 14.225.17.146:56028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicxgAAAkU"], referer: http://healthylifegourmet.org/wordpress
[Mon Jul 20 06:02:41.372148 2026] [security2:error] [pid 796567:tid 796625] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OYbLfyzVz2SrjZpic1gACGjk"]
[Mon Jul 20 06:02:41.372286 2026] [security2:error] [pid 796567:tid 796703] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OYbLfyzVz2SrjZpic1gACGjk"]
[Mon Jul 20 06:02:41.500764 2026] [security2:error] [pid 796928:tid 797175] [client 14.225.17.146:55445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4OX-sTy9vX-htKvPn9QQAAAw4"], referer: http://soloceos.com/wordpress
[Mon Jul 20 06:02:41.688433 2026] [security2:error] [pid 796928:tid 797112] [client 72.255.10.154:26235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9hgAAAs8"]
[Mon Jul 20 06:02:41.688573 2026] [security2:error] [pid 796928:tid 797112] [client 72.255.10.154:26235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9hgAAAs8"]
[Mon Jul 20 06:02:41.798518 2026] [security2:error] [pid 796928:tid 797171] [client 150.228.148.150:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9igAAAwo"]
[Mon Jul 20 06:02:41.806193 2026] [security2:error] [pid 796928:tid 797171] [client 150.228.148.150:62457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9igAAAwo"]
[Mon Jul 20 06:02:41.875599 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:52294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicmQAAAhg"], referer: http://ksands.co.uk/wordpress
[Mon Jul 20 06:02:41.920506 2026] [security2:error] [pid 796928:tid 797130] [client 193.37.33.231:40495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abilite.uk"] [uri "/wp-login.php"] [unique_id "al4OYesTy9vX-htKvPn9jQAAAuE"]
[Mon Jul 20 06:02:41.970891 2026] [security2:error] [pid 796928:tid 797100] [client 95.70.205.159:31048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.205.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aprendeameditar.co"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9jgAAAsM"]
[Mon Jul 20 06:02:41.971133 2026] [security2:error] [pid 796928:tid 797100] [client 95.70.205.159:31048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aprendeameditar.co"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9jgAAAsM"]
[Mon Jul 20 06:02:42.014910 2026] [security2:error] [pid 796567:tid 796777] [client 14.225.17.146:56072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicowAAAmQ"], referer: http://alexsandbergmusic.com/wordpress
[Mon Jul 20 06:02:42.328674 2026] [security2:error] [pid 796928:tid 797106] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYusTy9vX-htKvPn9lQAAAsk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:42.455411 2026] [security2:error] [pid 796928:tid 797108] [client 65.1.132.125:19936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OYusTy9vX-htKvPn9ogAAAss"]
[Mon Jul 20 06:02:42.455496 2026] [security2:error] [pid 796928:tid 797108] [client 65.1.132.125:19936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OYusTy9vX-htKvPn9ogAAAss"]
[Mon Jul 20 06:02:42.816431 2026] [security2:error] [pid 796567:tid 796773] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYrLfyzVz2SrjZpic_wAAAmA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:43.195570 2026] [security2:error] [pid 796928:tid 797123] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYusTy9vX-htKvPn9tQAAAto"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:43.217229 2026] [security2:error] [pid 796928:tid 797073] [client 185.132.186.70:56021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4OY-sTy9vX-htKvPn9xgAAAqg"]
[Mon Jul 20 06:02:43.367105 2026] [security2:error] [pid 796928:tid 797088] [client 50.116.65.227:48574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OY-sTy9vX-htKvPn9zgAAArc"]
[Mon Jul 20 06:02:43.377880 2026] [security2:error] [pid 796567:tid 796738] [client 50.116.65.227:48576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OY7LfyzVz2SrjZpidIAAAAj0"]
[Mon Jul 20 06:02:43.759339 2026] [security2:error] [pid 796928:tid 797180] [client 103.95.123.246:20334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OY-sTy9vX-htKvPn94QAAAxM"]
[Mon Jul 20 06:02:43.760154 2026] [security2:error] [pid 796928:tid 797180] [client 103.95.123.246:20334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OY-sTy9vX-htKvPn94QAAAxM"]
[Mon Jul 20 06:02:43.860185 2026] [security2:error] [pid 796567:tid 796707] [client 106.192.104.4:54007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OY7LfyzVz2SrjZpidOgAAAh4"]
[Mon Jul 20 06:02:43.860310 2026] [security2:error] [pid 796567:tid 796707] [client 106.192.104.4:54007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OY7LfyzVz2SrjZpidOgAAAh4"]
[Mon Jul 20 06:02:43.875183 2026] [security2:error] [pid 796928:tid 797124] [client 124.156.157.91:55064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4OYusTy9vX-htKvPn9mAAAAts"]
[Mon Jul 20 06:02:44.066518 2026] [security2:error] [pid 796928:tid 797168] [client 18.228.171.129:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn97wAAAwc"]
[Mon Jul 20 06:02:44.066627 2026] [security2:error] [pid 796928:tid 797168] [client 18.228.171.129:37888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn97wAAAwc"]
[Mon Jul 20 06:02:44.079720 2026] [security2:error] [pid 796928:tid 797013] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn98QADEFQ"]
[Mon Jul 20 06:02:44.079965 2026] [security2:error] [pid 796928:tid 797177] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn98QADEFQ"]
[Mon Jul 20 06:02:44.141416 2026] [security2:error] [pid 796928:tid 797093] [client 57.141.18.107:51488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OX-sTy9vX-htKvPn9OwACvBo"]
[Mon Jul 20 06:02:44.318362 2026] [security2:error] [pid 796928:tid 797167] [client 115.246.21.170:24557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn99gAAAwY"]
[Mon Jul 20 06:02:44.320094 2026] [security2:error] [pid 796928:tid 797167] [client 115.246.21.170:24557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn99gAAAwY"]
[Mon Jul 20 06:02:44.404007 2026] [security2:error] [pid 796567:tid 796797] [client 14.225.17.146:51072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4OY7LfyzVz2SrjZpidOAAAAng"], referer: http://onewingpictures.com/wordpress
[Mon Jul 20 06:02:44.584839 2026] [security2:error] [pid 796567:tid 796617] [remote 8.217.108.67:1452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OZLLfyzVz2SrjZpidVAACaDE"]
[Mon Jul 20 06:02:44.838443 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZLLfyzVz2SrjZpidTwAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:45.085942 2026] [security2:error] [pid 796567:tid 796789] [client 14.225.17.146:56268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4OY7LfyzVz2SrjZpidKQAAAnA"], referer: http://omrobuildingcenter.com/wordpress
[Mon Jul 20 06:02:45.163157 2026] [security2:error] [pid 796567:tid 796725] [client 185.132.186.65:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/fm.php"] [unique_id "al4OZbLfyzVz2SrjZpidcAAAAjA"]
[Mon Jul 20 06:02:45.585382 2026] [security2:error] [pid 796567:tid 796750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZbLfyzVz2SrjZpidbAAAAkk"]
[Mon Jul 20 06:02:45.588689 2026] [security2:error] [pid 796928:tid 797064] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZesTy9vX-htKvPn-IQAAAp8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:45.618886 2026] [security2:error] [pid 796567:tid 796687] [remote 5.161.225.162:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OZbLfyzVz2SrjZpidgQACPnc"]
[Mon Jul 20 06:02:45.619048 2026] [security2:error] [pid 796567:tid 796739] [client 5.161.225.162:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OZbLfyzVz2SrjZpidgQACPnc"]
[Mon Jul 20 06:02:45.851981 2026] [security2:error] [pid 796567:tid 796692] [remote 8.217.108.67:1452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OZbLfyzVz2SrjZpidiAACinw"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:02:45.927128 2026] [security2:error] [pid 796928:tid 797103] [client 129.222.187.209:29930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OZesTy9vX-htKvPn-RgAAAsY"]
[Mon Jul 20 06:02:45.927235 2026] [security2:error] [pid 796928:tid 797103] [client 129.222.187.209:29930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OZesTy9vX-htKvPn-RgAAAsY"]
[Mon Jul 20 06:02:45.968211 2026] [security2:error] [pid 796567:tid 796706] [client 57.141.18.113:28930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicvgACHUA"]
[Mon Jul 20 06:02:46.474958 2026] [security2:error] [pid 796567:tid 796807] [client 41.173.37.102:8040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OZrLfyzVz2SrjZpidmQAAAoI"]
[Mon Jul 20 06:02:46.475075 2026] [security2:error] [pid 796567:tid 796807] [client 41.173.37.102:8040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OZrLfyzVz2SrjZpidmQAAAoI"]
[Mon Jul 20 06:02:46.673428 2026] [security2:error] [pid 796928:tid 797124] [client 173.239.254.41:46723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OZusTy9vX-htKvPn-YgAAAts"]
[Mon Jul 20 06:02:46.684883 2026] [core:error] [pid 796567:tid 796779] [client 14.225.17.146:55628] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wordpress
[Mon Jul 20 06:02:46.684903 2026] [core:error] [pid 796567:tid 796779] [client 14.225.17.146:55628] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wordpress
[Mon Jul 20 06:02:46.725712 2026] [security2:error] [pid 796928:tid 797102] [client 193.19.109.227:46759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OZusTy9vX-htKvPn-ZgAAAsU"]
[Mon Jul 20 06:02:46.726597 2026] [security2:error] [pid 796928:tid 797061] [client 193.19.109.216:42649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OZusTy9vX-htKvPn-ZwAAApw"]
[Mon Jul 20 06:02:46.911296 2026] [security2:error] [pid 796928:tid 797029] [remote 57.141.18.86:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4388353"] [unique_id "al4OZusTy9vX-htKvPn-cQAC6mQ"]
[Mon Jul 20 06:02:47.104385 2026] [security2:error] [pid 796567:tid 796792] [client 185.132.186.80:49953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "al4OZ7LfyzVz2SrjZpiduAAAAnM"]
[Mon Jul 20 06:02:47.134283 2026] [security2:error] [pid 796567:tid 796767] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZrLfyzVz2SrjZpidpwAAAlo"]
[Mon Jul 20 06:02:47.152238 2026] [security2:error] [pid 796567:tid 796577] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidugACMAk"]
[Mon Jul 20 06:02:47.152456 2026] [security2:error] [pid 796567:tid 796725] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidugACMAk"]
[Mon Jul 20 06:02:47.607449 2026] [security2:error] [pid 796928:tid 797144] [client 210.212.97.243:10428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ-sTy9vX-htKvPn-jAAAAu8"]
[Mon Jul 20 06:02:47.607561 2026] [security2:error] [pid 796928:tid 797144] [client 210.212.97.243:10428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ-sTy9vX-htKvPn-jAAAAu8"]
[Mon Jul 20 06:02:47.619556 2026] [security2:error] [pid 796928:tid 797041] [remote 162.19.86.63:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4OZ-sTy9vX-htKvPn-jwAC83A"]
[Mon Jul 20 06:02:47.722281 2026] [security2:error] [pid 796567:tid 796729] [client 65.1.132.125:30632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidywAAAjQ"]
[Mon Jul 20 06:02:47.722384 2026] [security2:error] [pid 796567:tid 796729] [client 65.1.132.125:30632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidywAAAjQ"]
[Mon Jul 20 06:02:47.840271 2026] [security2:error] [pid 796928:tid 797042] [remote 162.19.86.63:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4OZ-sTy9vX-htKvPn-lQACw3E"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:02:48.001265 2026] [security2:error] [pid 796567:tid 796786] [client 14.225.17.146:56632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4OZ7LfyzVz2SrjZpidzgAAAm0"], referer: http://longevityperformanceclinic.com/wordpress
[Mon Jul 20 06:02:48.416869 2026] [security2:error] [pid 796567:tid 796666] [remote 188.166.241.141:47226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OaLLfyzVz2SrjZpieFAACOmI"]
[Mon Jul 20 06:02:48.439623 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-rAAAAxg"]
[Mon Jul 20 06:02:48.439811 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:60275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-rAAAAxg"]
[Mon Jul 20 06:02:48.529058 2026] [security2:error] [pid 796928:tid 797091] [client 164.100.212.184:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-sQAAAro"]
[Mon Jul 20 06:02:48.529207 2026] [security2:error] [pid 796928:tid 797091] [client 164.100.212.184:62523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-sQAAAro"]
[Mon Jul 20 06:02:48.565295 2026] [security2:error] [pid 796928:tid 797114] [client 57.141.18.57:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OY-sTy9vX-htKvPn9wgAC0Uo"]
[Mon Jul 20 06:02:48.787674 2026] [security2:error] [pid 796567:tid 796644] [remote 188.166.241.141:47226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OaLLfyzVz2SrjZpieHAACMEw"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:02:48.848496 2026] [security2:error] [pid 796928:tid 797059] [client 14.224.227.113:50776] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OaOsTy9vX-htKvPn-uAAAApo"]
[Mon Jul 20 06:02:48.923185 2026] [security2:error] [pid 796567:tid 796767] [client 181.224.94.124:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaLLfyzVz2SrjZpieIwAAAlo"]
[Mon Jul 20 06:02:49.047136 2026] [security2:error] [pid 796567:tid 796722] [client 185.132.186.83:46945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/adminfuns.php7"] [unique_id "al4OabLfyzVz2SrjZpieJgAAAi0"]
[Mon Jul 20 06:02:49.373355 2026] [security2:error] [pid 796567:tid 796665] [remote 152.228.213.32:45480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OabLfyzVz2SrjZpieMAACdmE"]
[Mon Jul 20 06:02:49.425023 2026] [security2:error] [pid 796567:tid 796767] [client 181.224.94.124:58957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaLLfyzVz2SrjZpieIwAAAlo"]
[Mon Jul 20 06:02:49.486325 2026] [security2:error] [pid 796567:tid 796649] [remote 8.217.108.67:1462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OabLfyzVz2SrjZpieNQACT1E"]
[Mon Jul 20 06:02:49.514700 2026] [security2:error] [pid 796928:tid 797071] [client 14.225.17.146:56735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4OaOsTy9vX-htKvPn-nwAAAqY"], referer: http://dadanetnet.net/wordpress
[Mon Jul 20 06:02:49.525506 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:25640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaesTy9vX-htKvPn-1gAAAp4"]
[Mon Jul 20 06:02:49.525711 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:25640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaesTy9vX-htKvPn-1gAAAp4"]
[Mon Jul 20 06:02:49.549878 2026] [security2:error] [pid 796567:tid 796585] [remote 152.228.213.32:45480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OabLfyzVz2SrjZpieOAACHxE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:02:50.067816 2026] [security2:error] [pid 796567:tid 796677] [remote 8.217.108.67:1462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OarLfyzVz2SrjZpieQQACe20"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:02:50.084884 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OabLfyzVz2SrjZpieOgAAAl0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:50.201842 2026] [security2:error] [pid 796928:tid 797162] [client 47.128.29.193:35514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "laceycaraccident.com"] [uri "/robots.txt"] [unique_id "al4OausTy9vX-htKvPn-_wAAAwE"]
[Mon Jul 20 06:02:50.999569 2026] [security2:error] [pid 796928:tid 797169] [client 185.132.186.84:48313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/about.php"] [unique_id "al4OausTy9vX-htKvPn_IwAAAwg"]
[Mon Jul 20 06:02:51.299895 2026] [security2:error] [pid 796928:tid 796942] [remote 167.233.114.32:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4Oa-sTy9vX-htKvPn_MwACmg0"]
[Mon Jul 20 06:02:51.571452 2026] [security2:error] [pid 796928:tid 796971] [remote 167.233.114.32:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4Oa-sTy9vX-htKvPn_QgACpSo"], referer: https://dlu.cjf.mybluehost.me/blog/wp-login.php
[Mon Jul 20 06:02:51.642849 2026] [security2:error] [pid 796928:tid 797182] [client 112.213.160.112:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oa-sTy9vX-htKvPn_SAAAAxU"]
[Mon Jul 20 06:02:51.642942 2026] [security2:error] [pid 796928:tid 797182] [client 112.213.160.112:31177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oa-sTy9vX-htKvPn_SAAAAxU"]
[Mon Jul 20 06:02:51.816123 2026] [security2:error] [pid 796928:tid 797157] [client 14.251.3.155:59541] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Oa-sTy9vX-htKvPn_VAAAAvw"]
[Mon Jul 20 06:02:52.477139 2026] [security2:error] [pid 796928:tid 797123] [client 150.228.148.150:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_dAAAAto"]
[Mon Jul 20 06:02:52.484608 2026] [security2:error] [pid 796928:tid 797123] [client 150.228.148.150:45821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_dAAAAto"]
[Mon Jul 20 06:02:52.688651 2026] [security2:error] [pid 796928:tid 797141] [client 27.96.94.195:37959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_dgAAAuw"]
[Mon Jul 20 06:02:52.744795 2026] [security2:error] [pid 796567:tid 796711] [client 77.110.127.138:54684] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4ObLLfyzVz2SrjZpiecQAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:52.940271 2026] [security2:error] [pid 796928:tid 797086] [client 185.132.186.68:30067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ini.php"] [unique_id "al4ObOsTy9vX-htKvPn_iQAAArU"]
[Mon Jul 20 06:02:52.969407 2026] [security2:error] [pid 796928:tid 797139] [client 72.255.10.154:26474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_iwAAAuo"]
[Mon Jul 20 06:02:52.969556 2026] [security2:error] [pid 796928:tid 797139] [client 72.255.10.154:26474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_iwAAAuo"]
[Mon Jul 20 06:02:53.214163 2026] [security2:error] [pid 796567:tid 796629] [remote 20.153.140.50:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ObbLfyzVz2SrjZpiefAACRz0"]
[Mon Jul 20 06:02:53.413492 2026] [security2:error] [pid 796928:tid 797105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ObesTy9vX-htKvPn_oAAAAsg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:53.428833 2026] [security2:error] [pid 796567:tid 796749] [client 57.141.18.45:55606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OZ7LfyzVz2SrjZpid0AACSCc"]
[Mon Jul 20 06:02:53.538979 2026] [security2:error] [pid 796928:tid 797000] [remote 102.134.101.35:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ObesTy9vX-htKvPn_qwADAkc"]
[Mon Jul 20 06:02:53.632997 2026] [security2:error] [pid 796567:tid 796641] [remote 20.153.140.50:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ObbLfyzVz2SrjZpieiQACQEk"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:02:53.638119 2026] [security2:error] [pid 796928:tid 797089] [client 50.116.65.227:52818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ObesTy9vX-htKvPn_tgAAArg"]
[Mon Jul 20 06:02:53.651764 2026] [security2:error] [pid 796567:tid 796746] [client 50.116.65.227:52820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ObbLfyzVz2SrjZpieiwAAAkU"]
[Mon Jul 20 06:02:53.987011 2026] [security2:error] [pid 796928:tid 797012] [remote 102.134.101.35:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ObesTy9vX-htKvPn_wwAC3VM"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:02:54.188613 2026] [security2:error] [pid 796928:tid 797116] [client 86.98.90.58:44824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPn_1AAAAtM"]
[Mon Jul 20 06:02:54.188831 2026] [security2:error] [pid 796928:tid 797116] [client 86.98.90.58:44824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPn_1AAAAtM"]
[Mon Jul 20 06:02:54.242336 2026] [security2:error] [pid 796928:tid 797078] [client 57.141.18.19:33528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OaOsTy9vX-htKvPn-vQACrXc"]
[Mon Jul 20 06:02:54.372872 2026] [security2:error] [pid 796928:tid 797024] [remote 124.55.178.99:41852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ObusTy9vX-htKvPn_3AAC_l8"]
[Mon Jul 20 06:02:54.554678 2026] [security2:error] [pid 796567:tid 796788] [client 106.192.104.4:54482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieoAAAAm8"]
[Mon Jul 20 06:02:54.559411 2026] [security2:error] [pid 796567:tid 796788] [client 106.192.104.4:54482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieoAAAAm8"]
[Mon Jul 20 06:02:54.712686 2026] [security2:error] [pid 796928:tid 797110] [client 14.225.17.146:56502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4ObesTy9vX-htKvPn_nAAAAs0"], referer: http://alchemygroup.ca/wordpress
[Mon Jul 20 06:02:54.735913 2026] [security2:error] [pid 796567:tid 796811] [client 18.228.171.129:46358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpiepwAAAoY"]
[Mon Jul 20 06:02:54.736049 2026] [security2:error] [pid 796567:tid 796811] [client 18.228.171.129:46358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpiepwAAAoY"]
[Mon Jul 20 06:02:54.805654 2026] [security2:error] [pid 796567:tid 796637] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieqQACg0U"]
[Mon Jul 20 06:02:54.805832 2026] [security2:error] [pid 796567:tid 796808] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieqQACg0U"]
[Mon Jul 20 06:02:54.806883 2026] [security2:error] [pid 796928:tid 797031] [remote 124.55.178.99:41852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ObusTy9vX-htKvPkAAwACr2Y"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:02:54.821609 2026] [security2:error] [pid 796928:tid 797180] [client 47.31.86.100:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkABQAAAxM"]
[Mon Jul 20 06:02:54.825434 2026] [security2:error] [pid 796928:tid 797180] [client 47.31.86.100:55578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkABQAAAxM"]
[Mon Jul 20 06:02:54.889338 2026] [security2:error] [pid 796567:tid 796750] [client 185.132.186.68:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "al4ObrLfyzVz2SrjZpieqgAAAkk"]
[Mon Jul 20 06:02:54.972141 2026] [security2:error] [pid 796928:tid 797172] [client 77.110.127.138:54677] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4ObusTy9vX-htKvPkADAAAAws"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:54.995412 2026] [security2:error] [pid 796928:tid 797160] [client 115.246.21.170:31104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkADQAAAv8"]
[Mon Jul 20 06:02:54.995525 2026] [security2:error] [pid 796928:tid 797160] [client 115.246.21.170:31104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkADQAAAv8"]
[Mon Jul 20 06:02:55.055945 2026] [security2:error] [pid 796928:tid 797041] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAEwADD3A"]
[Mon Jul 20 06:02:55.056129 2026] [security2:error] [pid 796928:tid 797176] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAEwADD3A"]
[Mon Jul 20 06:02:55.153203 2026] [security2:error] [pid 796928:tid 797173] [client 46.110.96.34:26461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4Ob-sTy9vX-htKvPkAGAAAAww"]
[Mon Jul 20 06:02:55.153338 2026] [security2:error] [pid 796928:tid 797173] [client 46.110.96.34:26461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4Ob-sTy9vX-htKvPkAGAAAAww"]
[Mon Jul 20 06:02:55.185111 2026] [security2:error] [pid 796928:tid 797168] [client 103.95.123.246:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAGgAAAwc"]
[Mon Jul 20 06:02:55.185247 2026] [security2:error] [pid 796928:tid 797168] [client 103.95.123.246:20837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAGgAAAwc"]
[Mon Jul 20 06:02:55.265203 2026] [security2:error] [pid 796928:tid 797167] [client 57.141.18.93:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OausTy9vX-htKvPn-_AADBg8"]
[Mon Jul 20 06:02:55.298321 2026] [security2:error] [pid 796928:tid 797105] [client 98.159.234.160:51481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Ob-sTy9vX-htKvPkAIAAAAsg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:55.680265 2026] [security2:error] [pid 796928:tid 797184] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ob-sTy9vX-htKvPkAKQAAAxc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:56.189586 2026] [security2:error] [pid 796928:tid 797056] [remote 47.251.82.1:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OcOsTy9vX-htKvPkAUQACrn8"]
[Mon Jul 20 06:02:56.341721 2026] [security2:error] [pid 796567:tid 796780] [client 179.0.122.163:22050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.122.0.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie1wAAAmc"]
[Mon Jul 20 06:02:56.341967 2026] [security2:error] [pid 796567:tid 796780] [client 179.0.122.163:22050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie1wAAAmc"]
[Mon Jul 20 06:02:56.536601 2026] [security2:error] [pid 796928:tid 797146] [client 14.182.195.220:51962] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OcOsTy9vX-htKvPkAYQAAAvE"]
[Mon Jul 20 06:02:56.566648 2026] [security2:error] [pid 796928:tid 796937] [remote 47.251.82.1:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OcOsTy9vX-htKvPkAYwADEwg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:02:56.567843 2026] [security2:error] [pid 796567:tid 796799] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OcLLfyzVz2SrjZpie1AAAAno"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:56.654787 2026] [security2:error] [pid 796567:tid 796737] [client 129.222.187.209:37327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie2wAAAjw"]
[Mon Jul 20 06:02:56.659899 2026] [security2:error] [pid 796567:tid 796737] [client 129.222.187.209:37327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie2wAAAjw"]
[Mon Jul 20 06:02:56.737290 2026] [security2:error] [pid 796928:tid 797068] [client 57.141.18.85:63940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oa-sTy9vX-htKvPn_UAACoy8"]
[Mon Jul 20 06:02:56.806648 2026] [security2:error] [pid 796928:tid 797070] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcOsTy9vX-htKvPkAdwAAAqU"]
[Mon Jul 20 06:02:56.839111 2026] [security2:error] [pid 796928:tid 797166] [client 185.132.186.69:42317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/blocks/calendar/index.php"] [unique_id "al4OcOsTy9vX-htKvPkAegAAAwU"]
[Mon Jul 20 06:02:56.922066 2026] [security2:error] [pid 796928:tid 797069] [client 178.152.178.232:36221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OcOsTy9vX-htKvPkAfgAAAqQ"]
[Mon Jul 20 06:02:56.922200 2026] [security2:error] [pid 796928:tid 797069] [client 178.152.178.232:36221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OcOsTy9vX-htKvPkAfgAAAqQ"]
[Mon Jul 20 06:02:57.107313 2026] [security2:error] [pid 796567:tid 796724] [client 41.173.37.102:8461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OcbLfyzVz2SrjZpie4wAAAi8"]
[Mon Jul 20 06:02:57.107394 2026] [security2:error] [pid 796567:tid 796724] [client 41.173.37.102:8461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OcbLfyzVz2SrjZpie4wAAAi8"]
[Mon Jul 20 06:02:57.344730 2026] [security2:error] [pid 796928:tid 797165] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcesTy9vX-htKvPkAiQAAAwQ"]
[Mon Jul 20 06:02:57.599901 2026] [security2:error] [pid 796567:tid 796777] [client 77.110.127.138:54510] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OcbLfyzVz2SrjZpie9AAAAmQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:57.683593 2026] [security2:error] [pid 796567:tid 796706] [client 57.141.18.14:32754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ObLLfyzVz2SrjZpiecgACHSg"]
[Mon Jul 20 06:02:57.734966 2026] [security2:error] [pid 796928:tid 796945] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OcesTy9vX-htKvPkAngADExA"]
[Mon Jul 20 06:02:57.735140 2026] [security2:error] [pid 796928:tid 797180] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OcesTy9vX-htKvPkAngADExA"]
[Mon Jul 20 06:02:57.808550 2026] [security2:error] [pid 796928:tid 797117] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OcesTy9vX-htKvPkAlQAAAtQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:57.900336 2026] [security2:error] [pid 796928:tid 797181] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcesTy9vX-htKvPkAowAAAxQ"]
[Mon Jul 20 06:02:57.945276 2026] [security2:error] [pid 796928:tid 797149] [client 14.225.17.146:56679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4OcesTy9vX-htKvPkAnwAAAvQ"], referer: http://myspineworld.com/wordpress
[Mon Jul 20 06:02:58.125657 2026] [security2:error] [pid 796928:tid 797096] [client 210.212.97.243:10429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkAsgAAAr8"]
[Mon Jul 20 06:02:58.125801 2026] [security2:error] [pid 796928:tid 797096] [client 210.212.97.243:10429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkAsgAAAr8"]
[Mon Jul 20 06:02:58.443488 2026] [security2:error] [pid 796928:tid 797137] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcusTy9vX-htKvPkAxQAAAug"]
[Mon Jul 20 06:02:58.471004 2026] [security2:error] [pid 796567:tid 796602] [remote 47.86.33.52:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OcrLfyzVz2SrjZpifDwACMiI"]
[Mon Jul 20 06:02:58.496660 2026] [security2:error] [pid 796567:tid 796776] [client 3.109.4.218:42900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OcrLfyzVz2SrjZpifEAAAAmM"]
[Mon Jul 20 06:02:58.496784 2026] [security2:error] [pid 796567:tid 796776] [client 3.109.4.218:42900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OcrLfyzVz2SrjZpifEAAAAmM"]
[Mon Jul 20 06:02:58.569321 2026] [security2:error] [pid 796928:tid 797061] [client 46.110.96.34:26461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkAzAAAApw"]
[Mon Jul 20 06:02:58.569425 2026] [security2:error] [pid 796928:tid 797061] [client 46.110.96.34:26461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkAzAAAApw"]
[Mon Jul 20 06:02:58.658181 2026] [security2:error] [pid 796928:tid 797139] [client 46.110.96.34:26461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkA0AAAAuo"]
[Mon Jul 20 06:02:58.658300 2026] [security2:error] [pid 796928:tid 797139] [client 46.110.96.34:26461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkA0AAAAuo"]
[Mon Jul 20 06:02:58.666836 2026] [security2:error] [pid 796928:tid 797162] [client 103.149.16.77:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkA0QAAAwE"]
[Mon Jul 20 06:02:58.666947 2026] [security2:error] [pid 796928:tid 797162] [client 103.149.16.77:60754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkA0QAAAwE"]
[Mon Jul 20 06:02:58.703903 2026] [security2:error] [pid 796928:tid 797155] [client 57.141.18.105:35008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ObusTy9vX-htKvPn_xQAC-lY"]
[Mon Jul 20 06:02:58.876487 2026] [security2:error] [pid 796928:tid 797166] [client 103.87.138.44:60842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4OcusTy9vX-htKvPkA0gAAAwU"]
[Mon Jul 20 06:02:58.894958 2026] [security2:error] [pid 796928:tid 797184] [client 14.225.17.146:63866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4OcusTy9vX-htKvPkA1AAAAxc"], referer: https://myspineworld.com/wordpress
[Mon Jul 20 06:02:59.125085 2026] [security2:error] [pid 796928:tid 797143] [client 164.100.212.184:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA4gAAAu4"]
[Mon Jul 20 06:02:59.125189 2026] [security2:error] [pid 796928:tid 797143] [client 164.100.212.184:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA4gAAAu4"]
[Mon Jul 20 06:02:59.191306 2026] [security2:error] [pid 796928:tid 796971] [remote 51.158.61.221:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Oc-sTy9vX-htKvPkA5AACpCo"]
[Mon Jul 20 06:02:59.402978 2026] [security2:error] [pid 796928:tid 796935] [remote 51.158.61.221:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Oc-sTy9vX-htKvPkA9wAC-QY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:02:59.425811 2026] [security2:error] [pid 796928:tid 797064] [client 57.141.18.67:24142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ObusTy9vX-htKvPkAAgACn2Q"]
[Mon Jul 20 06:02:59.426387 2026] [security2:error] [pid 796928:tid 797094] [client 181.224.94.124:60581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA-QAAAr0"]
[Mon Jul 20 06:02:59.426558 2026] [security2:error] [pid 796928:tid 797094] [client 181.224.94.124:60581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA-QAAAr0"]
[Mon Jul 20 06:02:59.973249 2026] [security2:error] [pid 796928:tid 796969] [remote 47.86.33.52:24638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Oc-sTy9vX-htKvPkBCQAC9ig"]
[Mon Jul 20 06:03:00.058286 2026] [security2:error] [pid 796928:tid 796951] [remote 188.166.241.141:37666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBDAADDxY"]
[Mon Jul 20 06:03:00.068079 2026] [security2:error] [pid 796928:tid 797161] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4Oc-sTy9vX-htKvPkBAwADAAU"], referer: http://assasalnazaha.com/wordpress
[Mon Jul 20 06:03:00.143410 2026] [security2:error] [pid 796928:tid 797132] [client 3.67.192.83:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBDwAAAuM"]
[Mon Jul 20 06:03:00.166902 2026] [security2:error] [pid 796928:tid 797093] [client 129.222.187.209:3591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OdOsTy9vX-htKvPkBEAAAArw"]
[Mon Jul 20 06:03:00.172844 2026] [security2:error] [pid 796928:tid 797093] [client 129.222.187.209:3591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OdOsTy9vX-htKvPkBEAAAArw"]
[Mon Jul 20 06:03:00.314317 2026] [security2:error] [pid 796928:tid 797111] [client 185.132.186.73:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4OdOsTy9vX-htKvPkBFgAAAs4"]
[Mon Jul 20 06:03:00.456157 2026] [security2:error] [pid 796928:tid 796980] [remote 188.166.241.141:37666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBGAADETM"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 06:03:00.510223 2026] [security2:error] [pid 796567:tid 796579] [remote 47.86.33.52:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OdLLfyzVz2SrjZpifVAAChQs"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:03:00.714048 2026] [security2:error] [pid 796928:tid 797140] [client 63.176.132.15:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBIgAAAus"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:03:00.765261 2026] [security2:error] [pid 796928:tid 797170] [client 14.225.17.146:65239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4Oc-sTy9vX-htKvPkA8gAAAwk"], referer: http://phillipbloch.com/wordpress
[Mon Jul 20 06:03:01.004583 2026] [security2:error] [pid 796928:tid 796978] [remote 47.86.33.52:24638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OdesTy9vX-htKvPkBMwAC2jE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:03:01.134188 2026] [security2:error] [pid 796567:tid 796748] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OdLLfyzVz2SrjZpifRwAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:01.442288 2026] [security2:error] [pid 796567:tid 796632] [remote 5.161.225.162:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OdbLfyzVz2SrjZpifdwACOEA"]
[Mon Jul 20 06:03:01.444394 2026] [security2:error] [pid 796928:tid 797131] [client 57.141.18.74:27718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OcOsTy9vX-htKvPkAcAAC4hU"]
[Mon Jul 20 06:03:01.621026 2026] [security2:error] [pid 796567:tid 796609] [remote 5.161.225.162:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OdbLfyzVz2SrjZpiffgAChyk"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:03:01.718135 2026] [security2:error] [pid 796928:tid 797168] [client 14.225.17.146:51725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4OdesTy9vX-htKvPkBSgAAAwc"], referer: http://mtlegnews.gov/wordpress
[Mon Jul 20 06:03:01.731132 2026] [security2:error] [pid 796928:tid 796992] [remote 57.141.18.53:34148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2637480"] [unique_id "al4OdesTy9vX-htKvPkBUQADCz8"]
[Mon Jul 20 06:03:01.788745 2026] [security2:error] [pid 796567:tid 796719] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OdbLfyzVz2SrjZpifgwAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:02.132421 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OdesTy9vX-htKvPkBSQAAAqw"]
[Mon Jul 20 06:03:02.194363 2026] [security2:error] [pid 796928:tid 797133] [client 14.225.17.146:54514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4OdusTy9vX-htKvPkBWwAAAuQ"], referer: http://blaizeaccountingservices.com/wordpress
[Mon Jul 20 06:03:02.251435 2026] [security2:error] [pid 796928:tid 797171] [client 185.132.186.53:58817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "al4OdusTy9vX-htKvPkBaAAAAwo"]
[Mon Jul 20 06:03:02.313917 2026] [security2:error] [pid 796928:tid 797067] [client 112.213.160.112:8294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OdusTy9vX-htKvPkBaQAAAqI"]
[Mon Jul 20 06:03:02.314418 2026] [security2:error] [pid 796928:tid 797067] [client 112.213.160.112:8294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OdusTy9vX-htKvPkBaQAAAqI"]
[Mon Jul 20 06:03:02.444953 2026] [security2:error] [pid 796567:tid 796569] [remote 8.217.108.67:1478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4OdrLfyzVz2SrjZpifoQACkAE"]
[Mon Jul 20 06:03:02.555093 2026] [security2:error] [pid 796928:tid 797165] [client 50.116.65.227:16664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OdusTy9vX-htKvPkBeAAAAwQ"]
[Mon Jul 20 06:03:02.567336 2026] [security2:error] [pid 796928:tid 797122] [client 50.116.65.227:16674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OdusTy9vX-htKvPkBegAAAtk"]
[Mon Jul 20 06:03:02.681384 2026] [security2:error] [pid 796567:tid 796709] [client 27.96.94.195:37985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OdrLfyzVz2SrjZpifpQAAAiA"]
[Mon Jul 20 06:03:02.737478 2026] [security2:error] [pid 796567:tid 796640] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OdrLfyzVz2SrjZpifsQACXkg"]
[Mon Jul 20 06:03:02.737687 2026] [security2:error] [pid 796567:tid 796771] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OdrLfyzVz2SrjZpifsQACXkg"]
[Mon Jul 20 06:03:03.041916 2026] [security2:error] [pid 796928:tid 797092] [client 150.228.148.150:11741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBhwAAArs"]
[Mon Jul 20 06:03:03.057925 2026] [security2:error] [pid 796928:tid 797092] [client 150.228.148.150:11741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBhwAAArs"]
[Mon Jul 20 06:03:03.075651 2026] [security2:error] [pid 796567:tid 796776] [client 49.206.10.250:41016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.10.206.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/xmlrpc.php"] [unique_id "al4Od7LfyzVz2SrjZpifxQAAAmM"]
[Mon Jul 20 06:03:03.075810 2026] [security2:error] [pid 796567:tid 796776] [client 49.206.10.250:41016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "asliceofleadership.com"] [uri "/xmlrpc.php"] [unique_id "al4Od7LfyzVz2SrjZpifxQAAAmM"]
[Mon Jul 20 06:03:03.132653 2026] [security2:error] [pid 796567:tid 796797] [client 50.116.65.227:16688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OdrLfyzVz2SrjZpifugAAAng"]
[Mon Jul 20 06:03:03.274637 2026] [security2:error] [pid 796567:tid 796786] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OdrLfyzVz2SrjZpifsAAAAm0"]
[Mon Jul 20 06:03:03.325564 2026] [security2:error] [pid 796567:tid 796794] [client 50.116.65.227:16704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Od7LfyzVz2SrjZpifyQAAAnU"]
[Mon Jul 20 06:03:03.607891 2026] [security2:error] [pid 796567:tid 796642] [remote 47.128.25.171:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lelandmc.org"] [uri "/robots.txt"] [unique_id "al4Od7LfyzVz2SrjZpif2gACg0o"]
[Mon Jul 20 06:03:03.790343 2026] [security2:error] [pid 796928:tid 797071] [client 86.98.90.58:45755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBpAAAAqY"]
[Mon Jul 20 06:03:03.865504 2026] [security2:error] [pid 796928:tid 797071] [client 86.98.90.58:45755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBpAAAAqY"]
[Mon Jul 20 06:03:03.885127 2026] [security2:error] [pid 796928:tid 797010] [remote 132.148.72.88:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4Od-sTy9vX-htKvPkBpQACrlE"]
[Mon Jul 20 06:03:04.038673 2026] [security2:error] [pid 796928:tid 797178] [client 94.154.43.179:25132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dwk.lce.mybluehost.me"] [uri "/.env"] [unique_id "al4OeOsTy9vX-htKvPkBqwAAAxE"]
[Mon Jul 20 06:03:04.045844 2026] [security2:error] [pid 796567:tid 796822] [client 94.154.43.187:31128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.dwk.lce.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4OeLLfyzVz2SrjZpif7QAAApE"]
[Mon Jul 20 06:03:04.050344 2026] [security2:error] [pid 796567:tid 796725] [client 94.154.43.185:42820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.dwk.lce.mybluehost.me"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4OeLLfyzVz2SrjZpif7gAAAjA"]
[Mon Jul 20 06:03:04.055800 2026] [security2:error] [pid 796928:tid 797174] [client 94.154.43.184:26640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dwk.lce.mybluehost.me"] [uri "/.env"] [unique_id "al4OeOsTy9vX-htKvPkBrAAAAw0"]
[Mon Jul 20 06:03:04.176879 2026] [security2:error] [pid 796567:tid 796604] [remote 173.212.252.15:48884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OeLLfyzVz2SrjZpif9wACbiQ"]
[Mon Jul 20 06:03:04.177067 2026] [security2:error] [pid 796567:tid 796787] [client 173.212.252.15:48884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OeLLfyzVz2SrjZpif9wACbiQ"]
[Mon Jul 20 06:03:04.204954 2026] [security2:error] [pid 796928:tid 797166] [client 185.132.186.70:52659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/instaall.php"] [unique_id "al4OeOsTy9vX-htKvPkBuwAAAwU"]
[Mon Jul 20 06:03:04.233835 2026] [security2:error] [pid 796928:tid 797161] [client 50.116.65.227:16730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4OeOsTy9vX-htKvPkBvQAAAwA"]
[Mon Jul 20 06:03:04.234853 2026] [security2:error] [pid 796928:tid 797135] [client 50.116.65.227:16738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4OeOsTy9vX-htKvPkBvgAAAuY"]
[Mon Jul 20 06:03:04.246976 2026] [security2:error] [pid 796928:tid 797007] [remote 132.148.72.88:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4OeOsTy9vX-htKvPkBwAADA04"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:03:04.593315 2026] [security2:error] [pid 796567:tid 796778] [client 57.141.18.20:46504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oc7LfyzVz2SrjZpifMQACZWI"]
[Mon Jul 20 06:03:04.851894 2026] [security2:error] [pid 796928:tid 797133] [client 62.150.67.110:22945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4OeOsTy9vX-htKvPkB0gAAAuQ"]
[Mon Jul 20 06:03:05.065211 2026] [security2:error] [pid 796567:tid 796813] [client 47.31.86.100:56219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigGgAAAog"]
[Mon Jul 20 06:03:05.065895 2026] [security2:error] [pid 796567:tid 796813] [client 47.31.86.100:56219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigGgAAAog"]
[Mon Jul 20 06:03:05.412957 2026] [security2:error] [pid 796928:tid 797028] [remote 45.90.123.233:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4OeesTy9vX-htKvPkCAgACrWM"]
[Mon Jul 20 06:03:05.413282 2026] [security2:error] [pid 796928:tid 797132] [client 18.228.171.129:26980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCAQAAAuM"]
[Mon Jul 20 06:03:05.413362 2026] [security2:error] [pid 796928:tid 797132] [client 18.228.171.129:26980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCAQAAAuM"]
[Mon Jul 20 06:03:05.584885 2026] [security2:error] [pid 796928:tid 797100] [client 115.246.21.170:9909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCBwAAAsM"]
[Mon Jul 20 06:03:05.585005 2026] [security2:error] [pid 796928:tid 797100] [client 115.246.21.170:9909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCBwAAAsM"]
[Mon Jul 20 06:03:05.595958 2026] [security2:error] [pid 796567:tid 796622] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigLAACMjY"]
[Mon Jul 20 06:03:05.596120 2026] [security2:error] [pid 796567:tid 796727] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigLAACMjY"]
[Mon Jul 20 06:03:05.665978 2026] [security2:error] [pid 796928:tid 797032] [remote 45.90.123.233:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4OeesTy9vX-htKvPkCFQACpWc"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:03:05.685069 2026] [security2:error] [pid 796928:tid 797172] [client 106.192.104.4:48429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCFgAAAws"]
[Mon Jul 20 06:03:05.685308 2026] [security2:error] [pid 796928:tid 797172] [client 106.192.104.4:48429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCFgAAAws"]
[Mon Jul 20 06:03:05.862694 2026] [security2:error] [pid 796567:tid 796818] [client 72.255.10.154:2247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigNAAAAo0"]
[Mon Jul 20 06:03:05.862853 2026] [security2:error] [pid 796567:tid 796818] [client 72.255.10.154:2247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigNAAAAo0"]
[Mon Jul 20 06:03:06.147367 2026] [security2:error] [pid 796928:tid 797095] [client 185.132.186.84:21309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/function.php"] [unique_id "al4OeusTy9vX-htKvPkCLQAAAr4"]
[Mon Jul 20 06:03:06.290606 2026] [security2:error] [pid 796928:tid 797183] [client 57.141.18.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4OeesTy9vX-htKvPkCGwAAAxY"]
[Mon Jul 20 06:03:06.524813 2026] [security2:error] [pid 796567:tid 796749] [client 103.95.123.246:21337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OerLfyzVz2SrjZpigUQAAAkg"]
[Mon Jul 20 06:03:06.524970 2026] [security2:error] [pid 796567:tid 796749] [client 103.95.123.246:21337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OerLfyzVz2SrjZpigUQAAAkg"]
[Mon Jul 20 06:03:06.638911 2026] [security2:error] [pid 796567:tid 796807] [client 43.173.178.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OerLfyzVz2SrjZpigRgAAAoI"]
[Mon Jul 20 06:03:06.661314 2026] [security2:error] [pid 796928:tid 797156] [client 43.173.176.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OeusTy9vX-htKvPkCLgAAAvs"]
[Mon Jul 20 06:03:06.665288 2026] [security2:error] [pid 796567:tid 796728] [client 43.173.173.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OerLfyzVz2SrjZpigSQAAAjM"]
[Mon Jul 20 06:03:06.666964 2026] [security2:error] [pid 796928:tid 797084] [client 43.173.180.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OeusTy9vX-htKvPkCMAAAArM"]
[Mon Jul 20 06:03:06.667491 2026] [security2:error] [pid 796567:tid 796714] [client 43.173.178.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OerLfyzVz2SrjZpigRwAAAiU"]
[Mon Jul 20 06:03:06.879854 2026] [security2:error] [pid 796928:tid 797122] [client 14.225.17.146:59510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4OeOsTy9vX-htKvPkBuAAAAtk"], referer: http://talknutritionwithlesley.com/wordpress
[Mon Jul 20 06:03:07.002206 2026] [security2:error] [pid 796928:tid 797117] [client 43.173.181.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OeusTy9vX-htKvPkCOwAAAtQ"]
[Mon Jul 20 06:03:07.013928 2026] [security2:error] [pid 796928:tid 797041] [remote 188.166.241.141:37670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4Oe-sTy9vX-htKvPkCSAAC9HA"]
[Mon Jul 20 06:03:07.049086 2026] [security2:error] [pid 796928:tid 797038] [remote 57.141.18.29:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3562735"] [unique_id "al4Oe-sTy9vX-htKvPkCSQAC1m0"]
[Mon Jul 20 06:03:07.228757 2026] [security2:error] [pid 796928:tid 797143] [client 14.224.227.113:59548] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Oe-sTy9vX-htKvPkCUQAAAu4"]
[Mon Jul 20 06:03:07.387599 2026] [security2:error] [pid 796928:tid 797128] [client 129.222.187.209:59414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCWwAAAt8"]
[Mon Jul 20 06:03:07.402062 2026] [security2:error] [pid 796928:tid 797128] [client 129.222.187.209:59414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCWwAAAt8"]
[Mon Jul 20 06:03:07.447767 2026] [security2:error] [pid 796928:tid 797035] [remote 188.166.241.141:37670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4Oe-sTy9vX-htKvPkCXwACyGo"], referer: https://omrobuildingcenter.com/wp-login.php
[Mon Jul 20 06:03:07.719216 2026] [security2:error] [pid 796928:tid 797060] [client 41.173.37.102:8873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCegAAAps"]
[Mon Jul 20 06:03:07.719364 2026] [security2:error] [pid 796928:tid 797060] [client 41.173.37.102:8873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCegAAAps"]
[Mon Jul 20 06:03:08.091644 2026] [security2:error] [pid 796928:tid 797059] [client 185.132.186.76:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/plugins.php"] [unique_id "al4OfOsTy9vX-htKvPkClAAAApo"]
[Mon Jul 20 06:03:08.131118 2026] [security2:error] [pid 796567:tid 796704] [client 43.172.195.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe7LfyzVz2SrjZpigigAAAhs"]
[Mon Jul 20 06:03:08.208061 2026] [core:error] [pid 796928:tid 797164] [client 20.220.225.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:08.208085 2026] [core:error] [pid 796928:tid 797164] [client 20.220.225.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:08.208248 2026] [security2:error] [pid 796928:tid 797164] [client 20.220.225.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "coaching-certification.secoaches.co"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkCmwAAAwM"]
[Mon Jul 20 06:03:08.213680 2026] [security2:error] [pid 796928:tid 797096] [client 43.173.174.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCgQAAAr8"]
[Mon Jul 20 06:03:08.221331 2026] [security2:error] [pid 796567:tid 796749] [client 43.173.173.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe7LfyzVz2SrjZpigkgAAAkg"]
[Mon Jul 20 06:03:08.221364 2026] [security2:error] [pid 796928:tid 797092] [client 43.173.179.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCfAAAArs"]
[Mon Jul 20 06:03:08.234785 2026] [security2:error] [pid 796928:tid 797166] [client 43.173.179.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCfQAAAwU"]
[Mon Jul 20 06:03:08.324487 2026] [security2:error] [pid 796928:tid 797043] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OfOsTy9vX-htKvPkCrAAC7HI"]
[Mon Jul 20 06:03:08.324667 2026] [security2:error] [pid 796928:tid 797141] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OfOsTy9vX-htKvPkCrAAC7HI"]
[Mon Jul 20 06:03:08.607085 2026] [security2:error] [pid 796928:tid 797079] [client 43.172.196.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkCowAAAq4"]
[Mon Jul 20 06:03:08.672115 2026] [security2:error] [pid 796567:tid 796726] [client 210.212.97.243:10430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OfLLfyzVz2SrjZpigtwAAAjE"]
[Mon Jul 20 06:03:08.672320 2026] [security2:error] [pid 796567:tid 796726] [client 210.212.97.243:10430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OfLLfyzVz2SrjZpigtwAAAjE"]
[Mon Jul 20 06:03:08.791178 2026] [security2:error] [pid 796567:tid 796820] [client 45.157.112.60:33761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OfLLfyzVz2SrjZpigvgAAAo8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:08.824149 2026] [security2:error] [pid 796928:tid 797083] [client 158.173.89.95:59235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OfOsTy9vX-htKvPkCuwAAArI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:09.238701 2026] [security2:error] [pid 796567:tid 796817] [client 57.141.18.42:23830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Od7LfyzVz2SrjZpif5QACjEc"]
[Mon Jul 20 06:03:09.258470 2026] [security2:error] [pid 796928:tid 797086] [client 94.154.43.188:53132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhavoctattoos-com.grndl.com"] [uri "/.env"] [unique_id "al4OfesTy9vX-htKvPkC1AAAArU"]
[Mon Jul 20 06:03:09.305906 2026] [security2:error] [pid 796928:tid 797175] [client 94.154.43.185:57988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jhavoctattoos.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al4OfesTy9vX-htKvPkC1gAAAw4"]
[Mon Jul 20 06:03:09.324240 2026] [security2:error] [pid 796928:tid 797140] [client 14.176.244.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkChQAAAus"]
[Mon Jul 20 06:03:09.325501 2026] [security2:error] [pid 796567:tid 796765] [client 94.154.43.188:53142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.jhavoctattoos.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4OfbLfyzVz2SrjZpig5QAAAlg"]
[Mon Jul 20 06:03:09.336621 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC2QAAAxg"]
[Mon Jul 20 06:03:09.336766 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:61247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC2QAAAxg"]
[Mon Jul 20 06:03:09.342086 2026] [security2:error] [pid 796928:tid 797141] [client 94.154.43.229:48622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.jhavoctattoos.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4OfesTy9vX-htKvPkC2gAAAuw"]
[Mon Jul 20 06:03:09.411924 2026] [security2:error] [pid 796928:tid 797146] [client 14.225.17.146:55589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkClgAAAvE"], referer: http://dnsplumbing.com/wordpress
[Mon Jul 20 06:03:09.551847 2026] [security2:error] [pid 796928:tid 797073] [client 13.201.64.214:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC5AAAAqg"]
[Mon Jul 20 06:03:09.551991 2026] [security2:error] [pid 796928:tid 797073] [client 13.201.64.214:64974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC5AAAAqg"]
[Mon Jul 20 06:03:09.723807 2026] [security2:error] [pid 796928:tid 797107] [client 164.100.212.184:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC7wAAAso"]
[Mon Jul 20 06:03:09.723921 2026] [security2:error] [pid 796928:tid 797107] [client 164.100.212.184:52450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC7wAAAso"]
[Mon Jul 20 06:03:09.728709 2026] [security2:error] [pid 796567:tid 796611] [remote 57.141.18.47:50636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5370396"] [unique_id "al4OfbLfyzVz2SrjZpig-wACGCs"]
[Mon Jul 20 06:03:09.818816 2026] [security2:error] [pid 796567:tid 796735] [client 94.154.43.183:57760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.jhavoctattoos.com"] [uri "/.env"] [unique_id "al4OfbLfyzVz2SrjZpihBQAAAjo"]
[Mon Jul 20 06:03:09.872673 2026] [security2:error] [pid 796567:tid 796727] [client 82.102.18.182:41306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "al4OfbLfyzVz2SrjZpihCQAAAjI"]
[Mon Jul 20 06:03:09.900049 2026] [security2:error] [pid 796928:tid 797056] [remote 124.55.178.99:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OfesTy9vX-htKvPkC-wAC4n8"]
[Mon Jul 20 06:03:09.982971 2026] [security2:error] [pid 796928:tid 797156] [client 181.224.94.124:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkDAAAAAvs"]
[Mon Jul 20 06:03:09.983130 2026] [security2:error] [pid 796928:tid 797156] [client 181.224.94.124:17490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkDAAAAAvs"]
[Mon Jul 20 06:03:09.999364 2026] [security2:error] [pid 796567:tid 796808] [client 94.154.43.188:53150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jhavoctattoos.com"] [uri "/.env"] [unique_id "al4OfbLfyzVz2SrjZpihEQAAAoM"]
[Mon Jul 20 06:03:10.011909 2026] [security2:error] [pid 796567:tid 796753] [client 185.132.186.82:26797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/atomlib.php"] [unique_id "al4OfrLfyzVz2SrjZpihEwAAAkw"]
[Mon Jul 20 06:03:10.207664 2026] [security2:error] [pid 796567:tid 796759] [client 43.172.194.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfbLfyzVz2SrjZpihCAAAAlI"]
[Mon Jul 20 06:03:10.265494 2026] [security2:error] [pid 796928:tid 797066] [client 43.173.180.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfesTy9vX-htKvPkC-gAAAqE"]
[Mon Jul 20 06:03:10.293574 2026] [security2:error] [pid 796567:tid 796783] [client 43.172.195.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfbLfyzVz2SrjZpihDwAAAmo"]
[Mon Jul 20 06:03:10.318394 2026] [security2:error] [pid 796928:tid 796930] [remote 124.55.178.99:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OfusTy9vX-htKvPkDCQAC6QE"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:03:10.333674 2026] [security2:error] [pid 796928:tid 797116] [client 43.173.182.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfesTy9vX-htKvPkC_wAAAtM"]
[Mon Jul 20 06:03:10.432924 2026] [security2:error] [pid 796567:tid 796763] [client 57.141.18.61:40152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OebLfyzVz2SrjZpigIgACVjM"]
[Mon Jul 20 06:03:10.547915 2026] [security2:error] [pid 796928:tid 797093] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCjwAAArw"]
[Mon Jul 20 06:03:10.760784 2026] [security2:error] [pid 796567:tid 796765] [client 129.222.187.209:38341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfrLfyzVz2SrjZpihPwAAAlg"]
[Mon Jul 20 06:03:10.761388 2026] [security2:error] [pid 796928:tid 797068] [client 43.172.198.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfusTy9vX-htKvPkDCwAAAqM"]
[Mon Jul 20 06:03:10.765520 2026] [security2:error] [pid 796567:tid 796765] [client 129.222.187.209:38341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfrLfyzVz2SrjZpihPwAAAlg"]
[Mon Jul 20 06:03:11.174950 2026] [security2:error] [pid 796928:tid 797131] [client 82.102.18.182:55353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Of-sTy9vX-htKvPkDNQAAAuI"]
[Mon Jul 20 06:03:11.344054 2026] [security2:error] [pid 796567:tid 796749] [client 43.172.194.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfrLfyzVz2SrjZpihTwAAAkg"]
[Mon Jul 20 06:03:11.451777 2026] [security2:error] [pid 796928:tid 797083] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Of-sTy9vX-htKvPkDOwAAArI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:11.531104 2026] [security2:error] [pid 796928:tid 797142] [client 94.154.43.179:27382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sun.xdu.mybluehost.me"] [uri "/.env"] [unique_id "al4Of-sTy9vX-htKvPkDSQAAAu0"]
[Mon Jul 20 06:03:11.612551 2026] [security2:error] [pid 796567:tid 796675] [remote 8.217.108.67:3670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4Of7LfyzVz2SrjZpihZgACYGs"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:03:11.619233 2026] [security2:error] [pid 796928:tid 797177] [client 94.154.43.186:62686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.sun.xdu.mybluehost.me"] [uri "/.env"] [unique_id "al4Of-sTy9vX-htKvPkDTAAAAxA"]
[Mon Jul 20 06:03:11.811182 2026] [security2:error] [pid 796928:tid 797135] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Of-sTy9vX-htKvPkDTQAAAuY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:11.851777 2026] [security2:error] [pid 796928:tid 797122] [client 82.102.18.182:41338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Of-sTy9vX-htKvPkDWQAAAtk"]
[Mon Jul 20 06:03:11.891949 2026] [security2:error] [pid 796567:tid 796787] [client 50.116.65.227:49622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Of7LfyzVz2SrjZpihcAAAAm4"]
[Mon Jul 20 06:03:11.905086 2026] [security2:error] [pid 796567:tid 796811] [client 50.116.65.227:49628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Of7LfyzVz2SrjZpihcQAAAoY"]
[Mon Jul 20 06:03:11.921179 2026] [security2:error] [pid 796928:tid 797144] [client 185.132.186.55:20783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content.php"] [unique_id "al4Of-sTy9vX-htKvPkDWgAAAu8"]
[Mon Jul 20 06:03:12.484976 2026] [security2:error] [pid 796928:tid 797105] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OgOsTy9vX-htKvPkDcAAAAsg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:12.509633 2026] [security2:error] [pid 796928:tid 797121] [client 82.102.18.182:41344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4OgOsTy9vX-htKvPkDfgAAAtg"]
[Mon Jul 20 06:03:12.610293 2026] [security2:error] [pid 796928:tid 797095] [client 14.225.17.146:64425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4Of-sTy9vX-htKvPkDVwAAAr4"], referer: http://processorstudio.com/wordpress
[Mon Jul 20 06:03:12.742732 2026] [security2:error] [pid 796928:tid 797094] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OgOsTy9vX-htKvPkDiwAAAr0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:12.955721 2026] [security2:error] [pid 796928:tid 797173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OgOsTy9vX-htKvPkDjQAAAww"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:12.979523 2026] [security2:error] [pid 796928:tid 797185] [client 112.213.160.112:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OgOsTy9vX-htKvPkDlQAAAxg"]
[Mon Jul 20 06:03:12.979645 2026] [security2:error] [pid 796928:tid 797185] [client 112.213.160.112:8295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OgOsTy9vX-htKvPkDlQAAAxg"]
[Mon Jul 20 06:03:13.177967 2026] [security2:error] [pid 796928:tid 797148] [client 82.102.18.182:41348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "al4OgesTy9vX-htKvPkDpAAAAvM"]
[Mon Jul 20 06:03:13.183569 2026] [security2:error] [pid 796928:tid 797164] [client 27.96.94.195:38211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDmAAAAwM"]
[Mon Jul 20 06:03:13.222920 2026] [security2:error] [pid 796567:tid 796755] [client 158.173.166.181:36781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OgbLfyzVz2SrjZpihlwAAAk4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:13.269434 2026] [security2:error] [pid 796928:tid 797167] [client 14.225.17.146:56365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4OfusTy9vX-htKvPkDAQAAAwY"], referer: http://vinovinhowine.com/wordpress
[Mon Jul 20 06:03:13.325294 2026] [security2:error] [pid 796928:tid 797015] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDrAACrlY"]
[Mon Jul 20 06:03:13.325454 2026] [security2:error] [pid 796928:tid 797079] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDrAACrlY"]
[Mon Jul 20 06:03:13.554851 2026] [security2:error] [pid 796928:tid 797141] [client 86.98.90.58:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDugAAAuw"]
[Mon Jul 20 06:03:13.554965 2026] [security2:error] [pid 796928:tid 797141] [client 86.98.90.58:46484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDugAAAuw"]
[Mon Jul 20 06:03:13.580397 2026] [security2:error] [pid 796928:tid 797149] [client 14.225.17.146:50798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4OgesTy9vX-htKvPkDuAAAAvQ"], referer: https://processorstudio.com/wordpress
[Mon Jul 20 06:03:13.666966 2026] [security2:error] [pid 796567:tid 796732] [client 150.228.148.150:55521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OgbLfyzVz2SrjZpihpQAAAjc"]
[Mon Jul 20 06:03:13.667063 2026] [security2:error] [pid 796567:tid 796732] [client 150.228.148.150:55521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OgbLfyzVz2SrjZpihpQAAAjc"]
[Mon Jul 20 06:03:13.806570 2026] [security2:error] [pid 796567:tid 796770] [client 82.102.18.182:59349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4OgbLfyzVz2SrjZpihqgAAAl0"]
[Mon Jul 20 06:03:13.870055 2026] [security2:error] [pid 796928:tid 797079] [client 185.132.186.56:36313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/chosen.php"] [unique_id "al4OgesTy9vX-htKvPkD1AAAAq4"]
[Mon Jul 20 06:03:13.932892 2026] [security2:error] [pid 796567:tid 796785] [client 77.110.127.138:54727] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OgbLfyzVz2SrjZpihrAAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:14.042295 2026] [security2:error] [pid 796928:tid 797094] [client 74.208.214.194:59732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OgusTy9vX-htKvPkD3AAAAr0"]
[Mon Jul 20 06:03:14.045206 2026] [security2:error] [pid 796928:tid 797061] [client 57.141.18.76:31316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkCtgACnEo"]
[Mon Jul 20 06:03:14.125511 2026] [security2:error] [pid 796928:tid 797120] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OgusTy9vX-htKvPkD3wAAAtc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:14.164527 2026] [security2:error] [pid 796928:tid 796966] [remote 216.73.216.55:53420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4OgusTy9vX-htKvPkD5QACsSU"]
[Mon Jul 20 06:03:14.441938 2026] [security2:error] [pid 796928:tid 797153] [client 82.102.18.182:41368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "al4OgusTy9vX-htKvPkD6gAAAvg"]
[Mon Jul 20 06:03:14.616692 2026] [core:error] [pid 796928:tid 797160] [client 93.159.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:14.616724 2026] [core:error] [pid 796928:tid 797160] [client 93.159.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:14.850041 2026] [security2:error] [pid 796567:tid 796747] [client 57.141.18.108:43966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OfbLfyzVz2SrjZpig7wACRhg"]
[Mon Jul 20 06:03:14.957656 2026] [security2:error] [pid 796567:tid 796627] [remote 173.212.252.15:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OgrLfyzVz2SrjZpih0QACYjs"]
[Mon Jul 20 06:03:15.115199 2026] [security2:error] [pid 796928:tid 797177] [client 82.102.18.182:41370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4Og-sTy9vX-htKvPkEBwAAAxA"]
[Mon Jul 20 06:03:15.248121 2026] [security2:error] [pid 796567:tid 796640] [remote 173.212.252.15:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Og7LfyzVz2SrjZpih3gACTEg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:03:15.391248 2026] [security2:error] [pid 796928:tid 797150] [client 47.31.86.100:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Og-sTy9vX-htKvPkEFgAAAvU"]
[Mon Jul 20 06:03:15.391406 2026] [security2:error] [pid 796928:tid 797150] [client 47.31.86.100:56679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Og-sTy9vX-htKvPkEFgAAAvU"]
[Mon Jul 20 06:03:15.742542 2026] [security2:error] [pid 796928:tid 797152] [client 82.102.18.182:31860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Og-sTy9vX-htKvPkEKQAAAvc"]
[Mon Jul 20 06:03:15.820026 2026] [security2:error] [pid 796928:tid 797098] [client 185.132.186.80:32543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Renderer/about.php"] [unique_id "al4Og-sTy9vX-htKvPkELAAAAsE"]
[Mon Jul 20 06:03:16.068138 2026] [security2:error] [pid 796567:tid 796584] [remote 188.166.241.141:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OhLLfyzVz2SrjZpih_gACehA"]
[Mon Jul 20 06:03:16.084297 2026] [security2:error] [pid 796567:tid 796773] [client 15.229.42.239:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpih_QAAAmA"]
[Mon Jul 20 06:03:16.084411 2026] [security2:error] [pid 796567:tid 796773] [client 15.229.42.239:61276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpih_QAAAmA"]
[Mon Jul 20 06:03:16.124604 2026] [security2:error] [pid 796567:tid 796796] [client 57.141.18.58:58054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OfrLfyzVz2SrjZpihNgACdyI"]
[Mon Jul 20 06:03:16.245719 2026] [security2:error] [pid 796567:tid 796597] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpiiBwACFR0"]
[Mon Jul 20 06:03:16.245889 2026] [security2:error] [pid 796567:tid 796698] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpiiBwACFR0"]
[Mon Jul 20 06:03:16.262176 2026] [security2:error] [pid 796928:tid 797139] [client 115.246.21.170:28828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OhOsTy9vX-htKvPkEPwAAAuo"]
[Mon Jul 20 06:03:16.262274 2026] [security2:error] [pid 796928:tid 797139] [client 115.246.21.170:28828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OhOsTy9vX-htKvPkEPwAAAuo"]
[Mon Jul 20 06:03:16.319729 2026] [security2:error] [pid 796567:tid 796809] [client 14.225.17.146:59225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4Og7LfyzVz2SrjZpih-AAAAoQ"], referer: http://backandneckpainrelieflaceychiropractor.com/wordpress
[Mon Jul 20 06:03:16.326969 2026] [security2:error] [pid 796928:tid 796932] [remote 188.40.28.4:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4OhOsTy9vX-htKvPkERQADBQM"]
[Mon Jul 20 06:03:16.414363 2026] [security2:error] [pid 796567:tid 796811] [client 82.102.18.182:41396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4OhLLfyzVz2SrjZpiiEQAAAoY"]
[Mon Jul 20 06:03:16.474450 2026] [security2:error] [pid 796567:tid 796572] [remote 188.166.241.141:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OhLLfyzVz2SrjZpiiEgACeQQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:03:16.535198 2026] [security2:error] [pid 796928:tid 796984] [remote 188.40.28.4:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4OhOsTy9vX-htKvPkESAAC4zc"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:03:16.619681 2026] [security2:error] [pid 796928:tid 797058] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OhOsTy9vX-htKvPkESQAAApk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:16.948202 2026] [security2:error] [pid 796567:tid 796734] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OhLLfyzVz2SrjZpiiLQAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:17.085757 2026] [security2:error] [pid 796567:tid 796762] [client 82.102.18.182:9982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4OhbLfyzVz2SrjZpiiMQAAAlU"]
[Mon Jul 20 06:03:17.217210 2026] [security2:error] [pid 796567:tid 796662] [remote 182.77.62.24:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4OhbLfyzVz2SrjZpiiNgACKl4"]
[Mon Jul 20 06:03:17.231621 2026] [security2:error] [pid 796928:tid 797181] [client 14.225.17.146:59208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4Og-sTy9vX-htKvPkELwAAAxQ"], referer: http://partnerselectricalllc.com/wordpress
[Mon Jul 20 06:03:17.421024 2026] [security2:error] [pid 796928:tid 797131] [client 103.95.123.246:17963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OhesTy9vX-htKvPkEYAAAAuI"]
[Mon Jul 20 06:03:17.421156 2026] [security2:error] [pid 796928:tid 797131] [client 103.95.123.246:17963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OhesTy9vX-htKvPkEYAAAAuI"]
[Mon Jul 20 06:03:17.679562 2026] [security2:error] [pid 796567:tid 796810] [client 106.192.104.4:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OhbLfyzVz2SrjZpiiRQAAAoU"]
[Mon Jul 20 06:03:17.679695 2026] [security2:error] [pid 796567:tid 796810] [client 106.192.104.4:55473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OhbLfyzVz2SrjZpiiRQAAAoU"]
[Mon Jul 20 06:03:17.761074 2026] [security2:error] [pid 796928:tid 797115] [client 82.102.18.182:48540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4OhesTy9vX-htKvPkEcgAAAtI"]
[Mon Jul 20 06:03:17.817019 2026] [security2:error] [pid 796928:tid 797070] [client 57.141.18.112:28244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OgOsTy9vX-htKvPkDaQACpRQ"]
[Mon Jul 20 06:03:18.001992 2026] [security2:error] [pid 796928:tid 797133] [client 178.152.178.232:37190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEewAAAuQ"]
[Mon Jul 20 06:03:18.002144 2026] [security2:error] [pid 796928:tid 797133] [client 178.152.178.232:37190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEewAAAuQ"]
[Mon Jul 20 06:03:18.041260 2026] [security2:error] [pid 796928:tid 797140] [client 185.132.186.86:33267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/index.php"] [unique_id "al4OhusTy9vX-htKvPkEfQAAAus"]
[Mon Jul 20 06:03:18.255336 2026] [security2:error] [pid 796928:tid 797068] [client 41.173.37.102:9289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEiQAAAqM"]
[Mon Jul 20 06:03:18.255494 2026] [security2:error] [pid 796928:tid 797068] [client 41.173.37.102:9289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEiQAAAqM"]
[Mon Jul 20 06:03:18.310554 2026] [security2:error] [pid 796928:tid 797121] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OhusTy9vX-htKvPkEhwAAAtg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:18.339931 2026] [security2:error] [pid 796567:tid 796765] [client 14.225.17.146:59989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4OhLLfyzVz2SrjZpiiKAAAAlg"], referer: http://slutilities.com/wordpress
[Mon Jul 20 06:03:18.397780 2026] [security2:error] [pid 796928:tid 797141] [client 82.102.18.182:48542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "al4OhusTy9vX-htKvPkEkgAAAuw"]
[Mon Jul 20 06:03:18.448777 2026] [security2:error] [pid 796567:tid 796668] [remote 182.77.62.24:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4OhrLfyzVz2SrjZpiiXAACLmQ"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:03:18.913971 2026] [security2:error] [pid 796928:tid 796967] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEqgAC-SY"]
[Mon Jul 20 06:03:18.914147 2026] [security2:error] [pid 796928:tid 797154] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEqgAC-SY"]
[Mon Jul 20 06:03:19.018605 2026] [security2:error] [pid 796928:tid 797155] [client 14.225.17.146:50152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4OhusTy9vX-htKvPkEpAAAAvo"], referer: http://thesoloceos.com/wordpress
[Mon Jul 20 06:03:19.060875 2026] [security2:error] [pid 796928:tid 797132] [client 82.102.18.182:48546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4Oh-sTy9vX-htKvPkEtAAAAuM"]
[Mon Jul 20 06:03:19.170028 2026] [security2:error] [pid 796928:tid 797108] [client 210.212.97.243:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Oh-sTy9vX-htKvPkEtgAAAss"]
[Mon Jul 20 06:03:19.170172 2026] [security2:error] [pid 796928:tid 797108] [client 210.212.97.243:10431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Oh-sTy9vX-htKvPkEtgAAAss"]
[Mon Jul 20 06:03:19.179919 2026] [security2:error] [pid 796928:tid 797061] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Oh-sTy9vX-htKvPkEtQAAApw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:19.621283 2026] [security2:error] [pid 796567:tid 796709] [client 216.73.216.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.mollycahill.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiifwAAAiA"]
[Mon Jul 20 06:03:19.747159 2026] [security2:error] [pid 796567:tid 796718] [client 82.102.18.182:35907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Oh7LfyzVz2SrjZpiihgAAAik"]
[Mon Jul 20 06:03:19.861166 2026] [security2:error] [pid 796567:tid 796737] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4Oh7LfyzVz2SrjZpiiiwAAAjw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:19.952559 2026] [security2:error] [pid 796928:tid 797092] [client 52.109.44.112:9477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Oh-sTy9vX-htKvPkE2AAAArs"]
[Mon Jul 20 06:03:19.984687 2026] [security2:error] [pid 796567:tid 796776] [client 185.132.186.95:58541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/about.php"] [unique_id "al4Oh7LfyzVz2SrjZpiikgAAAmM"]
[Mon Jul 20 06:03:20.029077 2026] [security2:error] [pid 796567:tid 796808] [client 14.225.17.146:53969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiijAAAAoM"], referer: https://thesoloceos.com/wordpress
[Mon Jul 20 06:03:20.090246 2026] [security2:error] [pid 796928:tid 797181] [client 52.109.44.112:9477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OiOsTy9vX-htKvPkE3gAAAxQ"]
[Mon Jul 20 06:03:20.219405 2026] [security2:error] [pid 796567:tid 796801] [client 103.149.16.77:61745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiioQAAAnw"]
[Mon Jul 20 06:03:20.219584 2026] [security2:error] [pid 796567:tid 796801] [client 103.149.16.77:61745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiioQAAAnw"]
[Mon Jul 20 06:03:20.261633 2026] [security2:error] [pid 796928:tid 797089] [client 164.100.212.184:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE4gAAArg"]
[Mon Jul 20 06:03:20.261758 2026] [security2:error] [pid 796928:tid 797089] [client 164.100.212.184:53015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE4gAAArg"]
[Mon Jul 20 06:03:20.381635 2026] [security2:error] [pid 796567:tid 796736] [client 65.1.132.125:27108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiiqwAAAjs"]
[Mon Jul 20 06:03:20.381731 2026] [security2:error] [pid 796567:tid 796736] [client 65.1.132.125:27108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiiqwAAAjs"]
[Mon Jul 20 06:03:20.384702 2026] [security2:error] [pid 796928:tid 797137] [client 82.102.18.182:48568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4OiOsTy9vX-htKvPkE6QAAAug"]
[Mon Jul 20 06:03:20.423530 2026] [security2:error] [pid 796928:tid 797148] [client 52.111.227.28:4801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4OiOsTy9vX-htKvPkE6wAAAvM"]
[Mon Jul 20 06:03:20.476440 2026] [security2:error] [pid 796928:tid 797112] [client 52.111.227.28:4801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OiOsTy9vX-htKvPkE7wAAAs8"]
[Mon Jul 20 06:03:20.572029 2026] [security2:error] [pid 796928:tid 797125] [client 181.224.94.124:20937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE9AAAAtw"]
[Mon Jul 20 06:03:20.572168 2026] [security2:error] [pid 796928:tid 797125] [client 181.224.94.124:20937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE9AAAAtw"]
[Mon Jul 20 06:03:20.650662 2026] [security2:error] [pid 796928:tid 797097] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiOsTy9vX-htKvPkE5wAAAsA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:20.689967 2026] [security2:error] [pid 796928:tid 797178] [client 50.116.65.227:41966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OiOsTy9vX-htKvPkE-QAAAxE"]
[Mon Jul 20 06:03:20.699525 2026] [security2:error] [pid 796928:tid 797180] [client 50.116.65.227:41984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OiOsTy9vX-htKvPkE_AAAAxM"]
[Mon Jul 20 06:03:20.939391 2026] [security2:error] [pid 796928:tid 797087] [client 57.141.18.100:61980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Og-sTy9vX-htKvPkEDAACtjI"]
[Mon Jul 20 06:03:20.957007 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiOsTy9vX-htKvPkFAgAAAtg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:21.008688 2026] [security2:error] [pid 796928:tid 797126] [client 82.102.18.182:48582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4OiesTy9vX-htKvPkFCwAAAt0"]
[Mon Jul 20 06:03:21.354208 2026] [security2:error] [pid 796928:tid 797092] [client 72.255.10.154:26242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFEwAAArs"]
[Mon Jul 20 06:03:21.354345 2026] [security2:error] [pid 796928:tid 797092] [client 72.255.10.154:26242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFEwAAArs"]
[Mon Jul 20 06:03:21.435844 2026] [security2:error] [pid 796928:tid 797023] [remote 40.77.167.28:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4OiesTy9vX-htKvPkFFwADCV4"]
[Mon Jul 20 06:03:21.490894 2026] [security2:error] [pid 796928:tid 797151] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OiesTy9vX-htKvPkFGAAAAvY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:21.529924 2026] [security2:error] [pid 796928:tid 797162] [client 129.222.187.209:50079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHQAAAwE"]
[Mon Jul 20 06:03:21.530071 2026] [security2:error] [pid 796928:tid 797162] [client 129.222.187.209:50079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHQAAAwE"]
[Mon Jul 20 06:03:21.588109 2026] [security2:error] [pid 796928:tid 797134] [client 129.222.187.209:45284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHgAAAuU"]
[Mon Jul 20 06:03:21.603516 2026] [security2:error] [pid 796928:tid 797134] [client 129.222.187.209:45284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHgAAAuU"]
[Mon Jul 20 06:03:21.651567 2026] [security2:error] [pid 796567:tid 796733] [client 14.225.17.146:53962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiiigAAAjg"], referer: http://swafforddetailing.com/wordpress
[Mon Jul 20 06:03:21.737660 2026] [security2:error] [pid 796928:tid 797026] [remote 42.200.84.61:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OiesTy9vX-htKvPkFIwADD2E"]
[Mon Jul 20 06:03:21.944404 2026] [security2:error] [pid 796928:tid 797079] [client 185.132.186.63:55155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/customize.php"] [unique_id "al4OiesTy9vX-htKvPkFMAAAAq4"]
[Mon Jul 20 06:03:22.005316 2026] [security2:error] [pid 796928:tid 797169] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OiesTy9vX-htKvPkFLwAAAwg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:22.043211 2026] [security2:error] [pid 796567:tid 796603] [remote 173.249.4.11:24742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4OirLfyzVz2SrjZpii5gACZyM"]
[Mon Jul 20 06:03:22.067287 2026] [security2:error] [pid 796928:tid 797171] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiesTy9vX-htKvPkFKAAAAwo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:22.100010 2026] [security2:error] [pid 796928:tid 797022] [remote 42.200.84.61:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OiusTy9vX-htKvPkFOgACy10"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:03:22.232218 2026] [security2:error] [pid 796928:tid 797105] [client 14.182.195.220:51964] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OiusTy9vX-htKvPkFPwAAAsg"]
[Mon Jul 20 06:03:22.296769 2026] [security2:error] [pid 796928:tid 797009] [remote 130.185.118.215:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OiusTy9vX-htKvPkFRQACvFA"]
[Mon Jul 20 06:03:22.403511 2026] [security2:error] [pid 796567:tid 796728] [client 57.141.18.29:37344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OhLLfyzVz2SrjZpiiGgACMzM"]
[Mon Jul 20 06:03:22.480336 2026] [security2:error] [pid 796928:tid 797005] [remote 130.185.118.215:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OiusTy9vX-htKvPkFSgACz0w"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 06:03:22.578471 2026] [security2:error] [pid 796928:tid 797035] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4OiusTy9vX-htKvPkFUwACymo"]
[Mon Jul 20 06:03:22.578630 2026] [security2:error] [pid 796928:tid 797035] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.aws/credentials"] [unique_id "al4OiusTy9vX-htKvPkFVgACymo"]
[Mon Jul 20 06:03:22.578646 2026] [security2:error] [pid 796928:tid 797107] [client 34.101.165.107:50324] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jenfarley.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4OiusTy9vX-htKvPkFUwACymo"]
[Mon Jul 20 06:03:22.614233 2026] [security2:error] [pid 796567:tid 796775] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpii8QAAAmI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:22.701707 2026] [security2:error] [pid 796567:tid 796583] [remote 173.249.4.11:24742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4OirLfyzVz2SrjZpijBwACbQ8"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 06:03:22.831964 2026] [security2:error] [pid 796928:tid 797167] [client 57.141.18.30:48660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OhesTy9vX-htKvPkEVQADBiA"]
[Mon Jul 20 06:03:22.881874 2026] [security2:error] [pid 796928:tid 797172] [client 98.94.182.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFZwADC3Y"]
[Mon Jul 20 06:03:23.084430 2026] [security2:error] [pid 796567:tid 796761] [client 74.7.227.179:45974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijFAACVE0"], referer: https://tejasenvironmental.com/p=247175
[Mon Jul 20 06:03:23.124028 2026] [security2:error] [pid 796567:tid 796738] [client 77.110.127.138:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4Oi7LfyzVz2SrjZpijJQAAAj0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:23.184564 2026] [security2:error] [pid 796567:tid 796773] [client 220.181.108.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijDQAAAmA"]
[Mon Jul 20 06:03:23.209159 2026] [security2:error] [pid 796928:tid 797091] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFcAAAAro"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:23.328518 2026] [security2:error] [pid 796928:tid 797053] [remote 72.167.132.114:44736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Oi-sTy9vX-htKvPkFfwAC2Hw"]
[Mon Jul 20 06:03:23.328835 2026] [security2:error] [pid 796928:tid 797121] [client 72.167.132.114:44736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Oi-sTy9vX-htKvPkFfwAC2Hw"]
[Mon Jul 20 06:03:23.335025 2026] [security2:error] [pid 796928:tid 797050] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.env.example"] [unique_id "al4Oi-sTy9vX-htKvPkFgAACynk"]
[Mon Jul 20 06:03:23.335196 2026] [security2:error] [pid 796928:tid 797107] [client 34.101.165.107:50324] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jenfarley.com"] [uri "/.env.example"] [unique_id "al4Oi-sTy9vX-htKvPkFgAACynk"]
[Mon Jul 20 06:03:23.336952 2026] [security2:error] [pid 796928:tid 797054] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env"] [unique_id "al4Oi-sTy9vX-htKvPkFgQACyn0"]
[Mon Jul 20 06:03:23.455215 2026] [security2:error] [pid 796567:tid 796633] [remote 160.187.68.132:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Oi7LfyzVz2SrjZpijLQACJUE"]
[Mon Jul 20 06:03:23.511360 2026] [core:error] [pid 796928:tid 797080] [client 14.225.17.146:59058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wordpress
[Mon Jul 20 06:03:23.511390 2026] [core:error] [pid 796928:tid 797080] [client 14.225.17.146:59058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wordpress
[Mon Jul 20 06:03:23.648286 2026] [security2:error] [pid 796567:tid 796818] [client 14.225.17.146:58869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijKwAAAo0"], referer: http://taskidsvirginia.com/wordpress
[Mon Jul 20 06:03:23.726321 2026] [security2:error] [pid 796567:tid 796752] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijMwAAAks"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:23.744948 2026] [security2:error] [pid 796567:tid 796712] [client 112.213.160.112:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oi7LfyzVz2SrjZpijPAAAAiM"]
[Mon Jul 20 06:03:23.745113 2026] [security2:error] [pid 796567:tid 796712] [client 112.213.160.112:8646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oi7LfyzVz2SrjZpijPAAAAiM"]
[Mon Jul 20 06:03:23.883782 2026] [security2:error] [pid 796928:tid 797139] [client 185.132.186.55:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/license.php"] [unique_id "al4Oi-sTy9vX-htKvPkFoQAAAuo"]
[Mon Jul 20 06:03:24.044347 2026] [security2:error] [pid 796928:tid 796930] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFowAC5AE"]
[Mon Jul 20 06:03:24.044510 2026] [security2:error] [pid 796928:tid 797133] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFowAC5AE"]
[Mon Jul 20 06:03:24.054067 2026] [security2:error] [pid 796928:tid 797174] [client 57.141.18.33:64002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OhusTy9vX-htKvPkElAADDUM"]
[Mon Jul 20 06:03:24.176602 2026] [security2:error] [pid 796567:tid 796798] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijQQAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:24.222576 2026] [security2:error] [pid 796928:tid 797107] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFUQACym4"]
[Mon Jul 20 06:03:24.238870 2026] [security2:error] [pid 796928:tid 797098] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYAAAAsE"]
[Mon Jul 20 06:03:24.261840 2026] [security2:error] [pid 796567:tid 796750] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijAwAAAkk"]
[Mon Jul 20 06:03:24.261980 2026] [security2:error] [pid 796928:tid 797134] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYgAAAuU"]
[Mon Jul 20 06:03:24.269592 2026] [security2:error] [pid 796928:tid 797078] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYQAAAq0"]
[Mon Jul 20 06:03:24.272976 2026] [security2:error] [pid 796567:tid 796783] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijAgAAAmo"]
[Mon Jul 20 06:03:24.274516 2026] [security2:error] [pid 796928:tid 797125] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYwAAAtw"]
[Mon Jul 20 06:03:24.275435 2026] [security2:error] [pid 796567:tid 796706] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijBQAAAh0"]
[Mon Jul 20 06:03:24.343784 2026] [security2:error] [pid 796928:tid 797172] [client 150.228.148.150:12768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFsQAAAws"]
[Mon Jul 20 06:03:24.343954 2026] [security2:error] [pid 796928:tid 797172] [client 150.228.148.150:12768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFsQAAAws"]
[Mon Jul 20 06:03:24.400540 2026] [security2:error] [pid 796928:tid 797175] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFagAAAw4"]
[Mon Jul 20 06:03:24.424188 2026] [security2:error] [pid 796567:tid 796636] [remote 160.187.68.132:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4OjLLfyzVz2SrjZpijVwACHkQ"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:03:24.438000 2026] [security2:error] [pid 796928:tid 797152] [client 27.96.94.195:37700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFrwAAAvc"]
[Mon Jul 20 06:03:24.693058 2026] [security2:error] [pid 796928:tid 797088] [client 46.110.96.34:5298] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OjOsTy9vX-htKvPkFxAAAArc"]
[Mon Jul 20 06:03:24.918142 2026] [security2:error] [pid 796567:tid 796810] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/robots.txt"] [unique_id "al4OjLLfyzVz2SrjZpijYwAAAoU"]
[Mon Jul 20 06:03:25.001806 2026] [security2:error] [pid 796567:tid 796742] [client 57.141.18.64:42784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiifgACQXQ"]
[Mon Jul 20 06:03:25.285411 2026] [security2:error] [pid 796928:tid 796931] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.bak"] [unique_id "al4OjesTy9vX-htKvPkF3gACygI"]
[Mon Jul 20 06:03:25.288543 2026] [security2:error] [pid 796567:tid 796740] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/"] [unique_id "al4OjbLfyzVz2SrjZpijbwAAAj8"]
[Mon Jul 20 06:03:25.493737 2026] [security2:error] [pid 796928:tid 797121] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF2QAAAtg"]
[Mon Jul 20 06:03:25.507147 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF2AAAApw"]
[Mon Jul 20 06:03:25.515874 2026] [security2:error] [pid 796928:tid 797064] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OjesTy9vX-htKvPkF5AAAAp8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:25.710257 2026] [security2:error] [pid 796928:tid 797144] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF5QAAAu8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:25.799422 2026] [security2:error] [pid 796928:tid 797098] [client 47.31.86.100:57121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OjesTy9vX-htKvPkF9AAAAsE"]
[Mon Jul 20 06:03:25.818302 2026] [security2:error] [pid 796928:tid 797098] [client 47.31.86.100:57121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OjesTy9vX-htKvPkF9AAAAsE"]
[Mon Jul 20 06:03:25.837496 2026] [security2:error] [pid 796567:tid 796793] [client 185.132.186.62:26931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al4OjbLfyzVz2SrjZpijgQAAAnQ"]
[Mon Jul 20 06:03:25.837495 2026] [security2:error] [pid 796567:tid 796818] [client 20.200.215.118:40006] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "elevator-data.com"] [uri "/wp-comments-post.php"] [unique_id "al4OjbLfyzVz2SrjZpijfAAAAo0"]
[Mon Jul 20 06:03:25.879358 2026] [security2:error] [pid 796567:tid 796818] [client 20.200.215.118:40006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "elevator-data.com"] [uri "/wp-comments-post.php"] [unique_id "al4OjbLfyzVz2SrjZpijfAAAAo0"]
[Mon Jul 20 06:03:26.007168 2026] [security2:error] [pid 796567:tid 796749] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjbLfyzVz2SrjZpijhQACSHg"]
[Mon Jul 20 06:03:26.007201 2026] [security2:error] [pid 796567:tid 796749] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjbLfyzVz2SrjZpijhQACSHg"]
[Mon Jul 20 06:03:26.058758 2026] [security2:error] [pid 796928:tid 797127] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OjesTy9vX-htKvPkGAAAAAt4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:26.269349 2026] [security2:error] [pid 796928:tid 797092] [client 14.225.17.146:59081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4OjOsTy9vX-htKvPkFwwAAArs"], referer: http://cloudspacesgroup.com/wordpress
[Mon Jul 20 06:03:26.294030 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjusTy9vX-htKvPkGBgAC9RA"], referer: http://aleishapenny.ca/wordpress
[Mon Jul 20 06:03:26.664198 2026] [security2:error] [pid 796567:tid 796792] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjrLfyzVz2SrjZpijmgACc24"]
[Mon Jul 20 06:03:26.802584 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:28848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijpAAAAh4"]
[Mon Jul 20 06:03:26.802676 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:28848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijpAAAAh4"]
[Mon Jul 20 06:03:26.855999 2026] [security2:error] [pid 796567:tid 796760] [client 114.119.153.132:62947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/resource/enhancing-low-carbon-development-greening-economy-policy-dialogue-advisory-services"] [unique_id "al4OjrLfyzVz2SrjZpijpgAAAlM"], referer: http://www.lowemissionsasia.org/resources?qt-resources=1
[Mon Jul 20 06:03:26.904181 2026] [security2:error] [pid 796567:tid 796706] [client 115.246.21.170:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijqgAAAh0"]
[Mon Jul 20 06:03:26.904338 2026] [security2:error] [pid 796567:tid 796706] [client 115.246.21.170:33509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijqgAAAh0"]
[Mon Jul 20 06:03:27.139255 2026] [security2:error] [pid 796928:tid 797120] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGJwAC10o"], referer: https://aleishapenny.ca/wordpress
[Mon Jul 20 06:03:27.167318 2026] [security2:error] [pid 796928:tid 796972] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/api/.env"] [unique_id "al4Oj-sTy9vX-htKvPkGLQAC3is"]
[Mon Jul 20 06:03:27.201474 2026] [security2:error] [pid 796928:tid 797168] [client 57.141.18.45:20528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OiesTy9vX-htKvPkFLQADB2c"]
[Mon Jul 20 06:03:27.321689 2026] [security2:error] [pid 796567:tid 796775] [client 14.225.17.146:60223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4OjrLfyzVz2SrjZpijiwAAAmI"], referer: http://musichaven.info/wordpress
[Mon Jul 20 06:03:27.326221 2026] [security2:error] [pid 796928:tid 796954] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.old"] [unique_id "al4Oj-sTy9vX-htKvPkGOQADAhk"]
[Mon Jul 20 06:03:27.354600 2026] [security2:error] [pid 796928:tid 797156] [client 14.225.17.146:64398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF1gAAAvs"], referer: http://fineartsfactory.net/wordpress
[Mon Jul 20 06:03:27.560538 2026] [security2:error] [pid 796567:tid 796757] [client 77.110.127.138:54683] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4Oj7LfyzVz2SrjZpijwQAAAlA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:27.618356 2026] [security2:error] [pid 796928:tid 796974] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/config/.env"] [unique_id "al4Oj-sTy9vX-htKvPkGRgADAi0"]
[Mon Jul 20 06:03:27.643243 2026] [security2:error] [pid 796928:tid 796951] [remote 176.56.118.182:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Oj-sTy9vX-htKvPkGRwAC-RY"]
[Mon Jul 20 06:03:27.770953 2026] [security2:error] [pid 796928:tid 797119] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGPQAAAtY"]
[Mon Jul 20 06:03:27.787118 2026] [security2:error] [pid 796928:tid 797136] [client 185.132.186.60:37317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/lock.php"] [unique_id "al4Oj-sTy9vX-htKvPkGTwAAAuc"]
[Mon Jul 20 06:03:27.805876 2026] [security2:error] [pid 796928:tid 796959] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/backend/.env"] [unique_id "al4Oj-sTy9vX-htKvPkGUAAC3x4"]
[Mon Jul 20 06:03:27.861128 2026] [security2:error] [pid 796928:tid 797080] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGMgACrwA"]
[Mon Jul 20 06:03:27.874913 2026] [security2:error] [pid 796928:tid 796977] [remote 176.56.118.182:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Oj-sTy9vX-htKvPkGUwAC7TA"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:03:27.897231 2026] [cgid:error] [pid 796567:tid 796748] [client 199.45.155.92:56808] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: https://www.website-fa490990.threethirds.co:443/cgi-bin
[Mon Jul 20 06:03:27.934083 2026] [security2:error] [pid 796928:tid 796987] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.backup"] [unique_id "al4Oj-sTy9vX-htKvPkGVgAC6zo"]
[Mon Jul 20 06:03:27.996099 2026] [security2:error] [pid 796928:tid 796984] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/graphql"] [unique_id "al4Oj-sTy9vX-htKvPkGXgADETc"]
[Mon Jul 20 06:03:27.998219 2026] [security2:error] [pid 796928:tid 797120] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oj-sTy9vX-htKvPkGVQAAAtc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:28.206502 2026] [security2:error] [pid 796928:tid 797184] [client 14.225.17.146:56080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4OkOsTy9vX-htKvPkGYgAAAxc"], referer: https://musichaven.info/wordpress
[Mon Jul 20 06:03:28.388074 2026] [security2:error] [pid 796928:tid 797133] [client 103.95.123.246:18648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGbQAAAuQ"]
[Mon Jul 20 06:03:28.388237 2026] [security2:error] [pid 796928:tid 797133] [client 103.95.123.246:18648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGbQAAAuQ"]
[Mon Jul 20 06:03:28.427080 2026] [security2:error] [pid 796928:tid 797155] [client 86.98.90.58:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGcQAAAvo"]
[Mon Jul 20 06:03:28.427188 2026] [security2:error] [pid 796928:tid 797155] [client 86.98.90.58:47174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGcQAAAvo"]
[Mon Jul 20 06:03:28.511153 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:47578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdQAAAuw"]
[Mon Jul 20 06:03:28.521162 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:47578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdQAAAuw"]
[Mon Jul 20 06:03:28.594547 2026] [security2:error] [pid 796928:tid 797121] [client 178.152.178.232:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdwAAAtg"]
[Mon Jul 20 06:03:28.594693 2026] [security2:error] [pid 796928:tid 797121] [client 178.152.178.232:37154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdwAAAtg"]
[Mon Jul 20 06:03:28.618685 2026] [security2:error] [pid 796928:tid 797069] [client 46.110.96.34:36243] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OkOsTy9vX-htKvPkGeQAAAqQ"]
[Mon Jul 20 06:03:28.920575 2026] [security2:error] [pid 796928:tid 797137] [client 41.173.37.102:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGiQAAAug"]
[Mon Jul 20 06:03:28.920687 2026] [security2:error] [pid 796928:tid 797137] [client 41.173.37.102:9705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGiQAAAug"]
[Mon Jul 20 06:03:28.929699 2026] [security2:error] [pid 796928:tid 797080] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OkOsTy9vX-htKvPkGfwAAAq8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:29.023394 2026] [security2:error] [pid 796567:tid 796819] [client 57.141.18.15:23080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijHAACjgo"]
[Mon Jul 20 06:03:29.051706 2026] [security2:error] [pid 796928:tid 797113] [client 77.110.127.138:54769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4OkesTy9vX-htKvPkGjgAAAtA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:29.055110 2026] [security2:error] [pid 796928:tid 797119] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkOsTy9vX-htKvPkGegAC1j8"]
[Mon Jul 20 06:03:29.369708 2026] [security2:error] [pid 796567:tid 796785] [client 57.141.18.43:25530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OjLLfyzVz2SrjZpijTgACbEw"]
[Mon Jul 20 06:03:29.431845 2026] [security2:error] [pid 796567:tid 796583] [remote 57.141.18.98:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4OkbLfyzVz2SrjZpikBQACWw8"]
[Mon Jul 20 06:03:29.433380 2026] [security2:error] [pid 796928:tid 796964] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/api/graphql"] [unique_id "al4OkesTy9vX-htKvPkGmwACnCM"]
[Mon Jul 20 06:03:29.467311 2026] [authz_core:error] [pid 796928:tid 797132] [client 34.101.165.107:0] AH01630: client denied by server configuration: /home2/laughio2/public_html/jenfarley/.htpasswd
[Mon Jul 20 06:03:29.581514 2026] [security2:error] [pid 796928:tid 797004] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGsQAC7Es"]
[Mon Jul 20 06:03:29.581835 2026] [security2:error] [pid 796928:tid 797141] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGsQAC7Es"]
[Mon Jul 20 06:03:29.640980 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGtQAAAws"]
[Mon Jul 20 06:03:29.641117 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGtQAAAws"]
[Mon Jul 20 06:03:29.741708 2026] [security2:error] [pid 796928:tid 797185] [client 185.132.186.96:29309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/gold.php"] [unique_id "al4OkesTy9vX-htKvPkGvAAAAxg"]
[Mon Jul 20 06:03:29.745957 2026] [security2:error] [pid 796928:tid 797084] [client 50.116.65.227:11848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OkesTy9vX-htKvPkGvQAAArM"]
[Mon Jul 20 06:03:29.755702 2026] [security2:error] [pid 796567:tid 796745] [client 50.116.65.227:11854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OkbLfyzVz2SrjZpikFAAAAkQ"]
[Mon Jul 20 06:03:29.833475 2026] [security2:error] [pid 796567:tid 796711] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijsgACIg4"]
[Mon Jul 20 06:03:29.950773 2026] [security2:error] [pid 796928:tid 797106] [client 106.192.104.4:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGxAAAAsk"]
[Mon Jul 20 06:03:29.950883 2026] [security2:error] [pid 796928:tid 797106] [client 106.192.104.4:55992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGxAAAAsk"]
[Mon Jul 20 06:03:30.043772 2026] [security2:error] [pid 796928:tid 797142] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OkesTy9vX-htKvPkGxgAAAu0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:30.277998 2026] [security2:error] [pid 796928:tid 797072] [client 14.225.17.146:59849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGWQAAAqc"]
[Mon Jul 20 06:03:30.343475 2026] [ssl:error] [pid 796928:tid 797153] [client 104.48.69.105:39116] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:03:30.404506 2026] [security2:error] [pid 796567:tid 796710] [client 77.110.127.138:54768] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OkrLfyzVz2SrjZpikMAAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:30.451294 2026] [security2:error] [pid 796928:tid 797001] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/v1/graphql"] [unique_id "al4OkusTy9vX-htKvPkG3QACnEg"]
[Mon Jul 20 06:03:30.779154 2026] [security2:error] [pid 796928:tid 797070] [client 103.149.16.77:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OkusTy9vX-htKvPkG6QAAAqU"]
[Mon Jul 20 06:03:30.779670 2026] [security2:error] [pid 796928:tid 797070] [client 103.149.16.77:62228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OkusTy9vX-htKvPkG6QAAAqU"]
[Mon Jul 20 06:03:30.829524 2026] [security2:error] [pid 796567:tid 796766] [client 164.100.212.184:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OkrLfyzVz2SrjZpikPgAAAlk"]
[Mon Jul 20 06:03:30.829621 2026] [security2:error] [pid 796567:tid 796766] [client 164.100.212.184:53586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OkrLfyzVz2SrjZpikPgAAAlk"]
[Mon Jul 20 06:03:30.944590 2026] [security2:error] [pid 796567:tid 796648] [remote 217.61.143.92:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4OkrLfyzVz2SrjZpikQAACJ1A"]
[Mon Jul 20 06:03:31.065909 2026] [security2:error] [pid 796928:tid 797127] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Ok-sTy9vX-htKvPkG7wAAAt4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:31.119619 2026] [security2:error] [pid 796567:tid 796738] [client 181.224.94.124:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok7LfyzVz2SrjZpikRwAAAj0"]
[Mon Jul 20 06:03:31.119724 2026] [security2:error] [pid 796567:tid 796738] [client 181.224.94.124:46224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok7LfyzVz2SrjZpikRwAAAj0"]
[Mon Jul 20 06:03:31.172517 2026] [security2:error] [pid 796567:tid 796704] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkbLfyzVz2SrjZpij_gAAAhs"]
[Mon Jul 20 06:03:31.204199 2026] [security2:error] [pid 796567:tid 796675] [remote 217.61.143.92:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4Ok7LfyzVz2SrjZpikSwACUWs"], referer: https://get.learnthissecret.com/wp-login.php
[Mon Jul 20 06:03:31.350375 2026] [security2:error] [pid 796928:tid 797181] [client 3.109.4.218:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok-sTy9vX-htKvPkHBgAAAxQ"]
[Mon Jul 20 06:03:31.350473 2026] [security2:error] [pid 796928:tid 797181] [client 3.109.4.218:60748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok-sTy9vX-htKvPkHBgAAAxQ"]
[Mon Jul 20 06:03:31.596852 2026] [security2:error] [pid 796567:tid 796786] [client 77.110.127.138:54767] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4Ok7LfyzVz2SrjZpikVQAAAm0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:31.630120 2026] [security2:error] [pid 796928:tid 797030] [remote 57.141.18.56:61772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4Ok-sTy9vX-htKvPkHDwAC8GU"]
[Mon Jul 20 06:03:31.670271 2026] [security2:error] [pid 796567:tid 796774] [client 185.132.186.57:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/atomlib.php"] [unique_id "al4Ok7LfyzVz2SrjZpikXAAAAmE"]
[Mon Jul 20 06:03:31.783887 2026] [security2:error] [pid 796928:tid 797034] [remote 57.141.18.75:22000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4Ok-sTy9vX-htKvPkHFwACwWk"]
[Mon Jul 20 06:03:31.795656 2026] [security2:error] [pid 796928:tid 797075] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ok-sTy9vX-htKvPkHEQAAAqo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:32.017656 2026] [security2:error] [pid 796928:tid 797072] [client 129.222.187.209:64538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OlOsTy9vX-htKvPkHIQAAAqc"]
[Mon Jul 20 06:03:32.023909 2026] [security2:error] [pid 796567:tid 796772] [client 72.255.10.154:26234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OlLLfyzVz2SrjZpikcgAAAl8"]
[Mon Jul 20 06:03:32.024036 2026] [security2:error] [pid 796567:tid 796772] [client 72.255.10.154:26234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OlLLfyzVz2SrjZpikcgAAAl8"]
[Mon Jul 20 06:03:32.032667 2026] [security2:error] [pid 796928:tid 797072] [client 129.222.187.209:64538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OlOsTy9vX-htKvPkHIQAAAqc"]
[Mon Jul 20 06:03:32.145944 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGmgACnEQ"]
[Mon Jul 20 06:03:32.180411 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGnAACnEc"]
[Mon Jul 20 06:03:32.181181 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGoAACnE8"]
[Mon Jul 20 06:03:32.186598 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGnwACnE0"]
[Mon Jul 20 06:03:32.187903 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGpQACnFI"]
[Mon Jul 20 06:03:32.206258 2026] [security2:error] [pid 796928:tid 797059] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGqgAAApo"]
[Mon Jul 20 06:03:32.211683 2026] [security2:error] [pid 796928:tid 797155] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGqwAAAvo"]
[Mon Jul 20 06:03:32.218852 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGoQACnFE"]
[Mon Jul 20 06:03:32.254972 2026] [security2:error] [pid 796567:tid 796817] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkbLfyzVz2SrjZpikCgAAAow"]
[Mon Jul 20 06:03:32.296017 2026] [security2:error] [pid 796567:tid 796709] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkbLfyzVz2SrjZpikHAAAAiA"]
[Mon Jul 20 06:03:32.395161 2026] [security2:error] [pid 796928:tid 797087] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkusTy9vX-htKvPkG5gAAArY"]
[Mon Jul 20 06:03:32.871865 2026] [security2:error] [pid 796928:tid 797152] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlOsTy9vX-htKvPkHLgAAAvc"]
[Mon Jul 20 06:03:33.147536 2026] [security2:error] [pid 796928:tid 797017] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.ssh/id_rsa"] [unique_id "al4OlesTy9vX-htKvPkHTAACylg"]
[Mon Jul 20 06:03:33.147538 2026] [security2:error] [pid 796928:tid 797049] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.ssh/id_dsa"] [unique_id "al4OlesTy9vX-htKvPkHUAACyng"]
[Mon Jul 20 06:03:33.262741 2026] [security2:error] [pid 796928:tid 797180] [client 35.227.39.208:27682] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "tumbletyn.com"] [uri "/wp-json/batch/v1"] [unique_id "al4OlesTy9vX-htKvPkHXQAAAxM"]
[Mon Jul 20 06:03:33.596669 2026] [security2:error] [pid 796567:tid 796790] [client 185.132.186.64:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/index.php"] [unique_id "al4OlbLfyzVz2SrjZpikrAAAAnE"]
[Mon Jul 20 06:03:34.128465 2026] [security2:error] [pid 796928:tid 797088] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OlusTy9vX-htKvPkHbgAAArc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:34.197466 2026] [security2:error] [pid 796928:tid 797110] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHWQAAAs0"]
[Mon Jul 20 06:03:34.226553 2026] [security2:error] [pid 796928:tid 797053] [remote 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHTgACynw"]
[Mon Jul 20 06:03:34.233365 2026] [security2:error] [pid 796928:tid 797136] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHWAAAAuc"]
[Mon Jul 20 06:03:34.233948 2026] [security2:error] [pid 796567:tid 796807] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlbLfyzVz2SrjZpiknQAAAoI"]
[Mon Jul 20 06:03:34.264101 2026] [security2:error] [pid 796928:tid 797146] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHWgAAAvE"]
[Mon Jul 20 06:03:34.282285 2026] [security2:error] [pid 796567:tid 796774] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlbLfyzVz2SrjZpiknAAAAmE"]
[Mon Jul 20 06:03:34.344181 2026] [security2:error] [pid 796567:tid 796729] [client 77.110.127.138:54768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 586 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OlrLfyzVz2SrjZpikzAAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:34.387295 2026] [security2:error] [pid 796928:tid 797058] [client 35.227.39.208:27682] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "tumbletyn.com"] [uri "/"] [unique_id "al4OlusTy9vX-htKvPkHgAAAApk"]
[Mon Jul 20 06:03:34.430525 2026] [security2:error] [pid 796567:tid 796746] [client 112.213.160.112:31151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OlrLfyzVz2SrjZpikzwAAAkU"]
[Mon Jul 20 06:03:34.430632 2026] [security2:error] [pid 796567:tid 796746] [client 112.213.160.112:31151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OlrLfyzVz2SrjZpikzwAAAkU"]
[Mon Jul 20 06:03:34.744690 2026] [security2:error] [pid 796928:tid 797040] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHlQADBm8"]
[Mon Jul 20 06:03:34.744843 2026] [security2:error] [pid 796928:tid 797167] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHlQADBm8"]
[Mon Jul 20 06:03:34.818718 2026] [security2:error] [pid 796928:tid 797144] [client 27.96.94.195:38030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHjgAAAu8"]
[Mon Jul 20 06:03:34.861787 2026] [security2:error] [pid 796928:tid 797075] [client 104.28.163.98:29940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "almaz-aura.net"] [uri "/wp-login.php"] [unique_id "al4OlusTy9vX-htKvPkHmgAAAqo"]
[Mon Jul 20 06:03:34.990139 2026] [security2:error] [pid 796928:tid 797082] [client 150.228.148.150:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHogAAArE"]
[Mon Jul 20 06:03:35.000956 2026] [security2:error] [pid 796928:tid 797082] [client 150.228.148.150:46039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHogAAArE"]
[Mon Jul 20 06:03:35.155626 2026] [security2:error] [pid 796567:tid 796601] [remote 123.30.154.30:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Ol7LfyzVz2SrjZpik7gACWCE"]
[Mon Jul 20 06:03:35.166712 2026] [security2:error] [pid 796567:tid 796718] [client 77.110.127.138:54684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4Ol7LfyzVz2SrjZpik8AAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:35.415324 2026] [autoindex:error] [pid 796567:tid 796802] [client 14.225.17.146:59432] AH01276: Cannot serve directory /home4/thrninis/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://39ishlife.com/wordpress
[Mon Jul 20 06:03:35.539544 2026] [security2:error] [pid 796567:tid 796777] [client 185.132.186.72:50529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/about.php"] [unique_id "al4Ol7LfyzVz2SrjZpik_wAAAmQ"]
[Mon Jul 20 06:03:35.687020 2026] [security2:error] [pid 796567:tid 796604] [remote 123.30.154.30:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Ol7LfyzVz2SrjZpilAgACUyQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:36.228086 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH0gAAAqs"]
[Mon Jul 20 06:03:36.228268 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:57556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH0gAAAqs"]
[Mon Jul 20 06:03:36.250637 2026] [security2:error] [pid 796928:tid 797069] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OmOsTy9vX-htKvPkH0QAAAqQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:36.426573 2026] [security2:error] [pid 796567:tid 796774] [client 193.19.109.236:45313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4OmLLfyzVz2SrjZpilGwAAAmE"]
[Mon Jul 20 06:03:36.584878 2026] [security2:error] [pid 796928:tid 797087] [client 86.98.90.58:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH3AAAArY"]
[Mon Jul 20 06:03:36.585052 2026] [security2:error] [pid 796928:tid 797087] [client 86.98.90.58:47979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH3AAAArY"]
[Mon Jul 20 06:03:36.642966 2026] [security2:error] [pid 796567:tid 796809] [client 74.208.214.194:45056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OmLLfyzVz2SrjZpilIwAAAoQ"]
[Mon Jul 20 06:03:36.950642 2026] [ssl:error] [pid 796928:tid 797174] [client 104.48.69.105:39128] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:03:37.160642 2026] [security2:error] [pid 796928:tid 797067] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OmesTy9vX-htKvPkH9wAAAqI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:37.354978 2026] [security2:error] [pid 796567:tid 796669] [remote 57.141.18.106:23556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5083626"] [unique_id "al4OmbLfyzVz2SrjZpilQQACSWU"]
[Mon Jul 20 06:03:37.488551 2026] [security2:error] [pid 796567:tid 796705] [client 185.132.186.77:24415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/wincust.php"] [unique_id "al4OmbLfyzVz2SrjZpilTAAAAhw"]
[Mon Jul 20 06:03:37.501271 2026] [security2:error] [pid 796928:tid 797105] [client 15.229.42.239:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAAAAAsg"]
[Mon Jul 20 06:03:37.501394 2026] [security2:error] [pid 796928:tid 797105] [client 15.229.42.239:32560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAAAAAsg"]
[Mon Jul 20 06:03:37.796742 2026] [security2:error] [pid 796928:tid 797111] [client 115.246.21.170:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAgAAAs4"]
[Mon Jul 20 06:03:37.796888 2026] [security2:error] [pid 796928:tid 797111] [client 115.246.21.170:52336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAgAAAs4"]
[Mon Jul 20 06:03:37.880796 2026] [security2:error] [pid 796567:tid 796739] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 853 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OmbLfyzVz2SrjZpilYAAAAj4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:37.917071 2026] [security2:error] [pid 796928:tid 797169] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAQADCFY"]
[Mon Jul 20 06:03:37.936928 2026] [security2:error] [pid 796567:tid 796685] [remote 192.241.143.148:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OmbLfyzVz2SrjZpilZwACbHU"]
[Mon Jul 20 06:03:37.997425 2026] [security2:error] [pid 796928:tid 797143] [client 113.160.97.242:57540] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OmesTy9vX-htKvPkICwAAAu4"]
[Mon Jul 20 06:03:38.097634 2026] [security2:error] [pid 796567:tid 796576] [remote 192.241.143.148:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OmrLfyzVz2SrjZpilbwACXgg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:38.130519 2026] [ssl:error] [pid 796928:tid 797132] [client 104.48.69.105:60508] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:03:38.490541 2026] [lsapi:warn] [pid 796567:tid 796649] [remote 66.93.167.235:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://ali-alghanim.net/
[Mon Jul 20 06:03:39.121603 2026] [security2:error] [pid 796928:tid 797079] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Om-sTy9vX-htKvPkIQAAAAq4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:39.121758 2026] [security2:error] [pid 796928:tid 797079] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Om-sTy9vX-htKvPkIQAAAAq4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:39.149717 2026] [security2:error] [pid 796567:tid 796706] [client 129.222.187.209:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilngAAAh0"]
[Mon Jul 20 06:03:39.159948 2026] [security2:error] [pid 796567:tid 796706] [client 129.222.187.209:34877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilngAAAh0"]
[Mon Jul 20 06:03:39.218971 2026] [security2:error] [pid 796567:tid 796805] [client 87.199.196.160:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4Om7LfyzVz2SrjZpilnwAAAoA"], referer: https://www.guidehunting.com/guide-school-and-training-in-utah/
[Mon Jul 20 06:03:39.219110 2026] [security2:error] [pid 796567:tid 796805] [client 87.199.196.160:53701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4Om7LfyzVz2SrjZpilnwAAAoA"], referer: https://www.guidehunting.com/guide-school-and-training-in-utah/
[Mon Jul 20 06:03:39.433983 2026] [security2:error] [pid 796567:tid 796744] [client 185.132.186.83:23391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/alfa-rex.php"] [unique_id "al4Om7LfyzVz2SrjZpilqQAAAkM"]
[Mon Jul 20 06:03:39.505812 2026] [security2:error] [pid 796567:tid 796720] [client 103.95.123.246:19148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrQAAAis"]
[Mon Jul 20 06:03:39.505919 2026] [security2:error] [pid 796567:tid 796720] [client 103.95.123.246:19148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrQAAAis"]
[Mon Jul 20 06:03:39.506847 2026] [security2:error] [pid 796567:tid 796697] [client 41.173.37.102:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrgAAAhQ"]
[Mon Jul 20 06:03:39.506918 2026] [security2:error] [pid 796567:tid 796697] [client 41.173.37.102:10125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrgAAAhQ"]
[Mon Jul 20 06:03:39.692717 2026] [security2:error] [pid 796567:tid 796627] [remote 154.66.198.148:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Om7LfyzVz2SrjZpiltQACbjs"]
[Mon Jul 20 06:03:39.776052 2026] [security2:error] [pid 796567:tid 796792] [client 50.116.65.227:60910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Om7LfyzVz2SrjZpilugAAAnM"]
[Mon Jul 20 06:03:39.789221 2026] [security2:error] [pid 796567:tid 796783] [client 50.116.65.227:60922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Om7LfyzVz2SrjZpiluwAAAmo"]
[Mon Jul 20 06:03:39.925293 2026] [security2:error] [pid 796928:tid 797125] [client 57.141.18.74:31472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHXwAC3EE"]
[Mon Jul 20 06:03:39.928606 2026] [security2:error] [pid 796928:tid 797130] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Om-sTy9vX-htKvPkIWQAAAuE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:39.941012 2026] [autoindex:error] [pid 796567:tid 796729] [client 168.144.134.248:60724] AH01276: Cannot serve directory /home4/retzkolo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:03:40.041542 2026] [security2:error] [pid 796567:tid 796767] [client 103.153.183.69:42838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../etc/nginx/nginx.conf"] [unique_id "al4OnLLfyzVz2SrjZpilyQAAAlo"], referer: https://www.google.com/search?q=8rlm59
[Mon Jul 20 06:03:40.113677 2026] [security2:error] [pid 796567:tid 796646] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OnLLfyzVz2SrjZpilzQACf04"]
[Mon Jul 20 06:03:40.113948 2026] [security2:error] [pid 796567:tid 796804] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OnLLfyzVz2SrjZpilzQACf04"]
[Mon Jul 20 06:03:40.167178 2026] [security2:error] [pid 796928:tid 797147] [client 210.212.97.243:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIZQAAAvI"]
[Mon Jul 20 06:03:40.167336 2026] [security2:error] [pid 796928:tid 797147] [client 210.212.97.243:10433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIZQAAAvI"]
[Mon Jul 20 06:03:40.209704 2026] [security2:error] [pid 796928:tid 796950] [remote 182.77.62.24:34012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIaQAC_hU"]
[Mon Jul 20 06:03:40.209817 2026] [security2:error] [pid 796928:tid 797159] [client 182.77.62.24:34012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "villa-m-medjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIaQAC_hU"]
[Mon Jul 20 06:03:40.375667 2026] [security2:error] [pid 796567:tid 796819] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 815 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OnLLfyzVz2SrjZpil1gAAAo4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:40.463197 2026] [security2:error] [pid 796928:tid 797140] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OnOsTy9vX-htKvPkIdAAAAus"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:40.617703 2026] [security2:error] [pid 796567:tid 796601] [remote 154.66.198.148:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OnLLfyzVz2SrjZpil3wACjCE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:03:40.705075 2026] [security2:error] [pid 796928:tid 797141] [client 57.141.18.74:20868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OlusTy9vX-htKvPkHcwAC7D0"]
[Mon Jul 20 06:03:40.816108 2026] [security2:error] [pid 796567:tid 796753] [client 14.225.17.146:63089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Om7LfyzVz2SrjZpillgAAAkw"], referer: http://expertcultures.com/wordpress
[Mon Jul 20 06:03:41.268048 2026] [security2:error] [pid 796567:tid 796742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OnLLfyzVz2SrjZpil8QAAAkE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:41.295242 2026] [security2:error] [pid 796928:tid 796939] [remote 202.51.202.242:33400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OnesTy9vX-htKvPkIkgACzwo"]
[Mon Jul 20 06:03:41.329275 2026] [security2:error] [pid 796928:tid 797096] [client 164.100.212.184:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIlgAAAr8"]
[Mon Jul 20 06:03:41.329375 2026] [security2:error] [pid 796928:tid 797096] [client 164.100.212.184:62566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIlgAAAr8"]
[Mon Jul 20 06:03:41.388676 2026] [security2:error] [pid 796928:tid 797123] [client 185.132.186.68:39577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-good.php"] [unique_id "al4OnesTy9vX-htKvPkImwAAAto"]
[Mon Jul 20 06:03:41.400267 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkInQAAAsQ"]
[Mon Jul 20 06:03:41.400422 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:62718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkInQAAAsQ"]
[Mon Jul 20 06:03:41.415140 2026] [security2:error] [pid 796928:tid 797060] [client 106.192.104.4:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIngAAAps"]
[Mon Jul 20 06:03:41.424391 2026] [security2:error] [pid 796928:tid 797060] [client 106.192.104.4:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIngAAAps"]
[Mon Jul 20 06:03:41.473364 2026] [security2:error] [pid 796928:tid 797166] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OnesTy9vX-htKvPkImgAAAwU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:41.519123 2026] [security2:error] [pid 796567:tid 796719] [client 57.141.18.18:28274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ol7LfyzVz2SrjZpik7AACKgI"]
[Mon Jul 20 06:03:41.705532 2026] [security2:error] [pid 796928:tid 797147] [client 181.224.94.124:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIrgAAAvI"]
[Mon Jul 20 06:03:41.705635 2026] [security2:error] [pid 796928:tid 797147] [client 181.224.94.124:63505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIrgAAAvI"]
[Mon Jul 20 06:03:41.993541 2026] [autoindex:error] [pid 796567:tid 796733] [client 14.225.17.146:59341] AH01276: Cannot serve directory /home1/tgdhcnmy/public_html/nextlevelpressurewashing/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://nextlevelpressurewashing.com/wordpress
[Mon Jul 20 06:03:42.023496 2026] [security2:error] [pid 796928:tid 797058] [client 57.141.18.52:34976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ol-sTy9vX-htKvPkHsgACmW0"]
[Mon Jul 20 06:03:42.139291 2026] [security2:error] [pid 796928:tid 797172] [client 46.110.96.34:12932] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OnusTy9vX-htKvPkIwAAAAws"]
[Mon Jul 20 06:03:42.185116 2026] [security2:error] [pid 796928:tid 797179] [client 193.19.109.235:22255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/wp-login.php"] [unique_id "al4OnusTy9vX-htKvPkIvgAAAxI"]
[Mon Jul 20 06:03:42.416470 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:51472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OnrLfyzVz2SrjZpimNwAAAhw"]
[Mon Jul 20 06:03:42.416567 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:51472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OnrLfyzVz2SrjZpimNwAAAhw"]
[Mon Jul 20 06:03:42.661822 2026] [security2:error] [pid 796928:tid 797175] [client 129.222.187.209:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI1wAAAw4"]
[Mon Jul 20 06:03:42.661928 2026] [security2:error] [pid 796928:tid 797175] [client 129.222.187.209:20306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI1wAAAw4"]
[Mon Jul 20 06:03:42.685542 2026] [security2:error] [pid 796928:tid 797142] [client 14.225.17.146:60349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4OnOsTy9vX-htKvPkIeAAAAu0"], referer: http://tacticaltreeoperations.com/wordpress
[Mon Jul 20 06:03:42.697718 2026] [security2:error] [pid 796928:tid 797081] [client 72.255.10.154:26466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI2wAAArA"]
[Mon Jul 20 06:03:42.697853 2026] [security2:error] [pid 796928:tid 797081] [client 72.255.10.154:26466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI2wAAArA"]
[Mon Jul 20 06:03:42.859845 2026] [security2:error] [pid 796928:tid 797143] [client 98.159.234.160:51761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OnusTy9vX-htKvPkI4wAAAu4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:43.343832 2026] [security2:error] [pid 796928:tid 797082] [client 14.225.17.146:49717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4OnesTy9vX-htKvPkItAAAArE"], referer: http://sarahholyfield.com/wordpress
[Mon Jul 20 06:03:43.344604 2026] [security2:error] [pid 796928:tid 797080] [client 185.132.186.65:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/index.php"] [unique_id "al4On-sTy9vX-htKvPkI8wAAAq8"]
[Mon Jul 20 06:03:43.899379 2026] [security2:error] [pid 796928:tid 797102] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4On-sTy9vX-htKvPkJFwAAAsU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:43.985395 2026] [security2:error] [pid 796928:tid 797093] [client 14.225.17.146:63710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4OnusTy9vX-htKvPkIvwAAArw"], referer: http://bigwormfishing.com/wordpress
[Mon Jul 20 06:03:44.114148 2026] [security2:error] [pid 796567:tid 796779] [client 198.44.157.34:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4OoLLfyzVz2SrjZpimdQAAAmY"]
[Mon Jul 20 06:03:44.114313 2026] [security2:error] [pid 796567:tid 796779] [client 198.44.157.34:40380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4OoLLfyzVz2SrjZpimdQAAAmY"]
[Mon Jul 20 06:03:44.154499 2026] [security2:error] [pid 796928:tid 797158] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OoOsTy9vX-htKvPkJIwAAAv0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:44.248076 2026] [security2:error] [pid 796567:tid 796791] [client 77.110.127.138:54767] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimfgAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.304543 2026] [security2:error] [pid 796567:tid 796748] [client 77.110.127.138:54768] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimggAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.328778 2026] [security2:error] [pid 796928:tid 797139] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OoOsTy9vX-htKvPkJMgAAAuo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:44.376026 2026] [security2:error] [pid 796567:tid 796701] [client 77.110.127.138:54684] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimhAAAAhg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.429495 2026] [security2:error] [pid 796567:tid 796774] [client 77.110.127.138:54767] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimiQAAAmE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.599520 2026] [autoindex:error] [pid 796928:tid 797073] [client 194.233.85.87:58846] AH01276: Cannot serve directory /home2/rhstevmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:03:44.650970 2026] [security2:error] [pid 796928:tid 797088] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OoOsTy9vX-htKvPkJOQAAArc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:44.838607 2026] [security2:error] [pid 796928:tid 797099] [client 57.141.18.44:64426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OmusTy9vX-htKvPkIMAACwh4"]
[Mon Jul 20 06:03:44.949187 2026] [security2:error] [pid 796928:tid 797152] [client 14.225.17.146:63525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4On-sTy9vX-htKvPkI-AAAAvc"], referer: http://carolinapressurewashers.com/wordpress
[Mon Jul 20 06:03:45.016054 2026] [security2:error] [pid 796567:tid 796821] [client 52.59.238.198:63306] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4OobLfyzVz2SrjZpimoQAAApA"]
[Mon Jul 20 06:03:45.035085 2026] [security2:error] [pid 796928:tid 797176] [client 14.225.17.146:65495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4OoOsTy9vX-htKvPkJUQAAAw8"], referer: https://bigwormfishing.com/wordpress
[Mon Jul 20 06:03:45.240319 2026] [security2:error] [pid 796567:tid 796728] [client 112.213.160.112:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimrAAAAjM"]
[Mon Jul 20 06:03:45.240457 2026] [security2:error] [pid 796567:tid 796728] [client 112.213.160.112:31109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimrAAAAjM"]
[Mon Jul 20 06:03:45.277810 2026] [security2:error] [pid 796567:tid 796707] [client 193.37.33.5:52447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetalkswithkay.com"] [uri "/wp-login.php"] [unique_id "al4OobLfyzVz2SrjZpimrwAAAh4"]
[Mon Jul 20 06:03:45.279689 2026] [security2:error] [pid 796928:tid 797133] [client 185.132.186.86:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al4OoesTy9vX-htKvPkJYgAAAuQ"]
[Mon Jul 20 06:03:45.594598 2026] [security2:error] [pid 796928:tid 797039] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OoesTy9vX-htKvPkJegACnW4"]
[Mon Jul 20 06:03:45.594772 2026] [security2:error] [pid 796928:tid 797062] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OoesTy9vX-htKvPkJegACnW4"]
[Mon Jul 20 06:03:45.698055 2026] [security2:error] [pid 796567:tid 796714] [client 150.228.148.150:52613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimvQAAAiU"]
[Mon Jul 20 06:03:45.705521 2026] [security2:error] [pid 796567:tid 796714] [client 150.228.148.150:52613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimvQAAAiU"]
[Mon Jul 20 06:03:45.760438 2026] [security2:error] [pid 796928:tid 797169] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OoesTy9vX-htKvPkJfgAAAwg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:45.762792 2026] [security2:error] [pid 796928:tid 797165] [client 14.225.17.146:52438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4OoesTy9vX-htKvPkJfAAAAwQ"], referer: http://dasmarque.com/wordpress
[Mon Jul 20 06:03:46.089253 2026] [security2:error] [pid 796928:tid 797082] [client 52.59.238.198:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4OoesTy9vX-htKvPkJeQAAArE"]
[Mon Jul 20 06:03:46.091743 2026] [security2:error] [pid 796928:tid 797084] [client 52.59.238.198:45974] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4OoesTy9vX-htKvPkJdgAAArM"]
[Mon Jul 20 06:03:46.583542 2026] [security2:error] [pid 796928:tid 797152] [client 47.31.86.100:57998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OousTy9vX-htKvPkJqQAAAvc"]
[Mon Jul 20 06:03:46.583693 2026] [security2:error] [pid 796928:tid 797152] [client 47.31.86.100:57998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OousTy9vX-htKvPkJqQAAAvc"]
[Mon Jul 20 06:03:46.972441 2026] [core:error] [pid 796567:tid 796700] [client 14.225.17.146:51331] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:46.972467 2026] [core:error] [pid 796567:tid 796700] [client 14.225.17.146:51331] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:47.217447 2026] [security2:error] [pid 796567:tid 796741] [client 185.132.186.92:25231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/autoload_classmap.php"] [unique_id "al4Oo7LfyzVz2SrjZpim7QAAAkA"]
[Mon Jul 20 06:03:47.348203 2026] [security2:error] [pid 796567:tid 796734] [client 18.184.179.151:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4OorLfyzVz2SrjZpim2QAAAjk"]
[Mon Jul 20 06:03:47.396188 2026] [security2:error] [pid 796567:tid 796804] [client 18.184.179.151:46922] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4OorLfyzVz2SrjZpim2AAAAn8"]
[Mon Jul 20 06:03:47.410241 2026] [security2:error] [pid 796928:tid 797144] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oo-sTy9vX-htKvPkJywAAAu8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:47.410389 2026] [security2:error] [pid 796928:tid 797144] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oo-sTy9vX-htKvPkJywAAAu8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:47.482186 2026] [security2:error] [pid 796928:tid 797086] [client 14.225.17.146:61155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4OousTy9vX-htKvPkJrwAAArU"], referer: http://idigress.group/wordpress
[Mon Jul 20 06:03:47.782910 2026] [security2:error] [pid 796928:tid 797062] [client 173.72.54.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ0AAAAp0"], referer: https://mollycahill.com/
[Mon Jul 20 06:03:47.794167 2026] [security2:error] [pid 796928:tid 797103] [client 193.37.33.4:24873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ3wAAAsY"]
[Mon Jul 20 06:03:47.806407 2026] [security2:error] [pid 796567:tid 796713] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oo7LfyzVz2SrjZpim_AAAAiQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:47.849018 2026] [security2:error] [pid 796928:tid 797147] [client 103.153.183.69:9492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../etc/apache2/apache2.conf"] [unique_id "al4Oo-sTy9vX-htKvPkJ5AAAAvI"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:03:47.935391 2026] [security2:error] [pid 796567:tid 796753] [client 94.154.43.187:64588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lzk.wao.mybluehost.me"] [uri "/.env"] [unique_id "al4Oo7LfyzVz2SrjZpinDQAAAkw"]
[Mon Jul 20 06:03:47.963513 2026] [security2:error] [pid 796567:tid 796747] [client 94.154.43.188:60362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lzk.wao.mybluehost.me"] [uri "/.env"] [unique_id "al4Oo7LfyzVz2SrjZpinEAAAAkY"]
[Mon Jul 20 06:03:48.197607 2026] [security2:error] [pid 796928:tid 797136] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OpOsTy9vX-htKvPkJ9AAAAuc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:48.232915 2026] [security2:error] [pid 796567:tid 796795] [client 77.110.127.138:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OpLLfyzVz2SrjZpinFQAAAnY"]
[Mon Jul 20 06:03:48.240691 2026] [security2:error] [pid 796928:tid 797127] [client 15.229.42.239:32180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkJ9gAAAt4"]
[Mon Jul 20 06:03:48.240803 2026] [security2:error] [pid 796928:tid 797127] [client 15.229.42.239:32180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkJ9gAAAt4"]
[Mon Jul 20 06:03:48.292816 2026] [security2:error] [pid 796567:tid 796751] [client 34.173.238.42:57330] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "fbvrealtors.com"] [uri "/"] [unique_id "al4OpLLfyzVz2SrjZpinFgAAAko"]
[Mon Jul 20 06:03:48.374472 2026] [security2:error] [pid 796928:tid 796965] [remote 188.166.241.141:44916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4OpOsTy9vX-htKvPkJ_QAC9SQ"]
[Mon Jul 20 06:03:48.457328 2026] [security2:error] [pid 796928:tid 797168] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OpOsTy9vX-htKvPkKAwAAAwc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:48.503646 2026] [security2:error] [pid 796928:tid 797180] [client 115.246.21.170:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKCQAAAxM"]
[Mon Jul 20 06:03:48.503789 2026] [security2:error] [pid 796928:tid 797180] [client 115.246.21.170:2187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKCQAAAxM"]
[Mon Jul 20 06:03:48.552679 2026] [security2:error] [pid 796928:tid 797151] [client 86.98.90.58:49659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKEAAAAvY"]
[Mon Jul 20 06:03:48.557473 2026] [security2:error] [pid 796928:tid 797151] [client 86.98.90.58:49659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKEAAAAvY"]
[Mon Jul 20 06:03:48.568987 2026] [security2:error] [pid 796567:tid 796822] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OpLLfyzVz2SrjZpinFAACkTQ"]
[Mon Jul 20 06:03:48.683787 2026] [security2:error] [pid 796928:tid 797171] [client 14.225.17.146:51973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ1AAAAwo"], referer: http://nikkidesigns.net/wordpress
[Mon Jul 20 06:03:48.774534 2026] [security2:error] [pid 796928:tid 797032] [remote 188.166.241.141:44916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4OpOsTy9vX-htKvPkKFwACumc"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 06:03:48.861315 2026] [security2:error] [pid 796928:tid 797099] [client 14.225.17.146:50999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJvgAAAsI"], referer: http://ironcitywellness.com/wordpress
[Mon Jul 20 06:03:48.930703 2026] [security2:error] [pid 796928:tid 797095] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpOsTy9vX-htKvPkKDAAAAr4"]
[Mon Jul 20 06:03:49.045251 2026] [security2:error] [pid 796928:tid 797096] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpOsTy9vX-htKvPkKEgAAAr8"]
[Mon Jul 20 06:03:49.169864 2026] [security2:error] [pid 796928:tid 797155] [client 185.132.186.101:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/about.php"] [unique_id "al4OpesTy9vX-htKvPkKMgAAAvo"]
[Mon Jul 20 06:03:49.344195 2026] [security2:error] [pid 796567:tid 796699] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpLLfyzVz2SrjZpinMgAAAhY"]
[Mon Jul 20 06:03:49.375151 2026] [security2:error] [pid 796928:tid 796932] [remote 152.228.213.32:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpesTy9vX-htKvPkKPQADDwM"]
[Mon Jul 20 06:03:49.413773 2026] [security2:error] [pid 796567:tid 796787] [client 57.141.18.55:55808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4On7LfyzVz2SrjZpimSwACbmk"]
[Mon Jul 20 06:03:49.427621 2026] [security2:error] [pid 796928:tid 797098] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OpesTy9vX-htKvPkKOwAAAsE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:49.568792 2026] [security2:error] [pid 796567:tid 796725] [client 14.225.17.146:51956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Oo7LfyzVz2SrjZpinAQAAAjA"], referer: http://according2plant.com/wordpress
[Mon Jul 20 06:03:49.571824 2026] [security2:error] [pid 796928:tid 797089] [client 129.222.187.209:18872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OpesTy9vX-htKvPkKSwAAArg"]
[Mon Jul 20 06:03:49.579595 2026] [security2:error] [pid 796928:tid 797089] [client 129.222.187.209:18872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OpesTy9vX-htKvPkKSwAAArg"]
[Mon Jul 20 06:03:49.589077 2026] [security2:error] [pid 796928:tid 796958] [remote 152.228.213.32:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpesTy9vX-htKvPkKTQACmR0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:49.922515 2026] [autoindex:error] [pid 796928:tid 797173] [client 14.225.17.146:61444] AH01276: Cannot serve directory /home3/thedocz6/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://thedoctorscuisine.com/wordpress
[Mon Jul 20 06:03:49.987519 2026] [autoindex:error] [pid 796928:tid 797184] [client 13.215.47.127:48398] AH01276: Cannot serve directory /home4/curlsnp2/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://curlsnpearlsss.com/wordpress
[Mon Jul 20 06:03:50.086875 2026] [security2:error] [pid 796928:tid 797151] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKdAAAAvY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:50.124373 2026] [security2:error] [pid 796567:tid 796703] [client 18.141.57.241:10996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OpbLfyzVz2SrjZpinOwAAAho"]
[Mon Jul 20 06:03:50.125024 2026] [security2:error] [pid 796567:tid 796784] [client 41.173.37.102:10551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OprLfyzVz2SrjZpinWAAAAms"]
[Mon Jul 20 06:03:50.125167 2026] [security2:error] [pid 796567:tid 796784] [client 41.173.37.102:10551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OprLfyzVz2SrjZpinWAAAAms"]
[Mon Jul 20 06:03:50.141732 2026] [security2:error] [pid 796567:tid 796804] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpbLfyzVz2SrjZpinOQAAAn8"]
[Mon Jul 20 06:03:50.151026 2026] [security2:error] [pid 796928:tid 797183] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpesTy9vX-htKvPkKLgAAAxY"]
[Mon Jul 20 06:03:50.257189 2026] [security2:error] [pid 796567:tid 796806] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpbLfyzVz2SrjZpinOgAAAoE"]
[Mon Jul 20 06:03:50.269059 2026] [security2:error] [pid 796928:tid 797158] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpesTy9vX-htKvPkKLwAAAv0"]
[Mon Jul 20 06:03:50.283513 2026] [security2:error] [pid 796567:tid 796811] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpbLfyzVz2SrjZpinTQAAAoY"]
[Mon Jul 20 06:03:50.315822 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:53217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4OpLLfyzVz2SrjZpinLgAAAn0"], referer: http://mourgroup.com/wordpress
[Mon Jul 20 06:03:50.320920 2026] [security2:error] [pid 796928:tid 797028] [remote 192.241.143.148:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKhgAC32M"]
[Mon Jul 20 06:03:50.356127 2026] [security2:error] [pid 796928:tid 797090] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OpusTy9vX-htKvPkKgAAAArk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:50.503348 2026] [security2:error] [pid 796928:tid 797127] [client 103.95.123.246:19632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKjgAAAt4"]
[Mon Jul 20 06:03:50.503392 2026] [security2:error] [pid 796928:tid 797027] [remote 192.241.143.148:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKjwACmmI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:50.503500 2026] [security2:error] [pid 796928:tid 797127] [client 103.95.123.246:19632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKjgAAAt4"]
[Mon Jul 20 06:03:50.696688 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKlgAAAws"]
[Mon Jul 20 06:03:50.696819 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKlgAAAws"]
[Mon Jul 20 06:03:50.715382 2026] [security2:error] [pid 796928:tid 797008] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKmwADDk8"]
[Mon Jul 20 06:03:50.715710 2026] [security2:error] [pid 796928:tid 797175] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKmwADDk8"]
[Mon Jul 20 06:03:50.902755 2026] [security2:error] [pid 796928:tid 797006] [remote 209.42.18.223:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKrAAC400"]
[Mon Jul 20 06:03:50.957275 2026] [security2:error] [pid 796928:tid 797105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpusTy9vX-htKvPkKnAAAAsg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:51.091658 2026] [security2:error] [pid 796928:tid 797011] [remote 209.42.18.223:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKuwAC-1I"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:03:51.130364 2026] [security2:error] [pid 796928:tid 797016] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.165.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKuQAC91c"], referer: https://jenfarley.com/login
[Mon Jul 20 06:03:51.178897 2026] [security2:error] [pid 796928:tid 797076] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpusTy9vX-htKvPkKqwAAAqs"]
[Mon Jul 20 06:03:51.329212 2026] [security2:error] [pid 796928:tid 797173] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKyAAAAww"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:51.377859 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Op7LfyzVz2SrjZpinfwAAAjY"]
[Mon Jul 20 06:03:51.377992 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Op7LfyzVz2SrjZpinfwAAAjY"]
[Mon Jul 20 06:03:51.395681 2026] [security2:error] [pid 796928:tid 797064] [client 193.37.33.1:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKyQAAAp8"]
[Mon Jul 20 06:03:51.499767 2026] [security2:error] [pid 796567:tid 796732] [client 57.141.18.105:44920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OobLfyzVz2SrjZpimrgACNzk"]
[Mon Jul 20 06:03:51.699286 2026] [security2:error] [pid 796567:tid 796797] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Op7LfyzVz2SrjZpinfgAAAng"]
[Mon Jul 20 06:03:51.711205 2026] [security2:error] [pid 796928:tid 797138] [client 103.153.183.69:26640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xc0\\xaf..\\xc0\\xafhome/.env"] [unique_id "al4Op-sTy9vX-htKvPkK4AAAAuk"], referer: https://t.co/b0xpmli95u
[Mon Jul 20 06:03:51.949004 2026] [security2:error] [pid 796928:tid 797123] [client 164.100.212.184:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Op-sTy9vX-htKvPkK6gAAAto"]
[Mon Jul 20 06:03:51.949110 2026] [security2:error] [pid 796928:tid 797123] [client 164.100.212.184:65453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Op-sTy9vX-htKvPkK6gAAAto"]
[Mon Jul 20 06:03:52.081382 2026] [proxy:error] [pid 796567:tid 796724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:52.081438 2026] [proxy_http:error] [pid 796567:tid 796724] [client 195.96.139.226:38445] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:52.082659 2026] [proxy:error] [pid 796567:tid 796724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:52.082695 2026] [proxy_http:error] [pid 796567:tid 796724] [client 195.96.139.226:38445] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:52.151155 2026] [security2:error] [pid 796567:tid 796767] [client 185.132.186.69:58307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/about.php"] [unique_id "al4OqLLfyzVz2SrjZpinmgAAAlo"]
[Mon Jul 20 06:03:52.167709 2026] [security2:error] [pid 796567:tid 796756] [client 103.149.16.77:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinmwAAAk8"]
[Mon Jul 20 06:03:52.167856 2026] [security2:error] [pid 796567:tid 796756] [client 103.149.16.77:63207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinmwAAAk8"]
[Mon Jul 20 06:03:52.271596 2026] [security2:error] [pid 796567:tid 796701] [client 181.224.94.124:45782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinnQAAAhg"]
[Mon Jul 20 06:03:52.271709 2026] [security2:error] [pid 796567:tid 796701] [client 181.224.94.124:45782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinnQAAAhg"]
[Mon Jul 20 06:03:52.711606 2026] [security2:error] [pid 796928:tid 797122] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OqOsTy9vX-htKvPkLDwAAAtk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:52.722370 2026] [security2:error] [pid 796928:tid 797039] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.165.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4OqOsTy9vX-htKvPkLFwACpG4"], referer: https://jenfarley.com/wp-admin/
[Mon Jul 20 06:03:52.898894 2026] [security2:error] [pid 796567:tid 796801] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqLLfyzVz2SrjZpinrAAAAnw"]
[Mon Jul 20 06:03:52.972813 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:50508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Op-sTy9vX-htKvPkKxAAAAro"], referer: http://colinkeyphotography.com/wordpress
[Mon Jul 20 06:03:53.011038 2026] [security2:error] [pid 796928:tid 797078] [client 14.225.17.146:61495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Op-sTy9vX-htKvPkK5QAAAq0"], referer: http://headachescarpaltunnelfibromyalgia.com/wordpress
[Mon Jul 20 06:03:53.298089 2026] [security2:error] [pid 796567:tid 796734] [client 129.222.187.209:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqbLfyzVz2SrjZpinwQAAAjk"]
[Mon Jul 20 06:03:53.304291 2026] [security2:error] [pid 796567:tid 796734] [client 129.222.187.209:50700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqbLfyzVz2SrjZpinwQAAAjk"]
[Mon Jul 20 06:03:53.323675 2026] [security2:error] [pid 796928:tid 797147] [client 72.255.10.154:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLJwAAAvI"]
[Mon Jul 20 06:03:53.323831 2026] [security2:error] [pid 796928:tid 797147] [client 72.255.10.154:63489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLJwAAAvI"]
[Mon Jul 20 06:03:53.377251 2026] [security2:error] [pid 796928:tid 797100] [client 106.192.104.4:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLKQAAAsM"]
[Mon Jul 20 06:03:53.377386 2026] [security2:error] [pid 796928:tid 797100] [client 106.192.104.4:56979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLKQAAAsM"]
[Mon Jul 20 06:03:53.390176 2026] [security2:error] [pid 796928:tid 797111] [client 14.225.17.146:61430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4OpusTy9vX-htKvPkKmAAAAs4"], referer: http://careysheatingandcooling.com/wordpress
[Mon Jul 20 06:03:53.411627 2026] [security2:error] [pid 796928:tid 797181] [client 14.225.17.146:59257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4Op-sTy9vX-htKvPkK1wAAAxQ"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/wordpress
[Mon Jul 20 06:03:53.447013 2026] [security2:error] [pid 796928:tid 797058] [client 13.201.64.214:17704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLLwAAApk"]
[Mon Jul 20 06:03:53.447122 2026] [security2:error] [pid 796928:tid 797058] [client 13.201.64.214:17704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLLwAAApk"]
[Mon Jul 20 06:03:53.451166 2026] [security2:error] [pid 796928:tid 797130] [client 57.141.18.67:55594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ0gAC4VM"]
[Mon Jul 20 06:03:53.700898 2026] [security2:error] [pid 796567:tid 796813] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqbLfyzVz2SrjZpinyQAAAog"]
[Mon Jul 20 06:03:53.810691 2026] [security2:error] [pid 796928:tid 797138] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OqesTy9vX-htKvPkLQAAAAuk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:53.914608 2026] [security2:error] [pid 796928:tid 797109] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqesTy9vX-htKvPkLOQAAAsw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:54.109616 2026] [security2:error] [pid 796928:tid 797078] [client 185.132.186.58:35447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/fonts/database.php"] [unique_id "al4OqusTy9vX-htKvPkLTQAAAq0"]
[Mon Jul 20 06:03:54.396021 2026] [proxy:error] [pid 796928:tid 797080] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:54.396104 2026] [proxy_http:error] [pid 796928:tid 797080] [client 198.235.24.25:61872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:54.396837 2026] [proxy:error] [pid 796928:tid 797080] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:54.396865 2026] [proxy_http:error] [pid 796928:tid 797080] [client 198.235.24.25:61872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:54.425821 2026] [security2:error] [pid 796928:tid 797153] [client 13.201.64.214:17714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OqusTy9vX-htKvPkLYQAAAvg"]
[Mon Jul 20 06:03:54.445681 2026] [security2:error] [pid 796928:tid 797144] [client 57.141.18.99:46298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OpOsTy9vX-htKvPkKCAAC7wY"]
[Mon Jul 20 06:03:54.450640 2026] [security2:error] [pid 796928:tid 797015] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.165.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4OqusTy9vX-htKvPkLZQADFFY"], referer: https://jenfarley.com/wp-admin/
[Mon Jul 20 06:03:54.552777 2026] [security2:error] [pid 796567:tid 796759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqrLfyzVz2SrjZpin3QAAAlI"]
[Mon Jul 20 06:03:55.275231 2026] [security2:error] [pid 796567:tid 796748] [client 13.229.83.156:28834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Oq7LfyzVz2SrjZpioBAAAAkc"]
[Mon Jul 20 06:03:55.280168 2026] [security2:error] [pid 796928:tid 797143] [client 14.225.17.146:55668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4OqesTy9vX-htKvPkLSAAAAu4"], referer: http://getgarrison.com/wordpress
[Mon Jul 20 06:03:55.376113 2026] [security2:error] [pid 796928:tid 797145] [client 3.109.4.218:45650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Oq-sTy9vX-htKvPkLlAAAAvA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:03:55.431160 2026] [security2:error] [pid 796928:tid 797155] [client 14.225.17.146:51399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Oq-sTy9vX-htKvPkLjAAAAvo"]
[Mon Jul 20 06:03:55.546569 2026] [security2:error] [pid 796928:tid 797150] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oq-sTy9vX-htKvPkLngAAAvU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:55.701946 2026] [security2:error] [pid 796928:tid 797150] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oq-sTy9vX-htKvPkLngAAAvU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:55.708687 2026] [security2:error] [pid 796567:tid 796646] [remote 154.66.198.148:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Oq7LfyzVz2SrjZpioDgACWU4"]
[Mon Jul 20 06:03:55.749502 2026] [security2:error] [pid 796928:tid 797183] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oq-sTy9vX-htKvPkLjwAAAxY"]
[Mon Jul 20 06:03:56.057191 2026] [security2:error] [pid 796928:tid 797171] [client 185.132.186.81:39819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ff2.php"] [unique_id "al4OrOsTy9vX-htKvPkLtQAAAwo"]
[Mon Jul 20 06:03:56.057938 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLtgAAAwU"]
[Mon Jul 20 06:03:56.058026 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLtgAAAwU"]
[Mon Jul 20 06:03:56.216402 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.110:37418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OprLfyzVz2SrjZpinWQACcgY"]
[Mon Jul 20 06:03:56.278991 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oq7LfyzVz2SrjZpioEwAAAl0"]
[Mon Jul 20 06:03:56.308555 2026] [security2:error] [pid 796928:tid 797168] [client 150.228.148.150:1126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLygAAAwc"]
[Mon Jul 20 06:03:56.308699 2026] [security2:error] [pid 796928:tid 797168] [client 150.228.148.150:1126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLygAAAwc"]
[Mon Jul 20 06:03:56.332719 2026] [security2:error] [pid 796928:tid 796966] [remote 202.51.202.242:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OrOsTy9vX-htKvPkLywACoSU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:03:56.344127 2026] [security2:error] [pid 796567:tid 796716] [client 13.215.47.127:27114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OrLLfyzVz2SrjZpioIgAAAic"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:03:56.494483 2026] [security2:error] [pid 796928:tid 797175] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OrOsTy9vX-htKvPkL1wAAAw4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:56.647895 2026] [security2:error] [pid 796567:tid 796592] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OrLLfyzVz2SrjZpioLgACTRg"]
[Mon Jul 20 06:03:56.648106 2026] [security2:error] [pid 796567:tid 796754] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OrLLfyzVz2SrjZpioLgACTRg"]
[Mon Jul 20 06:03:56.719928 2026] [security2:error] [pid 796928:tid 797078] [client 14.225.17.146:62287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4OrOsTy9vX-htKvPkLxgAAAq0"], referer: http://overloadcomedy.com/wordpress
[Mon Jul 20 06:03:56.740650 2026] [security2:error] [pid 796928:tid 797182] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrOsTy9vX-htKvPkL2wAAAxU"]
[Mon Jul 20 06:03:57.011022 2026] [security2:error] [pid 796567:tid 796762] [client 47.31.86.100:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OrbLfyzVz2SrjZpioPAAAAlU"]
[Mon Jul 20 06:03:57.011239 2026] [security2:error] [pid 796567:tid 796762] [client 47.31.86.100:58429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OrbLfyzVz2SrjZpioPAAAAlU"]
[Mon Jul 20 06:03:57.025424 2026] [security2:error] [pid 796567:tid 796591] [remote 154.66.198.148:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OrbLfyzVz2SrjZpioPQACkhc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:03:57.202597 2026] [security2:error] [pid 796928:tid 797141] [client 114.119.156.181:25673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/category/tablescapes/holidays-tablescapes/cinco-de-mayo-tablescapes/"] [unique_id "al4OresTy9vX-htKvPkL-QAAAuw"], referer: https://lifeisbetterlakeside.com/lemurs-up-close-and-personal-at-the-alabama-gulf-coast-zoo-part-2/
[Mon Jul 20 06:03:57.253573 2026] [security2:error] [pid 796928:tid 797111] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OresTy9vX-htKvPkL-gAAAs4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:57.393262 2026] [security2:error] [pid 796567:tid 796698] [client 45.157.112.60:24997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OrbLfyzVz2SrjZpioTAAAAhU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:57.738309 2026] [security2:error] [pid 796928:tid 797081] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OresTy9vX-htKvPkMEwAAArA"]
[Mon Jul 20 06:03:57.968421 2026] [security2:error] [pid 796567:tid 796760] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrbLfyzVz2SrjZpioRwAAAlM"]
[Mon Jul 20 06:03:57.999521 2026] [security2:error] [pid 796567:tid 796758] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrbLfyzVz2SrjZpioUwAAAlE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:58.005655 2026] [security2:error] [pid 796928:tid 797059] [client 185.132.186.104:52701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Exception-wp.php"] [unique_id "al4OrusTy9vX-htKvPkMKQAAApo"]
[Mon Jul 20 06:03:58.179846 2026] [security2:error] [pid 796928:tid 797137] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OresTy9vX-htKvPkMHwAAAug"]
[Mon Jul 20 06:03:58.225143 2026] [security2:error] [pid 796928:tid 797116] [client 50.116.65.227:59178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OrusTy9vX-htKvPkMMwAAAtM"]
[Mon Jul 20 06:03:58.236701 2026] [security2:error] [pid 796928:tid 797113] [client 50.116.65.227:59186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OrusTy9vX-htKvPkMNAAAAtA"]
[Mon Jul 20 06:03:58.366547 2026] [security2:error] [pid 796567:tid 796742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrrLfyzVz2SrjZpioZgAAAkE"]
[Mon Jul 20 06:03:58.621697 2026] [security2:error] [pid 796567:tid 796812] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrrLfyzVz2SrjZpiobQAAAoc"]
[Mon Jul 20 06:03:58.638133 2026] [security2:error] [pid 796928:tid 797088] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OrusTy9vX-htKvPkMSwAAArc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:58.724471 2026] [security2:error] [pid 796567:tid 796598] [remote 5.223.65.249:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4OrrLfyzVz2SrjZpiodAACSx4"]
[Mon Jul 20 06:03:58.813050 2026] [security2:error] [pid 796928:tid 797093] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OrusTy9vX-htKvPkMVwAAArw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:58.853188 2026] [security2:error] [pid 796928:tid 797085] [client 15.229.42.239:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OrusTy9vX-htKvPkMWQAAArQ"]
[Mon Jul 20 06:03:58.853337 2026] [security2:error] [pid 796928:tid 797085] [client 15.229.42.239:55360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OrusTy9vX-htKvPkMWQAAArQ"]
[Mon Jul 20 06:03:58.879510 2026] [security2:error] [pid 796928:tid 797125] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OrusTy9vX-htKvPkMVQAAAtw"], referer: https://effingweirdmuseums.com/.git/config
[Mon Jul 20 06:03:58.966580 2026] [security2:error] [pid 796567:tid 796735] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrrLfyzVz2SrjZpiodQAAAjo"]
[Mon Jul 20 06:03:58.988404 2026] [security2:error] [pid 796928:tid 797123] [client 66.249.79.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4OrusTy9vX-htKvPkMTAAC2mk"]
[Mon Jul 20 06:03:59.112938 2026] [security2:error] [pid 796928:tid 797062] [client 115.246.21.170:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMbQAAAp0"]
[Mon Jul 20 06:03:59.113080 2026] [security2:error] [pid 796928:tid 797062] [client 115.246.21.170:8008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMbQAAAp0"]
[Mon Jul 20 06:03:59.164910 2026] [security2:error] [pid 796567:tid 796608] [remote 5.223.65.249:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4Or7LfyzVz2SrjZpiogwACLCg"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 06:03:59.205978 2026] [security2:error] [pid 796567:tid 796750] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OrrLfyzVz2SrjZpioeQACSUw"]
[Mon Jul 20 06:03:59.221641 2026] [security2:error] [pid 796928:tid 797127] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Or-sTy9vX-htKvPkMbgAAAt4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:59.301048 2026] [security2:error] [pid 796928:tid 797130] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or-sTy9vX-htKvPkMbAAAAuE"]
[Mon Jul 20 06:03:59.353901 2026] [security2:error] [pid 796928:tid 797076] [client 77.110.127.138:54677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or-sTy9vX-htKvPkMagAAAqs"]
[Mon Jul 20 06:03:59.589038 2026] [security2:error] [pid 796567:tid 796777] [client 158.173.166.181:26663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Or7LfyzVz2SrjZpiomgAAAmQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:59.633889 2026] [security2:error] [pid 796567:tid 796747] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or7LfyzVz2SrjZpiokgAAAkY"]
[Mon Jul 20 06:03:59.675649 2026] [security2:error] [pid 796567:tid 796729] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or7LfyzVz2SrjZpiokQAAAjQ"]
[Mon Jul 20 06:03:59.751561 2026] [security2:error] [pid 796567:tid 796744] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or7LfyzVz2SrjZpiolwAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:59.785025 2026] [security2:error] [pid 796567:tid 796660] [remote 20.173.88.122:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4Or7LfyzVz2SrjZpionwACFVw"]
[Mon Jul 20 06:03:59.902340 2026] [security2:error] [pid 796928:tid 797058] [client 86.98.90.58:50487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMkgAAApk"]
[Mon Jul 20 06:03:59.902486 2026] [security2:error] [pid 796928:tid 797058] [client 86.98.90.58:50487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMkgAAApk"]
[Mon Jul 20 06:03:59.954808 2026] [security2:error] [pid 796928:tid 797163] [client 185.132.186.57:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/plugin.php"] [unique_id "al4Or-sTy9vX-htKvPkMnAAAAwI"]
[Mon Jul 20 06:03:59.983783 2026] [security2:error] [pid 796567:tid 796776] [client 158.173.89.95:21809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Or7LfyzVz2SrjZpioqQAAAmM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:00.065594 2026] [security2:error] [pid 796928:tid 797185] [client 57.141.18.110:37426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OqusTy9vX-htKvPkLaAADGGQ"]
[Mon Jul 20 06:04:00.163424 2026] [security2:error] [pid 796567:tid 796676] [remote 20.173.88.122:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4OsLLfyzVz2SrjZpiorQACW2w"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:04:00.271978 2026] [security2:error] [pid 796928:tid 797178] [client 129.222.187.209:29321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMogAAAxE"]
[Mon Jul 20 06:04:00.282722 2026] [security2:error] [pid 796928:tid 797178] [client 129.222.187.209:29321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMogAAAxE"]
[Mon Jul 20 06:04:00.356445 2026] [security2:error] [pid 796567:tid 796675] [remote 47.86.33.52:31078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OsLLfyzVz2SrjZpiosAACRWs"]
[Mon Jul 20 06:04:00.512867 2026] [security2:error] [pid 796928:tid 797086] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsOsTy9vX-htKvPkMsAAAArU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:00.595859 2026] [security2:error] [pid 796928:tid 797083] [client 193.19.109.211:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getgarrison.com"] [uri "/wp-login.php"] [unique_id "al4OsOsTy9vX-htKvPkMswAAArI"]
[Mon Jul 20 06:04:00.741482 2026] [security2:error] [pid 796928:tid 797037] [remote 8.217.108.67:12758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OsOsTy9vX-htKvPkMwgACxmw"]
[Mon Jul 20 06:04:00.773932 2026] [security2:error] [pid 796928:tid 797176] [client 41.173.37.102:10969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMxgAAAw8"]
[Mon Jul 20 06:04:00.774104 2026] [security2:error] [pid 796928:tid 797176] [client 41.173.37.102:10969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMxgAAAw8"]
[Mon Jul 20 06:04:00.782999 2026] [security2:error] [pid 796928:tid 797089] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OsOsTy9vX-htKvPkMwAAAArg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:00.866004 2026] [security2:error] [pid 796567:tid 796669] [remote 47.86.33.52:31078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OsLLfyzVz2SrjZpioxAACdWU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:00.915688 2026] [security2:error] [pid 796928:tid 797109] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMvwAAAsw"]
[Mon Jul 20 06:04:01.047765 2026] [security2:error] [pid 796928:tid 797105] [client 178.152.178.232:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM3QAAAsg"]
[Mon Jul 20 06:04:01.047917 2026] [security2:error] [pid 796928:tid 797105] [client 178.152.178.232:36691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM3QAAAsg"]
[Mon Jul 20 06:04:01.105677 2026] [security2:error] [pid 796928:tid 797173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMxQAAAww"]
[Mon Jul 20 06:04:01.134134 2026] [security2:error] [pid 796928:tid 797152] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMygAAAvc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:01.141367 2026] [security2:error] [pid 796928:tid 797147] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkM4gAAAvI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:01.149506 2026] [security2:error] [pid 796928:tid 797113] [client 216.73.217.138:52738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkM3AAC0BM"]
[Mon Jul 20 06:04:01.204622 2026] [security2:error] [pid 796567:tid 796707] [client 210.212.97.243:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio2AAAAh4"]
[Mon Jul 20 06:04:01.204787 2026] [security2:error] [pid 796567:tid 796707] [client 210.212.97.243:10435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio2AAAAh4"]
[Mon Jul 20 06:04:01.246480 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkM2wAAAtg"]
[Mon Jul 20 06:04:01.250570 2026] [security2:error] [pid 796928:tid 797127] [client 14.225.17.146:62355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMvQAAAt4"], referer: http://bruceledewitz.com/wordpress
[Mon Jul 20 06:04:01.253337 2026] [security2:error] [pid 796928:tid 796945] [remote 8.217.108.67:12758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkM6QACmxA"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:04:01.319339 2026] [security2:error] [pid 796567:tid 796671] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio4QACd2c"]
[Mon Jul 20 06:04:01.319550 2026] [security2:error] [pid 796567:tid 796796] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio4QACd2c"]
[Mon Jul 20 06:04:01.379839 2026] [security2:error] [pid 796928:tid 797078] [client 103.95.123.246:20127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM8gAAAq0"]
[Mon Jul 20 06:04:01.379952 2026] [security2:error] [pid 796928:tid 797078] [client 103.95.123.246:20127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM8gAAAq0"]
[Mon Jul 20 06:04:01.417294 2026] [security2:error] [pid 796567:tid 796726] [client 27.96.94.195:36944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio1QAAAjE"]
[Mon Jul 20 06:04:01.709796 2026] [security2:error] [pid 796928:tid 797160] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkNAAAAAv8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:01.709948 2026] [security2:error] [pid 796928:tid 797160] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkNAAAAAv8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:01.757955 2026] [security2:error] [pid 796567:tid 796785] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio2gAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:01.833048 2026] [security2:error] [pid 796567:tid 796762] [client 69.171.231.113:54564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio6AACVQ0"]
[Mon Jul 20 06:04:01.899282 2026] [security2:error] [pid 796567:tid 796804] [client 185.132.186.69:53607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/autoload_classmap.php"] [unique_id "al4OsbLfyzVz2SrjZpio7gAAAn8"]
[Mon Jul 20 06:04:01.931878 2026] [security2:error] [pid 796928:tid 797088] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkNBQACtyo"], referer: http://ali-alghanim.net/wordpress
[Mon Jul 20 06:04:02.154319 2026] [security2:error] [pid 796567:tid 796808] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio2QAAAoM"]
[Mon Jul 20 06:04:02.220363 2026] [security2:error] [pid 796567:tid 796730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio5AAAAjU"]
[Mon Jul 20 06:04:02.507357 2026] [security2:error] [pid 796928:tid 797119] [client 164.100.212.184:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNKAAAAtY"]
[Mon Jul 20 06:04:02.507464 2026] [security2:error] [pid 796928:tid 797119] [client 164.100.212.184:49789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNKAAAAtY"]
[Mon Jul 20 06:04:02.520011 2026] [security2:error] [pid 796567:tid 796755] [client 57.141.18.73:41124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OrbLfyzVz2SrjZpioSgACTlI"]
[Mon Jul 20 06:04:02.624483 2026] [security2:error] [pid 796928:tid 797176] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsusTy9vX-htKvPkNIgAAAw8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:02.655209 2026] [security2:error] [pid 796567:tid 796752] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsrLfyzVz2SrjZpipBAAAAks"]
[Mon Jul 20 06:04:02.692828 2026] [security2:error] [pid 796928:tid 796989] [remote 130.185.118.215:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNNQAC5Dw"]
[Mon Jul 20 06:04:02.692986 2026] [security2:error] [pid 796928:tid 797133] [client 130.185.118.215:40316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNNQAC5Dw"]
[Mon Jul 20 06:04:02.890620 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNPwAAAsQ"]
[Mon Jul 20 06:04:02.890848 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:63705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNPwAAAsQ"]
[Mon Jul 20 06:04:02.946313 2026] [proxy:error] [pid 796567:tid 796771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:02.946365 2026] [proxy_http:error] [pid 796567:tid 796771] [client 91.92.40.117:40828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:02.946784 2026] [proxy:error] [pid 796567:tid 796771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:02.946806 2026] [proxy_http:error] [pid 796567:tid 796771] [client 91.92.40.117:40828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:02.946886 2026] [security2:error] [pid 796567:tid 796771] [client 91.92.40.117:40828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.according2plant.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4OsrLfyzVz2SrjZpipEwAAAl4"]
[Mon Jul 20 06:04:03.011201 2026] [security2:error] [pid 796567:tid 796725] [client 193.19.109.236:52427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cygnuswines.co.uk"] [uri "/wp-login.php"] [unique_id "al4Os7LfyzVz2SrjZpipGAAAAjA"]
[Mon Jul 20 06:04:03.135189 2026] [security2:error] [pid 796928:tid 797164] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNTgAAAwM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:03.195655 2026] [security2:error] [pid 796928:tid 797069] [client 181.224.94.124:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNVAAAAqQ"]
[Mon Jul 20 06:04:03.195840 2026] [security2:error] [pid 796928:tid 797069] [client 181.224.94.124:21486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNVAAAAqQ"]
[Mon Jul 20 06:04:03.302844 2026] [proxy:error] [pid 796928:tid 797096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:03.302932 2026] [proxy_http:error] [pid 796928:tid 797096] [client 91.92.40.117:40844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:03.304131 2026] [proxy:error] [pid 796928:tid 797096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:03.304165 2026] [proxy_http:error] [pid 796928:tid 797096] [client 91.92.40.117:40844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:03.304283 2026] [security2:error] [pid 796928:tid 797096] [client 91.92.40.117:40844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.according2plant.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4Os-sTy9vX-htKvPkNWQAAAr8"]
[Mon Jul 20 06:04:03.326277 2026] [security2:error] [pid 796567:tid 796713] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsrLfyzVz2SrjZpipFQAAAiQ"]
[Mon Jul 20 06:04:03.400799 2026] [security2:error] [pid 796928:tid 797117] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNRwAAAtQ"]
[Mon Jul 20 06:04:03.446225 2026] [security2:error] [pid 796928:tid 797090] [client 47.128.52.83:48528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/news/"] [unique_id "al4Os-sTy9vX-htKvPkNXAAAArk"]
[Mon Jul 20 06:04:03.502967 2026] [security2:error] [pid 796928:tid 797073] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Os-sTy9vX-htKvPkNYAAAAqg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:03.513300 2026] [security2:error] [pid 796928:tid 797020] [remote 144.79.133.30:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Os-sTy9vX-htKvPkNYQACz1s"]
[Mon Jul 20 06:04:03.715960 2026] [security2:error] [pid 796567:tid 796761] [client 13.201.64.214:63250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Os7LfyzVz2SrjZpipQAAAAlQ"]
[Mon Jul 20 06:04:03.716060 2026] [security2:error] [pid 796567:tid 796761] [client 13.201.64.214:63250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Os7LfyzVz2SrjZpipQAAAAlQ"]
[Mon Jul 20 06:04:03.787880 2026] [security2:error] [pid 796928:tid 797127] [client 129.222.187.209:27934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNdQAAAt4"]
[Mon Jul 20 06:04:03.788105 2026] [security2:error] [pid 796928:tid 797127] [client 129.222.187.209:27934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNdQAAAt4"]
[Mon Jul 20 06:04:03.827899 2026] [security2:error] [pid 796928:tid 797095] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Os-sTy9vX-htKvPkNdAAAAr4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:03.839372 2026] [security2:error] [pid 796567:tid 796730] [client 185.132.186.86:29307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/jp.php"] [unique_id "al4Os7LfyzVz2SrjZpipRgAAAjU"]
[Mon Jul 20 06:04:03.955553 2026] [security2:error] [pid 796928:tid 797098] [client 72.255.10.154:26446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNewAAAsE"]
[Mon Jul 20 06:04:03.955697 2026] [security2:error] [pid 796928:tid 797098] [client 72.255.10.154:26446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNewAAAsE"]
[Mon Jul 20 06:04:04.179739 2026] [security2:error] [pid 796928:tid 797133] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNbAAAAuQ"]
[Mon Jul 20 06:04:04.216919 2026] [security2:error] [pid 796928:tid 797008] [remote 192.241.143.148:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNgQADFk8"]
[Mon Jul 20 06:04:04.258174 2026] [security2:error] [pid 796567:tid 796708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Os7LfyzVz2SrjZpipQgAAAh8"]
[Mon Jul 20 06:04:04.337739 2026] [security2:error] [pid 796928:tid 797162] [client 13.201.64.214:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNhgAAAwE"]
[Mon Jul 20 06:04:04.337839 2026] [security2:error] [pid 796928:tid 797162] [client 13.201.64.214:63254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNhgAAAwE"]
[Mon Jul 20 06:04:04.411443 2026] [security2:error] [pid 796928:tid 796993] [remote 192.241.143.148:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNigACpUA"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:04:04.468507 2026] [security2:error] [pid 796928:tid 797092] [client 106.192.104.4:57509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNjgAAArs"]
[Mon Jul 20 06:04:04.468695 2026] [security2:error] [pid 796928:tid 797092] [client 106.192.104.4:57509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNjgAAArs"]
[Mon Jul 20 06:04:04.515961 2026] [security2:error] [pid 796567:tid 796750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipUgAAAkk"]
[Mon Jul 20 06:04:04.542008 2026] [security2:error] [pid 796928:tid 797072] [client 62.150.67.110:24572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4OtOsTy9vX-htKvPkNiwAAAqc"]
[Mon Jul 20 06:04:04.599138 2026] [security2:error] [pid 796567:tid 796735] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipWgAAAjo"]
[Mon Jul 20 06:04:04.686011 2026] [security2:error] [pid 796928:tid 797112] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNlwAAAs8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:04.812970 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipYAAAAiU"]
[Mon Jul 20 06:04:04.921273 2026] [security2:error] [pid 796928:tid 797031] [remote 144.79.133.30:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNnQACqmY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:04:05.090698 2026] [security2:error] [pid 796928:tid 797180] [client 14.225.17.146:53968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNTwAAAxM"], referer: http://nwcarvingacademy.com/wordpress
[Mon Jul 20 06:04:05.527201 2026] [security2:error] [pid 796567:tid 796723] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtbLfyzVz2SrjZpipeAAAAi4"]
[Mon Jul 20 06:04:05.557242 2026] [security2:error] [pid 796928:tid 797155] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNuwAAAvo"]
[Mon Jul 20 06:04:05.682042 2026] [security2:error] [pid 796928:tid 797172] [client 57.141.18.8:49672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMowADC3E"]
[Mon Jul 20 06:04:05.709522 2026] [security2:error] [pid 796567:tid 796775] [client 77.110.127.138:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OtbLfyzVz2SrjZpipgwAAAmI"]
[Mon Jul 20 06:04:05.776965 2026] [security2:error] [pid 796928:tid 797125] [client 185.132.186.100:24057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-atom.php"] [unique_id "al4OtesTy9vX-htKvPkN3QAAAtw"]
[Mon Jul 20 06:04:05.783436 2026] [security2:error] [pid 796567:tid 796778] [client 173.252.70.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.younutrition.gr"] [uri "/index.php"] [unique_id "al4Os7LfyzVz2SrjZpipMwAAAmU"]
[Mon Jul 20 06:04:05.827352 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4OtbLfyzVz2SrjZpiphAAAAjU"]
[Mon Jul 20 06:04:05.907692 2026] [security2:error] [pid 796928:tid 797076] [client 57.141.18.27:24398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMrQACq1w"]
[Mon Jul 20 06:04:05.964745 2026] [security2:error] [pid 796928:tid 797061] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNygAAApw"]
[Mon Jul 20 06:04:06.205058 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:64624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkN5QAAAro"], referer: https://nwcarvingacademy.com/wordpress
[Mon Jul 20 06:04:06.327496 2026] [security2:error] [pid 796567:tid 796605] [remote 45.90.123.233:48558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpiplQACMiU"]
[Mon Jul 20 06:04:06.400039 2026] [security2:error] [pid 796567:tid 796611] [remote 47.86.33.52:19370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpipmQACHys"]
[Mon Jul 20 06:04:06.494332 2026] [security2:error] [pid 796928:tid 797089] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkN9QAAArg"]
[Mon Jul 20 06:04:06.551228 2026] [security2:error] [pid 796567:tid 796646] [remote 45.90.123.233:48558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpipngACT04"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:06.571809 2026] [security2:error] [pid 796928:tid 797039] [remote 202.51.202.242:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4OtusTy9vX-htKvPkODQACz24"]
[Mon Jul 20 06:04:06.742275 2026] [security2:error] [pid 796928:tid 796986] [remote 47.86.33.52:19360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOHAADFjk"]
[Mon Jul 20 06:04:06.742553 2026] [security2:error] [pid 796928:tid 797183] [client 47.86.33.52:19360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOHAADFjk"]
[Mon Jul 20 06:04:06.760445 2026] [security2:error] [pid 796567:tid 796819] [client 14.225.17.146:61791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipaAAAAo4"], referer: http://goyalsatyam.com/wordpress
[Mon Jul 20 06:04:06.773839 2026] [security2:error] [pid 796567:tid 796814] [client 112.213.160.112:8244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OtrLfyzVz2SrjZpipogAAAok"]
[Mon Jul 20 06:04:06.773955 2026] [security2:error] [pid 796567:tid 796814] [client 112.213.160.112:8244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OtrLfyzVz2SrjZpipogAAAok"]
[Mon Jul 20 06:04:06.786256 2026] [security2:error] [pid 796567:tid 796603] [remote 47.86.33.52:19370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpipowACJSM"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 06:04:06.795868 2026] [security2:error] [pid 796928:tid 797166] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkODwAAAwU"]
[Mon Jul 20 06:04:06.920852 2026] [security2:error] [pid 796928:tid 797035] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOJgAC72o"]
[Mon Jul 20 06:04:06.921068 2026] [security2:error] [pid 796928:tid 797144] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOJgAC72o"]
[Mon Jul 20 06:04:07.086464 2026] [security2:error] [pid 796567:tid 796762] [client 50.116.65.227:53974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Ot7LfyzVz2SrjZpiprwAAAlU"]
[Mon Jul 20 06:04:07.100062 2026] [security2:error] [pid 796567:tid 796737] [client 50.116.65.227:53980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Ot7LfyzVz2SrjZpipsgAAAjw"]
[Mon Jul 20 06:04:07.331138 2026] [security2:error] [pid 796928:tid 797147] [client 57.141.18.52:44950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkNEQAC8ik"]
[Mon Jul 20 06:04:07.363139 2026] [security2:error] [pid 796928:tid 796958] [remote 202.51.202.242:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4Ot-sTy9vX-htKvPkOPAAC5B0"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 06:04:07.444122 2026] [security2:error] [pid 796928:tid 797177] [client 14.225.17.146:54040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkN2AAAAxA"], referer: http://maplerespiteservices.com/wordpress
[Mon Jul 20 06:04:07.479254 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:25123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOTgAAAuw"]
[Mon Jul 20 06:04:07.479415 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:25123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOTgAAAuw"]
[Mon Jul 20 06:04:07.500695 2026] [security2:error] [pid 796928:tid 797110] [client 47.31.86.100:58877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOUQAAAs0"]
[Mon Jul 20 06:04:07.501183 2026] [security2:error] [pid 796928:tid 797110] [client 47.31.86.100:58877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOUQAAAs0"]
[Mon Jul 20 06:04:07.662351 2026] [security2:error] [pid 796567:tid 796772] [client 14.251.3.155:59560] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Ot7LfyzVz2SrjZpipvQAAAl8"]
[Mon Jul 20 06:04:07.721694 2026] [security2:error] [pid 796928:tid 797152] [client 185.132.186.79:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOWAAAAvc"]
[Mon Jul 20 06:04:07.779954 2026] [security2:error] [pid 796928:tid 797094] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOVQAAAr0"]
[Mon Jul 20 06:04:07.811740 2026] [security2:error] [pid 796928:tid 797106] [client 14.225.17.146:62400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkN7QAAAsk"], referer: http://oldracelimited.com/wordpress
[Mon Jul 20 06:04:07.901220 2026] [security2:error] [pid 796567:tid 796592] [remote 216.73.216.55:29852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4Ot7LfyzVz2SrjZpipxAACaBg"]
[Mon Jul 20 06:04:07.903038 2026] [security2:error] [pid 796928:tid 796935] [remote 20.233.187.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4Ot-sTy9vX-htKvPkOYQADEQY"]
[Mon Jul 20 06:04:08.022067 2026] [security2:error] [pid 796928:tid 797068] [client 14.225.17.146:61828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNswAAAqM"], referer: http://mrbambooplus.com/wordpress
[Mon Jul 20 06:04:08.067426 2026] [access_compat:error] [pid 796567:tid 796752] [client 157.148.43.65:58749] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:08.161004 2026] [security2:error] [pid 796928:tid 797084] [client 14.225.17.146:61878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOZwAAArM"], referer: http://lutheranphilosopher.com/wordpress
[Mon Jul 20 06:04:08.334548 2026] [security2:error] [pid 796928:tid 796973] [remote 20.233.187.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4OuOsTy9vX-htKvPkOeAAC7Cw"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:04:08.387869 2026] [security2:error] [pid 796928:tid 797136] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOPQAAAuc"]
[Mon Jul 20 06:04:08.503051 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.93:41872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Os7LfyzVz2SrjZpipJwACcnk"]
[Mon Jul 20 06:04:08.503199 2026] [security2:error] [pid 796928:tid 797145] [client 57.141.18.112:58170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNWwAC8DY"]
[Mon Jul 20 06:04:08.562234 2026] [security2:error] [pid 796928:tid 797086] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOcAAAArU"]
[Mon Jul 20 06:04:08.642401 2026] [security2:error] [pid 796928:tid 797107] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OuOsTy9vX-htKvPkOiQAAAso"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:08.965888 2026] [security2:error] [pid 796928:tid 797081] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOmAAAArA"]
[Mon Jul 20 06:04:08.990683 2026] [security2:error] [pid 796567:tid 796773] [client 14.225.17.146:62850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4Ot7LfyzVz2SrjZpiptwAAAmA"], referer: http://cephasnext.com/wordpress
[Mon Jul 20 06:04:09.068572 2026] [security2:error] [pid 796928:tid 797137] [client 14.225.17.146:56680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOVAAAAug"], referer: http://ghivs.com/wordpress
[Mon Jul 20 06:04:09.107992 2026] [security2:error] [pid 796928:tid 797150] [client 50.116.65.227:54046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOhQAAAvU"]
[Mon Jul 20 06:04:09.245984 2026] [security2:error] [pid 796928:tid 797168] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOpAAAAwc"]
[Mon Jul 20 06:04:09.259990 2026] [lsapi:warn] [pid 796928:tid 797174] [client 34.204.28.244:51701] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.260030 2026] [lsapi:warn] [pid 796928:tid 797174] [client 34.204.28.244:51701] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.346152 2026] [lsapi:warn] [pid 796567:tid 796711] [client 50.116.65.227:14096] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.346183 2026] [lsapi:warn] [pid 796567:tid 796711] [client 50.116.65.227:14096] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.465286 2026] [security2:error] [pid 796928:tid 797105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuesTy9vX-htKvPkOuAAAAsg"]
[Mon Jul 20 06:04:09.486160 2026] [security2:error] [pid 796928:tid 797068] [client 18.228.171.129:34826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkOxQAAAqM"]
[Mon Jul 20 06:04:09.486282 2026] [security2:error] [pid 796928:tid 797068] [client 18.228.171.129:34826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkOxQAAAqM"]
[Mon Jul 20 06:04:09.540719 2026] [access_compat:error] [pid 796928:tid 797165] [client 183.47.122.163:53165] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:09.669108 2026] [security2:error] [pid 796928:tid 797180] [client 185.132.186.93:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/up.php"] [unique_id "al4OuesTy9vX-htKvPkOzgAAAxM"]
[Mon Jul 20 06:04:09.701273 2026] [security2:error] [pid 796567:tid 796770] [client 50.116.65.227:14086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4OubLfyzVz2SrjZpip6gAAAl0"]
[Mon Jul 20 06:04:09.707638 2026] [security2:error] [pid 796928:tid 797155] [client 115.246.21.170:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkO0AAAAvo"]
[Mon Jul 20 06:04:09.707765 2026] [security2:error] [pid 796928:tid 797155] [client 115.246.21.170:16640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkO0AAAAvo"]
[Mon Jul 20 06:04:09.774189 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuesTy9vX-htKvPkOyQAAAtg"]
[Mon Jul 20 06:04:09.805509 2026] [security2:error] [pid 796567:tid 796813] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OubLfyzVz2SrjZpip9wACiBo"]
[Mon Jul 20 06:04:10.116423 2026] [security2:error] [pid 796567:tid 796763] [client 181.238.134.114:23536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4OubLfyzVz2SrjZpiqAAAAAlY"]
[Mon Jul 20 06:04:10.275233 2026] [security2:error] [pid 796928:tid 797095] [client 57.141.18.102:57496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNpgACvlc"]
[Mon Jul 20 06:04:10.292964 2026] [security2:error] [pid 796928:tid 797119] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkO7AAAAtY"]
[Mon Jul 20 06:04:10.584797 2026] [security2:error] [pid 796928:tid 797164] [client 27.96.94.195:38171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPAwAAAwM"]
[Mon Jul 20 06:04:10.632809 2026] [security2:error] [pid 796928:tid 797041] [remote 130.51.180.8:48510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPDAACzHA"]
[Mon Jul 20 06:04:10.632977 2026] [security2:error] [pid 796928:tid 797109] [client 130.51.180.8:48510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPDAACzHA"]
[Mon Jul 20 06:04:10.696681 2026] [security2:error] [pid 796928:tid 797062] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkO-QAAAp0"]
[Mon Jul 20 06:04:10.724008 2026] [security2:error] [pid 796567:tid 796821] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OurLfyzVz2SrjZpiqFgAAApA"]
[Mon Jul 20 06:04:10.805402 2026] [security2:error] [pid 796928:tid 797080] [client 129.222.187.209:15121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPEwAAAq8"]
[Mon Jul 20 06:04:10.809906 2026] [security2:error] [pid 796928:tid 797080] [client 129.222.187.209:15121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPEwAAAq8"]
[Mon Jul 20 06:04:11.059593 2026] [security2:error] [pid 796928:tid 797112] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkPGQAAAs8"]
[Mon Jul 20 06:04:11.074592 2026] [security2:error] [pid 796928:tid 797135] [client 57.141.18.79:39156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkN4wAC5mk"]
[Mon Jul 20 06:04:11.122393 2026] [security2:error] [pid 796567:tid 796785] [client 77.110.127.138:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou7LfyzVz2SrjZpiqKAAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:11.129627 2026] [security2:error] [pid 796928:tid 797139] [client 114.119.132.28:20537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/page/44"] [unique_id "al4Ou-sTy9vX-htKvPkPLAAAAuo"], referer: https://www.thewelloiledlife.com/page/45?hc_location=ufi
[Mon Jul 20 06:04:11.235188 2026] [security2:error] [pid 796928:tid 797117] [client 104.234.53.90:46375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ou-sTy9vX-htKvPkPLQAAAtQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:11.396542 2026] [security2:error] [pid 796928:tid 797086] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ou-sTy9vX-htKvPkPJwAAArU"]
[Mon Jul 20 06:04:11.397652 2026] [security2:error] [pid 796928:tid 797068] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Ou-sTy9vX-htKvPkPMgAAAqM"]
[Mon Jul 20 06:04:11.420136 2026] [security2:error] [pid 796928:tid 797133] [client 41.173.37.102:11404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPOgAAAuQ"]
[Mon Jul 20 06:04:11.420294 2026] [security2:error] [pid 796928:tid 797133] [client 41.173.37.102:11404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPOgAAAuQ"]
[Mon Jul 20 06:04:11.625279 2026] [security2:error] [pid 796928:tid 797141] [client 185.132.186.61:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/bypass.php"] [unique_id "al4Ou-sTy9vX-htKvPkPUgAAAuw"]
[Mon Jul 20 06:04:11.773351 2026] [security2:error] [pid 796928:tid 797059] [client 210.212.97.243:10436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWQAAApo"]
[Mon Jul 20 06:04:11.773465 2026] [security2:error] [pid 796928:tid 797059] [client 210.212.97.243:10436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWQAAApo"]
[Mon Jul 20 06:04:11.830723 2026] [security2:error] [pid 796928:tid 797083] [client 86.98.90.58:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWwAAArI"]
[Mon Jul 20 06:04:11.830836 2026] [security2:error] [pid 796928:tid 797083] [client 86.98.90.58:51256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWwAAArI"]
[Mon Jul 20 06:04:11.869981 2026] [security2:error] [pid 796928:tid 797128] [client 44.245.170.32:40084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ou-sTy9vX-htKvPkPXAAAAt8"]
[Mon Jul 20 06:04:11.972423 2026] [security2:error] [pid 796928:tid 797005] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPXwACyUw"]
[Mon Jul 20 06:04:11.973761 2026] [security2:error] [pid 796928:tid 797106] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPXwACyUw"]
[Mon Jul 20 06:04:11.983042 2026] [security2:error] [pid 796928:tid 797071] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ou-sTy9vX-htKvPkPVAAAAqY"]
[Mon Jul 20 06:04:12.061486 2026] [security2:error] [pid 796928:tid 797061] [client 57.141.18.45:36118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkOGAACnG8"]
[Mon Jul 20 06:04:12.297290 2026] [security2:error] [pid 796567:tid 796759] [client 103.95.123.246:20643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OvLLfyzVz2SrjZpiqUwAAAlI"]
[Mon Jul 20 06:04:12.297392 2026] [security2:error] [pid 796567:tid 796759] [client 103.95.123.246:20643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OvLLfyzVz2SrjZpiqUwAAAlI"]
[Mon Jul 20 06:04:12.307068 2026] [security2:error] [pid 796567:tid 796596] [remote 217.61.143.92:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OvLLfyzVz2SrjZpiqVAACkxw"]
[Mon Jul 20 06:04:12.442744 2026] [security2:error] [pid 796567:tid 796764] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvLLfyzVz2SrjZpiqTQAAAlc"]
[Mon Jul 20 06:04:12.453968 2026] [security2:error] [pid 796567:tid 796750] [client 40.77.167.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OvLLfyzVz2SrjZpiqUgACSWA"]
[Mon Jul 20 06:04:12.491677 2026] [security2:error] [pid 796928:tid 797156] [client 104.234.53.64:43741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OvOsTy9vX-htKvPkPcAAAAvs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:12.540978 2026] [security2:error] [pid 796567:tid 796674] [remote 217.61.143.92:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OvLLfyzVz2SrjZpiqXQACMGo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:04:12.654071 2026] [security2:error] [pid 796567:tid 796765] [client 57.141.18.98:51152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ot7LfyzVz2SrjZpiptgACWBM"]
[Mon Jul 20 06:04:12.777221 2026] [security2:error] [pid 796928:tid 797074] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvOsTy9vX-htKvPkPdAAAAqk"]
[Mon Jul 20 06:04:12.788364 2026] [security2:error] [pid 796928:tid 797124] [client 57.141.18.95:45826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOSAAC2xM"]
[Mon Jul 20 06:04:13.127659 2026] [security2:error] [pid 796928:tid 797147] [client 164.100.212.184:50041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OvesTy9vX-htKvPkPnQAAAvI"]
[Mon Jul 20 06:04:13.127743 2026] [security2:error] [pid 796928:tid 797147] [client 164.100.212.184:50041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OvesTy9vX-htKvPkPnQAAAvI"]
[Mon Jul 20 06:04:13.279157 2026] [security2:error] [pid 796928:tid 797125] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkPlQAAAtw"]
[Mon Jul 20 06:04:13.451646 2026] [security2:error] [pid 796567:tid 796702] [client 103.149.16.77:64201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqdQAAAhk"]
[Mon Jul 20 06:04:13.451799 2026] [security2:error] [pid 796567:tid 796702] [client 103.149.16.77:64201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqdQAAAhk"]
[Mon Jul 20 06:04:13.567155 2026] [security2:error] [pid 796928:tid 797085] [client 185.132.186.72:27615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/images/admin.php"] [unique_id "al4OvesTy9vX-htKvPkPtQAAArQ"]
[Mon Jul 20 06:04:13.589926 2026] [security2:error] [pid 796928:tid 797082] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkPqAAAArE"]
[Mon Jul 20 06:04:13.706188 2026] [security2:error] [pid 796567:tid 796706] [client 77.110.127.138:54767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/dkt2tlik92n5.php"] [unique_id "al4OvbLfyzVz2SrjZpiqfQAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:13.740329 2026] [autoindex:error] [pid 796928:tid 797165] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:13.755463 2026] [security2:error] [pid 796567:tid 796704] [client 181.224.94.124:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqgQAAAhs"]
[Mon Jul 20 06:04:13.755556 2026] [security2:error] [pid 796567:tid 796704] [client 181.224.94.124:55045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqgQAAAhs"]
[Mon Jul 20 06:04:13.757639 2026] [autoindex:error] [pid 796928:tid 797105] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:04:13.861853 2026] [security2:error] [pid 796567:tid 796707] [client 104.234.53.94:22641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OvbLfyzVz2SrjZpiqhAAAAh4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:13.867354 2026] [security2:error] [pid 796928:tid 797089] [client 50.116.65.227:33382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4OvesTy9vX-htKvPkP2wAAArg"]
[Mon Jul 20 06:04:13.882487 2026] [security2:error] [pid 796928:tid 797099] [client 50.116.65.227:14208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4OvesTy9vX-htKvPkP3QAAAvY"]
[Mon Jul 20 06:04:13.924078 2026] [security2:error] [pid 796928:tid 797176] [client 77.110.127.138:54677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkPxQAAAw8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:13.991271 2026] [security2:error] [pid 796928:tid 797068] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkP0AAAAqM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.073614 2026] [security2:error] [pid 796928:tid 797109] [client 77.110.127.138:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/frontend/vh6mbu8i2typ.php"] [unique_id "al4OvusTy9vX-htKvPkP5gAAAsw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.119005 2026] [autoindex:error] [pid 796928:tid 797061] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:14.131801 2026] [autoindex:error] [pid 796928:tid 797103] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.283275 2026] [security2:error] [pid 796928:tid 797083] [client 77.110.127.138:55020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkP5wAAArI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.300341 2026] [access_compat:error] [pid 796928:tid 797171] [client 183.47.107.57:48625] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:14.321926 2026] [security2:error] [pid 796928:tid 797087] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkP8QAAArY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.406274 2026] [security2:error] [pid 796928:tid 797113] [client 14.225.17.146:60088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4OvOsTy9vX-htKvPkPeQAAAtA"]
[Mon Jul 20 06:04:14.412698 2026] [security2:error] [pid 796928:tid 797146] [client 129.222.187.209:31539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvusTy9vX-htKvPkQAgAAAvE"]
[Mon Jul 20 06:04:14.420273 2026] [security2:error] [pid 796928:tid 797146] [client 129.222.187.209:31539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvusTy9vX-htKvPkQAgAAAvE"]
[Mon Jul 20 06:04:14.462651 2026] [access_compat:error] [pid 796928:tid 797167] [client 110.248.25.49:5391] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:14.573663 2026] [security2:error] [pid 796928:tid 797078] [client 77.110.127.138:55011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/frontend/classic/5nvj5ghks9vj.php"] [unique_id "al4OvusTy9vX-htKvPkQDQAAAq0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.579642 2026] [security2:error] [pid 796567:tid 796726] [client 72.255.10.154:26314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OvrLfyzVz2SrjZpiqpgAAAjE"]
[Mon Jul 20 06:04:14.579775 2026] [security2:error] [pid 796567:tid 796726] [client 72.255.10.154:26314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OvrLfyzVz2SrjZpiqpgAAAjE"]
[Mon Jul 20 06:04:14.603022 2026] [autoindex:error] [pid 796928:tid 797135] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/classic/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:14.736298 2026] [autoindex:error] [pid 796928:tid 797184] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/classic/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.825284 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvrLfyzVz2SrjZpiqqgAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.853309 2026] [security2:error] [pid 796928:tid 797141] [client 77.110.127.138:55021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkQDgAAAuw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.020336 2026] [security2:error] [pid 796928:tid 797060] [client 14.225.17.146:50313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkQHQAAAps"], referer: http://adastra.love/wordpress
[Mon Jul 20 06:04:15.087102 2026] [security2:error] [pid 796567:tid 796721] [client 77.110.127.138:54715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/baking/feed/i82pgjyuer2d.php"] [unique_id "al4Ov7LfyzVz2SrjZpiqxgAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.259041 2026] [security2:error] [pid 796928:tid 797068] [client 4.218.23.144:30215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Ov-sTy9vX-htKvPkQRAAAAqM"]
[Mon Jul 20 06:04:15.277241 2026] [security2:error] [pid 796928:tid 796977] [remote 57.141.18.32:36636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3503928"] [unique_id "al4Ov-sTy9vX-htKvPkQRwADEzA"]
[Mon Jul 20 06:04:15.341008 2026] [security2:error] [pid 796928:tid 797086] [client 13.201.64.214:48118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQSgAAArU"]
[Mon Jul 20 06:04:15.341104 2026] [security2:error] [pid 796928:tid 797086] [client 13.201.64.214:48118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQSgAAArU"]
[Mon Jul 20 06:04:15.390876 2026] [security2:error] [pid 796928:tid 797061] [client 4.218.23.144:30215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Ov-sTy9vX-htKvPkQTgAAApw"]
[Mon Jul 20 06:04:15.401574 2026] [security2:error] [pid 796567:tid 796724] [client 52.109.16.52:16451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Ov7LfyzVz2SrjZpiq0gAAAi8"]
[Mon Jul 20 06:04:15.411272 2026] [security2:error] [pid 796928:tid 797147] [client 77.110.127.138:55025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ov-sTy9vX-htKvPkQOAAAAvI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.438781 2026] [security2:error] [pid 796928:tid 797084] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ov-sTy9vX-htKvPkQPQAAArM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.453068 2026] [security2:error] [pid 796567:tid 796796] [client 52.109.16.52:16451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Ov7LfyzVz2SrjZpiq2QAAAnc"]
[Mon Jul 20 06:04:15.466225 2026] [security2:error] [pid 796567:tid 796792] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ov7LfyzVz2SrjZpiqzAAAAnM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.515075 2026] [security2:error] [pid 796928:tid 797164] [client 185.132.186.92:57021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/index.php"] [unique_id "al4Ov-sTy9vX-htKvPkQWQAAAwM"]
[Mon Jul 20 06:04:15.562378 2026] [access_compat:error] [pid 796928:tid 797143] [client 183.47.122.226:50519] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:15.735180 2026] [security2:error] [pid 796567:tid 796781] [client 57.141.18.6:53742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OubLfyzVz2SrjZpip_wACaGY"]
[Mon Jul 20 06:04:15.764169 2026] [security2:error] [pid 796928:tid 797066] [client 106.192.104.4:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQYwAAAqE"]
[Mon Jul 20 06:04:15.768432 2026] [security2:error] [pid 796928:tid 797066] [client 106.192.104.4:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQYwAAAqE"]
[Mon Jul 20 06:04:16.261735 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4OwOsTy9vX-htKvPkQdgAAAs8"]
[Mon Jul 20 06:04:16.261852 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4OwOsTy9vX-htKvPkQdgAAAs8"]
[Mon Jul 20 06:04:16.265968 2026] [security2:error] [pid 796928:tid 797159] [client 57.141.18.20:23870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkPCgAC_l8"]
[Mon Jul 20 06:04:16.295864 2026] [security2:error] [pid 796928:tid 797160] [client 50.116.65.227:14294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OwOsTy9vX-htKvPkQegAAAv8"]
[Mon Jul 20 06:04:16.306583 2026] [security2:error] [pid 796928:tid 797088] [client 50.116.65.227:14304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OwOsTy9vX-htKvPkQfAAAArc"]
[Mon Jul 20 06:04:16.328176 2026] [security2:error] [pid 796928:tid 797004] [remote 173.249.4.11:15456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OwOsTy9vX-htKvPkQfwADB0s"]
[Mon Jul 20 06:04:16.561717 2026] [security2:error] [pid 796928:tid 797018] [remote 173.249.4.11:15456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OwOsTy9vX-htKvPkQkgADAFk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:04:16.616585 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4OwOsTy9vX-htKvPkQkwAAAqU"]
[Mon Jul 20 06:04:16.616717 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4OwOsTy9vX-htKvPkQkwAAAqU"]
[Mon Jul 20 06:04:16.844665 2026] [security2:error] [pid 796567:tid 796786] [client 50.116.65.227:14346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OwLLfyzVz2SrjZpiq-wAAAm0"]
[Mon Jul 20 06:04:16.997474 2026] [security2:error] [pid 796567:tid 796802] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xyn.php"] [unique_id "al4OwLLfyzVz2SrjZpirDAAAAn0"]
[Mon Jul 20 06:04:16.997620 2026] [security2:error] [pid 796567:tid 796802] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xyn.php"] [unique_id "al4OwLLfyzVz2SrjZpirDAAAAn0"]
[Mon Jul 20 06:04:17.027022 2026] [security2:error] [pid 796567:tid 796780] [client 50.116.65.227:14358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OwLLfyzVz2SrjZpirBwAAAmc"]
[Mon Jul 20 06:04:17.354880 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/patie.php"] [unique_id "al4OwesTy9vX-htKvPkQuAAAAwo"]
[Mon Jul 20 06:04:17.354981 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/patie.php"] [unique_id "al4OwesTy9vX-htKvPkQuAAAAwo"]
[Mon Jul 20 06:04:17.435626 2026] [security2:error] [pid 796928:tid 797084] [client 35.180.166.19:30000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQugAAArM"]
[Mon Jul 20 06:04:17.498572 2026] [security2:error] [pid 796928:tid 797117] [client 185.132.186.71:46927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQvAAAAtQ"]
[Mon Jul 20 06:04:17.596152 2026] [security2:error] [pid 796928:tid 797061] [client 112.213.160.112:8498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQwgAAApw"]
[Mon Jul 20 06:04:17.596299 2026] [security2:error] [pid 796928:tid 797061] [client 112.213.160.112:8498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQwgAAApw"]
[Mon Jul 20 06:04:17.620343 2026] [security2:error] [pid 796928:tid 797006] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQxAAC3E0"]
[Mon Jul 20 06:04:17.620469 2026] [security2:error] [pid 796928:tid 797125] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQxAAC3E0"]
[Mon Jul 20 06:04:17.700016 2026] [security2:error] [pid 796567:tid 796787] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/aa.php"] [unique_id "al4OwbLfyzVz2SrjZpirHAAAAm4"]
[Mon Jul 20 06:04:17.700134 2026] [security2:error] [pid 796567:tid 796787] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/aa.php"] [unique_id "al4OwbLfyzVz2SrjZpirHAAAAm4"]
[Mon Jul 20 06:04:17.717802 2026] [security2:error] [pid 796928:tid 797070] [client 193.37.33.1:47709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQzwAAAqU"]
[Mon Jul 20 06:04:17.735355 2026] [security2:error] [pid 796928:tid 797151] [client 193.19.109.250:58471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQzgAAAvY"]
[Mon Jul 20 06:04:17.933313 2026] [security2:error] [pid 796928:tid 797113] [client 150.228.148.150:23927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQ4gAAAtA"]
[Mon Jul 20 06:04:17.941019 2026] [security2:error] [pid 796928:tid 797113] [client 150.228.148.150:23927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQ4gAAAtA"]
[Mon Jul 20 06:04:17.958373 2026] [security2:error] [pid 796928:tid 797169] [client 35.180.166.19:30014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQ5wAAAwg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:04:17.975816 2026] [access_compat:error] [pid 796928:tid 797180] [client 157.148.43.150:43779] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:18.055105 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xwpg.php"] [unique_id "al4OwusTy9vX-htKvPkQ7wAAAvU"]
[Mon Jul 20 06:04:18.055216 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xwpg.php"] [unique_id "al4OwusTy9vX-htKvPkQ7wAAAvU"]
[Mon Jul 20 06:04:18.056190 2026] [security2:error] [pid 796928:tid 797175] [client 57.141.18.111:54358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OvOsTy9vX-htKvPkPewADDkM"]
[Mon Jul 20 06:04:18.062756 2026] [security2:error] [pid 796928:tid 797131] [client 47.31.86.100:59386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OwusTy9vX-htKvPkQ8QAAAuI"]
[Mon Jul 20 06:04:18.062864 2026] [security2:error] [pid 796928:tid 797131] [client 47.31.86.100:59386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OwusTy9vX-htKvPkQ8QAAAuI"]
[Mon Jul 20 06:04:18.076106 2026] [security2:error] [pid 796928:tid 797001] [remote 130.185.118.215:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OwusTy9vX-htKvPkQ8gAC70g"]
[Mon Jul 20 06:04:18.231713 2026] [security2:error] [pid 796928:tid 797125] [client 77.110.127.138:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OwusTy9vX-htKvPkQ9wAAAtw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:18.292597 2026] [security2:error] [pid 796928:tid 797007] [remote 130.185.118.215:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OwusTy9vX-htKvPkQ_QADBU4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:18.434488 2026] [security2:error] [pid 796928:tid 797159] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ops.php"] [unique_id "al4OwusTy9vX-htKvPkRBgAAAv4"]
[Mon Jul 20 06:04:18.434604 2026] [security2:error] [pid 796928:tid 797159] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ops.php"] [unique_id "al4OwusTy9vX-htKvPkRBgAAAv4"]
[Mon Jul 20 06:04:18.720955 2026] [security2:error] [pid 796928:tid 797180] [client 50.116.65.227:33398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4OwusTy9vX-htKvPkREgAAAxM"]
[Mon Jul 20 06:04:18.733272 2026] [security2:error] [pid 796928:tid 797110] [client 50.116.65.227:14386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4OwusTy9vX-htKvPkRFAAAAs0"]
[Mon Jul 20 06:04:18.812975 2026] [security2:error] [pid 796567:tid 796714] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mac.php"] [unique_id "al4OwrLfyzVz2SrjZpirSAAAAiU"]
[Mon Jul 20 06:04:18.813145 2026] [security2:error] [pid 796567:tid 796714] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mac.php"] [unique_id "al4OwrLfyzVz2SrjZpirSAAAAiU"]
[Mon Jul 20 06:04:19.181569 2026] [security2:error] [pid 796567:tid 796716] [client 14.225.17.146:62231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4OwbLfyzVz2SrjZpirFQAAAic"], referer: http://tntcatholic.com/wordpress
[Mon Jul 20 06:04:19.224599 2026] [security2:error] [pid 796567:tid 796759] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mg.php"] [unique_id "al4Ow7LfyzVz2SrjZpirUwAAAlI"]
[Mon Jul 20 06:04:19.224776 2026] [security2:error] [pid 796567:tid 796759] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mg.php"] [unique_id "al4Ow7LfyzVz2SrjZpirUwAAAlI"]
[Mon Jul 20 06:04:19.449389 2026] [security2:error] [pid 796928:tid 797152] [client 185.132.186.63:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/simple/function.php"] [unique_id "al4Ow-sTy9vX-htKvPkRTQAAAvc"]
[Mon Jul 20 06:04:19.463153 2026] [security2:error] [pid 796567:tid 796824] [client 27.96.94.195:36882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Ow7LfyzVz2SrjZpirVgAAApM"]
[Mon Jul 20 06:04:19.595699 2026] [security2:error] [pid 796928:tid 797168] [client 193.19.109.226:48179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Ow-sTy9vX-htKvPkRUgAAAwc"]
[Mon Jul 20 06:04:19.597834 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-post-data.php"] [unique_id "al4Ow7LfyzVz2SrjZpirXQAAAog"]
[Mon Jul 20 06:04:19.597954 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-post-data.php"] [unique_id "al4Ow7LfyzVz2SrjZpirXQAAAog"]
[Mon Jul 20 06:04:19.604134 2026] [security2:error] [pid 796928:tid 797184] [client 173.239.254.42:40305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Ow-sTy9vX-htKvPkRUQAAAxc"]
[Mon Jul 20 06:04:19.624838 2026] [security2:error] [pid 796928:tid 797058] [client 193.19.109.221:24703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Ow-sTy9vX-htKvPkRUAAAApk"]
[Mon Jul 20 06:04:19.905163 2026] [security2:error] [pid 796567:tid 796801] [client 5.161.177.47:34982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Ow7LfyzVz2SrjZpirZAAAAnw"], referer: https://windowtx.com
[Mon Jul 20 06:04:20.009061 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/pucci.php"] [unique_id "al4OxLLfyzVz2SrjZpiragAAAmk"]
[Mon Jul 20 06:04:20.009186 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/pucci.php"] [unique_id "al4OxLLfyzVz2SrjZpiragAAAmk"]
[Mon Jul 20 06:04:20.056273 2026] [security2:error] [pid 796928:tid 797161] [client 14.225.17.146:55263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4OwusTy9vX-htKvPkRAAAAAwA"], referer: http://reosportsboats.com/wordpress
[Mon Jul 20 06:04:20.176186 2026] [security2:error] [pid 796928:tid 797155] [client 193.19.109.218:31409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4OxOsTy9vX-htKvPkRcAAAAvo"]
[Mon Jul 20 06:04:20.269504 2026] [security2:error] [pid 796928:tid 797122] [client 18.228.171.129:34130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRdgAAAtk"]
[Mon Jul 20 06:04:20.269695 2026] [security2:error] [pid 796928:tid 797122] [client 18.228.171.129:34130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRdgAAAtk"]
[Mon Jul 20 06:04:20.280636 2026] [security2:error] [pid 796928:tid 797081] [client 115.246.21.170:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRegAAArA"]
[Mon Jul 20 06:04:20.280744 2026] [security2:error] [pid 796928:tid 797081] [client 115.246.21.170:13726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRegAAArA"]
[Mon Jul 20 06:04:20.364713 2026] [security2:error] [pid 796567:tid 796707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OxLLfyzVz2SrjZpirdgAAAh4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:20.433040 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/black.php"] [unique_id "al4OxOsTy9vX-htKvPkRggAAAwg"]
[Mon Jul 20 06:04:20.433126 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/black.php"] [unique_id "al4OxOsTy9vX-htKvPkRggAAAwg"]
[Mon Jul 20 06:04:20.466801 2026] [security2:error] [pid 796928:tid 797083] [client 57.141.18.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4OxOsTy9vX-htKvPkRfAAAArI"]
[Mon Jul 20 06:04:20.589953 2026] [security2:error] [pid 796928:tid 797149] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRdwAC9Bc"]
[Mon Jul 20 06:04:20.703001 2026] [security2:error] [pid 796928:tid 797102] [client 159.138.109.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OxOsTy9vX-htKvPkRjQACxQI"]
[Mon Jul 20 06:04:20.786498 2026] [security2:error] [pid 796567:tid 796712] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zlece.php"] [unique_id "al4OxLLfyzVz2SrjZpirfQAAAiM"]
[Mon Jul 20 06:04:20.786627 2026] [security2:error] [pid 796567:tid 796712] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zlece.php"] [unique_id "al4OxLLfyzVz2SrjZpirfQAAAiM"]
[Mon Jul 20 06:04:20.963514 2026] [security2:error] [pid 796928:tid 797181] [client 14.225.17.146:61636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4OxOsTy9vX-htKvPkRnAAAAxQ"], referer: https://reosportsboats.com/wordpress
[Mon Jul 20 06:04:21.034652 2026] [security2:error] [pid 796928:tid 797160] [client 74.208.214.194:37008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OxesTy9vX-htKvPkRqwAAAv8"]
[Mon Jul 20 06:04:21.179645 2026] [security2:error] [pid 796928:tid 797184] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/vssrs.php"] [unique_id "al4OxesTy9vX-htKvPkRtQAAAxc"]
[Mon Jul 20 06:04:21.179774 2026] [security2:error] [pid 796928:tid 797184] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/vssrs.php"] [unique_id "al4OxesTy9vX-htKvPkRtQAAAxc"]
[Mon Jul 20 06:04:21.309215 2026] [security2:error] [pid 796928:tid 797124] [client 129.222.187.209:14002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkRugAAAts"]
[Mon Jul 20 06:04:21.316844 2026] [security2:error] [pid 796928:tid 797124] [client 129.222.187.209:14002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkRugAAAts"]
[Mon Jul 20 06:04:21.459303 2026] [access_compat:error] [pid 796928:tid 797150] [client 101.19.156.87:20072] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:21.519189 2026] [security2:error] [pid 796567:tid 796793] [client 77.110.127.138:55033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxbLfyzVz2SrjZpirjAAAAnQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.525729 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wicked.php"] [unique_id "al4OxbLfyzVz2SrjZpirjQAAAmE"]
[Mon Jul 20 06:04:21.525933 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wicked.php"] [unique_id "al4OxbLfyzVz2SrjZpirjQAAAmE"]
[Mon Jul 20 06:04:21.570974 2026] [security2:error] [pid 796928:tid 797059] [client 77.110.127.138:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkRzQAAApo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.671464 2026] [autoindex:error] [pid 796928:tid 797159] [client 14.225.17.146:52909] AH01276: Cannot serve directory /home4/koaconsu/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://koaconsultants.com/wordpress
[Mon Jul 20 06:04:21.696638 2026] [security2:error] [pid 796928:tid 797119] [client 77.110.127.138:55025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkR1QAAAtY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.768841 2026] [security2:error] [pid 796567:tid 796773] [client 77.110.127.138:55028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxbLfyzVz2SrjZpirkwAAAmA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.821074 2026] [security2:error] [pid 796928:tid 796989] [remote 130.185.118.215:34592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkR4wACpTw"]
[Mon Jul 20 06:04:21.821273 2026] [security2:error] [pid 796928:tid 797070] [client 130.185.118.215:34592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkR4wACpTw"]
[Mon Jul 20 06:04:21.824465 2026] [security2:error] [pid 796567:tid 796824] [client 77.110.127.138:54869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxbLfyzVz2SrjZpirlAAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.884782 2026] [security2:error] [pid 796567:tid 796799] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/24.php"] [unique_id "al4OxbLfyzVz2SrjZpirlQAAAno"]
[Mon Jul 20 06:04:21.884882 2026] [security2:error] [pid 796567:tid 796799] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/24.php"] [unique_id "al4OxbLfyzVz2SrjZpirlQAAAno"]
[Mon Jul 20 06:04:21.887788 2026] [security2:error] [pid 796928:tid 797156] [client 14.225.17.146:53916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4OxesTy9vX-htKvPkRywAAAvs"], referer: http://aljosour-alarabia.com/wordpress
[Mon Jul 20 06:04:22.001237 2026] [security2:error] [pid 796567:tid 796751] [client 77.110.127.138:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxrLfyzVz2SrjZpiroAAAAko"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:22.073551 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:11855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR8wAAAp8"]
[Mon Jul 20 06:04:22.073678 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:11855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR8wAAAp8"]
[Mon Jul 20 06:04:22.205283 2026] [security2:error] [pid 796928:tid 797095] [client 178.152.178.232:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR-QAAAr4"]
[Mon Jul 20 06:04:22.205456 2026] [security2:error] [pid 796928:tid 797095] [client 178.152.178.232:36278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR-QAAAr4"]
[Mon Jul 20 06:04:22.246534 2026] [security2:error] [pid 796567:tid 796756] [client 57.141.18.33:23812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OwLLfyzVz2SrjZpiq9AACTwE"]
[Mon Jul 20 06:04:22.247073 2026] [security2:error] [pid 796928:tid 797148] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xacs.php"] [unique_id "al4OxusTy9vX-htKvPkR-wAAAvM"]
[Mon Jul 20 06:04:22.247166 2026] [security2:error] [pid 796928:tid 797148] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xacs.php"] [unique_id "al4OxusTy9vX-htKvPkR-wAAAvM"]
[Mon Jul 20 06:04:22.323955 2026] [security2:error] [pid 796928:tid 797180] [client 193.19.109.220:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4OxusTy9vX-htKvPkR_wAAAxM"]
[Mon Jul 20 06:04:22.375899 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSAgAAAqw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:22.387695 2026] [security2:error] [pid 796928:tid 797136] [client 210.212.97.243:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSAwAAAuc"]
[Mon Jul 20 06:04:22.387861 2026] [security2:error] [pid 796928:tid 797136] [client 210.212.97.243:10437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSAwAAAuc"]
[Mon Jul 20 06:04:22.434139 2026] [security2:error] [pid 796928:tid 797161] [client 185.132.186.54:44333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ext.php"] [unique_id "al4OxusTy9vX-htKvPkSBgAAAwA"]
[Mon Jul 20 06:04:22.542313 2026] [security2:error] [pid 796567:tid 796633] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OxrLfyzVz2SrjZpirrAACN0E"]
[Mon Jul 20 06:04:22.542431 2026] [security2:error] [pid 796567:tid 796732] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OxrLfyzVz2SrjZpirrAACN0E"]
[Mon Jul 20 06:04:22.610280 2026] [security2:error] [pid 796928:tid 797168] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zildan.php"] [unique_id "al4OxusTy9vX-htKvPkSGAAAAwc"]
[Mon Jul 20 06:04:22.610391 2026] [security2:error] [pid 796928:tid 797168] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zildan.php"] [unique_id "al4OxusTy9vX-htKvPkSGAAAAwc"]
[Mon Jul 20 06:04:22.674799 2026] [security2:error] [pid 796928:tid 796979] [remote 130.185.118.215:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OxusTy9vX-htKvPkSHQAC9zI"]
[Mon Jul 20 06:04:22.760060 2026] [security2:error] [pid 796928:tid 797027] [remote 95.217.78.234:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSIQACpWI"]
[Mon Jul 20 06:04:22.760288 2026] [security2:error] [pid 796928:tid 797070] [client 95.217.78.234:39762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSIQACpWI"]
[Mon Jul 20 06:04:22.853400 2026] [security2:error] [pid 796928:tid 797038] [remote 130.185.118.215:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OxusTy9vX-htKvPkSIwAC3m0"], referer: https://mail.pju.xqs.mybluehost.me/wp-login.php
[Mon Jul 20 06:04:22.963738 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/csa.php"] [unique_id "al4OxusTy9vX-htKvPkSKgAAAwQ"]
[Mon Jul 20 06:04:22.963859 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/csa.php"] [unique_id "al4OxusTy9vX-htKvPkSKgAAAwQ"]
[Mon Jul 20 06:04:23.121709 2026] [security2:error] [pid 796928:tid 797100] [client 57.141.18.3:56866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OwesTy9vX-htKvPkQrAACw1o"]
[Mon Jul 20 06:04:23.176700 2026] [security2:error] [pid 796567:tid 796775] [client 86.98.90.58:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirvgAAAmI"]
[Mon Jul 20 06:04:23.177052 2026] [security2:error] [pid 796567:tid 796775] [client 86.98.90.58:52121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirvgAAAmI"]
[Mon Jul 20 06:04:23.268234 2026] [security2:error] [pid 796928:tid 797072] [client 103.95.123.246:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSOwAAAqc"]
[Mon Jul 20 06:04:23.268412 2026] [security2:error] [pid 796928:tid 797072] [client 103.95.123.246:21131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSOwAAAqc"]
[Mon Jul 20 06:04:23.275633 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:58862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4OxrLfyzVz2SrjZpirsQAAAn0"], referer: http://waterproofgoods.com/wordpress
[Mon Jul 20 06:04:23.310447 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/w3llscc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSPwAAAwg"]
[Mon Jul 20 06:04:23.310587 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/w3llscc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSPwAAAwg"]
[Mon Jul 20 06:04:23.696791 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wpx.php"] [unique_id "al4Ox-sTy9vX-htKvPkSWQAAAwQ"]
[Mon Jul 20 06:04:23.696918 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wpx.php"] [unique_id "al4Ox-sTy9vX-htKvPkSWQAAAwQ"]
[Mon Jul 20 06:04:23.742716 2026] [security2:error] [pid 796928:tid 797138] [client 164.100.212.184:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSXQAAAuk"]
[Mon Jul 20 06:04:23.742840 2026] [security2:error] [pid 796928:tid 797138] [client 164.100.212.184:50618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSXQAAAuk"]
[Mon Jul 20 06:04:23.909936 2026] [security2:error] [pid 796567:tid 796787] [client 181.224.94.124:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirzgAAAm4"]
[Mon Jul 20 06:04:24.073639 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-css.php"] [unique_id "al4OyOsTy9vX-htKvPkSbwAAAt0"]
[Mon Jul 20 06:04:24.073742 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-css.php"] [unique_id "al4OyOsTy9vX-htKvPkSbwAAAt0"]
[Mon Jul 20 06:04:24.379323 2026] [security2:error] [pid 796928:tid 797138] [client 185.132.186.92:27755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/delpaths.php"] [unique_id "al4OyOsTy9vX-htKvPkSigAAAuk"]
[Mon Jul 20 06:04:24.418561 2026] [security2:error] [pid 796567:tid 796787] [client 181.224.94.124:8905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirzgAAAm4"]
[Mon Jul 20 06:04:24.427286 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/alfa_shell_4.1.php"] [unique_id "al4OyOsTy9vX-htKvPkSiwAAAvU"]
[Mon Jul 20 06:04:24.427435 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/alfa_shell_4.1.php"] [unique_id "al4OyOsTy9vX-htKvPkSiwAAAvU"]
[Mon Jul 20 06:04:24.546690 2026] [security2:error] [pid 796567:tid 796823] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyLLfyzVz2SrjZpir2gAAApI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:24.687534 2026] [security2:error] [pid 796567:tid 796738] [client 14.225.17.146:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Ox7LfyzVz2SrjZpiryAAAAj0"], referer: http://ncsynchro.com/wordpress
[Mon Jul 20 06:04:24.764774 2026] [security2:error] [pid 796928:tid 797181] [client 129.222.187.209:30797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OyOsTy9vX-htKvPkSqwAAAxQ"]
[Mon Jul 20 06:04:24.768417 2026] [security2:error] [pid 796928:tid 797181] [client 129.222.187.209:30797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OyOsTy9vX-htKvPkSqwAAAxQ"]
[Mon Jul 20 06:04:24.812119 2026] [security2:error] [pid 796928:tid 797089] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ho.php"] [unique_id "al4OyOsTy9vX-htKvPkSsAAAArg"]
[Mon Jul 20 06:04:24.812249 2026] [security2:error] [pid 796928:tid 797089] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ho.php"] [unique_id "al4OyOsTy9vX-htKvPkSsAAAArg"]
[Mon Jul 20 06:04:24.914280 2026] [security2:error] [pid 796567:tid 796671] [remote 98.156.100.191:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4OyLLfyzVz2SrjZpir7wACRmc"]
[Mon Jul 20 06:04:25.099358 2026] [security2:error] [pid 796567:tid 796780] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyLLfyzVz2SrjZpir7AAAAmc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.162406 2026] [security2:error] [pid 796928:tid 797185] [client 57.141.18.48:43236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OwusTy9vX-htKvPkRHAADGHI"]
[Mon Jul 20 06:04:25.175360 2026] [security2:error] [pid 796567:tid 796781] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xy.php"] [unique_id "al4OybLfyzVz2SrjZpir_gAAAmg"]
[Mon Jul 20 06:04:25.175452 2026] [security2:error] [pid 796567:tid 796781] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xy.php"] [unique_id "al4OybLfyzVz2SrjZpir_gAAAmg"]
[Mon Jul 20 06:04:25.178252 2026] [security2:error] [pid 796567:tid 796774] [client 103.149.16.77:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpir_wAAAmE"]
[Mon Jul 20 06:04:25.178344 2026] [security2:error] [pid 796567:tid 796774] [client 103.149.16.77:64672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpir_wAAAmE"]
[Mon Jul 20 06:04:25.396036 2026] [security2:error] [pid 796567:tid 796724] [client 72.255.10.154:2421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpisCAAAAi8"]
[Mon Jul 20 06:04:25.396178 2026] [security2:error] [pid 796567:tid 796724] [client 72.255.10.154:2421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpisCAAAAi8"]
[Mon Jul 20 06:04:25.428160 2026] [security2:error] [pid 796928:tid 797145] [client 77.110.127.138:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OyesTy9vX-htKvPkSygAAAvA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.472948 2026] [security2:error] [pid 796567:tid 796699] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OybLfyzVz2SrjZpisAwAAAhY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.482308 2026] [security2:error] [pid 796567:tid 796737] [client 50.116.65.227:34532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OybLfyzVz2SrjZpisCQAAAjw"]
[Mon Jul 20 06:04:25.493338 2026] [security2:error] [pid 796567:tid 796705] [client 50.116.65.227:34544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OybLfyzVz2SrjZpisCwAAAhw"]
[Mon Jul 20 06:04:25.530343 2026] [security2:error] [pid 796928:tid 797090] [client 173.239.254.43:63305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4OyesTy9vX-htKvPkS0QAAArk"]
[Mon Jul 20 06:04:25.535231 2026] [security2:error] [pid 796928:tid 797074] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/loader.php"] [unique_id "al4OyesTy9vX-htKvPkS1gAAAqk"]
[Mon Jul 20 06:04:25.535362 2026] [security2:error] [pid 796928:tid 797074] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/loader.php"] [unique_id "al4OyesTy9vX-htKvPkS1gAAAqk"]
[Mon Jul 20 06:04:25.554827 2026] [security2:error] [pid 796567:tid 796794] [client 193.19.109.245:49483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisEAAAAnU"]
[Mon Jul 20 06:04:25.573320 2026] [security2:error] [pid 796567:tid 796762] [client 193.19.109.234:32385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisDwAAAlU"]
[Mon Jul 20 06:04:25.716077 2026] [security2:error] [pid 796928:tid 797121] [client 104.234.53.62:56105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OyesTy9vX-htKvPkS2AAAAtg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:25.733141 2026] [security2:error] [pid 796567:tid 796572] [remote 98.156.100.191:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisGwACbQQ"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:04:25.851685 2026] [security2:error] [pid 796567:tid 796688] [remote 97.74.87.194:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisHwAChHg"]
[Mon Jul 20 06:04:25.885969 2026] [security2:error] [pid 796567:tid 796796] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OybLfyzVz2SrjZpisFQAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.889738 2026] [security2:error] [pid 796928:tid 797155] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/spadex.php"] [unique_id "al4OyesTy9vX-htKvPkS6AAAAvo"]
[Mon Jul 20 06:04:25.889907 2026] [security2:error] [pid 796928:tid 797155] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/spadex.php"] [unique_id "al4OyesTy9vX-htKvPkS6AAAAvo"]
[Mon Jul 20 06:04:26.013988 2026] [security2:error] [pid 796928:tid 797149] [client 104.234.53.62:56105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OyesTy9vX-htKvPkS8AAAAvQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:26.060221 2026] [security2:error] [pid 796928:tid 796935] [remote 72.167.132.114:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4OyusTy9vX-htKvPkS9gAC5QY"]
[Mon Jul 20 06:04:26.260706 2026] [security2:error] [pid 796567:tid 796681] [remote 97.74.87.194:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4OyrLfyzVz2SrjZpisNAACjnE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:04:26.260859 2026] [security2:error] [pid 796928:tid 797106] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/2x.php"] [unique_id "al4OyusTy9vX-htKvPkTBgAAAsk"]
[Mon Jul 20 06:04:26.260996 2026] [security2:error] [pid 796928:tid 797106] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/2x.php"] [unique_id "al4OyusTy9vX-htKvPkTBgAAAsk"]
[Mon Jul 20 06:04:26.262489 2026] [security2:error] [pid 796928:tid 796949] [remote 72.167.132.114:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4OyusTy9vX-htKvPkTBQADChQ"], referer: https://snctaxgroup.com/wp-login.php
[Mon Jul 20 06:04:26.331326 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.96:26663] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/1.php"] [unique_id "al4OyrLfyzVz2SrjZpisNwAAAis"]
[Mon Jul 20 06:04:26.331434 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.96:26663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/1.php"] [unique_id "al4OyrLfyzVz2SrjZpisNwAAAis"]
[Mon Jul 20 06:04:26.378174 2026] [security2:error] [pid 796928:tid 797161] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyusTy9vX-htKvPkTAgAAAwA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:26.616863 2026] [security2:error] [pid 796567:tid 796767] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ctex1.php"] [unique_id "al4OyrLfyzVz2SrjZpisPQAAAlo"]
[Mon Jul 20 06:04:26.617048 2026] [security2:error] [pid 796567:tid 796767] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ctex1.php"] [unique_id "al4OyrLfyzVz2SrjZpisPQAAAlo"]
[Mon Jul 20 06:04:26.726126 2026] [security2:error] [pid 796928:tid 797146] [client 104.234.53.70:42359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OyusTy9vX-htKvPkTHwAAAvE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:26.797228 2026] [proxy:error] [pid 796567:tid 796768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:26.797271 2026] [proxy_http:error] [pid 796567:tid 796768] [client 94.154.43.183:55608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:26.797950 2026] [proxy:error] [pid 796567:tid 796768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:26.797982 2026] [proxy_http:error] [pid 796567:tid 796768] [client 94.154.43.183:55608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:27.041515 2026] [security2:error] [pid 796928:tid 797059] [client 106.192.104.4:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Oy-sTy9vX-htKvPkTQgAAApo"]
[Mon Jul 20 06:04:27.041768 2026] [security2:error] [pid 796928:tid 797059] [client 106.192.104.4:58481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Oy-sTy9vX-htKvPkTQgAAApo"]
[Mon Jul 20 06:04:27.048089 2026] [proxy:error] [pid 796928:tid 797090] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:27.048165 2026] [proxy_http:error] [pid 796928:tid 797090] [client 94.154.43.183:23808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:27.050216 2026] [proxy:error] [pid 796928:tid 797090] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:27.050281 2026] [proxy_http:error] [pid 796928:tid 797090] [client 94.154.43.183:23808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:27.077231 2026] [security2:error] [pid 796928:tid 797071] [client 14.225.17.146:56286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4OyusTy9vX-htKvPkTJgAAAqY"], referer: http://maxenengineering.com/wordpress
[Mon Jul 20 06:04:27.099500 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyusTy9vX-htKvPkTNQAAAqw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:27.146310 2026] [security2:error] [pid 796928:tid 797144] [client 74.7.227.179:55528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Oy-sTy9vX-htKvPkTQQAC718"], referer: https://tejasenvironmental.com/p=2454848
[Mon Jul 20 06:04:27.246276 2026] [security2:error] [pid 796928:tid 797124] [client 193.37.33.5:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colt-innovate.com"] [uri "/wp-login.php"] [unique_id "al4Oy-sTy9vX-htKvPkTTAAAAts"]
[Mon Jul 20 06:04:27.335630 2026] [security2:error] [pid 796567:tid 796766] [client 114.119.158.50:45099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/weekly-sales-for-april-15th-thru-april-20th-2019__trashed/jackson-floor-lamp-2000885/"] [unique_id "al4Oy7LfyzVz2SrjZpisUgAAAlk"], referer: https://www.liquidationteam.com/weekly-sales-for-april-15th-thru-april-20th-2019__trashed/jackson-floor-lamp-2000885/
[Mon Jul 20 06:04:27.376538 2026] [security2:error] [pid 796928:tid 797111] [client 57.141.18.119:28158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OxesTy9vX-htKvPkRtgACzjY"]
[Mon Jul 20 06:04:27.440874 2026] [security2:error] [pid 796928:tid 797117] [client 14.225.17.146:64858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4OyusTy9vX-htKvPkTDAAAAtQ"], referer: http://adultdaycarereno.com/wordpress
[Mon Jul 20 06:04:27.529182 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/edorxrr.php"] [unique_id "al4Oy7LfyzVz2SrjZpisXAAAAh8"]
[Mon Jul 20 06:04:27.529322 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/edorxrr.php"] [unique_id "al4Oy7LfyzVz2SrjZpisXAAAAh8"]
[Mon Jul 20 06:04:27.531583 2026] [security2:error] [pid 796928:tid 797084] [client 57.141.18.71:44296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OxesTy9vX-htKvPkRuQACszA"]
[Mon Jul 20 06:04:27.620214 2026] [security2:error] [pid 796567:tid 796750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oy7LfyzVz2SrjZpisVQAAAkk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:27.823818 2026] [security2:error] [pid 796928:tid 797075] [client 14.225.17.146:51497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4Oy-sTy9vX-htKvPkTcQAAAqo"], referer: http://collectingrealestate.com/wordpress
[Mon Jul 20 06:04:27.902673 2026] [security2:error] [pid 796928:tid 797138] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/miru1.php"] [unique_id "al4Oy-sTy9vX-htKvPkTfgAAAuk"]
[Mon Jul 20 06:04:27.902810 2026] [security2:error] [pid 796928:tid 797138] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/miru1.php"] [unique_id "al4Oy-sTy9vX-htKvPkTfgAAAuk"]
[Mon Jul 20 06:04:27.903372 2026] [security2:error] [pid 796567:tid 796677] [remote 152.228.213.32:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4Oy7LfyzVz2SrjZpisaAACTG0"]
[Mon Jul 20 06:04:28.017839 2026] [security2:error] [pid 796928:tid 797113] [client 104.234.53.82:48525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OzOsTy9vX-htKvPkThgAAAtA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:28.025677 2026] [security2:error] [pid 796567:tid 796818] [client 14.225.17.146:54124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Oy7LfyzVz2SrjZpisagAAAo0"], referer: https://maxenengineering.com/wordpress
[Mon Jul 20 06:04:28.122584 2026] [security2:error] [pid 796567:tid 796631] [remote 152.228.213.32:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4OzLLfyzVz2SrjZpisdgACUT8"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:04:28.200299 2026] [security2:error] [pid 796928:tid 797176] [client 114.119.135.223:45911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4OzOsTy9vX-htKvPkTmgAAAw8"], referer: http://www.xxhjyc.com/online.asp?Page=31406
[Mon Jul 20 06:04:28.270471 2026] [security2:error] [pid 796928:tid 797067] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sump1.php"] [unique_id "al4OzOsTy9vX-htKvPkTnQAAAqI"]
[Mon Jul 20 06:04:28.270568 2026] [security2:error] [pid 796928:tid 797067] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sump1.php"] [unique_id "al4OzOsTy9vX-htKvPkTnQAAAqI"]
[Mon Jul 20 06:04:28.303584 2026] [security2:error] [pid 796928:tid 797071] [client 185.132.186.101:38675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/wp-login.php"] [unique_id "al4OzOsTy9vX-htKvPkTnAAAAqY"]
[Mon Jul 20 06:04:28.305393 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:58273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4OzLLfyzVz2SrjZpiseQAAAn0"], referer: https://adultdaycarereno.com/wordpress
[Mon Jul 20 06:04:28.330812 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:59897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpAAAAqs"]
[Mon Jul 20 06:04:28.341377 2026] [security2:error] [pid 796928:tid 796997] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpQAC-0Q"]
[Mon Jul 20 06:04:28.341490 2026] [security2:error] [pid 796928:tid 797156] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpQAC-0Q"]
[Mon Jul 20 06:04:28.345524 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:59897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpAAAAqs"]
[Mon Jul 20 06:04:28.382298 2026] [security2:error] [pid 796928:tid 797084] [client 112.213.160.112:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTqQAAArM"]
[Mon Jul 20 06:04:28.382404 2026] [security2:error] [pid 796928:tid 797084] [client 112.213.160.112:30824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTqQAAArM"]
[Mon Jul 20 06:04:28.535844 2026] [security2:error] [pid 796928:tid 797169] [client 150.228.148.150:49189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTuAAAAwg"]
[Mon Jul 20 06:04:28.556777 2026] [security2:error] [pid 796928:tid 797169] [client 150.228.148.150:49189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTuAAAAwg"]
[Mon Jul 20 06:04:28.616291 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/file5.php"] [unique_id "al4OzOsTy9vX-htKvPkTvgAAAwo"]
[Mon Jul 20 06:04:28.616406 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/file5.php"] [unique_id "al4OzOsTy9vX-htKvPkTvgAAAwo"]
[Mon Jul 20 06:04:28.637434 2026] [security2:error] [pid 796928:tid 797093] [client 57.141.18.20:57940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OxusTy9vX-htKvPkSAAACvFc"]
[Mon Jul 20 06:04:28.769357 2026] [security2:error] [pid 796928:tid 797107] [client 14.225.17.146:55969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkTvAAAAso"], referer: http://lifeisbetterlakeside.com/wordpress
[Mon Jul 20 06:04:28.788868 2026] [security2:error] [pid 796567:tid 796791] [client 77.110.127.138:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OzLLfyzVz2SrjZpisgwAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:28.973260 2026] [security2:error] [pid 796928:tid 797143] [client 180.191.235.27:53212] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 27.235.191.180.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-comments-post.php"] [unique_id "al4OzOsTy9vX-htKvPkT1gAAAu4"]
[Mon Jul 20 06:04:28.973409 2026] [security2:error] [pid 796928:tid 797143] [client 180.191.235.27:53212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "adambergeron.com"] [uri "/wp-comments-post.php"] [unique_id "al4OzOsTy9vX-htKvPkT1gAAAu4"]
[Mon Jul 20 06:04:29.002185 2026] [security2:error] [pid 796928:tid 797180] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkTxQAAAxM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:29.193877 2026] [security2:error] [pid 796928:tid 797145] [client 35.90.38.209:18942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4OzesTy9vX-htKvPkT4AAAAvA"]
[Mon Jul 20 06:04:29.238425 2026] [security2:error] [pid 796928:tid 797078] [client 43.205.139.3:19848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OyusTy9vX-htKvPkTDgAAAq0"]
[Mon Jul 20 06:04:29.327155 2026] [security2:error] [pid 796928:tid 797113] [client 35.90.38.209:18954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OzesTy9vX-htKvPkT6AAAAtA"]
[Mon Jul 20 06:04:29.328482 2026] [security2:error] [pid 796567:tid 796751] [client 98.159.234.160:39475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OzbLfyzVz2SrjZpiskQAAAko"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:29.387780 2026] [security2:error] [pid 796928:tid 797130] [client 104.234.53.89:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OzesTy9vX-htKvPkT6gAAAuE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:29.612604 2026] [core:error] [pid 796928:tid 797106] [client 14.225.17.146:54891] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:04:29.612627 2026] [core:error] [pid 796928:tid 797106] [client 14.225.17.146:54891] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:04:30.085106 2026] [security2:error] [pid 796928:tid 797113] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/0xD.php"] [unique_id "al4OzusTy9vX-htKvPkUGAAAAtA"]
[Mon Jul 20 06:04:30.085241 2026] [security2:error] [pid 796928:tid 797113] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/0xD.php"] [unique_id "al4OzusTy9vX-htKvPkUGAAAAtA"]
[Mon Jul 20 06:04:30.462696 2026] [security2:error] [pid 796928:tid 797183] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fnstall.php"] [unique_id "al4OzusTy9vX-htKvPkUKQAAAxY"]
[Mon Jul 20 06:04:30.462844 2026] [security2:error] [pid 796928:tid 797183] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fnstall.php"] [unique_id "al4OzusTy9vX-htKvPkUKQAAAxY"]
[Mon Jul 20 06:04:30.735708 2026] [security2:error] [pid 796567:tid 796805] [client 104.234.53.90:32771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OzrLfyzVz2SrjZpiswAAAAoA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:30.812973 2026] [security2:error] [pid 796928:tid 797075] [client 185.132.186.77:61757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/install.php"] [unique_id "al4OzusTy9vX-htKvPkUPwAAAqo"]
[Mon Jul 20 06:04:30.835333 2026] [security2:error] [pid 796567:tid 796718] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/acp.php"] [unique_id "al4OzrLfyzVz2SrjZpiswgAAAik"]
[Mon Jul 20 06:04:30.835499 2026] [security2:error] [pid 796567:tid 796718] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/acp.php"] [unique_id "al4OzrLfyzVz2SrjZpiswgAAAik"]
[Mon Jul 20 06:04:30.841772 2026] [security2:error] [pid 796928:tid 797085] [client 115.246.21.170:5450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OzusTy9vX-htKvPkUQQAAArQ"]
[Mon Jul 20 06:04:30.841885 2026] [security2:error] [pid 796928:tid 797085] [client 115.246.21.170:5450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OzusTy9vX-htKvPkUQQAAArQ"]
[Mon Jul 20 06:04:31.010228 2026] [security2:error] [pid 796928:tid 797152] [client 57.141.18.26:53622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OyOsTy9vX-htKvPkStgAC91M"]
[Mon Jul 20 06:04:31.049174 2026] [security2:error] [pid 796567:tid 796815] [client 18.228.171.129:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz7LfyzVz2SrjZpisygAAAoo"]
[Mon Jul 20 06:04:31.049287 2026] [security2:error] [pid 796567:tid 796815] [client 18.228.171.129:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz7LfyzVz2SrjZpisygAAAoo"]
[Mon Jul 20 06:04:31.185618 2026] [security2:error] [pid 796567:tid 796713] [client 14.225.17.146:65152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Oz7LfyzVz2SrjZpiszwAAAiQ"], referer: http://friendlyspreadsheet.com/wordpress
[Mon Jul 20 06:04:31.202337 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mosty.php"] [unique_id "al4Oz-sTy9vX-htKvPkUWAAAAtk"]
[Mon Jul 20 06:04:31.202472 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mosty.php"] [unique_id "al4Oz-sTy9vX-htKvPkUWAAAAtk"]
[Mon Jul 20 06:04:31.248629 2026] [security2:error] [pid 796928:tid 797086] [client 14.225.17.146:58284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkToQAAArU"], referer: http://hilltopnurseryinc.com/wordpress
[Mon Jul 20 06:04:31.382798 2026] [security2:error] [pid 796567:tid 796779] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz7LfyzVz2SrjZpisxwACZgw"]
[Mon Jul 20 06:04:31.581471 2026] [security2:error] [pid 796567:tid 796721] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/6.php"] [unique_id "al4Oz7LfyzVz2SrjZpis4QAAAiw"]
[Mon Jul 20 06:04:31.581597 2026] [security2:error] [pid 796567:tid 796721] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/6.php"] [unique_id "al4Oz7LfyzVz2SrjZpis4QAAAiw"]
[Mon Jul 20 06:04:31.599069 2026] [security2:error] [pid 796928:tid 797154] [client 57.141.18.26:53634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OyesTy9vX-htKvPkS0gAC-R8"]
[Mon Jul 20 06:04:31.694481 2026] [security2:error] [pid 796928:tid 797115] [client 14.225.17.146:51756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4OzesTy9vX-htKvPkT5gAAAtI"], referer: http://secretkeynumerology.com/wordpress
[Mon Jul 20 06:04:31.779798 2026] [security2:error] [pid 796567:tid 796733] [client 136.112.200.207:43536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "bucknutscoffeeco.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Oz7LfyzVz2SrjZpis7wAAAjg"]
[Mon Jul 20 06:04:31.930421 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/32e17094cfindex.php"] [unique_id "al4Oz7LfyzVz2SrjZpis9AAAAig"]
[Mon Jul 20 06:04:31.930565 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/32e17094cfindex.php"] [unique_id "al4Oz7LfyzVz2SrjZpis9AAAAig"]
[Mon Jul 20 06:04:31.950372 2026] [security2:error] [pid 796928:tid 797117] [client 129.222.187.209:64818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz-sTy9vX-htKvPkUggAAAtQ"]
[Mon Jul 20 06:04:31.960744 2026] [security2:error] [pid 796928:tid 797117] [client 129.222.187.209:64818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz-sTy9vX-htKvPkUggAAAtQ"]
[Mon Jul 20 06:04:31.962496 2026] [security2:error] [pid 796567:tid 796697] [client 136.112.200.207:43536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "bucknutscoffeeco.com"] [uri "/"] [unique_id "al4Oz7LfyzVz2SrjZpis9gAAAhQ"]
[Mon Jul 20 06:04:31.967521 2026] [security2:error] [pid 796928:tid 796931] [remote 182.77.62.24:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Oz-sTy9vX-htKvPkUgQAC7AI"]
[Mon Jul 20 06:04:32.066296 2026] [security2:error] [pid 796928:tid 797059] [client 14.225.17.146:54245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Oz-sTy9vX-htKvPkUgwAAApo"], referer: https://friendlyspreadsheet.com/wordpress
[Mon Jul 20 06:04:32.284379 2026] [security2:error] [pid 796567:tid 796798] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/qqqa.php"] [unique_id "al4O0LLfyzVz2SrjZpis_wAAAnk"]
[Mon Jul 20 06:04:32.284518 2026] [security2:error] [pid 796567:tid 796798] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/qqqa.php"] [unique_id "al4O0LLfyzVz2SrjZpis_wAAAnk"]
[Mon Jul 20 06:04:32.335636 2026] [security2:error] [pid 796567:tid 796791] [client 50.116.65.227:58798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4O0LLfyzVz2SrjZpitAAAAAnI"]
[Mon Jul 20 06:04:32.347211 2026] [security2:error] [pid 796928:tid 797125] [client 50.116.65.227:11904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4O0OsTy9vX-htKvPkUpQAAAtw"]
[Mon Jul 20 06:04:32.515405 2026] [security2:error] [pid 796928:tid 797003] [remote 182.77.62.24:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4O0OsTy9vX-htKvPkUswACrko"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:04:32.643639 2026] [security2:error] [pid 796928:tid 797130] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/aunmc.php"] [unique_id "al4O0OsTy9vX-htKvPkUvgAAAuE"]
[Mon Jul 20 06:04:32.643772 2026] [security2:error] [pid 796928:tid 797130] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/aunmc.php"] [unique_id "al4O0OsTy9vX-htKvPkUvgAAAuE"]
[Mon Jul 20 06:04:32.664236 2026] [security2:error] [pid 796928:tid 797151] [client 41.173.37.102:12290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwAAAAvY"]
[Mon Jul 20 06:04:32.664372 2026] [security2:error] [pid 796928:tid 797151] [client 41.173.37.102:12290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwAAAAvY"]
[Mon Jul 20 06:04:32.687217 2026] [security2:error] [pid 796928:tid 797128] [client 14.225.17.146:50577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUsgAAAt8"], referer: https://secretkeynumerology.com/wordpress
[Mon Jul 20 06:04:32.687527 2026] [security2:error] [pid 796928:tid 797119] [client 14.225.17.146:50614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUuQAAAtY"], referer: http://momheadquarters.com/wordpress
[Mon Jul 20 06:04:32.764951 2026] [security2:error] [pid 796928:tid 797167] [client 185.132.186.79:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/sunrise/admin.php"] [unique_id "al4O0OsTy9vX-htKvPkUwgAAAwY"]
[Mon Jul 20 06:04:32.812976 2026] [security2:error] [pid 796928:tid 797099] [client 178.152.178.232:37350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwwAAAsI"]
[Mon Jul 20 06:04:32.813138 2026] [security2:error] [pid 796928:tid 797099] [client 178.152.178.232:37350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwwAAAsI"]
[Mon Jul 20 06:04:32.874625 2026] [security2:error] [pid 796928:tid 797176] [client 77.110.127.138:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUywAAAw8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:32.888403 2026] [security2:error] [pid 796928:tid 797107] [client 210.212.97.243:10438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUzAAAAso"]
[Mon Jul 20 06:04:32.888574 2026] [security2:error] [pid 796928:tid 797107] [client 210.212.97.243:10438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUzAAAAso"]
[Mon Jul 20 06:04:32.928670 2026] [security2:error] [pid 796928:tid 797182] [client 77.110.127.138:55058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4O0OsTy9vX-htKvPkU0gAAAxU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:33.127603 2026] [security2:error] [pid 796928:tid 796967] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O0esTy9vX-htKvPkU5wADESY"]
[Mon Jul 20 06:04:33.127795 2026] [security2:error] [pid 796928:tid 797178] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O0esTy9vX-htKvPkU5wADESY"]
[Mon Jul 20 06:04:33.381198 2026] [security2:error] [pid 796928:tid 797070] [client 57.141.18.23:31284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oy-sTy9vX-htKvPkTRAACpSc"]
[Mon Jul 20 06:04:33.402931 2026] [security2:error] [pid 796928:tid 797161] [client 14.225.17.146:56930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUtAAAAwA"]
[Mon Jul 20 06:04:33.437538 2026] [security2:error] [pid 796928:tid 797185] [client 14.225.17.146:58957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4Oz-sTy9vX-htKvPkUVAAAAxg"]
[Mon Jul 20 06:04:33.658489 2026] [security2:error] [pid 796567:tid 796715] [client 104.168.59.36:37808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "genlius.com"] [uri "/"] [unique_id "al4O0bLfyzVz2SrjZpitJwAAAiY"]
[Mon Jul 20 06:04:33.846776 2026] [security2:error] [pid 796567:tid 796746] [client 192.236.168.43:45160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.genlius.com"] [uri "/"] [unique_id "al4O0bLfyzVz2SrjZpitLgAAAkU"]
[Mon Jul 20 06:04:33.905664 2026] [security2:error] [pid 796567:tid 796783] [client 57.141.18.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4O0bLfyzVz2SrjZpitLAAAAmo"]
[Mon Jul 20 06:04:33.927589 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/uoocf.php"] [unique_id "al4O0esTy9vX-htKvPkVEQAAAsM"]
[Mon Jul 20 06:04:33.927694 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/uoocf.php"] [unique_id "al4O0esTy9vX-htKvPkVEQAAAsM"]
[Mon Jul 20 06:04:34.027871 2026] [security2:error] [pid 796928:tid 797142] [client 103.95.123.246:17604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVFQAAAu0"]
[Mon Jul 20 06:04:34.027994 2026] [security2:error] [pid 796928:tid 797142] [client 103.95.123.246:17604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVFQAAAu0"]
[Mon Jul 20 06:04:34.084660 2026] [security2:error] [pid 796567:tid 796588] [remote 20.173.88.122:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4O0rLfyzVz2SrjZpitOAACZxQ"]
[Mon Jul 20 06:04:34.271446 2026] [security2:error] [pid 796567:tid 796742] [client 164.100.212.184:51185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitQQAAAkE"]
[Mon Jul 20 06:04:34.271560 2026] [security2:error] [pid 796567:tid 796742] [client 164.100.212.184:51185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitQQAAAkE"]
[Mon Jul 20 06:04:34.309860 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/iywwi.php"] [unique_id "al4O0usTy9vX-htKvPkVIgAAAwY"]
[Mon Jul 20 06:04:34.309989 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/iywwi.php"] [unique_id "al4O0usTy9vX-htKvPkVIgAAAwY"]
[Mon Jul 20 06:04:34.435872 2026] [security2:error] [pid 796928:tid 797158] [client 181.224.94.124:35891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVLgAAAv0"]
[Mon Jul 20 06:04:34.435996 2026] [security2:error] [pid 796928:tid 797158] [client 181.224.94.124:35891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVLgAAAv0"]
[Mon Jul 20 06:04:34.453880 2026] [security2:error] [pid 796567:tid 796661] [remote 20.173.88.122:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4O0rLfyzVz2SrjZpitRQACil0"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 06:04:34.540216 2026] [security2:error] [pid 796567:tid 796767] [client 14.225.17.146:50247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4O0rLfyzVz2SrjZpitQAAAAlo"], referer: http://massagelacey.com/wordpress
[Mon Jul 20 06:04:34.716891 2026] [security2:error] [pid 796928:tid 797157] [client 185.132.186.74:34831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/gifclass.php"] [unique_id "al4O0usTy9vX-htKvPkVQQAAAvw"]
[Mon Jul 20 06:04:34.718461 2026] [security2:error] [pid 796928:tid 797117] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/gqgsa.php"] [unique_id "al4O0usTy9vX-htKvPkVQgAAAtQ"]
[Mon Jul 20 06:04:34.718544 2026] [security2:error] [pid 796928:tid 797117] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/gqgsa.php"] [unique_id "al4O0usTy9vX-htKvPkVQgAAAtQ"]
[Mon Jul 20 06:04:34.784220 2026] [security2:error] [pid 796567:tid 796792] [client 103.149.16.77:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitVAAAAnM"]
[Mon Jul 20 06:04:34.784363 2026] [security2:error] [pid 796567:tid 796792] [client 103.149.16.77:65039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitVAAAAnM"]
[Mon Jul 20 06:04:34.903676 2026] [security2:error] [pid 796567:tid 796706] [client 104.234.53.62:31815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4O0rLfyzVz2SrjZpitVQAAAh0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:34.964641 2026] [security2:error] [pid 796928:tid 796993] [remote 47.86.33.52:32326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O0usTy9vX-htKvPkVTgACzUA"]
[Mon Jul 20 06:04:35.021284 2026] [security2:error] [pid 796567:tid 796799] [client 85.204.70.112:60164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4O07LfyzVz2SrjZpitVgAAAno"]
[Mon Jul 20 06:04:35.095764 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/elbzl.php"] [unique_id "al4O0-sTy9vX-htKvPkVWwAAAqQ"]
[Mon Jul 20 06:04:35.095863 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/elbzl.php"] [unique_id "al4O0-sTy9vX-htKvPkVWwAAAqQ"]
[Mon Jul 20 06:04:35.250330 2026] [security2:error] [pid 796567:tid 796754] [client 104.234.53.62:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4O07LfyzVz2SrjZpitYQAAAk0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:35.350845 2026] [security2:error] [pid 796928:tid 797005] [remote 47.86.33.52:32326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O0-sTy9vX-htKvPkVaQACr0w"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:04:35.395352 2026] [security2:error] [pid 796928:tid 797163] [client 57.141.18.93:35116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkT0gADAmk"]
[Mon Jul 20 06:04:35.412420 2026] [security2:error] [pid 796928:tid 797135] [client 129.222.187.209:19982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkVbwAAAuY"]
[Mon Jul 20 06:04:35.415211 2026] [security2:error] [pid 796928:tid 797135] [client 129.222.187.209:19982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkVbwAAAuY"]
[Mon Jul 20 06:04:35.443004 2026] [security2:error] [pid 796928:tid 797102] [client 85.204.70.112:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkVcQAAAsU"]
[Mon Jul 20 06:04:35.463660 2026] [security2:error] [pid 796567:tid 796715] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/adjig.php"] [unique_id "al4O07LfyzVz2SrjZpitZAAAAiY"]
[Mon Jul 20 06:04:35.463784 2026] [security2:error] [pid 796567:tid 796715] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/adjig.php"] [unique_id "al4O07LfyzVz2SrjZpitZAAAAiY"]
[Mon Jul 20 06:04:35.554421 2026] [security2:error] [pid 796567:tid 796760] [client 86.98.90.58:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O07LfyzVz2SrjZpitZwAAAlM"]
[Mon Jul 20 06:04:35.583453 2026] [security2:error] [pid 796567:tid 796760] [client 86.98.90.58:52887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O07LfyzVz2SrjZpitZwAAAlM"]
[Mon Jul 20 06:04:35.747129 2026] [autoindex:error] [pid 796928:tid 797068] [client 188.166.248.173:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:35.780548 2026] [security2:error] [pid 796928:tid 796948] [remote 98.156.100.191:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkViwADFhM"]
[Mon Jul 20 06:04:35.780766 2026] [security2:error] [pid 796928:tid 797183] [client 98.156.100.191:38664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkViwADFhM"]
[Mon Jul 20 06:04:35.788221 2026] [security2:error] [pid 796567:tid 796720] [client 14.225.17.146:50631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4O0bLfyzVz2SrjZpitLQAAAis"], referer: http://nurturemarple.co.uk/wordpress
[Mon Jul 20 06:04:35.825708 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/byp.php"] [unique_id "al4O0-sTy9vX-htKvPkVjQAAAs8"]
[Mon Jul 20 06:04:35.825823 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/byp.php"] [unique_id "al4O0-sTy9vX-htKvPkVjQAAAs8"]
[Mon Jul 20 06:04:36.014052 2026] [security2:error] [pid 796567:tid 796758] [client 72.255.10.154:2417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O1LLfyzVz2SrjZpitdAAAAlE"]
[Mon Jul 20 06:04:36.014261 2026] [security2:error] [pid 796567:tid 796758] [client 72.255.10.154:2417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O1LLfyzVz2SrjZpitdAAAAlE"]
[Mon Jul 20 06:04:36.215819 2026] [security2:error] [pid 796567:tid 796730] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ortasekerli1.php"] [unique_id "al4O1LLfyzVz2SrjZpitfwAAAjU"]
[Mon Jul 20 06:04:36.215908 2026] [security2:error] [pid 796567:tid 796730] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ortasekerli1.php"] [unique_id "al4O1LLfyzVz2SrjZpitfwAAAjU"]
[Mon Jul 20 06:04:36.576914 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/classwithtostring.php"] [unique_id "al4O1OsTy9vX-htKvPkVpQAAAtk"]
[Mon Jul 20 06:04:36.577014 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/classwithtostring.php"] [unique_id "al4O1OsTy9vX-htKvPkVpQAAAtk"]
[Mon Jul 20 06:04:36.903736 2026] [security2:error] [pid 796567:tid 796779] [client 85.204.70.112:60184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4O1LLfyzVz2SrjZpitmQAAAmY"]
[Mon Jul 20 06:04:36.955286 2026] [security2:error] [pid 796567:tid 796749] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/root.php"] [unique_id "al4O1LLfyzVz2SrjZpitmgAAAkg"]
[Mon Jul 20 06:04:36.955386 2026] [security2:error] [pid 796567:tid 796749] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/root.php"] [unique_id "al4O1LLfyzVz2SrjZpitmgAAAkg"]
[Mon Jul 20 06:04:37.131914 2026] [ssl:error] [pid 796567:tid 796777] [client 2.194.133.19:38316] AH02032: Hostname www.perrysnopeep.com provided via SNI and hostname www.forbes.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:04:37.302066 2026] [security2:error] [pid 796928:tid 797083] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4O1esTy9vX-htKvPkVzAAAArI"]
[Mon Jul 20 06:04:37.404567 2026] [security2:error] [pid 796928:tid 797109] [client 43.205.139.3:63372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O1esTy9vX-htKvPkVywAAAsw"]
[Mon Jul 20 06:04:37.420864 2026] [security2:error] [pid 796567:tid 796812] [client 85.204.70.112:60188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4O1bLfyzVz2SrjZpitpwAAAoc"]
[Mon Jul 20 06:04:37.508785 2026] [security2:error] [pid 796928:tid 797168] [client 14.225.17.146:58389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4O1esTy9vX-htKvPkV1AAAAwc"], referer: https://nurturemarple.co.uk/wordpress
[Mon Jul 20 06:04:37.538765 2026] [security2:error] [pid 796567:tid 796766] [client 57.141.18.125:51712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oz7LfyzVz2SrjZpisyQACWW8"]
[Mon Jul 20 06:04:37.592328 2026] [security2:error] [pid 796928:tid 797079] [client 106.192.104.4:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O1esTy9vX-htKvPkV4QAAAq4"]
[Mon Jul 20 06:04:37.592456 2026] [security2:error] [pid 796928:tid 797079] [client 106.192.104.4:58939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O1esTy9vX-htKvPkV4QAAAq4"]
[Mon Jul 20 06:04:37.649359 2026] [security2:error] [pid 796928:tid 797089] [client 185.132.186.78:30961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugin.php"] [unique_id "al4O1esTy9vX-htKvPkV5AAAArg"]
[Mon Jul 20 06:04:37.649951 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sym403.php"] [unique_id "al4O1esTy9vX-htKvPkV5QAAAwU"]
[Mon Jul 20 06:04:37.650067 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sym403.php"] [unique_id "al4O1esTy9vX-htKvPkV5QAAAwU"]
[Mon Jul 20 06:04:37.866845 2026] [security2:error] [pid 796567:tid 796702] [client 57.141.18.57:62478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oz7LfyzVz2SrjZpis2AACGSo"]
[Mon Jul 20 06:04:37.942513 2026] [security2:error] [pid 796928:tid 797170] [client 77.110.127.138:55087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4O1esTy9vX-htKvPkV9gAAAwk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:38.051493 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/v543.php"] [unique_id "al4O1usTy9vX-htKvPkV-wAAAvU"]
[Mon Jul 20 06:04:38.051651 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/v543.php"] [unique_id "al4O1usTy9vX-htKvPkV-wAAAvU"]
[Mon Jul 20 06:04:38.116284 2026] [security2:error] [pid 796567:tid 796619] [remote 57.141.18.59:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4O1rLfyzVz2SrjZpitxQACcjM"]
[Mon Jul 20 06:04:38.315475 2026] [security2:error] [pid 796567:tid 796775] [client 85.204.70.112:50292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4O1rLfyzVz2SrjZpitywAAAmI"]
[Mon Jul 20 06:04:38.407199 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sixxis.php"] [unique_id "al4O1rLfyzVz2SrjZpit0QAAAko"]
[Mon Jul 20 06:04:38.407281 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sixxis.php"] [unique_id "al4O1rLfyzVz2SrjZpit0QAAAko"]
[Mon Jul 20 06:04:38.428442 2026] [security2:error] [pid 796928:tid 797091] [client 77.110.127.138:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O1usTy9vX-htKvPkWEQAAAro"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:38.787856 2026] [security2:error] [pid 796928:tid 797173] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ip.php"] [unique_id "al4O1usTy9vX-htKvPkWKQAAAww"]
[Mon Jul 20 06:04:38.787964 2026] [security2:error] [pid 796928:tid 797173] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ip.php"] [unique_id "al4O1usTy9vX-htKvPkWKQAAAww"]
[Mon Jul 20 06:04:38.817112 2026] [security2:error] [pid 796567:tid 796788] [client 47.31.86.100:60365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O1rLfyzVz2SrjZpit4wAAAm8"]
[Mon Jul 20 06:04:38.830842 2026] [security2:error] [pid 796567:tid 796788] [client 47.31.86.100:60365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O1rLfyzVz2SrjZpit4wAAAm8"]
[Mon Jul 20 06:04:38.834908 2026] [security2:error] [pid 796567:tid 796753] [client 57.141.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4O1rLfyzVz2SrjZpit3gAAAkw"]
[Mon Jul 20 06:04:38.998948 2026] [security2:error] [pid 796928:tid 797145] [client 52.59.238.198:28836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O1usTy9vX-htKvPkWNQAAAvA"]
[Mon Jul 20 06:04:39.100064 2026] [security2:error] [pid 796567:tid 796703] [client 112.213.160.112:8255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7QAAAho"]
[Mon Jul 20 06:04:39.100178 2026] [security2:error] [pid 796567:tid 796703] [client 112.213.160.112:8255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7QAAAho"]
[Mon Jul 20 06:04:39.144296 2026] [security2:error] [pid 796928:tid 797136] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/kq1.php"] [unique_id "al4O1-sTy9vX-htKvPkWPAAAAuc"]
[Mon Jul 20 06:04:39.144389 2026] [security2:error] [pid 796928:tid 797136] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/kq1.php"] [unique_id "al4O1-sTy9vX-htKvPkWPAAAAuc"]
[Mon Jul 20 06:04:39.214643 2026] [security2:error] [pid 796567:tid 796803] [client 150.228.148.150:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7wAAAn4"]
[Mon Jul 20 06:04:39.214860 2026] [security2:error] [pid 796567:tid 796803] [client 150.228.148.150:55447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7wAAAn4"]
[Mon Jul 20 06:04:39.507661 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fw/faiyy.php"] [unique_id "al4O17LfyzVz2SrjZpit-QAAAmE"]
[Mon Jul 20 06:04:39.507793 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fw/faiyy.php"] [unique_id "al4O17LfyzVz2SrjZpit-QAAAmE"]
[Mon Jul 20 06:04:39.530368 2026] [security2:error] [pid 796567:tid 796800] [client 14.225.17.146:65509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpit8gAAAns"], referer: http://latiendadejorge.com.gt/wordpress
[Mon Jul 20 06:04:39.531151 2026] [security2:error] [pid 796928:tid 797097] [client 57.141.18.5:58768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUxgACwDc"]
[Mon Jul 20 06:04:39.532712 2026] [security2:error] [pid 796928:tid 797155] [client 57.141.18.25:31138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUygAC-gA"]
[Mon Jul 20 06:04:39.564588 2026] [security2:error] [pid 796928:tid 797166] [client 63.176.132.15:57904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O1-sTy9vX-htKvPkWUwAAAwU"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:04:39.594157 2026] [security2:error] [pid 796567:tid 796714] [client 185.132.186.86:20261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/bypass.php"] [unique_id "al4O17LfyzVz2SrjZpit_wAAAiU"]
[Mon Jul 20 06:04:39.617147 2026] [security2:error] [pid 796567:tid 796767] [client 77.110.127.138:55060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4O17LfyzVz2SrjZpiuAAAAAlo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:39.670367 2026] [security2:error] [pid 796567:tid 796745] [client 47.128.96.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpit9wAAAkQ"]
[Mon Jul 20 06:04:39.739136 2026] [security2:error] [pid 796928:tid 797099] [client 85.204.70.112:50308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4O1-sTy9vX-htKvPkWYAAAAsI"]
[Mon Jul 20 06:04:39.907976 2026] [security2:error] [pid 796567:tid 796792] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/h02ugyh.php"] [unique_id "al4O17LfyzVz2SrjZpiuCgAAAnM"]
[Mon Jul 20 06:04:39.908067 2026] [security2:error] [pid 796567:tid 796792] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/h02ugyh.php"] [unique_id "al4O17LfyzVz2SrjZpiuCgAAAnM"]
[Mon Jul 20 06:04:39.978919 2026] [security2:error] [pid 796567:tid 796711] [client 14.225.17.146:54338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpiuDAAAAiI"], referer: http://grndl.com/wordpress
[Mon Jul 20 06:04:40.205075 2026] [security2:error] [pid 796567:tid 796818] [client 85.204.70.112:50310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4O2LLfyzVz2SrjZpiuFgAAAo0"]
[Mon Jul 20 06:04:40.281484 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-temp.php"] [unique_id "al4O2OsTy9vX-htKvPkWegAAAtk"]
[Mon Jul 20 06:04:40.281599 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-temp.php"] [unique_id "al4O2OsTy9vX-htKvPkWegAAAtk"]
[Mon Jul 20 06:04:40.292966 2026] [security2:error] [pid 796567:tid 796743] [client 57.141.18.41:21954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O0bLfyzVz2SrjZpitJQACQn8"]
[Mon Jul 20 06:04:40.452009 2026] [security2:error] [pid 796928:tid 797110] [client 77.110.127.138:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O2OsTy9vX-htKvPkWggAAAs0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:40.636111 2026] [security2:error] [pid 796928:tid 797086] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-content/cong.php"] [unique_id "al4O2OsTy9vX-htKvPkWkwAAArU"]
[Mon Jul 20 06:04:40.636249 2026] [security2:error] [pid 796928:tid 797086] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-content/cong.php"] [unique_id "al4O2OsTy9vX-htKvPkWkwAAArU"]
[Mon Jul 20 06:04:40.707387 2026] [security2:error] [pid 796928:tid 797077] [client 85.204.70.112:50316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4O2OsTy9vX-htKvPkWlQAAAqw"]
[Mon Jul 20 06:04:40.805315 2026] [security2:error] [pid 796928:tid 797126] [client 74.208.214.194:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4O2OsTy9vX-htKvPkWlwAAAt0"]
[Mon Jul 20 06:04:41.052702 2026] [security2:error] [pid 796928:tid 797182] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O2OsTy9vX-htKvPkWnwAAAxU"]
[Mon Jul 20 06:04:41.143271 2026] [security2:error] [pid 796928:tid 797146] [client 85.204.70.112:50322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4O2esTy9vX-htKvPkWqAAAAvE"]
[Mon Jul 20 06:04:41.243742 2026] [security2:error] [pid 796928:tid 797152] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4O2esTy9vX-htKvPkWrwAAAvc"]
[Mon Jul 20 06:04:41.243901 2026] [security2:error] [pid 796928:tid 797152] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4O2esTy9vX-htKvPkWrwAAAvc"]
[Mon Jul 20 06:04:41.308505 2026] [security2:error] [pid 796928:tid 797122] [client 18.140.64.130:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWsQAAAtk"]
[Mon Jul 20 06:04:41.308679 2026] [security2:error] [pid 796928:tid 797122] [client 18.140.64.130:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWsQAAAtk"]
[Mon Jul 20 06:04:41.505995 2026] [security2:error] [pid 796567:tid 796784] [client 115.246.21.170:52303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O2bLfyzVz2SrjZpiuTAAAAms"]
[Mon Jul 20 06:04:41.506120 2026] [security2:error] [pid 796567:tid 796784] [client 115.246.21.170:52303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O2bLfyzVz2SrjZpiuTAAAAms"]
[Mon Jul 20 06:04:41.524144 2026] [security2:error] [pid 796928:tid 797064] [client 85.204.70.112:50328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4O2esTy9vX-htKvPkWuAAAAp8"]
[Mon Jul 20 06:04:41.545304 2026] [security2:error] [pid 796567:tid 796708] [client 185.132.186.100:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/update-core.php"] [unique_id "al4O2bLfyzVz2SrjZpiuUwAAAh8"]
[Mon Jul 20 06:04:41.607634 2026] [security2:error] [pid 796928:tid 797175] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/jj.php"] [unique_id "al4O2esTy9vX-htKvPkWvAAAAw4"]
[Mon Jul 20 06:04:41.607738 2026] [security2:error] [pid 796928:tid 797175] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/jj.php"] [unique_id "al4O2esTy9vX-htKvPkWvAAAAw4"]
[Mon Jul 20 06:04:41.716814 2026] [security2:error] [pid 796567:tid 796722] [client 57.141.18.38:47554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O07LfyzVz2SrjZpitWwACLWA"]
[Mon Jul 20 06:04:41.741072 2026] [security2:error] [pid 796567:tid 796721] [client 57.141.18.66:23186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O07LfyzVz2SrjZpitWgACLBw"]
[Mon Jul 20 06:04:41.917735 2026] [security2:error] [pid 796928:tid 797106] [client 85.204.70.112:50338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4O2esTy9vX-htKvPkWxQAAAsk"]
[Mon Jul 20 06:04:41.962944 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al4O2esTy9vX-htKvPkWywAAArA"]
[Mon Jul 20 06:04:41.963106 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al4O2esTy9vX-htKvPkWywAAArA"]
[Mon Jul 20 06:04:42.007827 2026] [security2:error] [pid 796928:tid 797134] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWvgAC5S0"]
[Mon Jul 20 06:04:42.259346 2026] [security2:error] [pid 796928:tid 797086] [client 56.125.35.21:47566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWwwAAArU"]
[Mon Jul 20 06:04:42.292971 2026] [security2:error] [pid 796567:tid 796791] [client 14.225.17.146:64088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpiuAwAAAnI"], referer: http://www.justinagrayman.com/wordpress
[Mon Jul 20 06:04:42.323817 2026] [security2:error] [pid 796928:tid 797169] [client 14.225.17.146:65436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4O2usTy9vX-htKvPkW0wAAAwg"], referer: http://sarahsnyder.net/wordpress
[Mon Jul 20 06:04:42.352311 2026] [security2:error] [pid 796928:tid 797181] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/txets.php"] [unique_id "al4O2usTy9vX-htKvPkW3gAAAxQ"]
[Mon Jul 20 06:04:42.352436 2026] [security2:error] [pid 796928:tid 797181] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/txets.php"] [unique_id "al4O2usTy9vX-htKvPkW3gAAAxQ"]
[Mon Jul 20 06:04:42.463878 2026] [security2:error] [pid 796567:tid 796812] [client 129.222.187.209:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiudwAAAoc"]
[Mon Jul 20 06:04:42.468621 2026] [security2:error] [pid 796567:tid 796812] [client 129.222.187.209:51164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiudwAAAoc"]
[Mon Jul 20 06:04:42.558868 2026] [security2:error] [pid 796567:tid 796654] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiufAACGVY"]
[Mon Jul 20 06:04:42.559050 2026] [security2:error] [pid 796567:tid 796702] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiufAACGVY"]
[Mon Jul 20 06:04:42.743232 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/dex.php"] [unique_id "al4O2usTy9vX-htKvPkW8QAAAwY"]
[Mon Jul 20 06:04:42.743392 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/dex.php"] [unique_id "al4O2usTy9vX-htKvPkW8QAAAwY"]
[Mon Jul 20 06:04:42.812997 2026] [security2:error] [pid 796567:tid 796784] [client 85.204.70.112:50354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4O2rLfyzVz2SrjZpiujAAAAms"]
[Mon Jul 20 06:04:42.949203 2026] [security2:error] [pid 796567:tid 796771] [client 57.141.18.95:26978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O1LLfyzVz2SrjZpitigACXgQ"]
[Mon Jul 20 06:04:43.147576 2026] [security2:error] [pid 796928:tid 797141] [client 18.141.57.241:55834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O2usTy9vX-htKvPkW6QAAAuw"]
[Mon Jul 20 06:04:43.296990 2026] [security2:error] [pid 796928:tid 797070] [client 41.173.37.102:12720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXDgAAAqU"]
[Mon Jul 20 06:04:43.297099 2026] [security2:error] [pid 796928:tid 797070] [client 41.173.37.102:12720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXDgAAAqU"]
[Mon Jul 20 06:04:43.334058 2026] [security2:error] [pid 796928:tid 797080] [client 85.204.70.112:50358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4O2-sTy9vX-htKvPkXEwAAAq8"]
[Mon Jul 20 06:04:43.410537 2026] [security2:error] [pid 796928:tid 797072] [client 27.96.94.195:37183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGgAAAqc"]
[Mon Jul 20 06:04:43.410774 2026] [security2:error] [pid 796928:tid 797072] [client 27.96.94.195:37183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGgAAAqc"]
[Mon Jul 20 06:04:43.418532 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:55181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4O27LfyzVz2SrjZpiuoQAAAhg"], referer: https://sarahsnyder.net/wordpress
[Mon Jul 20 06:04:43.433911 2026] [security2:error] [pid 796928:tid 797108] [client 178.152.178.232:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGwAAAss"]
[Mon Jul 20 06:04:43.434031 2026] [security2:error] [pid 796928:tid 797108] [client 178.152.178.232:37388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGwAAAss"]
[Mon Jul 20 06:04:43.502114 2026] [security2:error] [pid 796928:tid 797174] [client 185.132.186.94:40399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "al4O2-sTy9vX-htKvPkXIQAAAw0"]
[Mon Jul 20 06:04:43.519148 2026] [security2:error] [pid 796567:tid 796741] [client 210.212.97.243:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O27LfyzVz2SrjZpiurwAAAkA"]
[Mon Jul 20 06:04:43.519303 2026] [security2:error] [pid 796567:tid 796741] [client 210.212.97.243:10439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O27LfyzVz2SrjZpiurwAAAkA"]
[Mon Jul 20 06:04:43.909474 2026] [security2:error] [pid 796928:tid 797070] [client 77.110.127.138:55087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXNgAAAqU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:43.914555 2026] [security2:error] [pid 796928:tid 797033] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXNQAC92g"]
[Mon Jul 20 06:04:43.914867 2026] [security2:error] [pid 796928:tid 797152] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXNQAC92g"]
[Mon Jul 20 06:04:44.004425 2026] [security2:error] [pid 796567:tid 796787] [client 14.225.17.146:63388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4O2bLfyzVz2SrjZpiuWgAAAm4"], referer: http://adirondackengineering.com/wordpress
[Mon Jul 20 06:04:44.200223 2026] [security2:error] [pid 796567:tid 796816] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xpwer1.php"] [unique_id "al4O3LLfyzVz2SrjZpiuywAAAos"]
[Mon Jul 20 06:04:44.200359 2026] [security2:error] [pid 796567:tid 796816] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xpwer1.php"] [unique_id "al4O3LLfyzVz2SrjZpiuywAAAos"]
[Mon Jul 20 06:04:44.308082 2026] [security2:error] [pid 796567:tid 796735] [client 85.204.70.112:50362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4O3LLfyzVz2SrjZpiuzgAAAjo"]
[Mon Jul 20 06:04:44.368043 2026] [security2:error] [pid 796928:tid 797167] [client 186.194.175.10:34304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4O3OsTy9vX-htKvPkXSQADBk8"]
[Mon Jul 20 06:04:44.530123 2026] [security2:error] [pid 796567:tid 796730] [client 45.157.112.60:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O3LLfyzVz2SrjZpiu1QAAAjU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:44.561232 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/flox.php"] [unique_id "al4O3LLfyzVz2SrjZpiu2gAAAko"]
[Mon Jul 20 06:04:44.561326 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/flox.php"] [unique_id "al4O3LLfyzVz2SrjZpiu2gAAAko"]
[Mon Jul 20 06:04:44.624682 2026] [security2:error] [pid 796928:tid 797134] [client 46.110.96.34:20695] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4O3OsTy9vX-htKvPkXXgAAAuU"]
[Mon Jul 20 06:04:44.731157 2026] [security2:error] [pid 796928:tid 797061] [client 85.204.70.112:50368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4O3OsTy9vX-htKvPkXZQAAApw"]
[Mon Jul 20 06:04:44.854818 2026] [security2:error] [pid 796567:tid 796824] [client 104.234.53.91:32533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4O3LLfyzVz2SrjZpiu4gAAApM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:44.923757 2026] [security2:error] [pid 796928:tid 797107] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/popo.php"] [unique_id "al4O3OsTy9vX-htKvPkXcQAAAso"]
[Mon Jul 20 06:04:44.923860 2026] [security2:error] [pid 796928:tid 797107] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/popo.php"] [unique_id "al4O3OsTy9vX-htKvPkXcQAAAso"]
[Mon Jul 20 06:04:44.940616 2026] [security2:error] [pid 796928:tid 797090] [client 181.224.94.124:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXcgAAArk"]
[Mon Jul 20 06:04:44.940746 2026] [security2:error] [pid 796928:tid 797090] [client 181.224.94.124:49795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXcgAAArk"]
[Mon Jul 20 06:04:44.976534 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O3LLfyzVz2SrjZpiu4wAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:44.984396 2026] [security2:error] [pid 796928:tid 797137] [client 103.95.123.246:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXdgAAAug"]
[Mon Jul 20 06:04:44.985181 2026] [security2:error] [pid 796928:tid 797137] [client 103.95.123.246:18427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXdgAAAug"]
[Mon Jul 20 06:04:45.125019 2026] [security2:error] [pid 796928:tid 797096] [client 85.204.70.112:50378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4O3esTy9vX-htKvPkXewAAAr8"]
[Mon Jul 20 06:04:45.234942 2026] [security2:error] [pid 796928:tid 797102] [client 57.141.18.20:61566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O1usTy9vX-htKvPkWGgACxRQ"]
[Mon Jul 20 06:04:45.267642 2026] [security2:error] [pid 796928:tid 797097] [client 158.173.166.181:45355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O3esTy9vX-htKvPkXhAAAAsA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:45.293516 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/yas.php"] [unique_id "al4O3bLfyzVz2SrjZpiu9wAAAog"]
[Mon Jul 20 06:04:45.293661 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/yas.php"] [unique_id "al4O3bLfyzVz2SrjZpiu9wAAAog"]
[Mon Jul 20 06:04:45.294600 2026] [security2:error] [pid 796567:tid 796742] [client 14.225.17.146:56154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4O3LLfyzVz2SrjZpiuwwAAAkE"], referer: http://travelbyfire.com/wordpress
[Mon Jul 20 06:04:45.321524 2026] [security2:error] [pid 796928:tid 797117] [client 46.110.96.34:64634] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4O3esTy9vX-htKvPkXhQAAAtQ"]
[Mon Jul 20 06:04:45.321650 2026] [security2:error] [pid 796928:tid 797117] [client 46.110.96.34:64634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4O3esTy9vX-htKvPkXhQAAAtQ"]
[Mon Jul 20 06:04:45.328541 2026] [security2:error] [pid 796928:tid 797120] [client 50.116.65.227:46962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4O3esTy9vX-htKvPkXhgAAAtc"]
[Mon Jul 20 06:04:45.340106 2026] [security2:error] [pid 796928:tid 797184] [client 50.116.65.227:46972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4O3esTy9vX-htKvPkXiAAAAxc"]
[Mon Jul 20 06:04:45.361472 2026] [security2:error] [pid 796928:tid 797103] [client 103.149.16.77:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXiQAAAsY"]
[Mon Jul 20 06:04:45.361601 2026] [security2:error] [pid 796928:tid 797103] [client 103.149.16.77:65414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXiQAAAsY"]
[Mon Jul 20 06:04:45.448059 2026] [security2:error] [pid 796567:tid 796734] [client 185.132.186.96:42949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-mail.php"] [unique_id "al4O3bLfyzVz2SrjZpiu_AAAAjk"]
[Mon Jul 20 06:04:45.650401 2026] [security2:error] [pid 796567:tid 796794] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/file61.php"] [unique_id "al4O3bLfyzVz2SrjZpivDAAAAnU"]
[Mon Jul 20 06:04:45.650477 2026] [security2:error] [pid 796567:tid 796794] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/file61.php"] [unique_id "al4O3bLfyzVz2SrjZpivDAAAAnU"]
[Mon Jul 20 06:04:45.674144 2026] [security2:error] [pid 796928:tid 797142] [client 164.100.212.184:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXngAAAu0"]
[Mon Jul 20 06:04:45.674276 2026] [security2:error] [pid 796928:tid 797142] [client 164.100.212.184:62802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXngAAAu0"]
[Mon Jul 20 06:04:45.792421 2026] [security2:error] [pid 796567:tid 796784] [client 104.234.53.91:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4O3bLfyzVz2SrjZpivEgAAAms"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:45.857252 2026] [security2:error] [pid 796567:tid 796703] [client 129.222.187.209:55650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3bLfyzVz2SrjZpivFQAAAho"]
[Mon Jul 20 06:04:45.867658 2026] [security2:error] [pid 796567:tid 796703] [client 129.222.187.209:55650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3bLfyzVz2SrjZpivFQAAAho"]
[Mon Jul 20 06:04:45.998123 2026] [security2:error] [pid 796928:tid 797154] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/water.php"] [unique_id "al4O3esTy9vX-htKvPkXrgAAAvk"]
[Mon Jul 20 06:04:45.998251 2026] [security2:error] [pid 796928:tid 797154] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/water.php"] [unique_id "al4O3esTy9vX-htKvPkXrgAAAvk"]
[Mon Jul 20 06:04:46.207066 2026] [security2:error] [pid 796928:tid 797095] [client 14.225.17.146:55571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4O3usTy9vX-htKvPkXtgAAAr4"], referer: https://travelbyfire.com/wordpress
[Mon Jul 20 06:04:46.369481 2026] [security2:error] [pid 796567:tid 796820] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/nano.php"] [unique_id "al4O3rLfyzVz2SrjZpivMgAAAo8"]
[Mon Jul 20 06:04:46.369583 2026] [security2:error] [pid 796567:tid 796820] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/nano.php"] [unique_id "al4O3rLfyzVz2SrjZpivMgAAAo8"]
[Mon Jul 20 06:04:46.483556 2026] [security2:error] [pid 796928:tid 797101] [client 104.234.53.89:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4O3usTy9vX-htKvPkXwwAAAsQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:46.561621 2026] [security2:error] [pid 796928:tid 797100] [client 86.98.90.58:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O3usTy9vX-htKvPkXygAAAsM"]
[Mon Jul 20 06:04:46.561987 2026] [security2:error] [pid 796928:tid 797100] [client 86.98.90.58:53715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O3usTy9vX-htKvPkXygAAAsM"]
[Mon Jul 20 06:04:46.602652 2026] [security2:error] [pid 796567:tid 796799] [client 72.255.10.154:2419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O3rLfyzVz2SrjZpivNgAAAno"]
[Mon Jul 20 06:04:46.602807 2026] [security2:error] [pid 796567:tid 796799] [client 72.255.10.154:2419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O3rLfyzVz2SrjZpivNgAAAno"]
[Mon Jul 20 06:04:46.639877 2026] [security2:error] [pid 796928:tid 797090] [client 85.204.70.112:50384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4O3usTy9vX-htKvPkXzQAAArk"]
[Mon Jul 20 06:04:46.749829 2026] [security2:error] [pid 796928:tid 797073] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/moon.php"] [unique_id "al4O3usTy9vX-htKvPkX0gAAAqg"]
[Mon Jul 20 06:04:46.749930 2026] [security2:error] [pid 796928:tid 797073] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/moon.php"] [unique_id "al4O3usTy9vX-htKvPkX0gAAAqg"]
[Mon Jul 20 06:04:47.024858 2026] [security2:error] [pid 796567:tid 796807] [client 57.141.18.24:33440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O2LLfyzVz2SrjZpiuJwACgk4"]
[Mon Jul 20 06:04:47.026295 2026] [security2:error] [pid 796928:tid 797062] [client 85.204.70.112:50394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4O3-sTy9vX-htKvPkX2QAAAp0"]
[Mon Jul 20 06:04:47.130554 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-info.php"] [unique_id "al4O3-sTy9vX-htKvPkX3gAAAr4"]
[Mon Jul 20 06:04:47.130650 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-info.php"] [unique_id "al4O3-sTy9vX-htKvPkX3gAAAr4"]
[Mon Jul 20 06:04:47.234462 2026] [autoindex:error] [pid 796928:tid 797146] [client 198.235.24.55:61028] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:47.392757 2026] [security2:error] [pid 796567:tid 796781] [client 185.132.186.101:26087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/admin.php"] [unique_id "al4O37LfyzVz2SrjZpivYQAAAmg"]
[Mon Jul 20 06:04:47.475641 2026] [security2:error] [pid 796567:tid 796753] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/2000.php"] [unique_id "al4O37LfyzVz2SrjZpivZAAAAkw"]
[Mon Jul 20 06:04:47.475741 2026] [security2:error] [pid 796567:tid 796753] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/2000.php"] [unique_id "al4O37LfyzVz2SrjZpivZAAAAkw"]
[Mon Jul 20 06:04:47.737320 2026] [security2:error] [pid 796567:tid 796761] [client 77.110.127.138:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O37LfyzVz2SrjZpivdQAAAlQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:47.752296 2026] [security2:error] [pid 796928:tid 797138] [client 50.116.65.227:47934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Saigon-Kiss-Street-Food-Tour-Feature-Image.jpg"] [unique_id "al4O3-sTy9vX-htKvPkX_AAAAuk"]
[Mon Jul 20 06:04:47.765651 2026] [security2:error] [pid 796567:tid 796776] [client 50.116.65.227:47082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Saigon-Kiss-Street-Food-Tour-Feature-Image.jpg"] [unique_id "al4O37LfyzVz2SrjZpivdgAAAmM"]
[Mon Jul 20 06:04:47.863176 2026] [security2:error] [pid 796928:tid 797121] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/122.php"] [unique_id "al4O3-sTy9vX-htKvPkYAgAAAtg"]
[Mon Jul 20 06:04:47.863350 2026] [security2:error] [pid 796928:tid 797121] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/122.php"] [unique_id "al4O3-sTy9vX-htKvPkYAgAAAtg"]
[Mon Jul 20 06:04:47.876137 2026] [security2:error] [pid 796567:tid 796755] [client 57.141.18.45:26070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O2bLfyzVz2SrjZpiuVAACTiI"]
[Mon Jul 20 06:04:48.038658 2026] [security2:error] [pid 796567:tid 796818] [client 13.201.64.214:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O4LLfyzVz2SrjZpivgQAAAo0"]
[Mon Jul 20 06:04:48.038801 2026] [security2:error] [pid 796567:tid 796818] [client 13.201.64.214:56848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O4LLfyzVz2SrjZpivgQAAAo0"]
[Mon Jul 20 06:04:48.236814 2026] [security2:error] [pid 796928:tid 797157] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mds.php"] [unique_id "al4O4OsTy9vX-htKvPkYFgAAAvw"]
[Mon Jul 20 06:04:48.236904 2026] [security2:error] [pid 796928:tid 797157] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mds.php"] [unique_id "al4O4OsTy9vX-htKvPkYFgAAAvw"]
[Mon Jul 20 06:04:48.639516 2026] [security2:error] [pid 796928:tid 797140] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-blink.php"] [unique_id "al4O4OsTy9vX-htKvPkYKgAAAus"]
[Mon Jul 20 06:04:48.639673 2026] [security2:error] [pid 796928:tid 797140] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-blink.php"] [unique_id "al4O4OsTy9vX-htKvPkYKgAAAus"]
[Mon Jul 20 06:04:48.674249 2026] [ssl:error] [pid 796928:tid 797156] [client 95.74.226.106:19306] AH02032: Hostname www.perrysnopeep.crmpfilms.com provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:04:48.757777 2026] [security2:error] [pid 796928:tid 797080] [client 106.192.104.4:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O4OsTy9vX-htKvPkYMQAAAq8"]
[Mon Jul 20 06:04:48.757896 2026] [security2:error] [pid 796928:tid 797080] [client 106.192.104.4:59458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O4OsTy9vX-htKvPkYMQAAAq8"]
[Mon Jul 20 06:04:48.933582 2026] [security2:error] [pid 796928:tid 797075] [client 103.153.183.69:25038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../etc/ssh/sshd_config"] [unique_id "al4O4OsTy9vX-htKvPkYPAAAAqo"], referer: https://t.co/ddzi1kh5xa
[Mon Jul 20 06:04:48.943972 2026] [security2:error] [pid 796567:tid 796814] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4O4LLfyzVz2SrjZpivkAAAAok"]
[Mon Jul 20 06:04:49.004403 2026] [security2:error] [pid 796567:tid 796731] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O4LLfyzVz2SrjZpivoQAAAjY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:49.024922 2026] [security2:error] [pid 796928:tid 797124] [client 158.173.89.95:53245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O4esTy9vX-htKvPkYRQAAAts"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:49.039429 2026] [security2:error] [pid 796928:tid 797088] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zc-208.php"] [unique_id "al4O4esTy9vX-htKvPkYRgAAArc"]
[Mon Jul 20 06:04:49.039557 2026] [security2:error] [pid 796928:tid 797088] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zc-208.php"] [unique_id "al4O4esTy9vX-htKvPkYRgAAArc"]
[Mon Jul 20 06:04:49.123897 2026] [security2:error] [pid 796928:tid 797064] [client 57.141.18.125:63354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O2usTy9vX-htKvPkW6gACn14"]
[Mon Jul 20 06:04:49.130000 2026] [security2:error] [pid 796567:tid 796688] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O4bLfyzVz2SrjZpivrAACang"]
[Mon Jul 20 06:04:49.130176 2026] [security2:error] [pid 796567:tid 796783] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O4bLfyzVz2SrjZpivrAACang"]
[Mon Jul 20 06:04:49.196522 2026] [security2:error] [pid 796928:tid 797161] [client 77.110.127.138:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O4esTy9vX-htKvPkYTwAAAwA"], referer: https://mezzacraft.com/contact-me/
[Mon Jul 20 06:04:49.255296 2026] [security2:error] [pid 796928:tid 797106] [client 47.31.86.100:60815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYWgAAAsk"]
[Mon Jul 20 06:04:49.256562 2026] [security2:error] [pid 796928:tid 797115] [client 103.153.183.69:25038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../root/.ssh/id_rsa"] [unique_id "al4O4esTy9vX-htKvPkYWQAAAtI"], referer: https://www.bing.com/search?q=bdwwhf
[Mon Jul 20 06:04:49.260049 2026] [security2:error] [pid 796928:tid 797106] [client 47.31.86.100:60815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYWgAAAsk"]
[Mon Jul 20 06:04:49.344150 2026] [security2:error] [pid 796567:tid 796727] [client 185.132.186.64:53395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/defaults.php"] [unique_id "al4O4bLfyzVz2SrjZpivtgAAAjI"]
[Mon Jul 20 06:04:49.416184 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sid4.php"] [unique_id "al4O4bLfyzVz2SrjZpivuQAAAmU"]
[Mon Jul 20 06:04:49.416372 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sid4.php"] [unique_id "al4O4bLfyzVz2SrjZpivuQAAAmU"]
[Mon Jul 20 06:04:49.637071 2026] [security2:error] [pid 796567:tid 796743] [client 57.141.18.51:53360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O27LfyzVz2SrjZpiumgACQmk"]
[Mon Jul 20 06:04:49.806871 2026] [security2:error] [pid 796567:tid 796808] [client 104.234.53.80:44685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4O4bLfyzVz2SrjZpivxAAAAoM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:49.836606 2026] [security2:error] [pid 796928:tid 797176] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O4esTy9vX-htKvPkYawAAAw8"]
[Mon Jul 20 06:04:49.902205 2026] [security2:error] [pid 796928:tid 797175] [client 112.213.160.112:8382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYdQAAAw4"]
[Mon Jul 20 06:04:49.902409 2026] [security2:error] [pid 796928:tid 797175] [client 112.213.160.112:8382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYdQAAAw4"]
[Mon Jul 20 06:04:49.951688 2026] [security2:error] [pid 796567:tid 796728] [client 57.141.18.80:60144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O27LfyzVz2SrjZpiupwACM2M"]
[Mon Jul 20 06:04:50.018004 2026] [security2:error] [pid 796928:tid 797064] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wmore1.php"] [unique_id "al4O4usTy9vX-htKvPkYfAAAAp8"]
[Mon Jul 20 06:04:50.018112 2026] [security2:error] [pid 796928:tid 797064] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wmore1.php"] [unique_id "al4O4usTy9vX-htKvPkYfAAAAp8"]
[Mon Jul 20 06:04:50.063710 2026] [security2:error] [pid 796567:tid 796801] [client 14.225.17.146:55747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4O37LfyzVz2SrjZpivaAAAAnw"], referer: http://itdynamix.com/wordpress
[Mon Jul 20 06:04:50.099926 2026] [security2:error] [pid 796928:tid 797126] [client 150.228.148.150:24914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O4usTy9vX-htKvPkYfgAAAt0"]
[Mon Jul 20 06:04:50.115562 2026] [security2:error] [pid 796928:tid 797126] [client 150.228.148.150:24914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O4usTy9vX-htKvPkYfgAAAt0"]
[Mon Jul 20 06:04:50.214791 2026] [security2:error] [pid 796928:tid 797155] [client 77.110.127.138:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O4usTy9vX-htKvPkYiwAAAvo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:50.396021 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/solo1.php"] [unique_id "al4O4usTy9vX-htKvPkYlAAAAsM"]
[Mon Jul 20 06:04:50.396120 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/solo1.php"] [unique_id "al4O4usTy9vX-htKvPkYlAAAAsM"]
[Mon Jul 20 06:04:50.831727 2026] [security2:error] [pid 796928:tid 797125] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O4usTy9vX-htKvPkYowAAAtw"]
[Mon Jul 20 06:04:51.036675 2026] [security2:error] [pid 796928:tid 797118] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/cong.php"] [unique_id "al4O4-sTy9vX-htKvPkYsQAAAtU"]
[Mon Jul 20 06:04:51.036809 2026] [security2:error] [pid 796928:tid 797118] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/cong.php"] [unique_id "al4O4-sTy9vX-htKvPkYsQAAAtU"]
[Mon Jul 20 06:04:51.052974 2026] [security2:error] [pid 796928:tid 796930] [remote 84.247.172.23:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4O4-sTy9vX-htKvPkYsgACwAE"]
[Mon Jul 20 06:04:51.192168 2026] [security2:error] [pid 796928:tid 797122] [client 14.225.17.146:63215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4O4usTy9vX-htKvPkYrgAAAtk"], referer: https://itdynamix.com/wordpress
[Mon Jul 20 06:04:51.212469 2026] [security2:error] [pid 796928:tid 797152] [client 57.141.18.68:58174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O3OsTy9vX-htKvPkXZAAC91o"]
[Mon Jul 20 06:04:51.267578 2026] [security2:error] [pid 796928:tid 797119] [client 14.225.17.146:56339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4O4-sTy9vX-htKvPkYtAAAAtY"], referer: http://transparentservices.online/wordpress
[Mon Jul 20 06:04:51.292470 2026] [security2:error] [pid 796567:tid 796742] [client 185.132.186.84:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "al4O47LfyzVz2SrjZpiwBwAAAkE"]
[Mon Jul 20 06:04:51.447187 2026] [security2:error] [pid 796567:tid 796719] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O47LfyzVz2SrjZpiwDAAAAio"]
[Mon Jul 20 06:04:51.455568 2026] [security2:error] [pid 796928:tid 797131] [client 14.225.17.146:57360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4O4esTy9vX-htKvPkYeQAAAuI"], referer: http://scott-assist.com/wordpress
[Mon Jul 20 06:04:51.468610 2026] [security2:error] [pid 796928:tid 797037] [remote 84.247.172.23:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4O4-sTy9vX-htKvPkYwgACsmw"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:04:51.536704 2026] [security2:error] [pid 796567:tid 796603] [remote 192.241.143.148:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4O47LfyzVz2SrjZpiwFQACKSM"]
[Mon Jul 20 06:04:51.637303 2026] [security2:error] [pid 796928:tid 797043] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al4O4-sTy9vX-htKvPkYxwACy3I"]
[Mon Jul 20 06:04:51.638877 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/public/css.php"] [unique_id "al4O47LfyzVz2SrjZpiwGgAAAh8"]
[Mon Jul 20 06:04:51.638953 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/public/css.php"] [unique_id "al4O47LfyzVz2SrjZpiwGgAAAh8"]
[Mon Jul 20 06:04:51.670001 2026] [security2:error] [pid 796928:tid 797077] [client 103.153.183.69:49848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4O4-sTy9vX-htKvPkYzAAAAqw"], referer: https://www.google.com/
[Mon Jul 20 06:04:51.706000 2026] [security2:error] [pid 796928:tid 797085] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O4-sTy9vX-htKvPkYxAAAArQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:51.706445 2026] [security2:error] [pid 796567:tid 796574] [remote 192.241.143.148:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4O47LfyzVz2SrjZpiwHgACkAY"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:04:51.754007 2026] [security2:error] [pid 796928:tid 797078] [client 103.153.183.69:49848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4O4-sTy9vX-htKvPkY1AAAAq0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:04:51.764615 2026] [security2:error] [pid 796567:tid 796776] [client 27.96.94.195:37968] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O47LfyzVz2SrjZpiwGwAAAmM"]
[Mon Jul 20 06:04:51.764771 2026] [security2:error] [pid 796567:tid 796776] [client 27.96.94.195:37968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O47LfyzVz2SrjZpiwGwAAAmM"]
[Mon Jul 20 06:04:51.921803 2026] [security2:error] [pid 796928:tid 797092] [client 57.141.18.102:51340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O3esTy9vX-htKvPkXlgACu0A"]
[Mon Jul 20 06:04:52.029790 2026] [security2:error] [pid 796567:tid 796711] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/output.php"] [unique_id "al4O5LLfyzVz2SrjZpiwKAAAAiI"]
[Mon Jul 20 06:04:52.029905 2026] [security2:error] [pid 796567:tid 796711] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/output.php"] [unique_id "al4O5LLfyzVz2SrjZpiwKAAAAiI"]
[Mon Jul 20 06:04:52.228887 2026] [security2:error] [pid 796928:tid 797168] [client 115.246.21.170:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkY7gAAAwc"]
[Mon Jul 20 06:04:52.228990 2026] [security2:error] [pid 796928:tid 797168] [client 115.246.21.170:28699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkY7gAAAwc"]
[Mon Jul 20 06:04:52.380489 2026] [security2:error] [pid 796567:tid 796726] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-file-120.php"] [unique_id "al4O5LLfyzVz2SrjZpiwNgAAAjE"]
[Mon Jul 20 06:04:52.380591 2026] [security2:error] [pid 796567:tid 796726] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-file-120.php"] [unique_id "al4O5LLfyzVz2SrjZpiwNgAAAjE"]
[Mon Jul 20 06:04:52.597003 2026] [security2:error] [pid 796567:tid 796725] [client 14.225.17.146:55807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4O4bLfyzVz2SrjZpivywAAAjA"], referer: http://idigress.studio/wordpress
[Mon Jul 20 06:04:52.696340 2026] [security2:error] [pid 796928:tid 797078] [client 77.110.127.138:55109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkZAAAAAq0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:52.700648 2026] [security2:error] [pid 796928:tid 797110] [client 56.125.35.21:53268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkY-AAAAs0"]
[Mon Jul 20 06:04:52.719283 2026] [security2:error] [pid 796567:tid 796765] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O5LLfyzVz2SrjZpiwOAACWE4"]
[Mon Jul 20 06:04:52.761186 2026] [security2:error] [pid 796567:tid 796704] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/special.php"] [unique_id "al4O5LLfyzVz2SrjZpiwTgAAAhs"]
[Mon Jul 20 06:04:52.761289 2026] [security2:error] [pid 796567:tid 796704] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/special.php"] [unique_id "al4O5LLfyzVz2SrjZpiwTgAAAhs"]
[Mon Jul 20 06:04:52.785612 2026] [security2:error] [pid 796928:tid 797045] [remote 103.82.22.235:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkZAgAC4nQ"]
[Mon Jul 20 06:04:52.785840 2026] [security2:error] [pid 796928:tid 797131] [client 103.82.22.235:42270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkZAgAC4nQ"]
[Mon Jul 20 06:04:53.003984 2026] [security2:error] [pid 796928:tid 796960] [remote 72.167.132.114:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O5OsTy9vX-htKvPkZCgACqx8"]
[Mon Jul 20 06:04:53.229112 2026] [security2:error] [pid 796928:tid 796945] [remote 72.167.132.114:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O5esTy9vX-htKvPkZFQACyhA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:53.255892 2026] [security2:error] [pid 796928:tid 797148] [client 185.132.186.99:48557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/ALFA_DATA/alfacgiapi/bypass.php"] [unique_id "al4O5esTy9vX-htKvPkZFwAAAvM"]
[Mon Jul 20 06:04:53.352692 2026] [security2:error] [pid 796567:tid 796732] [client 104.234.53.69:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwbAAAAjc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:53.556272 2026] [security2:error] [pid 796567:tid 796749] [client 178.152.178.232:37514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiweAAAAkg"]
[Mon Jul 20 06:04:53.556398 2026] [security2:error] [pid 796567:tid 796749] [client 178.152.178.232:37514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiweAAAAkg"]
[Mon Jul 20 06:04:53.567007 2026] [security2:error] [pid 796567:tid 796757] [client 57.141.18.7:63436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O37LfyzVz2SrjZpivTgACUCQ"]
[Mon Jul 20 06:04:53.652102 2026] [security2:error] [pid 796567:tid 796674] [remote 40.77.167.247:37960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marscafe.com"] [uri "/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwfgAChmo"]
[Mon Jul 20 06:04:53.677291 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/as.php"] [unique_id "al4O5bLfyzVz2SrjZpiwgAAAAmU"]
[Mon Jul 20 06:04:53.677407 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/as.php"] [unique_id "al4O5bLfyzVz2SrjZpiwgAAAAmU"]
[Mon Jul 20 06:04:53.749756 2026] [security2:error] [pid 796928:tid 797128] [client 14.224.227.113:55575] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4O5esTy9vX-htKvPkZKwAAAt8"]
[Mon Jul 20 06:04:53.918014 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiwiQAAAkU"]
[Mon Jul 20 06:04:53.918153 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiwiQAAAkU"]
[Mon Jul 20 06:04:53.944193 2026] [security2:error] [pid 796567:tid 796724] [client 24.77.48.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwhQACLxM"]
[Mon Jul 20 06:04:53.977365 2026] [security2:error] [pid 796928:tid 797151] [client 210.212.97.243:10440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O5esTy9vX-htKvPkZOQAAAvY"]
[Mon Jul 20 06:04:53.977519 2026] [security2:error] [pid 796928:tid 797151] [client 210.212.97.243:10440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O5esTy9vX-htKvPkZOQAAAvY"]
[Mon Jul 20 06:04:54.037202 2026] [security2:error] [pid 796928:tid 797111] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/cgi-bin/index.php"] [unique_id "al4O5usTy9vX-htKvPkZOwAAAs4"]
[Mon Jul 20 06:04:54.037346 2026] [security2:error] [pid 796928:tid 797111] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/cgi-bin/index.php"] [unique_id "al4O5usTy9vX-htKvPkZOwAAAs4"]
[Mon Jul 20 06:04:54.329942 2026] [security2:error] [pid 796928:tid 797176] [client 14.225.17.146:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4O5OsTy9vX-htKvPkZCAAAAw8"], referer: http://mazzucelli.com/wordpress
[Mon Jul 20 06:04:54.371226 2026] [security2:error] [pid 796567:tid 796766] [client 57.141.18.17:27812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O37LfyzVz2SrjZpivbgACWRQ"]
[Mon Jul 20 06:04:54.392856 2026] [security2:error] [pid 796567:tid 796775] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/w1px.php"] [unique_id "al4O5rLfyzVz2SrjZpiwnwAAAmI"]
[Mon Jul 20 06:04:54.392970 2026] [security2:error] [pid 796567:tid 796775] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/w1px.php"] [unique_id "al4O5rLfyzVz2SrjZpiwnwAAAmI"]
[Mon Jul 20 06:04:54.453640 2026] [security2:error] [pid 796567:tid 796679] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O5rLfyzVz2SrjZpiwpwACVm8"]
[Mon Jul 20 06:04:54.453817 2026] [security2:error] [pid 796567:tid 796763] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O5rLfyzVz2SrjZpiwpwACVm8"]
[Mon Jul 20 06:04:54.717521 2026] [security2:error] [pid 796567:tid 796814] [client 14.225.17.146:55064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4O5LLfyzVz2SrjZpiwPAAAAok"], referer: http://fluidtemple.org/wordpress
[Mon Jul 20 06:04:54.775704 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/yawa.php"] [unique_id "al4O5usTy9vX-htKvPkZUgAAAwU"]
[Mon Jul 20 06:04:54.775832 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/yawa.php"] [unique_id "al4O5usTy9vX-htKvPkZUgAAAwU"]
[Mon Jul 20 06:04:55.138108 2026] [security2:error] [pid 796928:tid 797062] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/js.php"] [unique_id "al4O5-sTy9vX-htKvPkZZAAAAp0"]
[Mon Jul 20 06:04:55.138194 2026] [security2:error] [pid 796928:tid 797062] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/js.php"] [unique_id "al4O5-sTy9vX-htKvPkZZAAAAp0"]
[Mon Jul 20 06:04:55.203549 2026] [security2:error] [pid 796928:tid 797117] [client 185.132.186.67:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/about.php"] [unique_id "al4O5-sTy9vX-htKvPkZZwAAAtQ"]
[Mon Jul 20 06:04:55.287338 2026] [security2:error] [pid 796928:tid 797151] [client 65.1.132.125:58140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZawAAAvY"]
[Mon Jul 20 06:04:55.287459 2026] [security2:error] [pid 796928:tid 797151] [client 65.1.132.125:58140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZawAAAvY"]
[Mon Jul 20 06:04:55.450465 2026] [security2:error] [pid 796928:tid 797111] [client 181.224.94.124:27658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZcwAAAs4"]
[Mon Jul 20 06:04:55.450596 2026] [security2:error] [pid 796928:tid 797111] [client 181.224.94.124:27658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZcwAAAs4"]
[Mon Jul 20 06:04:55.494719 2026] [security2:error] [pid 796567:tid 796808] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/core.php"] [unique_id "al4O57LfyzVz2SrjZpiw0gAAAoM"]
[Mon Jul 20 06:04:55.494875 2026] [security2:error] [pid 796567:tid 796808] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/core.php"] [unique_id "al4O57LfyzVz2SrjZpiw0gAAAoM"]
[Mon Jul 20 06:04:55.846186 2026] [security2:error] [pid 796928:tid 797119] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/19.php"] [unique_id "al4O5-sTy9vX-htKvPkZgwAAAtY"]
[Mon Jul 20 06:04:55.846309 2026] [security2:error] [pid 796928:tid 797119] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/19.php"] [unique_id "al4O5-sTy9vX-htKvPkZgwAAAtY"]
[Mon Jul 20 06:04:55.973574 2026] [security2:error] [pid 796928:tid 796994] [remote 162.19.86.63:42064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O5-sTy9vX-htKvPkZiwACo0E"]
[Mon Jul 20 06:04:56.224266 2026] [security2:error] [pid 796928:tid 797146] [client 103.149.16.77:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O6OsTy9vX-htKvPkZnwAAAvE"]
[Mon Jul 20 06:04:56.224418 2026] [security2:error] [pid 796928:tid 797146] [client 103.149.16.77:49408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O6OsTy9vX-htKvPkZnwAAAvE"]
[Mon Jul 20 06:04:56.325290 2026] [security2:error] [pid 796928:tid 797131] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O6OsTy9vX-htKvPkZkQAAAuI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:56.411946 2026] [security2:error] [pid 796928:tid 797184] [client 57.141.18.93:62416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O4esTy9vX-htKvPkYbAADF3w"]
[Mon Jul 20 06:04:56.669135 2026] [security2:error] [pid 796567:tid 796722] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/inc.php"] [unique_id "al4O6LLfyzVz2SrjZpixBAAAAi0"]
[Mon Jul 20 06:04:56.669248 2026] [security2:error] [pid 796567:tid 796722] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/inc.php"] [unique_id "al4O6LLfyzVz2SrjZpixBAAAAi0"]
[Mon Jul 20 06:04:57.028700 2026] [security2:error] [pid 796928:tid 796978] [remote 162.19.86.63:42064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O6esTy9vX-htKvPkZxwACzjE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:04:57.038857 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-ppoxua4.php"] [unique_id "al4O6bLfyzVz2SrjZpixFgAAAmE"]
[Mon Jul 20 06:04:57.038970 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-ppoxua4.php"] [unique_id "al4O6bLfyzVz2SrjZpixFgAAAmE"]
[Mon Jul 20 06:04:57.154550 2026] [security2:error] [pid 796928:tid 797155] [client 185.132.186.100:45807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/about.php"] [unique_id "al4O6esTy9vX-htKvPkZ1gAAAvo"]
[Mon Jul 20 06:04:57.185415 2026] [security2:error] [pid 796567:tid 796704] [client 72.255.10.154:2433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O6bLfyzVz2SrjZpixHwAAAhs"]
[Mon Jul 20 06:04:57.185550 2026] [security2:error] [pid 796567:tid 796704] [client 72.255.10.154:2433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O6bLfyzVz2SrjZpixHwAAAhs"]
[Mon Jul 20 06:04:57.292611 2026] [security2:error] [pid 796567:tid 796800] [client 14.182.195.220:51983] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O6bLfyzVz2SrjZpixJAAAAns"]
[Mon Jul 20 06:04:57.296157 2026] [security2:error] [pid 796567:tid 796731] [client 14.182.195.220:51985] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O6bLfyzVz2SrjZpixJQAAAjY"]
[Mon Jul 20 06:04:57.298718 2026] [security2:error] [pid 796928:tid 797069] [client 14.182.195.220:51984] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O6esTy9vX-htKvPkZ2wAAAqQ"]
[Mon Jul 20 06:04:57.401860 2026] [security2:error] [pid 796928:tid 797105] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al4O6esTy9vX-htKvPkZ3gAAAsg"]
[Mon Jul 20 06:04:57.401987 2026] [security2:error] [pid 796928:tid 797105] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al4O6esTy9vX-htKvPkZ3gAAAsg"]
[Mon Jul 20 06:04:57.734706 2026] [security2:error] [pid 796928:tid 797130] [client 14.225.17.146:52556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4O5usTy9vX-htKvPkZWAAAAuE"], referer: http://worbals.com/wordpress
[Mon Jul 20 06:04:57.757474 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ss.php"] [unique_id "al4O6esTy9vX-htKvPkZ9gAAArA"]
[Mon Jul 20 06:04:57.757594 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ss.php"] [unique_id "al4O6esTy9vX-htKvPkZ9gAAArA"]
[Mon Jul 20 06:04:57.875263 2026] [security2:error] [pid 796928:tid 797164] [client 57.141.18.11:27912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O4-sTy9vX-htKvPkYvAADAw4"]
[Mon Jul 20 06:04:57.901927 2026] [security2:error] [pid 796567:tid 796740] [client 77.110.127.138:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6bLfyzVz2SrjZpixPQAAAj8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:57.963217 2026] [security2:error] [pid 796928:tid 797117] [client 14.225.17.146:56556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4O6esTy9vX-htKvPkZ8AAAAtQ"]
[Mon Jul 20 06:04:58.013449 2026] [security2:error] [pid 796928:tid 797140] [client 64.71.131.243:47754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4O5-sTy9vX-htKvPkZggAAAus"]
[Mon Jul 20 06:04:58.161769 2026] [security2:error] [pid 796928:tid 797066] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/min.php"] [unique_id "al4O6usTy9vX-htKvPkaCQAAAqE"]
[Mon Jul 20 06:04:58.161917 2026] [security2:error] [pid 796928:tid 797066] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/min.php"] [unique_id "al4O6usTy9vX-htKvPkaCQAAAqE"]
[Mon Jul 20 06:04:58.198419 2026] [security2:error] [pid 796928:tid 797110] [client 104.234.53.57:37283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4O6usTy9vX-htKvPkaDAAAAs0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:58.456688 2026] [security2:error] [pid 796567:tid 796786] [client 14.225.17.146:57766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4O6LLfyzVz2SrjZpixEwAAAm0"], referer: http://betterbonddogtraining.com/wordpress
[Mon Jul 20 06:04:58.543702 2026] [security2:error] [pid 796567:tid 796762] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al4O6rLfyzVz2SrjZpixYQAAAlU"]
[Mon Jul 20 06:04:58.543921 2026] [security2:error] [pid 796567:tid 796762] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al4O6rLfyzVz2SrjZpixYQAAAlU"]
[Mon Jul 20 06:04:58.636035 2026] [security2:error] [pid 796928:tid 797058] [client 77.110.127.138:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaIwAAApk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:58.879402 2026] [security2:error] [pid 796928:tid 797117] [client 77.110.127.138:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaKgAAAtQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:58.899132 2026] [security2:error] [pid 796567:tid 796818] [client 3.109.4.218:38894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O6rLfyzVz2SrjZpixfAAAAo0"]
[Mon Jul 20 06:04:58.899297 2026] [security2:error] [pid 796567:tid 796818] [client 3.109.4.218:38894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O6rLfyzVz2SrjZpixfAAAAo0"]
[Mon Jul 20 06:04:58.908672 2026] [security2:error] [pid 796928:tid 797094] [client 103.95.123.246:18875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaKwAAAr0"]
[Mon Jul 20 06:04:58.908812 2026] [security2:error] [pid 796928:tid 797094] [client 103.95.123.246:18875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaKwAAAr0"]
[Mon Jul 20 06:04:58.926225 2026] [security2:error] [pid 796928:tid 797102] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/autoload_classmap.php"] [unique_id "al4O6usTy9vX-htKvPkaLAAAAsU"]
[Mon Jul 20 06:04:58.926338 2026] [security2:error] [pid 796928:tid 797102] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/autoload_classmap.php"] [unique_id "al4O6usTy9vX-htKvPkaLAAAAsU"]
[Mon Jul 20 06:04:58.990261 2026] [security2:error] [pid 796567:tid 796761] [client 74.249.226.166:29377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4O6rLfyzVz2SrjZpixgAAAAlQ"]
[Mon Jul 20 06:04:59.043807 2026] [security2:error] [pid 796567:tid 796750] [client 74.249.226.166:29377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4O67LfyzVz2SrjZpixhAAAAkk"]
[Mon Jul 20 06:04:59.087177 2026] [security2:error] [pid 796567:tid 796746] [client 185.132.186.58:35601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/2023/05/404.php"] [unique_id "al4O67LfyzVz2SrjZpixiQAAAkU"]
[Mon Jul 20 06:04:59.195950 2026] [security2:error] [pid 796567:tid 796718] [client 14.225.17.146:57770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4O6bLfyzVz2SrjZpixFQAAAik"], referer: http://webgardensbypaula.com/wordpress
[Mon Jul 20 06:04:59.317548 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-link-zorm.php"] [unique_id "al4O6-sTy9vX-htKvPkaQAAAAqU"]
[Mon Jul 20 06:04:59.317689 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-link-zorm.php"] [unique_id "al4O6-sTy9vX-htKvPkaQAAAAqU"]
[Mon Jul 20 06:04:59.438616 2026] [security2:error] [pid 796567:tid 796792] [client 57.141.18.9:35768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwYgACc10"]
[Mon Jul 20 06:04:59.634637 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixowAAAi8"]
[Mon Jul 20 06:04:59.634816 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:59946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixowAAAi8"]
[Mon Jul 20 06:04:59.670428 2026] [security2:error] [pid 796928:tid 797167] [client 77.110.127.138:55167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6-sTy9vX-htKvPkaVQAAAwY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:59.694340 2026] [security2:error] [pid 796928:tid 797079] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-link-szoppm.php"] [unique_id "al4O6-sTy9vX-htKvPkaVgAAAq4"]
[Mon Jul 20 06:04:59.694444 2026] [security2:error] [pid 796928:tid 797079] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-link-szoppm.php"] [unique_id "al4O6-sTy9vX-htKvPkaVgAAAq4"]
[Mon Jul 20 06:04:59.695899 2026] [security2:error] [pid 796567:tid 796742] [client 47.31.86.100:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixpQAAAkE"]
[Mon Jul 20 06:04:59.696000 2026] [security2:error] [pid 796567:tid 796742] [client 47.31.86.100:61227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixpQAAAkE"]
[Mon Jul 20 06:04:59.795388 2026] [security2:error] [pid 796567:tid 796610] [remote 217.61.143.92:48604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixrwACKCo"]
[Mon Jul 20 06:04:59.795602 2026] [security2:error] [pid 796567:tid 796717] [client 217.61.143.92:48604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixrwACKCo"]
[Mon Jul 20 06:04:59.795866 2026] [access_compat:error] [pid 796567:tid 796751] [client 183.47.125.206:52045] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:59.821615 2026] [security2:error] [pid 796928:tid 797083] [client 77.110.127.138:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6-sTy9vX-htKvPkaYgAAArI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:59.855200 2026] [security2:error] [pid 796928:tid 797098] [client 57.141.18.82:55110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5esTy9vX-htKvPkZJgACwQg"]
[Mon Jul 20 06:04:59.972806 2026] [security2:error] [pid 796567:tid 796576] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al4O67LfyzVz2SrjZpixtQACGgg"]
[Mon Jul 20 06:05:00.077434 2026] [security2:error] [pid 796928:tid 797149] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/albin.php"] [unique_id "al4O7OsTy9vX-htKvPkabgAAAvQ"]
[Mon Jul 20 06:05:00.077543 2026] [security2:error] [pid 796928:tid 797149] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/albin.php"] [unique_id "al4O7OsTy9vX-htKvPkabgAAAvQ"]
[Mon Jul 20 06:05:00.143717 2026] [security2:error] [pid 796928:tid 797071] [client 77.110.127.138:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkabwAAAqY"]
[Mon Jul 20 06:05:00.176582 2026] [security2:error] [pid 796567:tid 796719] [client 195.96.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sk-financial.com"] [uri "/index.php"] [unique_id "al4O7LLfyzVz2SrjZpixuQAAAio"]
[Mon Jul 20 06:05:00.182944 2026] [security2:error] [pid 796567:tid 796738] [client 185.247.137.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sk-financial.com"] [uri "/index.php"] [unique_id "al4O7LLfyzVz2SrjZpixugAAAj0"]
[Mon Jul 20 06:05:00.255304 2026] [access_compat:error] [pid 796928:tid 797122] [client 183.47.107.86:60457] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:00.316528 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkaeQAAAqw"]
[Mon Jul 20 06:05:00.390961 2026] [security2:error] [pid 796567:tid 796629] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O7LLfyzVz2SrjZpixyQACUD0"]
[Mon Jul 20 06:05:00.391151 2026] [security2:error] [pid 796567:tid 796757] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O7LLfyzVz2SrjZpixyQACUD0"]
[Mon Jul 20 06:05:00.406135 2026] [access_compat:error] [pid 796567:tid 796714] [client 112.90.2.135:44615] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:00.475254 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/cilus.php"] [unique_id "al4O7OsTy9vX-htKvPkaigAAAwg"]
[Mon Jul 20 06:05:00.475350 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/cilus.php"] [unique_id "al4O7OsTy9vX-htKvPkaigAAAwg"]
[Mon Jul 20 06:05:00.580299 2026] [security2:error] [pid 796928:tid 797067] [client 150.228.148.150:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkalAAAAqI"]
[Mon Jul 20 06:05:00.580519 2026] [security2:error] [pid 796928:tid 797067] [client 150.228.148.150:56763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkalAAAAqI"]
[Mon Jul 20 06:05:00.604837 2026] [security2:error] [pid 796928:tid 797094] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O7OsTy9vX-htKvPkaegAAAr0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:00.669920 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkamAAAAwU"]
[Mon Jul 20 06:05:00.670101 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkamAAAAwU"]
[Mon Jul 20 06:05:00.841026 2026] [security2:error] [pid 796567:tid 796819] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/gptsh.php"] [unique_id "al4O7LLfyzVz2SrjZpix2AAAAo4"]
[Mon Jul 20 06:05:00.841130 2026] [security2:error] [pid 796567:tid 796819] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/gptsh.php"] [unique_id "al4O7LLfyzVz2SrjZpix2AAAAo4"]
[Mon Jul 20 06:05:00.847691 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.24:45840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5rLfyzVz2SrjZpiwpgACNXE"]
[Mon Jul 20 06:05:01.032385 2026] [security2:error] [pid 796567:tid 796812] [client 185.132.186.58:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/maint.php"] [unique_id "al4O7bLfyzVz2SrjZpix4QAAAoc"]
[Mon Jul 20 06:05:01.217152 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/rithin.php"] [unique_id "al4O7bLfyzVz2SrjZpix6gAAAig"]
[Mon Jul 20 06:05:01.217264 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/rithin.php"] [unique_id "al4O7bLfyzVz2SrjZpix6gAAAig"]
[Mon Jul 20 06:05:01.314904 2026] [security2:error] [pid 796928:tid 797072] [client 52.109.124.141:33665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4O7esTy9vX-htKvPkaqgAAAqc"]
[Mon Jul 20 06:05:01.494237 2026] [security2:error] [pid 796928:tid 797067] [client 52.109.124.141:33665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4O7esTy9vX-htKvPkatwAAAqI"]
[Mon Jul 20 06:05:01.577155 2026] [security2:error] [pid 796928:tid 797090] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fffm.php"] [unique_id "al4O7esTy9vX-htKvPkavAAAArk"]
[Mon Jul 20 06:05:01.577365 2026] [security2:error] [pid 796928:tid 797090] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fffm.php"] [unique_id "al4O7esTy9vX-htKvPkavAAAArk"]
[Mon Jul 20 06:05:01.649120 2026] [security2:error] [pid 796928:tid 797170] [client 57.141.18.107:38586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5-sTy9vX-htKvPkZaAADCVY"]
[Mon Jul 20 06:05:01.955087 2026] [security2:error] [pid 796567:tid 796672] [remote 182.77.62.24:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O7bLfyzVz2SrjZpiyCgACdGg"]
[Mon Jul 20 06:05:01.988810 2026] [access_compat:error] [pid 796567:tid 796773] [client 183.47.125.177:52311] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:02.048517 2026] [security2:error] [pid 796928:tid 796942] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4O7usTy9vX-htKvPka1wAC8g0"]
[Mon Jul 20 06:05:02.194947 2026] [security2:error] [pid 796928:tid 797059] [client 57.141.18.56:28628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5-sTy9vX-htKvPkZgQACmhk"]
[Mon Jul 20 06:05:02.380062 2026] [security2:error] [pid 796928:tid 797001] [remote 72.167.132.114:43660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O7usTy9vX-htKvPka5gAC7kg"]
[Mon Jul 20 06:05:02.482165 2026] [security2:error] [pid 796567:tid 796580] [remote 182.77.62.24:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O7rLfyzVz2SrjZpiyIgACiAw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:05:02.611340 2026] [security2:error] [pid 796567:tid 796809] [client 52.233.165.60:29168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4O7rLfyzVz2SrjZpiyKgAAAoQ"]
[Mon Jul 20 06:05:02.711900 2026] [security2:error] [pid 796928:tid 796988] [remote 72.167.132.114:43660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O7usTy9vX-htKvPka_AACmjs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:02.757335 2026] [security2:error] [pid 796567:tid 796815] [client 52.233.165.60:29168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4O7rLfyzVz2SrjZpiyLgAAAoo"]
[Mon Jul 20 06:05:02.881719 2026] [security2:error] [pid 796928:tid 797096] [client 115.246.21.170:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O7usTy9vX-htKvPkbBgAAAr8"]
[Mon Jul 20 06:05:02.881840 2026] [security2:error] [pid 796928:tid 797096] [client 115.246.21.170:53167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O7usTy9vX-htKvPkbBgAAAr8"]
[Mon Jul 20 06:05:02.904984 2026] [security2:error] [pid 796928:tid 797139] [client 57.141.18.33:44190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O6OsTy9vX-htKvPkZuAAC6ko"]
[Mon Jul 20 06:05:02.973246 2026] [security2:error] [pid 796928:tid 797078] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/dfre.php"] [unique_id "al4O7usTy9vX-htKvPkbEQAAAq0"]
[Mon Jul 20 06:05:02.973352 2026] [security2:error] [pid 796928:tid 797078] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/dfre.php"] [unique_id "al4O7usTy9vX-htKvPkbEQAAAq0"]
[Mon Jul 20 06:05:03.020061 2026] [security2:error] [pid 796928:tid 797070] [client 14.225.17.146:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4O7usTy9vX-htKvPkbAQAAAqU"], referer: http://savilerowtravel.com/wordpress
[Mon Jul 20 06:05:03.020725 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.63:24595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/bypass.php"] [unique_id "al4O77LfyzVz2SrjZpiyQgAAAis"]
[Mon Jul 20 06:05:03.417598 2026] [security2:error] [pid 796567:tid 796823] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O77LfyzVz2SrjZpiyRAACkgI"]
[Mon Jul 20 06:05:03.486993 2026] [security2:error] [pid 796928:tid 797167] [client 56.125.35.21:36516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O7-sTy9vX-htKvPkbGQAAAwY"]
[Mon Jul 20 06:05:03.546994 2026] [security2:error] [pid 796928:tid 797105] [client 14.225.17.146:65308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4O7-sTy9vX-htKvPkbIgAAAsg"], referer: https://north-woods-engineering.com/wordpress
[Mon Jul 20 06:05:03.795088 2026] [security2:error] [pid 796928:tid 797180] [client 27.96.94.195:37993] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O7-sTy9vX-htKvPkbMwAAAxM"]
[Mon Jul 20 06:05:03.795253 2026] [security2:error] [pid 796928:tid 797180] [client 27.96.94.195:37993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O7-sTy9vX-htKvPkbMwAAAxM"]
[Mon Jul 20 06:05:03.850841 2026] [security2:error] [pid 796928:tid 797101] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O7-sTy9vX-htKvPkbKwAAAsQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:03.989058 2026] [security2:error] [pid 796928:tid 797040] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al4O7-sTy9vX-htKvPkbNgACsm8"]
[Mon Jul 20 06:05:04.111557 2026] [security2:error] [pid 796928:tid 797163] [client 14.225.17.146:63200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4O7-sTy9vX-htKvPkbNAAAAwI"], referer: https://savilerowtravel.com/wordpress
[Mon Jul 20 06:05:04.163814 2026] [security2:error] [pid 796928:tid 797025] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al4O8OsTy9vX-htKvPkbPgAC8GA"]
[Mon Jul 20 06:05:04.291737 2026] [security2:error] [pid 796567:tid 796761] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-happy.php"] [unique_id "al4O8LLfyzVz2SrjZpiyfwAAAlQ"]
[Mon Jul 20 06:05:04.291871 2026] [security2:error] [pid 796567:tid 796761] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-happy.php"] [unique_id "al4O8LLfyzVz2SrjZpiyfwAAAlQ"]
[Mon Jul 20 06:05:04.400187 2026] [fcgid:warn] [pid 796567:tid 796728] (70014)End of file found: [client 167.94.146.53:11742] mod_fcgid: can't get data from http client
[Mon Jul 20 06:05:04.423157 2026] [security2:error] [pid 796928:tid 797061] [client 57.141.18.98:21196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O6esTy9vX-htKvPkZ_AACnBw"]
[Mon Jul 20 06:05:04.471689 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O8LLfyzVz2SrjZpiyiAAAAkU"]
[Mon Jul 20 06:05:04.471821 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O8LLfyzVz2SrjZpiyiAAAAkU"]
[Mon Jul 20 06:05:04.576942 2026] [security2:error] [pid 796567:tid 796705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8LLfyzVz2SrjZpiygwAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:04.641645 2026] [security2:error] [pid 796567:tid 796765] [client 57.141.18.39:20841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O6rLfyzVz2SrjZpixRwACWE8"]
[Mon Jul 20 06:05:04.647272 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fpr4.php"] [unique_id "al4O8LLfyzVz2SrjZpiykgAAAmk"]
[Mon Jul 20 06:05:04.647365 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fpr4.php"] [unique_id "al4O8LLfyzVz2SrjZpiykgAAAmk"]
[Mon Jul 20 06:05:04.971149 2026] [security2:error] [pid 796928:tid 797176] [client 185.132.186.99:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/aa.php"] [unique_id "al4O8OsTy9vX-htKvPkbaQAAAw8"]
[Mon Jul 20 06:05:05.100723 2026] [security2:error] [pid 796928:tid 797051] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkbbwADF3o"]
[Mon Jul 20 06:05:05.100875 2026] [security2:error] [pid 796928:tid 797184] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkbbwADF3o"]
[Mon Jul 20 06:05:05.268293 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O8bLfyzVz2SrjZpiyqgAAAjY"]
[Mon Jul 20 06:05:05.268390 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O8bLfyzVz2SrjZpiyqgAAAjY"]
[Mon Jul 20 06:05:05.278465 2026] [security2:error] [pid 796928:tid 797061] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/file88.php"] [unique_id "al4O8esTy9vX-htKvPkbeQAAApw"]
[Mon Jul 20 06:05:05.278552 2026] [security2:error] [pid 796928:tid 797061] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/file88.php"] [unique_id "al4O8esTy9vX-htKvPkbeQAAApw"]
[Mon Jul 20 06:05:05.279300 2026] [security2:error] [pid 796928:tid 797073] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8OsTy9vX-htKvPkbagAAAqg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:05.617446 2026] [access_compat:error] [pid 796928:tid 797163] [client 112.111.232.9:8327] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:05.654979 2026] [security2:error] [pid 796928:tid 797161] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ccc.php"] [unique_id "al4O8esTy9vX-htKvPkbggAAAwA"]
[Mon Jul 20 06:05:05.655126 2026] [security2:error] [pid 796928:tid 797161] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ccc.php"] [unique_id "al4O8esTy9vX-htKvPkbggAAAwA"]
[Mon Jul 20 06:05:05.822464 2026] [security2:error] [pid 796928:tid 797171] [client 14.182.195.220:51992] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O8esTy9vX-htKvPkbkwAAAwo"]
[Mon Jul 20 06:05:05.833709 2026] [security2:error] [pid 796928:tid 797173] [client 14.182.195.220:51993] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O8esTy9vX-htKvPkblgAAAww"]
[Mon Jul 20 06:05:05.990365 2026] [security2:error] [pid 796928:tid 797149] [client 181.224.94.124:43101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkboAAAAvQ"]
[Mon Jul 20 06:05:05.990637 2026] [security2:error] [pid 796928:tid 797149] [client 181.224.94.124:43101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkboAAAAvQ"]
[Mon Jul 20 06:05:06.015131 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/777.php"] [unique_id "al4O8usTy9vX-htKvPkbogAAAr4"]
[Mon Jul 20 06:05:06.015238 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/777.php"] [unique_id "al4O8usTy9vX-htKvPkbogAAAr4"]
[Mon Jul 20 06:05:06.084549 2026] [security2:error] [pid 796567:tid 796749] [client 14.182.195.220:51994] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O8rLfyzVz2SrjZpiyxQAAAkg"]
[Mon Jul 20 06:05:06.135508 2026] [security2:error] [pid 796928:tid 797058] [client 14.225.17.146:55577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4O8OsTy9vX-htKvPkbWgAAApk"]
[Mon Jul 20 06:05:06.156707 2026] [security2:error] [pid 796928:tid 797157] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8esTy9vX-htKvPkblAAAAvw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:06.211201 2026] [security2:error] [pid 796928:tid 797185] [client 158.173.241.141:56503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4O8esTy9vX-htKvPkbngAAAxg"], referer: http://sesamegreenbeans.com/planning-for-rugby-world-cup-france-2023/
[Mon Jul 20 06:05:06.377010 2026] [security2:error] [pid 796567:tid 796700] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/for.php"] [unique_id "al4O8rLfyzVz2SrjZpiy2wAAAhc"]
[Mon Jul 20 06:05:06.377144 2026] [security2:error] [pid 796567:tid 796700] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/for.php"] [unique_id "al4O8rLfyzVz2SrjZpiy2wAAAhc"]
[Mon Jul 20 06:05:06.467611 2026] [security2:error] [pid 796567:tid 796753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8rLfyzVz2SrjZpiy0wAAAkw"]
[Mon Jul 20 06:05:06.734356 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ssla.php"] [unique_id "al4O8usTy9vX-htKvPkbyQAAAt0"]
[Mon Jul 20 06:05:06.734466 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ssla.php"] [unique_id "al4O8usTy9vX-htKvPkbyQAAAt0"]
[Mon Jul 20 06:05:06.892325 2026] [security2:error] [pid 796928:tid 797090] [client 50.116.65.227:18208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4O8usTy9vX-htKvPkbzAAAArk"]
[Mon Jul 20 06:05:06.904351 2026] [security2:error] [pid 796928:tid 797116] [client 50.116.65.227:58160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4O8usTy9vX-htKvPkbzQAAAtM"]
[Mon Jul 20 06:05:06.934926 2026] [security2:error] [pid 796928:tid 797089] [client 185.132.186.94:40601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/index2.php"] [unique_id "al4O8usTy9vX-htKvPkbzgAAArg"]
[Mon Jul 20 06:05:07.098036 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zc-131.php"] [unique_id "al4O8-sTy9vX-htKvPkb1gAAAqQ"]
[Mon Jul 20 06:05:07.098168 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zc-131.php"] [unique_id "al4O8-sTy9vX-htKvPkb1gAAAqQ"]
[Mon Jul 20 06:05:07.220320 2026] [security2:error] [pid 796928:tid 797172] [client 103.149.16.77:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkb2wAAAws"]
[Mon Jul 20 06:05:07.220414 2026] [security2:error] [pid 796928:tid 797172] [client 103.149.16.77:49809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkb2wAAAws"]
[Mon Jul 20 06:05:07.322025 2026] [security2:error] [pid 796567:tid 796744] [client 210.212.97.243:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O87LfyzVz2SrjZpiy_QAAAkM"]
[Mon Jul 20 06:05:07.322179 2026] [security2:error] [pid 796567:tid 796744] [client 210.212.97.243:10441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O87LfyzVz2SrjZpiy_QAAAkM"]
[Mon Jul 20 06:05:07.328693 2026] [security2:error] [pid 796567:tid 796697] [client 57.141.18.13:40138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O7bLfyzVz2SrjZpix9wACFCs"]
[Mon Jul 20 06:05:07.644849 2026] [security2:error] [pid 796928:tid 797059] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8-sTy9vX-htKvPkb7gAAApo"]
[Mon Jul 20 06:05:07.767685 2026] [security2:error] [pid 796928:tid 797146] [client 72.255.10.154:26387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcBgAAAvE"]
[Mon Jul 20 06:05:07.767824 2026] [security2:error] [pid 796928:tid 797146] [client 72.255.10.154:26387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcBgAAAvE"]
[Mon Jul 20 06:05:07.823893 2026] [security2:error] [pid 796928:tid 797165] [client 103.95.123.246:19265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcCgAAAwQ"]
[Mon Jul 20 06:05:07.824558 2026] [security2:error] [pid 796928:tid 797165] [client 103.95.123.246:19265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcCgAAAwQ"]
[Mon Jul 20 06:05:07.869917 2026] [security2:error] [pid 796928:tid 797123] [client 57.141.18.60:35396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O7esTy9vX-htKvPkaywAC2iE"]
[Mon Jul 20 06:05:08.011957 2026] [security2:error] [pid 796567:tid 796816] [client 120.59.197.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4O87LfyzVz2SrjZpizEwAAAos"]
[Mon Jul 20 06:05:08.176432 2026] [security2:error] [pid 796567:tid 796750] [client 87.167.134.220:60462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4O87LfyzVz2SrjZpizAgAAAkk"]
[Mon Jul 20 06:05:08.765287 2026] [security2:error] [pid 796567:tid 796593] [remote 81.173.115.7:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O9LLfyzVz2SrjZpizOAACGRk"]
[Mon Jul 20 06:05:08.898580 2026] [security2:error] [pid 796567:tid 796762] [client 185.132.186.88:49963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/hello-element/footer.php"] [unique_id "al4O9LLfyzVz2SrjZpizPgAAAlU"]
[Mon Jul 20 06:05:08.988487 2026] [security2:error] [pid 796567:tid 796662] [remote 81.173.115.7:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O9LLfyzVz2SrjZpizQQACFF4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:09.892539 2026] [security2:error] [pid 796928:tid 797183] [client 13.201.64.214:25594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O9esTy9vX-htKvPkcUQAAAxY"]
[Mon Jul 20 06:05:09.892671 2026] [security2:error] [pid 796928:tid 797183] [client 13.201.64.214:25594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O9esTy9vX-htKvPkcUQAAAxY"]
[Mon Jul 20 06:05:09.983634 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:60407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O9bLfyzVz2SrjZpizcQAAAi8"]
[Mon Jul 20 06:05:09.983802 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:60407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O9bLfyzVz2SrjZpizcQAAAi8"]
[Mon Jul 20 06:05:10.012266 2026] [security2:error] [pid 796567:tid 796719] [client 57.141.18.8:62844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O8LLfyzVz2SrjZpiygAACKlw"]
[Mon Jul 20 06:05:10.117650 2026] [security2:error] [pid 796928:tid 797117] [client 47.31.86.100:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcVQAAAtQ"]
[Mon Jul 20 06:05:10.117799 2026] [security2:error] [pid 796928:tid 797117] [client 47.31.86.100:61615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcVQAAAtQ"]
[Mon Jul 20 06:05:10.714733 2026] [security2:error] [pid 796567:tid 796658] [remote 68.178.160.25:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O9rLfyzVz2SrjZpizkAACdVo"]
[Mon Jul 20 06:05:10.846374 2026] [security2:error] [pid 796567:tid 796782] [client 185.132.186.90:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/admin.php"] [unique_id "al4O9rLfyzVz2SrjZpizmgAAAmk"]
[Mon Jul 20 06:05:10.866880 2026] [security2:error] [pid 796567:tid 796680] [remote 23.79.233.44:43864] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "drawingthedog.com"] [uri "/"] [unique_id "al4O9rLfyzVz2SrjZpizmwACa3A"]
[Mon Jul 20 06:05:10.891667 2026] [security2:error] [pid 796928:tid 796971] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcbgAC-So"]
[Mon Jul 20 06:05:10.892033 2026] [security2:error] [pid 796928:tid 797154] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcbgAC-So"]
[Mon Jul 20 06:05:10.896549 2026] [security2:error] [pid 796928:tid 797169] [client 57.141.18.108:53812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O8esTy9vX-htKvPkbdAADCG4"]
[Mon Jul 20 06:05:11.071956 2026] [security2:error] [pid 796567:tid 796809] [client 193.19.109.223:27709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizowAAAoQ"]
[Mon Jul 20 06:05:11.080435 2026] [security2:error] [pid 796567:tid 796712] [client 193.19.109.241:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizogAAAiM"]
[Mon Jul 20 06:05:11.087188 2026] [security2:error] [pid 796928:tid 797150] [client 77.110.127.138:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/install.php"] [unique_id "al4O9-sTy9vX-htKvPkcewAAAvU"]
[Mon Jul 20 06:05:11.119246 2026] [security2:error] [pid 796567:tid 796642] [remote 68.178.160.25:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizpwACgko"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:11.142981 2026] [security2:error] [pid 796928:tid 797088] [client 77.110.127.138:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/upgrade.php"] [unique_id "al4O9-sTy9vX-htKvPkcfAAAArc"]
[Mon Jul 20 06:05:11.280914 2026] [security2:error] [pid 796567:tid 796766] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O97LfyzVz2SrjZpizpAAAAlk"]
[Mon Jul 20 06:05:11.336002 2026] [security2:error] [pid 796567:tid 796710] [client 3.109.4.218:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizrwAAAiE"]
[Mon Jul 20 06:05:11.442727 2026] [security2:error] [pid 796928:tid 797179] [client 150.228.148.150:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchQAAAxI"]
[Mon Jul 20 06:05:11.442857 2026] [security2:error] [pid 796928:tid 797179] [client 150.228.148.150:5334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchQAAAxI"]
[Mon Jul 20 06:05:11.453202 2026] [security2:error] [pid 796928:tid 797138] [client 112.213.160.112:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchwAAAuk"]
[Mon Jul 20 06:05:11.453323 2026] [security2:error] [pid 796928:tid 797138] [client 112.213.160.112:30824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchwAAAuk"]
[Mon Jul 20 06:05:11.559938 2026] [security2:error] [pid 796567:tid 796786] [client 50.116.65.227:48608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4O97LfyzVz2SrjZpizuAAAAm0"]
[Mon Jul 20 06:05:11.570153 2026] [security2:error] [pid 796567:tid 796776] [client 50.116.65.227:48620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4O97LfyzVz2SrjZpizuQAAAmM"]
[Mon Jul 20 06:05:11.731279 2026] [security2:error] [pid 796928:tid 797182] [client 43.173.182.226:35622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4O9-sTy9vX-htKvPkckgAAAxU"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:11.765501 2026] [security2:error] [pid 796567:tid 796692] [remote 192.241.143.148:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizxgACjXw"]
[Mon Jul 20 06:05:11.872109 2026] [security2:error] [pid 796567:tid 796622] [remote 95.217.78.234:35870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpiz0QACTTY"]
[Mon Jul 20 06:05:11.948645 2026] [security2:error] [pid 796567:tid 796630] [remote 192.241.143.148:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpiz0wACID4"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 06:05:12.025079 2026] [security2:error] [pid 796567:tid 796816] [client 43.172.197.28:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4O-LLfyzVz2SrjZpiz2QAAAos"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:12.118900 2026] [security2:error] [pid 796567:tid 796626] [remote 95.217.78.234:35870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O-LLfyzVz2SrjZpiz3AACIzo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:12.138180 2026] [security2:error] [pid 796567:tid 796697] [client 43.172.195.7:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4O-LLfyzVz2SrjZpiz3QAAAhQ"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:12.215932 2026] [security2:error] [pid 796567:tid 796637] [remote 167.233.114.32:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4O-LLfyzVz2SrjZpiz4wACP0U"]
[Mon Jul 20 06:05:12.242822 2026] [security2:error] [pid 796928:tid 797081] [client 43.173.176.41:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4O-OsTy9vX-htKvPkcpAAAArA"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:12.425243 2026] [security2:error] [pid 796567:tid 796603] [remote 167.233.114.32:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4O-LLfyzVz2SrjZpiz8AACOSM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:05:12.547343 2026] [security2:error] [pid 796567:tid 796704] [client 14.225.17.146:59755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4O9rLfyzVz2SrjZpizkgAAAhs"], referer: http://areitoproducciones.com/wordpress
[Mon Jul 20 06:05:12.598625 2026] [security2:error] [pid 796928:tid 797111] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O-OsTy9vX-htKvPkcqAAAAs4"]
[Mon Jul 20 06:05:12.784185 2026] [security2:error] [pid 796928:tid 797109] [client 185.132.186.55:39807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/2index.php"] [unique_id "al4O-OsTy9vX-htKvPkcygAAAsw"]
[Mon Jul 20 06:05:13.011587 2026] [security2:error] [pid 796928:tid 797136] [client 57.141.18.114:20114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O8-sTy9vX-htKvPkb4wAC51M"]
[Mon Jul 20 06:05:13.245888 2026] [security2:error] [pid 796567:tid 796820] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4O-bLfyzVz2SrjZpi0CgAAAo8"], referer: https://duckduckgo.com/?q=pirql
[Mon Jul 20 06:05:13.356164 2026] [security2:error] [pid 796567:tid 796601] [remote 97.74.93.24:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O-bLfyzVz2SrjZpi0FAACYiE"]
[Mon Jul 20 06:05:13.449309 2026] [security2:error] [pid 796567:tid 796782] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/passwd"] [unique_id "al4O-bLfyzVz2SrjZpi0HgAAAmk"], referer: https://www.google.com/search?q=gbsmx5
[Mon Jul 20 06:05:13.626869 2026] [security2:error] [pid 796928:tid 797125] [client 193.19.109.241:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4O-esTy9vX-htKvPkc5gAAAtw"]
[Mon Jul 20 06:05:13.628735 2026] [security2:error] [pid 796567:tid 796823] [client 193.37.33.1:50185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4O-bLfyzVz2SrjZpi0IQAAApI"]
[Mon Jul 20 06:05:13.658496 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:8283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O-bLfyzVz2SrjZpi0JQAAAkk"]
[Mon Jul 20 06:05:13.658634 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:8283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O-bLfyzVz2SrjZpi0JQAAAkk"]
[Mon Jul 20 06:05:13.667598 2026] [security2:error] [pid 796928:tid 797131] [client 193.19.109.216:58657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4O-esTy9vX-htKvPkc5QAAAuI"]
[Mon Jul 20 06:05:13.669276 2026] [security2:error] [pid 796567:tid 796807] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/shadow"] [unique_id "al4O-bLfyzVz2SrjZpi0JgAAAoI"], referer: https://www.bing.com/search?q=qpc72d
[Mon Jul 20 06:05:13.763732 2026] [security2:error] [pid 796567:tid 796582] [remote 97.74.93.24:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O-bLfyzVz2SrjZpi0KAACfQ4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:13.898888 2026] [security2:error] [pid 796567:tid 796742] [client 51.15.143.46:40722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4O-bLfyzVz2SrjZpi0MAAAAkE"]
[Mon Jul 20 06:05:13.911436 2026] [security2:error] [pid 796928:tid 797151] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O-esTy9vX-htKvPkc6AAC9g4"]
[Mon Jul 20 06:05:14.031334 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.35:32588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9LLfyzVz2SrjZpizJQACNUc"]
[Mon Jul 20 06:05:14.274507 2026] [security2:error] [pid 796567:tid 796704] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O-rLfyzVz2SrjZpi0OgAAAhs"]
[Mon Jul 20 06:05:14.436905 2026] [security2:error] [pid 796567:tid 796717] [client 104.234.53.68:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4O-rLfyzVz2SrjZpi0SgAAAig"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:14.500071 2026] [security2:error] [pid 796928:tid 797071] [client 43.205.139.3:29468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O-OsTy9vX-htKvPkcwQAAAqY"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:05:14.505320 2026] [security2:error] [pid 796567:tid 796736] [client 13.201.64.214:25610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O-rLfyzVz2SrjZpi0TQAAAjs"]
[Mon Jul 20 06:05:14.631860 2026] [security2:error] [pid 796928:tid 797152] [client 193.19.109.249:55889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abilite.uk"] [uri "/wp-login.php"] [unique_id "al4O-usTy9vX-htKvPkdCwAAAvc"]
[Mon Jul 20 06:05:14.711199 2026] [security2:error] [pid 796567:tid 796796] [client 14.225.17.146:57158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4O-LLfyzVz2SrjZpiz7wAAAnc"], referer: http://qualitycoatingsinspection.com/wordpress
[Mon Jul 20 06:05:14.728324 2026] [security2:error] [pid 796928:tid 797125] [client 185.132.186.59:37623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/plugins.php"] [unique_id "al4O-usTy9vX-htKvPkdEgAAAtw"]
[Mon Jul 20 06:05:14.874245 2026] [security2:error] [pid 796928:tid 797110] [client 178.152.178.232:36903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O-usTy9vX-htKvPkdHAAAAs0"]
[Mon Jul 20 06:05:14.881162 2026] [security2:error] [pid 796928:tid 797110] [client 178.152.178.232:36903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O-usTy9vX-htKvPkdHAAAAs0"]
[Mon Jul 20 06:05:15.051736 2026] [security2:error] [pid 796928:tid 797063] [client 210.212.97.243:10442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdIQAAAp4"]
[Mon Jul 20 06:05:15.051895 2026] [security2:error] [pid 796928:tid 797063] [client 210.212.97.243:10442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdIQAAAp4"]
[Mon Jul 20 06:05:15.087030 2026] [security2:error] [pid 796928:tid 797131] [client 41.173.37.102:14005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdJAAAAuI"]
[Mon Jul 20 06:05:15.087125 2026] [security2:error] [pid 796928:tid 797131] [client 41.173.37.102:14005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdJAAAAuI"]
[Mon Jul 20 06:05:15.110901 2026] [security2:error] [pid 796928:tid 797173] [client 43.172.197.201:50088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4O--sTy9vX-htKvPkdJQAAAww"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:05:15.166282 2026] [autoindex:error] [pid 796567:tid 796738] [client 147.93.171.188:54546] AH01276: Cannot serve directory /home1/effingwe/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:05:15.256666 2026] [security2:error] [pid 796928:tid 797179] [client 43.173.182.128:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4O--sTy9vX-htKvPkdMQAAAxI"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:05:15.271355 2026] [security2:error] [pid 796928:tid 797143] [client 43.172.195.34:35080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4O--sTy9vX-htKvPkdNQAAAu4"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:05:15.287995 2026] [security2:error] [pid 796928:tid 797083] [client 57.141.18.121:62172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9esTy9vX-htKvPkcSQACsgI"]
[Mon Jul 20 06:05:15.367601 2026] [security2:error] [pid 796567:tid 796785] [client 57.141.18.83:59278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9bLfyzVz2SrjZpizZwACbGs"]
[Mon Jul 20 06:05:15.566651 2026] [security2:error] [pid 796928:tid 797059] [client 3.109.4.218:53938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O--sTy9vX-htKvPkdPgAAApo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:05:15.644682 2026] [security2:error] [pid 796928:tid 797067] [client 13.38.91.115:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.91.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdSAAAAqI"]
[Mon Jul 20 06:05:15.644794 2026] [security2:error] [pid 796928:tid 797067] [client 13.38.91.115:21424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdSAAAAqI"]
[Mon Jul 20 06:05:15.788757 2026] [security2:error] [pid 796928:tid 796937] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdTAAC0gg"]
[Mon Jul 20 06:05:15.788872 2026] [security2:error] [pid 796928:tid 797115] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdTAAC0gg"]
[Mon Jul 20 06:05:15.793643 2026] [security2:error] [pid 796567:tid 796702] [client 14.225.17.146:51573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4O-7LfyzVz2SrjZpi0eQAAAhk"], referer: https://qualitycoatingsinspection.com/wordpress
[Mon Jul 20 06:05:16.378678 2026] [security2:error] [pid 796928:tid 797058] [client 98.159.234.160:58493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O_OsTy9vX-htKvPkdXwAAApk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:16.511952 2026] [security2:error] [pid 796928:tid 797133] [client 181.224.94.124:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O_OsTy9vX-htKvPkdYwAAAuQ"]
[Mon Jul 20 06:05:16.512091 2026] [security2:error] [pid 796928:tid 797133] [client 181.224.94.124:35628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O_OsTy9vX-htKvPkdYwAAAuQ"]
[Mon Jul 20 06:05:16.848091 2026] [security2:error] [pid 796567:tid 796737] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/hosts"] [unique_id "al4O_LLfyzVz2SrjZpi0rAAAAjw"], referer: https://www.facebook.com/
[Mon Jul 20 06:05:17.113616 2026] [security2:error] [pid 796928:tid 797126] [client 57.141.18.124:38764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9-sTy9vX-htKvPkcjgAC3Sg"]
[Mon Jul 20 06:05:17.214073 2026] [security2:error] [pid 796928:tid 797077] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.origine.nz"] [uri "/index.php"] [unique_id "al4O_OsTy9vX-htKvPkdcgACrG0"]
[Mon Jul 20 06:05:17.663770 2026] [security2:error] [pid 796928:tid 797014] [remote 45.90.123.233:40372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4O_esTy9vX-htKvPkdiQACr1U"]
[Mon Jul 20 06:05:17.899483 2026] [security2:error] [pid 796928:tid 797155] [client 103.149.16.77:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O_esTy9vX-htKvPkdmgAAAvo"]
[Mon Jul 20 06:05:17.899610 2026] [security2:error] [pid 796928:tid 797155] [client 103.149.16.77:50356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O_esTy9vX-htKvPkdmgAAAvo"]
[Mon Jul 20 06:05:17.901484 2026] [security2:error] [pid 796928:tid 796982] [remote 45.90.123.233:40372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4O_esTy9vX-htKvPkdnAACwTU"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 06:05:18.096736 2026] [security2:error] [pid 796567:tid 796733] [client 103.153.183.69:35030] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//proc/self/environ"] [unique_id "al4O_rLfyzVz2SrjZpi06QAAAjg"], referer: https://www.google.com/
[Mon Jul 20 06:05:18.241730 2026] [security2:error] [pid 796928:tid 797082] [client 185.132.186.77:51385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/shell.php"] [unique_id "al4O_usTy9vX-htKvPkdrQAAArE"]
[Mon Jul 20 06:05:18.328873 2026] [security2:error] [pid 796928:tid 797064] [client 72.255.10.154:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O_usTy9vX-htKvPkdrwAAAp8"]
[Mon Jul 20 06:05:18.328997 2026] [security2:error] [pid 796928:tid 797064] [client 72.255.10.154:26390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O_usTy9vX-htKvPkdrwAAAp8"]
[Mon Jul 20 06:05:18.769179 2026] [security2:error] [pid 796567:tid 796809] [client 57.141.18.6:38244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O-bLfyzVz2SrjZpi0GwAChFQ"]
[Mon Jul 20 06:05:18.955626 2026] [security2:error] [pid 796928:tid 797071] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O_usTy9vX-htKvPkdtQAAAqY"]
[Mon Jul 20 06:05:19.318532 2026] [security2:error] [pid 796567:tid 796817] [client 103.95.123.246:19768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O_7LfyzVz2SrjZpi1JAAAAow"]
[Mon Jul 20 06:05:19.318624 2026] [security2:error] [pid 796567:tid 796817] [client 103.95.123.246:19768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O_7LfyzVz2SrjZpi1JAAAAow"]
[Mon Jul 20 06:05:19.422557 2026] [proxy:error] [pid 796567:tid 796745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.422653 2026] [proxy_http:error] [pid 796567:tid 796745] [client 82.102.18.116:39628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.423780 2026] [proxy:error] [pid 796567:tid 796745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.423856 2026] [proxy_http:error] [pid 796567:tid 796745] [client 82.102.18.116:39628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.497524 2026] [security2:error] [pid 796928:tid 797054] [remote 157.66.26.183:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O_-sTy9vX-htKvPkd1gAC2n0"]
[Mon Jul 20 06:05:19.670276 2026] [security2:error] [pid 796567:tid 796636] [remote 57.141.18.42:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2909670"] [unique_id "al4O_7LfyzVz2SrjZpi1MAACP0Q"]
[Mon Jul 20 06:05:19.750395 2026] [proxy:error] [pid 796928:tid 797093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.750463 2026] [proxy_http:error] [pid 796928:tid 797093] [client 82.102.18.116:39654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.751246 2026] [proxy:error] [pid 796928:tid 797093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.751280 2026] [proxy_http:error] [pid 796928:tid 797093] [client 82.102.18.116:39654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.957832 2026] [security2:error] [pid 796928:tid 797003] [remote 157.66.26.183:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O_-sTy9vX-htKvPkd_gAC3Uo"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:05:20.040735 2026] [security2:error] [pid 796928:tid 797115] [client 20.1.181.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rentorangegrove.com"] [uri "/index.php"] [unique_id "al4O_-sTy9vX-htKvPkd_QAAAtI"]
[Mon Jul 20 06:05:20.054249 2026] [security2:error] [pid 796567:tid 796810] [client 57.141.18.92:64550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O-rLfyzVz2SrjZpi0WgAChVg"]
[Mon Jul 20 06:05:20.099823 2026] [security2:error] [pid 796567:tid 796812] [client 82.102.18.116:39668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4PALLfyzVz2SrjZpi1QgAAAoc"]
[Mon Jul 20 06:05:20.138560 2026] [security2:error] [pid 796567:tid 796744] [client 104.234.53.84:38633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PALLfyzVz2SrjZpi1QQAAAkM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:20.191391 2026] [security2:error] [pid 796928:tid 797141] [client 185.132.186.99:35587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/content.php"] [unique_id "al4PAOsTy9vX-htKvPkeBwAAAuw"]
[Mon Jul 20 06:05:20.194991 2026] [security2:error] [pid 796567:tid 796727] [client 86.98.90.58:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1RgAAAjI"]
[Mon Jul 20 06:05:20.195132 2026] [security2:error] [pid 796567:tid 796727] [client 86.98.90.58:56261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1RgAAAjI"]
[Mon Jul 20 06:05:20.430409 2026] [security2:error] [pid 796928:tid 797096] [client 82.102.18.116:39670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeFAAAAr8"]
[Mon Jul 20 06:05:20.620779 2026] [security2:error] [pid 796567:tid 796796] [client 74.208.214.194:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PALLfyzVz2SrjZpi1VAAAAnc"]
[Mon Jul 20 06:05:20.798444 2026] [security2:error] [pid 796928:tid 797136] [client 103.141.108.143:58027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeHgAAAuc"]
[Mon Jul 20 06:05:20.800529 2026] [proxy:error] [pid 796567:tid 796777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:20.800591 2026] [proxy_http:error] [pid 796567:tid 796777] [client 82.102.18.116:39686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:20.801230 2026] [proxy:error] [pid 796567:tid 796777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:20.801257 2026] [proxy_http:error] [pid 796567:tid 796777] [client 82.102.18.116:39686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:20.821332 2026] [security2:error] [pid 796928:tid 797069] [client 193.19.109.249:33975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PAOsTy9vX-htKvPkeIwAAAqQ"]
[Mon Jul 20 06:05:20.850314 2026] [security2:error] [pid 796928:tid 797173] [client 65.1.132.125:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeJwAAAww"]
[Mon Jul 20 06:05:20.850407 2026] [security2:error] [pid 796928:tid 797173] [client 65.1.132.125:28686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeJwAAAww"]
[Mon Jul 20 06:05:20.902894 2026] [security2:error] [pid 796567:tid 796784] [client 106.192.104.4:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1YwAAAms"]
[Mon Jul 20 06:05:20.903018 2026] [security2:error] [pid 796567:tid 796784] [client 106.192.104.4:60900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1YwAAAms"]
[Mon Jul 20 06:05:20.907103 2026] [security2:error] [pid 796928:tid 797071] [client 193.19.109.247:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PAOsTy9vX-htKvPkeKQAAAqY"]
[Mon Jul 20 06:05:21.059384 2026] [security2:error] [pid 796567:tid 796759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PALLfyzVz2SrjZpi1XQAAAlI"]
[Mon Jul 20 06:05:21.124711 2026] [security2:error] [pid 796567:tid 796779] [client 57.141.18.19:28498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O-7LfyzVz2SrjZpi0fgACZlo"]
[Mon Jul 20 06:05:21.140952 2026] [security2:error] [pid 796928:tid 797089] [client 82.102.18.116:39698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4PAesTy9vX-htKvPkeOgAAArg"]
[Mon Jul 20 06:05:21.260465 2026] [security2:error] [pid 796928:tid 797076] [client 193.19.109.218:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeQgAAAqs"]
[Mon Jul 20 06:05:21.282258 2026] [security2:error] [pid 796928:tid 797141] [client 193.19.109.214:53899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeQQAAAuw"]
[Mon Jul 20 06:05:21.290665 2026] [security2:error] [pid 796928:tid 797140] [client 104.234.53.61:23613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PAesTy9vX-htKvPkePQAAAus"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:21.310813 2026] [security2:error] [pid 796928:tid 797111] [client 193.19.109.228:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeQwAAAs4"]
[Mon Jul 20 06:05:21.453699 2026] [security2:error] [pid 796567:tid 796712] [client 82.102.18.116:39710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4PAbLfyzVz2SrjZpi1fQAAAiM"]
[Mon Jul 20 06:05:21.484693 2026] [security2:error] [pid 796928:tid 797136] [client 103.141.108.143:58027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeHgAAAuc"]
[Mon Jul 20 06:05:21.560774 2026] [security2:error] [pid 796928:tid 797169] [client 104.234.53.61:23613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeTwAAAwg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:21.621192 2026] [security2:error] [pid 796928:tid 797158] [client 150.228.148.150:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeVQAAAv0"]
[Mon Jul 20 06:05:21.639674 2026] [security2:error] [pid 796928:tid 797158] [client 150.228.148.150:57087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeVQAAAv0"]
[Mon Jul 20 06:05:21.775208 2026] [security2:error] [pid 796928:tid 797095] [client 82.102.18.116:39714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4PAesTy9vX-htKvPkeWAAAAr4"]
[Mon Jul 20 06:05:21.923569 2026] [security2:error] [pid 796928:tid 796999] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeYwACnEY"]
[Mon Jul 20 06:05:21.923803 2026] [security2:error] [pid 796928:tid 797061] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeYwACnEY"]
[Mon Jul 20 06:05:22.119997 2026] [security2:error] [pid 796928:tid 797128] [client 185.132.186.64:37815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/about.php"] [unique_id "al4PAusTy9vX-htKvPkebgAAAt8"]
[Mon Jul 20 06:05:22.134433 2026] [security2:error] [pid 796928:tid 797123] [client 82.102.18.116:39724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4PAusTy9vX-htKvPkebwAAAto"]
[Mon Jul 20 06:05:22.174798 2026] [security2:error] [pid 796928:tid 797113] [client 112.213.160.112:8383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PAusTy9vX-htKvPkedgAAAtA"]
[Mon Jul 20 06:05:22.174904 2026] [security2:error] [pid 796928:tid 797113] [client 112.213.160.112:8383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PAusTy9vX-htKvPkedgAAAtA"]
[Mon Jul 20 06:05:22.452189 2026] [security2:error] [pid 796567:tid 796796] [client 82.102.18.116:39740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4PArLfyzVz2SrjZpi1owAAAnc"]
[Mon Jul 20 06:05:22.779027 2026] [security2:error] [pid 796567:tid 796739] [client 82.102.18.116:39754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4PArLfyzVz2SrjZpi1rAAAAj4"]
[Mon Jul 20 06:05:22.831512 2026] [security2:error] [pid 796928:tid 797170] [client 57.141.18.64:62090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O_esTy9vX-htKvPkdiwADCUQ"]
[Mon Jul 20 06:05:22.850700 2026] [security2:error] [pid 796928:tid 797090] [client 104.234.53.69:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PAusTy9vX-htKvPkelAAAArk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:23.090436 2026] [security2:error] [pid 796567:tid 796763] [client 82.102.18.116:39768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4PA7LfyzVz2SrjZpi1uAAAAlY"]
[Mon Jul 20 06:05:23.410069 2026] [security2:error] [pid 796928:tid 797139] [client 82.102.18.116:39784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4PA-sTy9vX-htKvPkerAAAAuo"]
[Mon Jul 20 06:05:23.466614 2026] [security2:error] [pid 796567:tid 796747] [client 57.141.18.86:56178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O_rLfyzVz2SrjZpi09AACRhI"]
[Mon Jul 20 06:05:23.473542 2026] [security2:error] [pid 796567:tid 796788] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PA7LfyzVz2SrjZpi1vwAAAm8"]
[Mon Jul 20 06:05:23.489731 2026] [security2:error] [pid 796928:tid 797050] [remote 57.141.18.102:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4PA-sTy9vX-htKvPkesgACzXk"]
[Mon Jul 20 06:05:23.515937 2026] [security2:error] [pid 796567:tid 796823] [client 57.141.18.24:32868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O_rLfyzVz2SrjZpi0-AACkhs"]
[Mon Jul 20 06:05:23.729233 2026] [security2:error] [pid 796928:tid 797175] [client 82.102.18.116:20207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4PA-sTy9vX-htKvPkevAAAAw4"]
[Mon Jul 20 06:05:24.049532 2026] [security2:error] [pid 796928:tid 797138] [client 104.234.53.80:61041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PA-sTy9vX-htKvPkexwAAAuk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:24.064020 2026] [security2:error] [pid 796928:tid 797167] [client 82.102.18.116:39802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4PBOsTy9vX-htKvPke0AAAAwY"]
[Mon Jul 20 06:05:24.067201 2026] [security2:error] [pid 796567:tid 796809] [client 185.132.186.67:65107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/atomlib.php"] [unique_id "al4PBLLfyzVz2SrjZpi14AAAAoQ"]
[Mon Jul 20 06:05:24.134458 2026] [security2:error] [pid 796928:tid 797074] [client 193.37.33.1:29757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4PBOsTy9vX-htKvPke0gAAAqk"]
[Mon Jul 20 06:05:24.205464 2026] [security2:error] [pid 796928:tid 797158] [client 115.246.21.170:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PBOsTy9vX-htKvPke0wAAAv0"]
[Mon Jul 20 06:05:24.205611 2026] [security2:error] [pid 796928:tid 797158] [client 115.246.21.170:9660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PBOsTy9vX-htKvPke0wAAAv0"]
[Mon Jul 20 06:05:24.328084 2026] [security2:error] [pid 796928:tid 797092] [client 104.234.53.80:61041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PBOsTy9vX-htKvPke2wAAArs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:24.377514 2026] [security2:error] [pid 796567:tid 796596] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PBLLfyzVz2SrjZpi16wACahw"]
[Mon Jul 20 06:05:24.377648 2026] [security2:error] [pid 796567:tid 796783] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PBLLfyzVz2SrjZpi16wACahw"]
[Mon Jul 20 06:05:24.410411 2026] [security2:error] [pid 796928:tid 797071] [client 82.102.18.116:39804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4PBOsTy9vX-htKvPke4QAAAqY"]
[Mon Jul 20 06:05:24.530791 2026] [security2:error] [pid 796928:tid 797059] [client 94.154.43.188:34130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al4PBOsTy9vX-htKvPke6AAAApo"]
[Mon Jul 20 06:05:24.539167 2026] [security2:error] [pid 796928:tid 797134] [client 94.154.43.178:53872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al4PBOsTy9vX-htKvPke6QAAAuU"]
[Mon Jul 20 06:05:24.626111 2026] [security2:error] [pid 796567:tid 796771] [client 74.249.226.166:2690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PBLLfyzVz2SrjZpi19gAAAl4"]
[Mon Jul 20 06:05:24.679073 2026] [security2:error] [pid 796567:tid 796805] [client 74.249.226.166:2690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PBLLfyzVz2SrjZpi1-AAAAoA"]
[Mon Jul 20 06:05:24.690778 2026] [security2:error] [pid 796567:tid 796793] [client 193.19.109.235:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PBLLfyzVz2SrjZpi19wAAAnQ"]
[Mon Jul 20 06:05:24.753013 2026] [security2:error] [pid 796567:tid 796739] [client 82.102.18.116:39810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4PBLLfyzVz2SrjZpi1-gAAAj4"]
[Mon Jul 20 06:05:24.865247 2026] [security2:error] [pid 796567:tid 796707] [client 94.154.43.179:21820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4PBLLfyzVz2SrjZpi2AAAAAh4"]
[Mon Jul 20 06:05:24.872004 2026] [security2:error] [pid 796928:tid 797166] [client 52.237.147.83:11397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PBOsTy9vX-htKvPke9gAAAwU"]
[Mon Jul 20 06:05:24.923072 2026] [security2:error] [pid 796928:tid 797113] [client 52.237.147.83:11397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PBOsTy9vX-htKvPke-gAAAtA"]
[Mon Jul 20 06:05:25.097922 2026] [security2:error] [pid 796567:tid 796788] [client 82.102.18.116:39814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4PBbLfyzVz2SrjZpi2DgAAAm8"]
[Mon Jul 20 06:05:25.134309 2026] [security2:error] [pid 796928:tid 797121] [client 104.234.53.85:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PBesTy9vX-htKvPkfCgAAAtg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:25.292210 2026] [security2:error] [pid 796928:tid 797139] [client 104.196.104.214:32672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "roguedragonstudio.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PBesTy9vX-htKvPkfDAAAAuo"]
[Mon Jul 20 06:05:25.418889 2026] [security2:error] [pid 796928:tid 797134] [client 104.196.104.214:32672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "roguedragonstudio.com"] [uri "/"] [unique_id "al4PBesTy9vX-htKvPkfDQAAAuU"]
[Mon Jul 20 06:05:25.422813 2026] [security2:error] [pid 796928:tid 797069] [client 82.102.18.116:39822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4PBesTy9vX-htKvPkfDgAAAqQ"]
[Mon Jul 20 06:05:25.612032 2026] [security2:error] [pid 796567:tid 796760] [client 178.152.178.232:36286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2IgAAAlM"]
[Mon Jul 20 06:05:25.612125 2026] [security2:error] [pid 796567:tid 796760] [client 178.152.178.232:36286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2IgAAAlM"]
[Mon Jul 20 06:05:25.626745 2026] [security2:error] [pid 796928:tid 797092] [client 210.212.97.243:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PBesTy9vX-htKvPkfGwAAArs"]
[Mon Jul 20 06:05:25.626850 2026] [security2:error] [pid 796928:tid 797092] [client 210.212.97.243:10443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PBesTy9vX-htKvPkfGwAAArs"]
[Mon Jul 20 06:05:25.679084 2026] [security2:error] [pid 796567:tid 796813] [client 41.173.37.102:14431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2JgAAAog"]
[Mon Jul 20 06:05:25.679224 2026] [security2:error] [pid 796567:tid 796813] [client 41.173.37.102:14431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2JgAAAog"]
[Mon Jul 20 06:05:25.752603 2026] [security2:error] [pid 796928:tid 797123] [client 82.102.18.116:39846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4PBesTy9vX-htKvPkfIQAAAto"]
[Mon Jul 20 06:05:25.843929 2026] [security2:error] [pid 796567:tid 796758] [client 57.141.18.125:63030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PALLfyzVz2SrjZpi1TQACUVw"]
[Mon Jul 20 06:05:25.862459 2026] [security2:error] [pid 796928:tid 797163] [client 186.17.234.147:35080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4PBesTy9vX-htKvPkfIAAAAwI"]
[Mon Jul 20 06:05:26.021730 2026] [security2:error] [pid 796928:tid 797072] [client 185.132.186.96:35043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/install.php"] [unique_id "al4PBusTy9vX-htKvPkfMQAAAqc"]
[Mon Jul 20 06:05:26.081728 2026] [security2:error] [pid 796567:tid 796726] [client 104.234.53.59:21587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PBrLfyzVz2SrjZpi2NAAAAjE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:26.485643 2026] [security2:error] [pid 796928:tid 797046] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PBusTy9vX-htKvPkfQwAC-nU"]
[Mon Jul 20 06:05:26.485819 2026] [security2:error] [pid 796928:tid 797155] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PBusTy9vX-htKvPkfQwAC-nU"]
[Mon Jul 20 06:05:26.623347 2026] [security2:error] [pid 796928:tid 797140] [client 103.153.183.69:44060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4PBusTy9vX-htKvPkfRwAAAus"], referer: https://www.facebook.com/
[Mon Jul 20 06:05:26.658304 2026] [security2:error] [pid 796567:tid 796772] [client 193.19.109.247:21541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "coltinnovate.com"] [uri "/wp-login.php"] [unique_id "al4PBrLfyzVz2SrjZpi2RwAAAl8"]
[Mon Jul 20 06:05:26.741039 2026] [security2:error] [pid 796567:tid 796789] [client 57.141.18.109:38408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PAbLfyzVz2SrjZpi1cwACcDM"]
[Mon Jul 20 06:05:26.768680 2026] [security2:error] [pid 796567:tid 796688] [remote 5.161.225.162:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4PBrLfyzVz2SrjZpi2SQACHng"]
[Mon Jul 20 06:05:27.025948 2026] [security2:error] [pid 796567:tid 796743] [client 181.224.94.124:10639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PB7LfyzVz2SrjZpi2VwAAAkI"]
[Mon Jul 20 06:05:27.026055 2026] [security2:error] [pid 796567:tid 796743] [client 181.224.94.124:10639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PB7LfyzVz2SrjZpi2VwAAAkI"]
[Mon Jul 20 06:05:27.037207 2026] [security2:error] [pid 796567:tid 796610] [remote 5.161.225.162:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4PB7LfyzVz2SrjZpi2WAACIyo"], referer: https://roguedragonstudio.com/wp-login.php
[Mon Jul 20 06:05:27.594551 2026] [security2:error] [pid 796928:tid 797179] [client 57.141.18.68:62040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PAusTy9vX-htKvPkecgADEnc"]
[Mon Jul 20 06:05:27.973921 2026] [security2:error] [pid 796928:tid 797095] [client 185.132.186.69:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/hehe.php"] [unique_id "al4PB-sTy9vX-htKvPkfbAAAAr4"]
[Mon Jul 20 06:05:28.139482 2026] [security2:error] [pid 796567:tid 796751] [client 57.141.18.35:21948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PArLfyzVz2SrjZpi1qwACSi4"]
[Mon Jul 20 06:05:28.422238 2026] [security2:error] [pid 796928:tid 796984] [remote 72.167.132.114:34884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PCOsTy9vX-htKvPkffQACojc"]
[Mon Jul 20 06:05:28.664349 2026] [security2:error] [pid 796928:tid 796932] [remote 72.167.132.114:34884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PCOsTy9vX-htKvPkfkwADDAM"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:05:28.837342 2026] [security2:error] [pid 796567:tid 796701] [client 104.234.53.59:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PCLLfyzVz2SrjZpi2oQAAAhg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:28.925656 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PCLLfyzVz2SrjZpi2lgAAAiU"]
[Mon Jul 20 06:05:29.022699 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:63525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4PCOsTy9vX-htKvPkflgAAAro"], referer: http://aljosour-alarabia.com/Wordpress
[Mon Jul 20 06:05:29.531867 2026] [security2:error] [pid 796567:tid 796583] [remote 216.73.216.55:39156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4PCbLfyzVz2SrjZpi2wwACUA8"]
[Mon Jul 20 06:05:29.703806 2026] [security2:error] [pid 796567:tid 796809] [client 72.255.10.154:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4PCbLfyzVz2SrjZpi2ygAAAoQ"]
[Mon Jul 20 06:05:29.703935 2026] [security2:error] [pid 796567:tid 796809] [client 72.255.10.154:52078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4PCbLfyzVz2SrjZpi2ygAAAoQ"]
[Mon Jul 20 06:05:29.882377 2026] [security2:error] [pid 796567:tid 796784] [client 57.141.18.84:34898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PBLLfyzVz2SrjZpi1_QACa0c"]
[Mon Jul 20 06:05:29.924130 2026] [security2:error] [pid 796567:tid 796773] [client 185.132.186.94:36597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/fonts/autoload_classmap.php"] [unique_id "al4PCbLfyzVz2SrjZpi21wAAAmA"]
[Mon Jul 20 06:05:30.088059 2026] [security2:error] [pid 796567:tid 796723] [client 136.67.36.183:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.36.67.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "css.gdz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PCrLfyzVz2SrjZpi24QAAAi4"]
[Mon Jul 20 06:05:30.259537 2026] [security2:error] [pid 796928:tid 797165] [client 74.7.227.179:34524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PCusTy9vX-htKvPkfwwADBCw"], referer: https://tejasenvironmental.com/p=589840
[Mon Jul 20 06:05:30.287542 2026] [security2:error] [pid 796928:tid 797069] [client 136.67.36.183:57664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4PCusTy9vX-htKvPkf0wAAAqQ"]
[Mon Jul 20 06:05:30.298541 2026] [security2:error] [pid 796928:tid 797101] [client 14.225.17.146:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4PCOsTy9vX-htKvPkfggAAAsQ"], referer: http://aandarealtygroup.com/Wordpress
[Mon Jul 20 06:05:30.512733 2026] [security2:error] [pid 796928:tid 797058] [client 50.116.65.227:52342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PCusTy9vX-htKvPkf1wAAApk"]
[Mon Jul 20 06:05:30.702897 2026] [security2:error] [pid 796928:tid 797083] [client 50.116.65.227:52348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PCusTy9vX-htKvPkf3AAAArI"]
[Mon Jul 20 06:05:30.744533 2026] [security2:error] [pid 796928:tid 797174] [client 136.67.36.183:57827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4PCusTy9vX-htKvPkf4QAAAw0"]
[Mon Jul 20 06:05:30.751232 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:49479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4PCrLfyzVz2SrjZpi27gAAAn0"], referer: http://ccsdifference.com/Wordpress
[Mon Jul 20 06:05:30.803782 2026] [security2:error] [pid 796928:tid 797080] [client 103.95.123.246:20312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PCusTy9vX-htKvPkf4gAAAq8"]
[Mon Jul 20 06:05:30.803887 2026] [security2:error] [pid 796928:tid 797080] [client 103.95.123.246:20312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PCusTy9vX-htKvPkf4gAAAq8"]
[Mon Jul 20 06:05:30.837694 2026] [security2:error] [pid 796928:tid 797127] [client 57.141.18.62:27518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PBesTy9vX-htKvPkfHgAC3gk"]
[Mon Jul 20 06:05:30.988417 2026] [security2:error] [pid 796928:tid 797148] [client 158.173.166.181:37011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PCusTy9vX-htKvPkf8QAAAvM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:31.230663 2026] [security2:error] [pid 796928:tid 797090] [client 136.67.36.183:64900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4PC-sTy9vX-htKvPkgAQAAArk"]
[Mon Jul 20 06:05:31.342007 2026] [security2:error] [pid 796928:tid 797132] [client 103.141.108.143:58569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgCQAAAuM"]
[Mon Jul 20 06:05:31.342133 2026] [security2:error] [pid 796928:tid 797132] [client 103.141.108.143:58569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgCQAAAuM"]
[Mon Jul 20 06:05:31.405041 2026] [autoindex:error] [pid 796928:tid 797167] [client 213.35.113.47:49233] AH01276: Cannot serve directory /home3/alaraycr/public_html/allisonrodrigue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:05:31.418526 2026] [security2:error] [pid 796567:tid 796789] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PC7LfyzVz2SrjZpi3CgAAAnA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:31.545292 2026] [security2:error] [pid 796928:tid 797063] [client 106.192.104.4:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgHgAAAp4"]
[Mon Jul 20 06:05:31.545453 2026] [security2:error] [pid 796928:tid 797063] [client 106.192.104.4:61430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgHgAAAp4"]
[Mon Jul 20 06:05:31.761876 2026] [security2:error] [pid 796928:tid 797172] [client 13.201.64.214:12894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgMgAAAws"]
[Mon Jul 20 06:05:31.761988 2026] [security2:error] [pid 796928:tid 797172] [client 13.201.64.214:12894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgMgAAAws"]
[Mon Jul 20 06:05:31.803440 2026] [security2:error] [pid 796928:tid 797082] [client 14.225.17.146:60015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4PC-sTy9vX-htKvPkgJgAAArE"], referer: https://ccsdifference.com/Wordpress
[Mon Jul 20 06:05:31.829222 2026] [security2:error] [pid 796928:tid 796994] [remote 81.173.115.7:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4PC-sTy9vX-htKvPkgNwADCUE"]
[Mon Jul 20 06:05:31.846393 2026] [security2:error] [pid 796928:tid 797085] [client 185.132.186.75:53063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/slider.php"] [unique_id "al4PC-sTy9vX-htKvPkgOQAAArQ"]
[Mon Jul 20 06:05:31.883388 2026] [security2:error] [pid 796928:tid 797184] [client 136.67.36.183:51258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4PC-sTy9vX-htKvPkgPQAAAxc"]
[Mon Jul 20 06:05:32.029941 2026] [security2:error] [pid 796928:tid 797163] [client 14.225.17.146:51046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4PC-sTy9vX-htKvPkgFQAAAwI"], referer: http://waterproofgoods.com/Wordpress
[Mon Jul 20 06:05:32.039165 2026] [security2:error] [pid 796928:tid 797038] [remote 81.173.115.7:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4PDOsTy9vX-htKvPkgSQACq20"], referer: https://website-19aec4aa.spencersadventures.com/wp-login.php
[Mon Jul 20 06:05:32.123253 2026] [security2:error] [pid 796928:tid 797171] [client 57.141.18.93:46682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PBusTy9vX-htKvPkfUgADChg"]
[Mon Jul 20 06:05:32.174133 2026] [security2:error] [pid 796567:tid 796705] [client 150.228.148.150:59955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3JAAAAhw"]
[Mon Jul 20 06:05:32.189591 2026] [security2:error] [pid 796567:tid 796705] [client 150.228.148.150:59955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3JAAAAhw"]
[Mon Jul 20 06:05:32.237314 2026] [security2:error] [pid 796928:tid 796981] [remote 100.42.189.89:32792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PDOsTy9vX-htKvPkgUAAC7DQ"]
[Mon Jul 20 06:05:32.301888 2026] [security2:error] [pid 796928:tid 797064] [client 14.225.17.146:64117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4PC-sTy9vX-htKvPkf9AAAAp8"], referer: http://ravmike.com/Wordpress
[Mon Jul 20 06:05:32.388339 2026] [security2:error] [pid 796928:tid 797081] [client 136.67.36.183:49388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4PDOsTy9vX-htKvPkgXAAAArA"]
[Mon Jul 20 06:05:32.441650 2026] [security2:error] [pid 796928:tid 796954] [remote 100.42.189.89:32792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PDOsTy9vX-htKvPkgYwADBBk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:05:32.546554 2026] [cgid:error] [pid 796567:tid 796814] [client 199.45.154.141:53876] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: https://smtracking.genesismbs.com:443/cgi-bin
[Mon Jul 20 06:05:32.581567 2026] [security2:error] [pid 796928:tid 797083] [client 14.225.17.146:59364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4PDOsTy9vX-htKvPkgVAAAArI"], referer: http://alrowad-hub.net/Wordpress
[Mon Jul 20 06:05:32.675457 2026] [security2:error] [pid 796928:tid 797054] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PDOsTy9vX-htKvPkgbgAC1X0"]
[Mon Jul 20 06:05:32.675643 2026] [security2:error] [pid 796928:tid 797118] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PDOsTy9vX-htKvPkgbgAC1X0"]
[Mon Jul 20 06:05:32.675926 2026] [security2:error] [pid 796567:tid 796721] [client 14.225.17.146:56090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4PDLLfyzVz2SrjZpi3IgAAAiw"], referer: http://talknutritionwithlesley.com/Wordpress
[Mon Jul 20 06:05:32.743620 2026] [security2:error] [pid 796567:tid 796718] [client 136.67.36.183:53548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4PDLLfyzVz2SrjZpi3NQAAAik"]
[Mon Jul 20 06:05:32.806995 2026] [security2:error] [pid 796928:tid 797145] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PDOsTy9vX-htKvPkgYgAAAvA"]
[Mon Jul 20 06:05:32.818718 2026] [security2:error] [pid 796928:tid 797140] [client 45.157.112.60:23877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PDOsTy9vX-htKvPkgcwAAAus"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:32.951187 2026] [security2:error] [pid 796567:tid 796805] [client 112.213.160.112:8277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3PAAAAoA"]
[Mon Jul 20 06:05:32.951297 2026] [security2:error] [pid 796567:tid 796805] [client 112.213.160.112:8277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3PAAAAoA"]
[Mon Jul 20 06:05:33.063225 2026] [security2:error] [pid 796928:tid 797110] [client 136.67.36.183:60562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4PDesTy9vX-htKvPkggwAAAs0"]
[Mon Jul 20 06:05:33.075112 2026] [security2:error] [pid 796567:tid 796702] [client 86.98.90.58:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PDbLfyzVz2SrjZpi3QQAAAhk"]
[Mon Jul 20 06:05:33.075507 2026] [security2:error] [pid 796567:tid 796702] [client 86.98.90.58:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PDbLfyzVz2SrjZpi3QQAAAhk"]
[Mon Jul 20 06:05:33.110177 2026] [security2:error] [pid 796928:tid 797120] [client 14.225.17.146:53615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4PDesTy9vX-htKvPkggQAAAtc"], referer: http://mourgroup.com/Wordpress
[Mon Jul 20 06:05:33.182609 2026] [security2:error] [pid 796567:tid 796787] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PDbLfyzVz2SrjZpi3QgAAAm4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:33.194831 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:64921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4PDesTy9vX-htKvPkghwAAAro"], referer: https://ravmike.com/Wordpress
[Mon Jul 20 06:05:33.219503 2026] [security2:error] [pid 796928:tid 797098] [client 136.67.36.183:63558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4PDesTy9vX-htKvPkgjAAAAsE"]
[Mon Jul 20 06:05:33.360544 2026] [security2:error] [pid 796567:tid 796745] [client 14.225.17.146:50342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4PDbLfyzVz2SrjZpi3RAAAAkQ"], referer: http://careysheatingandcooling.com/Wordpress
[Mon Jul 20 06:05:33.482368 2026] [security2:error] [pid 796567:tid 796804] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PDbLfyzVz2SrjZpi3UAAAAn8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:33.609246 2026] [security2:error] [pid 796567:tid 796815] [client 136.67.36.183:63561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4PDbLfyzVz2SrjZpi3XgAAAoo"]
[Mon Jul 20 06:05:33.796026 2026] [security2:error] [pid 796567:tid 796732] [client 185.132.186.64:47281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/dir.php"] [unique_id "al4PDbLfyzVz2SrjZpi3YQAAAjc"]
[Mon Jul 20 06:05:34.008844 2026] [security2:error] [pid 796928:tid 797077] [client 136.67.36.183:49468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4PDusTy9vX-htKvPkguAAAAqw"]
[Mon Jul 20 06:05:34.200709 2026] [security2:error] [pid 796928:tid 797100] [client 136.67.36.183:56639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4PDusTy9vX-htKvPkgwAAAAsM"]
[Mon Jul 20 06:05:34.291645 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.53:60718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PCbLfyzVz2SrjZpi2rAACY2g"]
[Mon Jul 20 06:05:34.499691 2026] [security2:error] [pid 796928:tid 797117] [client 136.67.36.183:56072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4PDusTy9vX-htKvPkg1wAAAtQ"]
[Mon Jul 20 06:05:34.812121 2026] [security2:error] [pid 796567:tid 796761] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PDrLfyzVz2SrjZpi3eAAAAlQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:34.863115 2026] [security2:error] [pid 796567:tid 796721] [client 115.246.21.170:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PDrLfyzVz2SrjZpi3fwAAAiw"]
[Mon Jul 20 06:05:34.864711 2026] [security2:error] [pid 796567:tid 796721] [client 115.246.21.170:58130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PDrLfyzVz2SrjZpi3fwAAAiw"]
[Mon Jul 20 06:05:35.041222 2026] [security2:error] [pid 796928:tid 796940] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PD-sTy9vX-htKvPkg7wACqws"]
[Mon Jul 20 06:05:35.041422 2026] [security2:error] [pid 796928:tid 797076] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PD-sTy9vX-htKvPkg7wACqws"]
[Mon Jul 20 06:05:35.086525 2026] [security2:error] [pid 796567:tid 796780] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PD7LfyzVz2SrjZpi3hQAAAmc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:35.206804 2026] [security2:error] [pid 796928:tid 797045] [remote 5.161.225.162:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4PD-sTy9vX-htKvPkg9QAC9XQ"]
[Mon Jul 20 06:05:35.235947 2026] [security2:error] [pid 796567:tid 796739] [client 158.173.241.141:38169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4PD7LfyzVz2SrjZpi3hAAAAj4"], referer: http://sesamegreenbeans.com/about-sesame-green-beans/
[Mon Jul 20 06:05:35.394285 2026] [security2:error] [pid 796928:tid 796952] [remote 5.161.225.162:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4PD-sTy9vX-htKvPkhAQAC7Rc"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:05:35.749705 2026] [security2:error] [pid 796928:tid 797094] [client 185.132.186.63:24607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/atomlib.php"] [unique_id "al4PD-sTy9vX-htKvPkhFAAAAr0"]
[Mon Jul 20 06:05:35.761450 2026] [security2:error] [pid 796567:tid 796747] [client 14.225.17.146:60844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4PDrLfyzVz2SrjZpi3bQAAAkY"], referer: http://vinovinhowine.com/Wordpress
[Mon Jul 20 06:05:35.891144 2026] [security2:error] [pid 796567:tid 796767] [client 93.152.221.118:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4PD7LfyzVz2SrjZpi3nAAAAlo"], referer: https://duckduckgo.com/
[Mon Jul 20 06:05:36.197763 2026] [security2:error] [pid 796928:tid 797053] [remote 124.55.178.99:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4PEOsTy9vX-htKvPkhLAACwHw"]
[Mon Jul 20 06:05:36.208255 2026] [security2:error] [pid 796928:tid 797124] [client 210.212.97.243:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PEOsTy9vX-htKvPkhLgAAAts"]
[Mon Jul 20 06:05:36.208352 2026] [security2:error] [pid 796928:tid 797124] [client 210.212.97.243:10444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PEOsTy9vX-htKvPkhLgAAAts"]
[Mon Jul 20 06:05:36.215131 2026] [security2:error] [pid 796928:tid 796941] [remote 8.217.229.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nzfoodstory.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PEOsTy9vX-htKvPkhMQACvAw"]
[Mon Jul 20 06:05:36.217346 2026] [security2:error] [pid 796928:tid 797105] [client 93.152.221.118:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4PEOsTy9vX-htKvPkhMgAAAsg"], referer: https://wordpress.org/
[Mon Jul 20 06:05:36.339562 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:14858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PELLfyzVz2SrjZpi3pgAAAmo"]
[Mon Jul 20 06:05:36.339649 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:14858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PELLfyzVz2SrjZpi3pgAAAmo"]
[Mon Jul 20 06:05:36.410121 2026] [security2:error] [pid 796928:tid 797153] [client 14.225.17.146:59080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4PEOsTy9vX-htKvPkhJQAAAvg"], referer: http://mrbambooplus.com/Wordpress
[Mon Jul 20 06:05:36.423413 2026] [security2:error] [pid 796928:tid 796978] [remote 8.217.229.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nzfoodstory.com"] [uri "/"] [unique_id "al4PEOsTy9vX-htKvPkhOwACpzE"]
[Mon Jul 20 06:05:36.615513 2026] [security2:error] [pid 796567:tid 796624] [remote 57.141.18.24:62580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4174419"] [unique_id "al4PELLfyzVz2SrjZpi3sAACgDg"]
[Mon Jul 20 06:05:36.624881 2026] [security2:error] [pid 796928:tid 796950] [remote 124.55.178.99:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4PEOsTy9vX-htKvPkhSQAC1BU"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:05:36.985896 2026] [security2:error] [pid 796928:tid 797035] [remote 8.217.229.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nzfoodstory.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PEOsTy9vX-htKvPkhWQADE2o"]
[Mon Jul 20 06:05:37.136366 2026] [security2:error] [pid 796928:tid 797068] [client 65.1.132.125:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhYwAAAqM"]
[Mon Jul 20 06:05:37.136442 2026] [security2:error] [pid 796928:tid 797068] [client 65.1.132.125:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhYwAAAqM"]
[Mon Jul 20 06:05:37.148387 2026] [security2:error] [pid 796928:tid 796968] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhZAACnCc"]
[Mon Jul 20 06:05:37.148502 2026] [security2:error] [pid 796928:tid 797061] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhZAACnCc"]
[Mon Jul 20 06:05:37.217792 2026] [security2:error] [pid 796567:tid 796771] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PELLfyzVz2SrjZpi3tgAAAl4"]
[Mon Jul 20 06:05:37.277413 2026] [security2:error] [pid 796928:tid 797147] [client 93.152.221.118:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4PEesTy9vX-htKvPkhawAAAvI"], referer: https://www.bing.com/
[Mon Jul 20 06:05:37.570608 2026] [security2:error] [pid 796928:tid 797127] [client 181.224.94.124:55922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhewAAAt4"]
[Mon Jul 20 06:05:37.570725 2026] [security2:error] [pid 796928:tid 797127] [client 181.224.94.124:55922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhewAAAt4"]
[Mon Jul 20 06:05:37.699887 2026] [security2:error] [pid 796928:tid 797143] [client 185.132.186.95:63763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/style.php"] [unique_id "al4PEesTy9vX-htKvPkhiQAAAu4"]
[Mon Jul 20 06:05:37.871014 2026] [security2:error] [pid 796928:tid 797064] [client 74.7.241.182:50336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ace-med.com"] [uri "/robots.txt"] [unique_id "al4PEesTy9vX-htKvPkhkAAAAp8"]
[Mon Jul 20 06:05:38.035359 2026] [security2:error] [pid 796567:tid 796747] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PEbLfyzVz2SrjZpi31QAAAkY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:38.150082 2026] [security2:error] [pid 796928:tid 797008] [remote 152.228.213.32:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PEusTy9vX-htKvPkhoQACvE8"]
[Mon Jul 20 06:05:38.218621 2026] [security2:error] [pid 796928:tid 797182] [client 57.141.18.101:59278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PDesTy9vX-htKvPkgiAADFSA"]
[Mon Jul 20 06:05:38.387174 2026] [security2:error] [pid 796928:tid 797000] [remote 152.228.213.32:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PEusTy9vX-htKvPkhqgAC30c"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:38.806256 2026] [security2:error] [pid 796928:tid 797054] [remote 57.141.18.37:32158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6055825"] [unique_id "al4PEusTy9vX-htKvPkhxAACpH0"]
[Mon Jul 20 06:05:39.083070 2026] [security2:error] [pid 796928:tid 797005] [remote 100.42.189.89:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PE-sTy9vX-htKvPkh2AAC10w"]
[Mon Jul 20 06:05:39.171838 2026] [security2:error] [pid 796928:tid 797109] [client 74.208.214.194:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PE-sTy9vX-htKvPkh3wAAAsw"]
[Mon Jul 20 06:05:39.276112 2026] [security2:error] [pid 796928:tid 797042] [remote 100.42.189.89:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PE-sTy9vX-htKvPkh5gACmnE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:05:39.326512 2026] [security2:error] [pid 796928:tid 797096] [client 158.173.89.95:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PE-sTy9vX-htKvPkh6AAAAr8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:39.652770 2026] [security2:error] [pid 796928:tid 797169] [client 185.132.186.72:32537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/libraries/phpmailer/updates.php"] [unique_id "al4PE-sTy9vX-htKvPkh-gAAAwg"]
[Mon Jul 20 06:05:39.755177 2026] [authz_core:error] [pid 796928:tid 797174] [client 43.165.167.69:59804] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini, referer: http://www.upsurgecommunications.com
[Mon Jul 20 06:05:39.763128 2026] [security2:error] [pid 796928:tid 797125] [client 57.141.18.120:52776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PDusTy9vX-htKvPkg4QAC3DM"]
[Mon Jul 20 06:05:40.108978 2026] [security2:error] [pid 796928:tid 797182] [client 14.225.17.146:53727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4PE-sTy9vX-htKvPkh4AAAAxU"], referer: http://walkingandtalking.net/Wordpress
[Mon Jul 20 06:05:40.594333 2026] [security2:error] [pid 796567:tid 796726] [client 14.225.17.146:63497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4PFLLfyzVz2SrjZpi3-wAAAjE"], referer: http://overloadcomedy.com/Wordpress
[Mon Jul 20 06:05:40.994653 2026] [security2:error] [pid 796567:tid 796733] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PFLLfyzVz2SrjZpi4DgAAAjg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:41.002395 2026] [security2:error] [pid 796928:tid 797154] [client 14.225.17.146:58261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4PFOsTy9vX-htKvPkiPAAAAvk"], referer: https://walkingandtalking.net/Wordpress
[Mon Jul 20 06:05:41.355088 2026] [security2:error] [pid 796928:tid 797077] [client 14.225.17.146:58613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4PFOsTy9vX-htKvPkiOgAAAqw"]
[Mon Jul 20 06:05:41.603521 2026] [security2:error] [pid 796928:tid 797125] [client 185.132.186.70:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/nf_tracking.php"] [unique_id "al4PFesTy9vX-htKvPkiYgAAAtw"]
[Mon Jul 20 06:05:41.612659 2026] [security2:error] [pid 796567:tid 796720] [client 50.116.65.227:26908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4PFbLfyzVz2SrjZpi4IwAAAis"]
[Mon Jul 20 06:05:41.624939 2026] [security2:error] [pid 796567:tid 796823] [client 50.116.65.227:58860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4PFbLfyzVz2SrjZpi4JAAAApI"]
[Mon Jul 20 06:05:41.854863 2026] [security2:error] [pid 796567:tid 796762] [client 57.141.18.51:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PEbLfyzVz2SrjZpi3uQACVTo"]
[Mon Jul 20 06:05:42.023107 2026] [security2:error] [pid 796928:tid 797094] [client 74.7.244.13:41674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "certasit.com"] [uri "/robots.txt"] [unique_id "al4PFusTy9vX-htKvPkibwAAAr0"]
[Mon Jul 20 06:05:42.157661 2026] [security2:error] [pid 796928:tid 797071] [client 103.141.108.143:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkifAAAAqY"]
[Mon Jul 20 06:05:42.158103 2026] [security2:error] [pid 796928:tid 797071] [client 103.141.108.143:59210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkifAAAAqY"]
[Mon Jul 20 06:05:42.211828 2026] [security2:error] [pid 796567:tid 796655] [remote 123.30.154.30:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PFrLfyzVz2SrjZpi4MgACalc"]
[Mon Jul 20 06:05:42.370890 2026] [security2:error] [pid 796567:tid 796800] [client 57.141.18.61:47136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PEbLfyzVz2SrjZpi3ygACezc"]
[Mon Jul 20 06:05:42.372665 2026] [security2:error] [pid 796928:tid 797112] [client 103.95.123.246:20850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkihgAAAs8"]
[Mon Jul 20 06:05:42.372779 2026] [security2:error] [pid 796928:tid 797112] [client 103.95.123.246:20850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkihgAAAs8"]
[Mon Jul 20 06:05:42.532593 2026] [security2:error] [pid 796567:tid 796788] [client 14.225.17.146:59607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4PFbLfyzVz2SrjZpi4EgAAAm8"], referer: http://eduardsales.com/Wordpress
[Mon Jul 20 06:05:42.658944 2026] [security2:error] [pid 796567:tid 796804] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PFrLfyzVz2SrjZpi4OgAAAn8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:42.733706 2026] [security2:error] [pid 796567:tid 796776] [client 106.192.104.4:61917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PFrLfyzVz2SrjZpi4PwAAAmM"]
[Mon Jul 20 06:05:42.733872 2026] [security2:error] [pid 796567:tid 796776] [client 106.192.104.4:61917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PFrLfyzVz2SrjZpi4PwAAAmM"]
[Mon Jul 20 06:05:42.782224 2026] [security2:error] [pid 796928:tid 797093] [client 43.205.139.3:25740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkijAAAArw"]
[Mon Jul 20 06:05:42.813642 2026] [security2:error] [pid 796567:tid 796620] [remote 123.30.154.30:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PFrLfyzVz2SrjZpi4QgACGjQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:05:42.968198 2026] [security2:error] [pid 796567:tid 796701] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PFrLfyzVz2SrjZpi4RAAAAhg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:42.979685 2026] [security2:error] [pid 796928:tid 797142] [client 150.228.148.150:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkiqgAAAu0"]
[Mon Jul 20 06:05:42.983341 2026] [security2:error] [pid 796928:tid 797142] [client 150.228.148.150:39256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkiqgAAAu0"]
[Mon Jul 20 06:05:43.248796 2026] [security2:error] [pid 796928:tid 797172] [client 13.201.64.214:27120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4PF-sTy9vX-htKvPkivwAAAws"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:05:43.256808 2026] [security2:error] [pid 796928:tid 797004] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPkiwAACuUs"]
[Mon Jul 20 06:05:43.257006 2026] [security2:error] [pid 796928:tid 797090] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPkiwAACuUs"]
[Mon Jul 20 06:05:43.353088 2026] [security2:error] [pid 796928:tid 797070] [client 34.34.21.42:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.ala.ppf.mybluehost.me"] [uri "/"] [unique_id "al4PF-sTy9vX-htKvPkixQAAAqU"]
[Mon Jul 20 06:05:43.353199 2026] [security2:error] [pid 796928:tid 797070] [client 34.34.21.42:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.ala.ppf.mybluehost.me"] [uri "/"] [unique_id "al4PF-sTy9vX-htKvPkixQAAAqU"]
[Mon Jul 20 06:05:43.554478 2026] [security2:error] [pid 796567:tid 796792] [client 185.132.186.68:28527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/about.php7"] [unique_id "al4PF7LfyzVz2SrjZpi4VQAAAnM"]
[Mon Jul 20 06:05:43.635993 2026] [security2:error] [pid 796928:tid 797134] [client 45.5.39.171:50217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4PF-sTy9vX-htKvPki0AAAAuU"]
[Mon Jul 20 06:05:43.664058 2026] [security2:error] [pid 796928:tid 797133] [client 112.213.160.112:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPki1wAAAuQ"]
[Mon Jul 20 06:05:43.664162 2026] [security2:error] [pid 796928:tid 797133] [client 112.213.160.112:8451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPki1wAAAuQ"]
[Mon Jul 20 06:05:43.867417 2026] [security2:error] [pid 796928:tid 797038] [remote 14.128.14.9:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PF-sTy9vX-htKvPki4wACom0"]
[Mon Jul 20 06:05:43.968759 2026] [security2:error] [pid 796567:tid 796802] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PF7LfyzVz2SrjZpi4XQAAAn0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:44.234634 2026] [security2:error] [pid 796928:tid 797119] [client 57.141.18.25:56460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PE-sTy9vX-htKvPkhzwAC1kg"]
[Mon Jul 20 06:05:44.431331 2026] [security2:error] [pid 796928:tid 796942] [remote 14.128.14.9:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PGOsTy9vX-htKvPkjCAADAg0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:05:44.797149 2026] [security2:error] [pid 796567:tid 796774] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PGLLfyzVz2SrjZpi4cAAAAmE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:44.961441 2026] [security2:error] [pid 796567:tid 796791] [client 14.225.17.146:58656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4PFrLfyzVz2SrjZpi4LQAAAnI"], referer: http://drewsasburyparkbeachhouse.com/Wordpress
[Mon Jul 20 06:05:45.011797 2026] [security2:error] [pid 796928:tid 797156] [client 57.141.18.87:43922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PE-sTy9vX-htKvPkh_gAC-0Y"]
[Mon Jul 20 06:05:45.094663 2026] [security2:error] [pid 796567:tid 796742] [client 86.98.90.58:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4ewAAAkE"]
[Mon Jul 20 06:05:45.094784 2026] [security2:error] [pid 796567:tid 796742] [client 86.98.90.58:57894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4ewAAAkE"]
[Mon Jul 20 06:05:45.312782 2026] [security2:error] [pid 796567:tid 796782] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PGbLfyzVz2SrjZpi4gQAAAmk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:45.465550 2026] [security2:error] [pid 796567:tid 796772] [client 57.141.18.78:44438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PFLLfyzVz2SrjZpi3_gACX00"]
[Mon Jul 20 06:05:45.501871 2026] [security2:error] [pid 796928:tid 797113] [client 115.246.21.170:10895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PGesTy9vX-htKvPkjNAAAAtA"]
[Mon Jul 20 06:05:45.502016 2026] [security2:error] [pid 796928:tid 797113] [client 115.246.21.170:10895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PGesTy9vX-htKvPkjNAAAAtA"]
[Mon Jul 20 06:05:45.663129 2026] [security2:error] [pid 796567:tid 796654] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4jwACSFY"]
[Mon Jul 20 06:05:45.663254 2026] [security2:error] [pid 796567:tid 796749] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4jwACSFY"]
[Mon Jul 20 06:05:45.922146 2026] [security2:error] [pid 796567:tid 796747] [client 3.109.4.218:55526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4PGbLfyzVz2SrjZpi4lwAAAkY"]
[Mon Jul 20 06:05:46.022068 2026] [security2:error] [pid 796928:tid 797040] [remote 50.28.1.50:41736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjSwAC3m8"]
[Mon Jul 20 06:05:46.216571 2026] [security2:error] [pid 796928:tid 797043] [remote 50.28.1.50:41736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjVAAC93I"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:46.218356 2026] [security2:error] [pid 796567:tid 796781] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PGrLfyzVz2SrjZpi4nAAAAmg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:46.355572 2026] [security2:error] [pid 796928:tid 797073] [client 14.225.17.146:51274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjVQAAAqg"], referer: http://backandneckpainrelieflaceychiropractor.com/Wordpress
[Mon Jul 20 06:05:46.507132 2026] [security2:error] [pid 796928:tid 797068] [client 185.132.186.77:44835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/filefuns.php"] [unique_id "al4PGusTy9vX-htKvPkjZQAAAqM"]
[Mon Jul 20 06:05:46.621778 2026] [security2:error] [pid 796928:tid 796995] [remote 167.233.114.32:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjaQAC-kI"]
[Mon Jul 20 06:05:46.645326 2026] [security2:error] [pid 796928:tid 797105] [client 57.141.18.123:28084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PFesTy9vX-htKvPkiWgACyCI"]
[Mon Jul 20 06:05:46.779120 2026] [security2:error] [pid 796567:tid 796756] [client 74.7.228.17:39500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4PGrLfyzVz2SrjZpi4sQAAAk8"]
[Mon Jul 20 06:05:46.833062 2026] [security2:error] [pid 796928:tid 797079] [client 14.225.17.146:51726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjawAAAq4"], referer: http://fluidtemple.org/Wordpress
[Mon Jul 20 06:05:46.838792 2026] [security2:error] [pid 796928:tid 797019] [remote 167.233.114.32:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjcgACs1o"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:05:46.913623 2026] [security2:error] [pid 796567:tid 796822] [client 41.173.37.102:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PGrLfyzVz2SrjZpi4uAAAApE"]
[Mon Jul 20 06:05:46.913724 2026] [security2:error] [pid 796567:tid 796822] [client 41.173.37.102:1359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PGrLfyzVz2SrjZpi4uAAAApE"]
[Mon Jul 20 06:05:46.936177 2026] [security2:error] [pid 796567:tid 796725] [client 74.7.228.17:54416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.asliceofleadership.com"] [uri "/index.php"] [unique_id "al4PGrLfyzVz2SrjZpi4uQACMEA"], referer: http://www.asliceofleadership.com/robots.txt
[Mon Jul 20 06:05:47.090649 2026] [security2:error] [pid 796567:tid 796704] [client 178.152.178.232:37164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PG7LfyzVz2SrjZpi4vQAAAhs"]
[Mon Jul 20 06:05:47.090758 2026] [security2:error] [pid 796567:tid 796704] [client 178.152.178.232:37164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PG7LfyzVz2SrjZpi4vQAAAhs"]
[Mon Jul 20 06:05:47.156838 2026] [security2:error] [pid 796928:tid 797112] [client 13.201.64.214:27126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4PG-sTy9vX-htKvPkjhAAAAs8"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:05:47.157219 2026] [security2:error] [pid 796928:tid 797125] [client 210.212.97.243:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjhQAAAtw"]
[Mon Jul 20 06:05:47.157313 2026] [security2:error] [pid 796928:tid 797125] [client 210.212.97.243:10445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjhQAAAtw"]
[Mon Jul 20 06:05:47.232254 2026] [security2:error] [pid 796567:tid 796804] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PG7LfyzVz2SrjZpi4wAAAAn8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:47.608640 2026] [security2:error] [pid 796928:tid 797157] [client 14.225.17.146:62968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjTwAAAvw"], referer: http://solkeetw.com/Wordpress
[Mon Jul 20 06:05:47.637480 2026] [security2:error] [pid 796567:tid 796714] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PG7LfyzVz2SrjZpi4zQAAAiU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:47.856851 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PG-sTy9vX-htKvPkjlgAAAqw"]
[Mon Jul 20 06:05:47.891816 2026] [security2:error] [pid 796928:tid 797122] [client 57.141.18.39:47815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PFusTy9vX-htKvPkikQAC2X8"]
[Mon Jul 20 06:05:47.956246 2026] [security2:error] [pid 796928:tid 796941] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjtwACwgw"]
[Mon Jul 20 06:05:47.956430 2026] [security2:error] [pid 796928:tid 797099] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjtwACwgw"]
[Mon Jul 20 06:05:48.026302 2026] [security2:error] [pid 796928:tid 797101] [client 193.19.109.244:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4PHOsTy9vX-htKvPkjugAAAsQ"]
[Mon Jul 20 06:05:48.118691 2026] [security2:error] [pid 796567:tid 796699] [client 181.224.94.124:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PHLLfyzVz2SrjZpi45QAAAhY"]
[Mon Jul 20 06:05:48.118815 2026] [security2:error] [pid 796567:tid 796699] [client 181.224.94.124:16989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PHLLfyzVz2SrjZpi45QAAAhY"]
[Mon Jul 20 06:05:48.119300 2026] [security2:error] [pid 796567:tid 796755] [client 50.116.65.227:59066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PHLLfyzVz2SrjZpi45AAAAk4"]
[Mon Jul 20 06:05:48.128963 2026] [security2:error] [pid 796928:tid 797110] [client 50.116.65.227:59072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PHOsTy9vX-htKvPkjwAAAAs0"]
[Mon Jul 20 06:05:48.431249 2026] [security2:error] [pid 796928:tid 797065] [client 14.177.167.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4PG-sTy9vX-htKvPkjqwAAAqA"]
[Mon Jul 20 06:05:48.455571 2026] [security2:error] [pid 796567:tid 796753] [client 185.132.186.67:45819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/class_api.php"] [unique_id "al4PHLLfyzVz2SrjZpi49QAAAkw"]
[Mon Jul 20 06:05:48.571183 2026] [security2:error] [pid 796567:tid 796692] [remote 152.228.213.32:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PHLLfyzVz2SrjZpi4-wACTXw"]
[Mon Jul 20 06:05:49.152948 2026] [security2:error] [pid 796567:tid 796574] [remote 152.228.213.32:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PHbLfyzVz2SrjZpi5FAACJAY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:49.320770 2026] [security2:error] [pid 796567:tid 796819] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PHbLfyzVz2SrjZpi5FwAAAo4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:49.549076 2026] [security2:error] [pid 796567:tid 796810] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PHbLfyzVz2SrjZpi5HgAAAoU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:49.776141 2026] [security2:error] [pid 796567:tid 796728] [client 14.225.17.146:52023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4PHbLfyzVz2SrjZpi5GQAAAjM"], referer: http://uritems.net/Wordpress
[Mon Jul 20 06:05:49.862915 2026] [security2:error] [pid 796928:tid 797082] [client 212.237.120.155:31404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4PHesTy9vX-htKvPkkBwAAArE"]
[Mon Jul 20 06:05:49.920710 2026] [security2:error] [pid 796928:tid 797095] [client 57.141.18.20:47702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGOsTy9vX-htKvPkjDgACvk0"]
[Mon Jul 20 06:05:50.054232 2026] [security2:error] [pid 796567:tid 796821] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PHbLfyzVz2SrjZpi5LAAAApA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:50.406645 2026] [security2:error] [pid 796928:tid 797075] [client 185.132.186.65:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/l.php"] [unique_id "al4PHusTy9vX-htKvPkkKwAAAqo"]
[Mon Jul 20 06:05:50.460197 2026] [security2:error] [pid 796928:tid 797133] [client 14.225.17.146:62213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4PHusTy9vX-htKvPkkHgAAAuQ"], referer: http://maxenengineering.com/Wordpress
[Mon Jul 20 06:05:50.592119 2026] [security2:error] [pid 796567:tid 796739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PHrLfyzVz2SrjZpi5PgAAAj4"]
[Mon Jul 20 06:05:50.783043 2026] [security2:error] [pid 796928:tid 797080] [client 57.141.18.124:54396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGesTy9vX-htKvPkjJwACr0M"]
[Mon Jul 20 06:05:51.390077 2026] [security2:error] [pid 796567:tid 796819] [client 14.225.17.146:52055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4PH7LfyzVz2SrjZpi5ZAAAAo4"], referer: https://maxenengineering.com/Wordpress
[Mon Jul 20 06:05:51.391054 2026] [security2:error] [pid 796567:tid 796765] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PH7LfyzVz2SrjZpi5ZQAAAlg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:51.649637 2026] [security2:error] [pid 796928:tid 797153] [client 57.141.18.47:30098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjVwAC-C4"]
[Mon Jul 20 06:05:51.655023 2026] [security2:error] [pid 796928:tid 797126] [client 57.141.18.55:37026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjWQAC3S8"]
[Mon Jul 20 06:05:52.355380 2026] [security2:error] [pid 796928:tid 797131] [client 185.132.186.82:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/repeater.php"] [unique_id "al4PIOsTy9vX-htKvPkkqQAAAuI"]
[Mon Jul 20 06:05:52.861005 2026] [security2:error] [pid 796567:tid 796774] [client 193.37.33.4:60821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4PILLfyzVz2SrjZpi5jwAAAmE"]
[Mon Jul 20 06:05:52.992181 2026] [security2:error] [pid 796928:tid 797097] [client 103.141.108.143:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PIOsTy9vX-htKvPkk0wAAAsA"]
[Mon Jul 20 06:05:52.992341 2026] [security2:error] [pid 796928:tid 797097] [client 103.141.108.143:59634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PIOsTy9vX-htKvPkk0wAAAsA"]
[Mon Jul 20 06:05:53.103424 2026] [security2:error] [pid 796928:tid 797137] [client 106.192.104.4:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk2AAAAug"]
[Mon Jul 20 06:05:53.103584 2026] [security2:error] [pid 796928:tid 797137] [client 106.192.104.4:62379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk2AAAAug"]
[Mon Jul 20 06:05:53.157479 2026] [security2:error] [pid 796928:tid 797095] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PIOsTy9vX-htKvPkkxwAAAr4"]
[Mon Jul 20 06:05:53.534883 2026] [security2:error] [pid 796928:tid 797181] [client 43.205.139.3:48906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk4QAAAxQ"]
[Mon Jul 20 06:05:53.570465 2026] [security2:error] [pid 796928:tid 797145] [client 14.225.17.146:52740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4PIOsTy9vX-htKvPkknwAAAvA"], referer: http://alchemygroup.ca/Wordpress
[Mon Jul 20 06:05:53.612309 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:40990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk8gAAAuw"]
[Mon Jul 20 06:05:53.612426 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:40990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk8gAAAuw"]
[Mon Jul 20 06:05:53.641545 2026] [security2:error] [pid 796928:tid 797091] [client 114.119.134.51:28373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/page/8"] [unique_id "al4PIesTy9vX-htKvPkk9wAAAro"], referer: https://www.jenfarley.com/
[Mon Jul 20 06:05:53.659346 2026] [security2:error] [pid 796567:tid 796699] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PIbLfyzVz2SrjZpi5mwAAAhY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:53.663004 2026] [security2:error] [pid 796928:tid 797155] [client 3.67.192.83:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4PIOsTy9vX-htKvPkkxAAAAvo"]
[Mon Jul 20 06:05:53.691937 2026] [security2:error] [pid 796928:tid 797067] [client 3.67.192.83:44294] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4PIOsTy9vX-htKvPkkwgAAAqI"]
[Mon Jul 20 06:05:54.033607 2026] [security2:error] [pid 796928:tid 797056] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklDwAC1X8"]
[Mon Jul 20 06:05:54.033843 2026] [security2:error] [pid 796928:tid 797118] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklDwAC1X8"]
[Mon Jul 20 06:05:54.177943 2026] [security2:error] [pid 796567:tid 796712] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PIrLfyzVz2SrjZpi5rAAAAiM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:54.297414 2026] [security2:error] [pid 796928:tid 797094] [client 185.132.186.100:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/wso.php"] [unique_id "al4PIusTy9vX-htKvPklGwAAAr0"]
[Mon Jul 20 06:05:54.362913 2026] [security2:error] [pid 796928:tid 797153] [client 112.213.160.112:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklHQAAAvg"]
[Mon Jul 20 06:05:54.363056 2026] [security2:error] [pid 796928:tid 797153] [client 112.213.160.112:8646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklHQAAAvg"]
[Mon Jul 20 06:05:54.703308 2026] [security2:error] [pid 796567:tid 796704] [client 103.95.123.246:21355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PIrLfyzVz2SrjZpi5wAAAAhs"]
[Mon Jul 20 06:05:54.703397 2026] [security2:error] [pid 796567:tid 796704] [client 103.95.123.246:21355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PIrLfyzVz2SrjZpi5wAAAAhs"]
[Mon Jul 20 06:05:55.072321 2026] [security2:error] [pid 796567:tid 796796] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botanicapatterndesigns.com"] [uri "/.well-known/about.php"] [unique_id "al4PI7LfyzVz2SrjZpi5zAAAAnc"]
[Mon Jul 20 06:05:55.072422 2026] [security2:error] [pid 796567:tid 796796] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "botanicapatterndesigns.com"] [uri "/.well-known/about.php"] [unique_id "al4PI7LfyzVz2SrjZpi5zAAAAnc"]
[Mon Jul 20 06:05:55.424617 2026] [security2:error] [pid 796928:tid 796938] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4PI-sTy9vX-htKvPklSAAC_wk"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:05:55.522453 2026] [security2:error] [pid 796928:tid 796937] [remote 8.217.108.67:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PI-sTy9vX-htKvPklVAACqgg"]
[Mon Jul 20 06:05:55.587265 2026] [security2:error] [pid 796567:tid 796804] [client 57.141.18.12:45908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PHrLfyzVz2SrjZpi5SgACfxU"]
[Mon Jul 20 06:05:55.627533 2026] [security2:error] [pid 796928:tid 796947] [remote 95.217.78.234:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PI-sTy9vX-htKvPklWwAC7hI"]
[Mon Jul 20 06:05:55.846151 2026] [security2:error] [pid 796928:tid 796949] [remote 95.217.78.234:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PI-sTy9vX-htKvPklbgACrBQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:05:55.898326 2026] [security2:error] [pid 796928:tid 797089] [client 57.141.18.21:57900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PHusTy9vX-htKvPkkOwACuA0"]
[Mon Jul 20 06:05:56.253155 2026] [security2:error] [pid 796928:tid 797072] [client 185.132.186.97:23689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/autoload_classmap.php"] [unique_id "al4PJOsTy9vX-htKvPklewAAAqc"]
[Mon Jul 20 06:05:56.346009 2026] [security2:error] [pid 796928:tid 797058] [client 14.225.17.146:55741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4PI-sTy9vX-htKvPklOgAAApk"], referer: http://christiancountytrumpet.com/Wordpress
[Mon Jul 20 06:05:56.437126 2026] [security2:error] [pid 796567:tid 796752] [client 14.225.17.146:64981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4PIrLfyzVz2SrjZpi5wgAAAks"], referer: http://wathenbartlett.co.uk/Wordpress
[Mon Jul 20 06:05:56.497928 2026] [security2:error] [pid 796928:tid 796961] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PJOsTy9vX-htKvPkliAADACA"]
[Mon Jul 20 06:05:56.498073 2026] [security2:error] [pid 796928:tid 797161] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PJOsTy9vX-htKvPkliAADACA"]
[Mon Jul 20 06:05:56.646436 2026] [security2:error] [pid 796928:tid 797173] [client 14.225.17.146:56336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4PJOsTy9vX-htKvPklegAAAww"], referer: http://idigress.group/Wordpress
[Mon Jul 20 06:05:56.648179 2026] [security2:error] [pid 796567:tid 796822] [client 103.77.203.233:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PJLLfyzVz2SrjZpi5_gAAApE"]
[Mon Jul 20 06:05:56.648335 2026] [security2:error] [pid 796567:tid 796822] [client 103.77.203.233:56940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PJLLfyzVz2SrjZpi5_gAAApE"]
[Mon Jul 20 06:05:56.746072 2026] [security2:error] [pid 796567:tid 796625] [remote 20.153.140.50:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PJLLfyzVz2SrjZpi6AgACgjk"]
[Mon Jul 20 06:05:56.856032 2026] [security2:error] [pid 796928:tid 796991] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PJOsTy9vX-htKvPkloAAC-T4"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:05:56.871689 2026] [security2:error] [pid 796567:tid 796818] [client 14.182.195.220:51995] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4PJLLfyzVz2SrjZpi6CQAAAo0"]
[Mon Jul 20 06:05:57.100208 2026] [security2:error] [pid 796928:tid 797094] [client 115.246.21.170:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklsAAAAr0"]
[Mon Jul 20 06:05:57.100306 2026] [security2:error] [pid 796928:tid 797094] [client 115.246.21.170:51486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklsAAAAr0"]
[Mon Jul 20 06:05:57.189443 2026] [security2:error] [pid 796567:tid 796683] [remote 20.153.140.50:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PJbLfyzVz2SrjZpi6FAACYHM"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:05:57.361903 2026] [security2:error] [pid 796928:tid 797175] [client 14.225.17.146:58049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4PJesTy9vX-htKvPkluQAAAw4"], referer: https://wathenbartlett.co.uk/Wordpress
[Mon Jul 20 06:05:57.435366 2026] [security2:error] [pid 796928:tid 797119] [client 50.116.65.227:35222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PJesTy9vX-htKvPklvQAAAtY"]
[Mon Jul 20 06:05:57.447388 2026] [security2:error] [pid 796928:tid 797162] [client 50.116.65.227:35234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PJesTy9vX-htKvPklvgAAAwE"]
[Mon Jul 20 06:05:57.535662 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:1808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklwgAAAp8"]
[Mon Jul 20 06:05:57.535777 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:1808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklwgAAAp8"]
[Mon Jul 20 06:05:57.621412 2026] [security2:error] [pid 796567:tid 796771] [client 57.141.18.60:26990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PILLfyzVz2SrjZpi5gAACXho"]
[Mon Jul 20 06:05:57.705566 2026] [security2:error] [pid 796567:tid 796739] [client 210.212.97.243:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PJbLfyzVz2SrjZpi6IwAAAj4"]
[Mon Jul 20 06:05:57.705671 2026] [security2:error] [pid 796567:tid 796739] [client 210.212.97.243:10446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PJbLfyzVz2SrjZpi6IwAAAj4"]
[Mon Jul 20 06:05:57.769829 2026] [security2:error] [pid 796928:tid 797104] [client 178.152.178.232:36014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPkl0wAAAsc"]
[Mon Jul 20 06:05:57.769945 2026] [security2:error] [pid 796928:tid 797104] [client 178.152.178.232:36014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPkl0wAAAsc"]
[Mon Jul 20 06:05:57.770254 2026] [security2:error] [pid 796567:tid 796803] [client 14.225.17.146:61041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4PJLLfyzVz2SrjZpi6AAAAAn4"], referer: http://ancestralidadytrance.space/Wordpress
[Mon Jul 20 06:05:58.136203 2026] [security2:error] [pid 796567:tid 796622] [remote 182.77.62.24:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4PJrLfyzVz2SrjZpi6LAACfzY"]
[Mon Jul 20 06:05:58.201496 2026] [security2:error] [pid 796567:tid 796806] [client 185.132.186.83:38481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/contacts.php"] [unique_id "al4PJrLfyzVz2SrjZpi6LgAAAoE"]
[Mon Jul 20 06:05:58.230578 2026] [security2:error] [pid 796928:tid 797084] [client 86.98.90.58:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkl7gAAArM"]
[Mon Jul 20 06:05:58.230844 2026] [security2:error] [pid 796928:tid 797084] [client 86.98.90.58:58925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkl7gAAArM"]
[Mon Jul 20 06:05:58.367194 2026] [security2:error] [pid 796928:tid 796936] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4PJusTy9vX-htKvPkl9wAC3Ac"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:05:58.473551 2026] [security2:error] [pid 796567:tid 796614] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PJrLfyzVz2SrjZpi6PAACVy4"]
[Mon Jul 20 06:05:58.473811 2026] [security2:error] [pid 796567:tid 796764] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PJrLfyzVz2SrjZpi6PAACVy4"]
[Mon Jul 20 06:05:58.557235 2026] [security2:error] [pid 796928:tid 797138] [client 57.141.18.10:47672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PIesTy9vX-htKvPkk4AAC6XU"]
[Mon Jul 20 06:05:58.644790 2026] [security2:error] [pid 796928:tid 797117] [client 181.224.94.124:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkmBgAAAtQ"]
[Mon Jul 20 06:05:58.644915 2026] [security2:error] [pid 796928:tid 797117] [client 181.224.94.124:11311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkmBgAAAtQ"]
[Mon Jul 20 06:05:58.724093 2026] [security2:error] [pid 796928:tid 797060] [client 190.115.89.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4PJusTy9vX-htKvPkl_QAAAps"]
[Mon Jul 20 06:05:58.755396 2026] [security2:error] [pid 796567:tid 796677] [remote 57.141.18.35:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5852913"] [unique_id "al4PJrLfyzVz2SrjZpi6QgACh20"]
[Mon Jul 20 06:05:58.767437 2026] [security2:error] [pid 796567:tid 796678] [remote 188.166.241.141:36268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PJrLfyzVz2SrjZpi6QwACK24"]
[Mon Jul 20 06:05:59.044166 2026] [security2:error] [pid 796567:tid 796762] [client 104.234.53.78:38015] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6SAAAAlU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:59.044327 2026] [security2:error] [pid 796567:tid 796762] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6SAAAAlU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:59.239276 2026] [security2:error] [pid 796567:tid 796706] [client 216.73.217.138:51662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6SgACHSc"]
[Mon Jul 20 06:05:59.265737 2026] [security2:error] [pid 796928:tid 797039] [remote 20.153.140.50:52874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PJ-sTy9vX-htKvPkmJwACnm4"]
[Mon Jul 20 06:05:59.265886 2026] [security2:error] [pid 796928:tid 797063] [client 20.153.140.50:52874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PJ-sTy9vX-htKvPkmJwACnm4"]
[Mon Jul 20 06:05:59.269836 2026] [security2:error] [pid 796567:tid 796621] [remote 182.77.62.24:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6UQACWTU"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:05:59.276957 2026] [security2:error] [pid 796567:tid 796611] [remote 188.166.241.141:36268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6UgACays"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:05:59.294180 2026] [security2:error] [pid 796928:tid 796959] [remote 100.42.189.89:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PJ-sTy9vX-htKvPkmKgACmh4"]
[Mon Jul 20 06:05:59.498795 2026] [security2:error] [pid 796928:tid 797029] [remote 100.42.189.89:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PJ-sTy9vX-htKvPkmLgACoWQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:59.531960 2026] [security2:error] [pid 796928:tid 796958] [remote 8.217.108.67:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4PJ-sTy9vX-htKvPkmMgACyB0"]
[Mon Jul 20 06:05:59.796403 2026] [security2:error] [pid 796928:tid 797056] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4PJ-sTy9vX-htKvPkmQQACun8"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:06:00.146374 2026] [security2:error] [pid 796928:tid 797075] [client 185.132.186.55:53681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wsa.php"] [unique_id "al4PKOsTy9vX-htKvPkmVgAAAqo"]
[Mon Jul 20 06:06:00.177866 2026] [security2:error] [pid 796567:tid 796744] [client 57.141.18.27:52166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PI7LfyzVz2SrjZpi5yQACQx8"]
[Mon Jul 20 06:06:00.214453 2026] [security2:error] [pid 796928:tid 796929] [remote 8.217.108.67:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PKOsTy9vX-htKvPkmWQACzwA"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:06:00.565958 2026] [security2:error] [pid 796928:tid 797134] [client 14.225.17.146:61164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4PJ-sTy9vX-htKvPkmIQAAAuU"], referer: http://alaraycreative.com/Wordpress
[Mon Jul 20 06:06:00.608435 2026] [security2:error] [pid 796928:tid 797085] [client 57.141.18.27:52178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PI-sTy9vX-htKvPklRgACtDY"]
[Mon Jul 20 06:06:00.911295 2026] [security2:error] [pid 796928:tid 797100] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmWgAAAsM"]
[Mon Jul 20 06:06:01.047533 2026] [security2:error] [pid 796928:tid 797048] [remote 8.217.108.67:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4PKesTy9vX-htKvPkmegAConc"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 06:06:01.165319 2026] [security2:error] [pid 796928:tid 797092] [client 14.225.17.146:60419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmWwAAArs"], referer: http://kromosenergy.com/Wordpress
[Mon Jul 20 06:06:01.952690 2026] [security2:error] [pid 796928:tid 797062] [client 14.225.17.146:54351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4PJ-sTy9vX-htKvPkmIgAAAp0"]
[Mon Jul 20 06:06:01.969950 2026] [access_compat:error] [pid 796567:tid 796742] [client 183.47.107.100:46131] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:02.032929 2026] [security2:error] [pid 796928:tid 797118] [client 57.141.18.53:61890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJOsTy9vX-htKvPkloQAC1X0"]
[Mon Jul 20 06:06:02.103386 2026] [security2:error] [pid 796928:tid 797095] [client 57.141.18.59:26506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJOsTy9vX-htKvPklowACvmI"]
[Mon Jul 20 06:06:02.107282 2026] [security2:error] [pid 796928:tid 797083] [client 185.132.186.79:53803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "al4PKusTy9vX-htKvPkmqwAAArI"]
[Mon Jul 20 06:06:02.190429 2026] [access_compat:error] [pid 796928:tid 797128] [client 157.148.43.42:51755] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:02.276371 2026] [access_compat:error] [pid 796928:tid 797145] [client 157.148.43.160:59217] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:02.362847 2026] [security2:error] [pid 796567:tid 796790] [client 14.225.17.146:60843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4PKLLfyzVz2SrjZpi6jgAAAnE"], referer: http://bbwipartnerconference.com/Wordpress
[Mon Jul 20 06:06:02.402320 2026] [security2:error] [pid 796928:tid 797107] [client 14.225.17.146:60547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmpgAAAso"], referer: http://younutrition.gr/Wordpress
[Mon Jul 20 06:06:02.558333 2026] [security2:error] [pid 796928:tid 797015] [remote 185.22.228.25:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PKusTy9vX-htKvPkm1AACxlY"]
[Mon Jul 20 06:06:02.582966 2026] [security2:error] [pid 796928:tid 797176] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmqQADDxg"], referer: http://assasalnazaha.com/Wordpress
[Mon Jul 20 06:06:02.588086 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmtgAAAtg"]
[Mon Jul 20 06:06:02.592924 2026] [security2:error] [pid 796567:tid 796699] [client 57.141.18.93:51902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJbLfyzVz2SrjZpi6FQACFgs"]
[Mon Jul 20 06:06:02.877579 2026] [security2:error] [pid 796567:tid 796636] [remote 152.228.213.32:46844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PKrLfyzVz2SrjZpi60QACjkQ"]
[Mon Jul 20 06:06:02.877814 2026] [security2:error] [pid 796567:tid 796819] [client 152.228.213.32:46844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PKrLfyzVz2SrjZpi60QACjkQ"]
[Mon Jul 20 06:06:03.066646 2026] [security2:error] [pid 796928:tid 797159] [client 14.225.17.146:62535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkm7wAAAv4"], referer: http://falconarrowshop.com/Wordpress
[Mon Jul 20 06:06:03.100036 2026] [security2:error] [pid 796928:tid 797025] [remote 81.173.115.7:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4PK-sTy9vX-htKvPkm_QAC6WA"]
[Mon Jul 20 06:06:03.231683 2026] [security2:error] [pid 796928:tid 797183] [client 57.141.18.25:47214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJesTy9vX-htKvPkl2QADFmM"]
[Mon Jul 20 06:06:03.293632 2026] [security2:error] [pid 796928:tid 797016] [remote 81.173.115.7:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4PK-sTy9vX-htKvPknDwACzFc"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:06:03.480166 2026] [access_compat:error] [pid 796928:tid 797112] [client 157.148.59.84:58515] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:03.615994 2026] [security2:error] [pid 796567:tid 796572] [remote 49.13.1.223:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PK7LfyzVz2SrjZpi64AACbwQ"]
[Mon Jul 20 06:06:03.673411 2026] [security2:error] [pid 796567:tid 796769] [client 103.141.108.143:60059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PK7LfyzVz2SrjZpi65QAAAlw"]
[Mon Jul 20 06:06:03.674180 2026] [security2:error] [pid 796567:tid 796769] [client 103.141.108.143:60059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PK7LfyzVz2SrjZpi65QAAAlw"]
[Mon Jul 20 06:06:03.684959 2026] [security2:error] [pid 796567:tid 796623] [remote 162.19.86.63:45042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PK7LfyzVz2SrjZpi65gACWDc"]
[Mon Jul 20 06:06:03.798919 2026] [security2:error] [pid 796567:tid 796615] [remote 49.13.1.223:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PK7LfyzVz2SrjZpi68gACSC8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:03.840134 2026] [security2:error] [pid 796928:tid 797144] [client 106.192.104.4:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PK-sTy9vX-htKvPknOAAAAu8"]
[Mon Jul 20 06:06:03.840274 2026] [security2:error] [pid 796928:tid 797144] [client 106.192.104.4:62855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PK-sTy9vX-htKvPknOAAAAu8"]
[Mon Jul 20 06:06:03.883801 2026] [security2:error] [pid 796928:tid 797079] [client 14.173.22.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4PK-sTy9vX-htKvPknKgACrm8"]
[Mon Jul 20 06:06:04.011903 2026] [security2:error] [pid 796928:tid 797085] [client 98.159.234.160:23283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PLOsTy9vX-htKvPknPQAAArQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:04.044542 2026] [security2:error] [pid 796928:tid 797083] [client 185.132.186.55:41805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/firewall.php7"] [unique_id "al4PLOsTy9vX-htKvPknPwAAArI"]
[Mon Jul 20 06:06:04.220216 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:62439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4PK7LfyzVz2SrjZpi64QAAAhg"], referer: http://gearwaterproof.com/Wordpress
[Mon Jul 20 06:06:04.340185 2026] [security2:error] [pid 796567:tid 796708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PK7LfyzVz2SrjZpi69wAAAh8"]
[Mon Jul 20 06:06:04.359060 2026] [security2:error] [pid 796928:tid 797131] [client 57.141.18.88:20220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJ-sTy9vX-htKvPkmGQAC4nQ"]
[Mon Jul 20 06:06:04.410505 2026] [security2:error] [pid 796567:tid 796657] [remote 162.19.86.63:45042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PLLLfyzVz2SrjZpi7AQACflk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:04.471054 2026] [security2:error] [pid 796928:tid 797100] [client 150.228.148.150:24455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknVAAAAsM"]
[Mon Jul 20 06:06:04.478718 2026] [security2:error] [pid 796928:tid 797100] [client 150.228.148.150:24455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknVAAAAsM"]
[Mon Jul 20 06:06:04.690393 2026] [security2:error] [pid 796928:tid 797132] [client 103.95.123.246:17985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknXQAAAuM"]
[Mon Jul 20 06:06:04.690552 2026] [security2:error] [pid 796928:tid 797132] [client 103.95.123.246:17985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknXQAAAuM"]
[Mon Jul 20 06:06:04.771506 2026] [security2:error] [pid 796567:tid 796798] [client 57.141.18.109:60022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6VQACeUU"]
[Mon Jul 20 06:06:05.080303 2026] [security2:error] [pid 796928:tid 797125] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4PLesTy9vX-htKvPkndgAAAtw"]
[Mon Jul 20 06:06:05.091863 2026] [security2:error] [pid 796928:tid 797128] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-plain.php"] [unique_id "al4PLesTy9vX-htKvPkndwAAAt8"], referer: www.google.com
[Mon Jul 20 06:06:05.105832 2026] [security2:error] [pid 796567:tid 796772] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al4PLbLfyzVz2SrjZpi7EQAAAl8"], referer: www.google.com
[Mon Jul 20 06:06:05.151623 2026] [security2:error] [pid 796928:tid 797118] [client 112.213.160.112:8232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknewAAAtU"]
[Mon Jul 20 06:06:05.151742 2026] [security2:error] [pid 796928:tid 797118] [client 112.213.160.112:8232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknewAAAtU"]
[Mon Jul 20 06:06:05.475198 2026] [security2:error] [pid 796928:tid 797154] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/qywpeqnn.php"] [unique_id "al4PLesTy9vX-htKvPknkgAAAvk"], referer: www.google.com
[Mon Jul 20 06:06:05.574302 2026] [security2:error] [pid 796567:tid 796812] [client 185.242.3.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4PLbLfyzVz2SrjZpi7FgAAAoc"], referer: www.google.com
[Mon Jul 20 06:06:05.648125 2026] [security2:error] [pid 796928:tid 797073] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PLesTy9vX-htKvPknjQAAAqg"]
[Mon Jul 20 06:06:05.682283 2026] [security2:error] [pid 796928:tid 797156] [client 57.141.18.75:61098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmVwAC-3M"]
[Mon Jul 20 06:06:05.794919 2026] [security2:error] [pid 796928:tid 796984] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknqgAC9jc"]
[Mon Jul 20 06:06:05.795058 2026] [security2:error] [pid 796928:tid 797151] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknqgAC9jc"]
[Mon Jul 20 06:06:05.817880 2026] [security2:error] [pid 796928:tid 796945] [remote 185.22.228.25:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PLesTy9vX-htKvPknqwACnhA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:05.840013 2026] [security2:error] [pid 796928:tid 797053] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al4PLesTy9vX-htKvPknrAACnXw"], referer: www.google.com
[Mon Jul 20 06:06:05.869235 2026] [access_compat:error] [pid 796567:tid 796715] [client 182.117.61.83:42044] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:05.933888 2026] [security2:error] [pid 796928:tid 796978] [remote 154.61.75.100:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PLesTy9vX-htKvPknsAADCDE"]
[Mon Jul 20 06:06:05.942353 2026] [security2:error] [pid 796928:tid 797066] [client 57.141.18.91:44348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmaQACoVs"]
[Mon Jul 20 06:06:05.997234 2026] [security2:error] [pid 796567:tid 796717] [client 185.132.186.73:49407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sodium_compat/index.php"] [unique_id "al4PLbLfyzVz2SrjZpi7PQAAAig"]
[Mon Jul 20 06:06:06.243158 2026] [security2:error] [pid 796928:tid 797032] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-plain.php"] [unique_id "al4PLusTy9vX-htKvPkntgACnGc"], referer: www.google.com
[Mon Jul 20 06:06:06.479207 2026] [security2:error] [pid 796928:tid 796983] [remote 154.61.75.100:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PLusTy9vX-htKvPknwwADAjY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:06.483001 2026] [security2:error] [pid 796567:tid 796762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PLbLfyzVz2SrjZpi7OAAAAlU"]
[Mon Jul 20 06:06:06.542896 2026] [security2:error] [pid 796928:tid 797148] [client 104.234.53.93:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PLusTy9vX-htKvPknxwAAAvM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:06.621863 2026] [security2:error] [pid 796567:tid 796809] [client 115.246.21.170:45565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PLrLfyzVz2SrjZpi7XQAAAoQ"]
[Mon Jul 20 06:06:06.623356 2026] [security2:error] [pid 796567:tid 796809] [client 115.246.21.170:45565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PLrLfyzVz2SrjZpi7XQAAAoQ"]
[Mon Jul 20 06:06:06.633048 2026] [security2:error] [pid 796567:tid 796628] [remote 91.142.222.105:44772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PLrLfyzVz2SrjZpi7XAACYzw"]
[Mon Jul 20 06:06:06.750421 2026] [security2:error] [pid 796928:tid 797033] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/vfmzhqxh.php"] [unique_id "al4PLusTy9vX-htKvPkn0wAC-Gg"], referer: www.google.com
[Mon Jul 20 06:06:07.063948 2026] [security2:error] [pid 796567:tid 796594] [remote 91.142.222.105:44772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PL7LfyzVz2SrjZpi7cQACcxo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:07.130534 2026] [security2:error] [pid 796928:tid 797180] [client 103.77.203.233:57018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn3gAAAxM"]
[Mon Jul 20 06:06:07.130661 2026] [security2:error] [pid 796928:tid 797180] [client 103.77.203.233:57018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn3gAAAxM"]
[Mon Jul 20 06:06:07.195455 2026] [security2:error] [pid 796567:tid 796775] [client 50.116.65.227:10462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PL7LfyzVz2SrjZpi7cwAAAmI"]
[Mon Jul 20 06:06:07.209279 2026] [security2:error] [pid 796567:tid 796816] [client 50.116.65.227:10464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PL7LfyzVz2SrjZpi7dAAAAos"]
[Mon Jul 20 06:06:07.261621 2026] [security2:error] [pid 796928:tid 796943] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn5gACuA4"]
[Mon Jul 20 06:06:07.261791 2026] [security2:error] [pid 796928:tid 797089] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn5gACuA4"]
[Mon Jul 20 06:06:07.274867 2026] [security2:error] [pid 796928:tid 796947] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al4PL-sTy9vX-htKvPkn5wAC1BI"]
[Mon Jul 20 06:06:07.346113 2026] [security2:error] [pid 796928:tid 797064] [client 14.225.17.146:61019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4PLesTy9vX-htKvPknsQAAAp8"], referer: http://phillipbloch.com/Wordpress
[Mon Jul 20 06:06:07.487774 2026] [security2:error] [pid 796928:tid 797150] [client 57.141.18.41:64034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKesTy9vX-htKvPkmoQAC9W0"]
[Mon Jul 20 06:06:07.526758 2026] [security2:error] [pid 796928:tid 796942] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4PL-sTy9vX-htKvPkn-AAC-Q0"]
[Mon Jul 20 06:06:07.580827 2026] [security2:error] [pid 796928:tid 797179] [client 57.141.18.28:24432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmsQADEig"]
[Mon Jul 20 06:06:07.743088 2026] [security2:error] [pid 796567:tid 796701] [client 27.96.94.195:38290] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PL7LfyzVz2SrjZpi7hwAAAhg"]
[Mon Jul 20 06:06:07.743219 2026] [security2:error] [pid 796567:tid 796701] [client 27.96.94.195:38290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PL7LfyzVz2SrjZpi7hwAAAhg"]
[Mon Jul 20 06:06:07.938279 2026] [security2:error] [pid 796567:tid 796781] [client 185.132.186.95:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/content.php"] [unique_id "al4PL7LfyzVz2SrjZpi7lAAAAmg"]
[Mon Jul 20 06:06:07.995023 2026] [security2:error] [pid 796928:tid 796948] [remote 57.141.18.17:27472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkm5wADBxM"]
[Mon Jul 20 06:06:08.137057 2026] [security2:error] [pid 796928:tid 797093] [client 41.173.37.102:2270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBAAAArw"]
[Mon Jul 20 06:06:08.137539 2026] [security2:error] [pid 796928:tid 797093] [client 41.173.37.102:2270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBAAAArw"]
[Mon Jul 20 06:06:08.167224 2026] [security2:error] [pid 796928:tid 797061] [client 86.98.90.58:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBQAAApw"]
[Mon Jul 20 06:06:08.167377 2026] [security2:error] [pid 796928:tid 797061] [client 86.98.90.58:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBQAAApw"]
[Mon Jul 20 06:06:08.179758 2026] [security2:error] [pid 796567:tid 796577] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al4PMLLfyzVz2SrjZpi7pgACNQk"]
[Mon Jul 20 06:06:08.287570 2026] [security2:error] [pid 796928:tid 797153] [client 210.212.97.243:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBgAAAvg"]
[Mon Jul 20 06:06:08.287673 2026] [security2:error] [pid 796928:tid 797153] [client 210.212.97.243:10447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBgAAAvg"]
[Mon Jul 20 06:06:08.417918 2026] [security2:error] [pid 796928:tid 797050] [remote 57.141.18.98:56980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PK-sTy9vX-htKvPkm-wACoHk"]
[Mon Jul 20 06:06:08.831511 2026] [security2:error] [pid 796567:tid 796641] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al4PMLLfyzVz2SrjZpi73AACbUk"]
[Mon Jul 20 06:06:08.847194 2026] [security2:error] [pid 796567:tid 796743] [client 185.242.3.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4PMLLfyzVz2SrjZpi7ywAAAkI"], referer: www.google.com
[Mon Jul 20 06:06:09.171139 2026] [security2:error] [pid 796567:tid 796769] [client 14.225.17.146:49159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4PMLLfyzVz2SrjZpi7nAAAAlw"], referer: http://nikkidesigns.net/Wordpress
[Mon Jul 20 06:06:09.174413 2026] [security2:error] [pid 796567:tid 796815] [client 181.224.94.124:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi79wAAAoo"]
[Mon Jul 20 06:06:09.174561 2026] [security2:error] [pid 796567:tid 796815] [client 181.224.94.124:26510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi79wAAAoo"]
[Mon Jul 20 06:06:09.193871 2026] [security2:error] [pid 796567:tid 796582] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi7-gACbg4"]
[Mon Jul 20 06:06:09.194137 2026] [security2:error] [pid 796567:tid 796787] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi7-gACbg4"]
[Mon Jul 20 06:06:09.252696 2026] [security2:error] [pid 796928:tid 796951] [remote 57.141.18.97:23198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PK-sTy9vX-htKvPknMQAC7RY"]
[Mon Jul 20 06:06:09.903013 2026] [security2:error] [pid 796567:tid 796727] [client 185.132.186.91:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/lv.php"] [unique_id "al4PMbLfyzVz2SrjZpi8MwAAAjI"]
[Mon Jul 20 06:06:10.736658 2026] [fcgid:warn] [pid 796567:tid 796706] (70014)End of file found: [client 66.132.172.198:57494] mod_fcgid: can't get data from http client
[Mon Jul 20 06:06:10.747185 2026] [security2:error] [pid 796928:tid 796962] [remote 57.141.18.2:63756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PLesTy9vX-htKvPknegACoyE"]
[Mon Jul 20 06:06:11.498485 2026] [security2:error] [pid 796567:tid 796736] [client 152.39.234.39:44005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8oAACOyo"], referer: https://www.savilerowtravel.com/perfectly-portugal/
[Mon Jul 20 06:06:11.516954 2026] [security2:error] [pid 796567:tid 796731] [client 104.234.53.67:33745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PM7LfyzVz2SrjZpi8pwAAAjY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:11.587682 2026] [security2:error] [pid 796567:tid 796700] [client 13.221.132.12:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4PMrLfyzVz2SrjZpi8agAAAhc"]
[Mon Jul 20 06:06:11.628470 2026] [security2:error] [pid 796567:tid 796796] [client 13.221.132.12:24152] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/limber-de-leche-milk-ice-pops/"] [unique_id "al4PMrLfyzVz2SrjZpi8ZQAAAnc"]
[Mon Jul 20 06:06:11.634052 2026] [security2:error] [pid 796567:tid 796726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8lAAAAjE"]
[Mon Jul 20 06:06:11.852030 2026] [security2:error] [pid 796567:tid 796782] [client 185.132.186.72:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/js1.php"] [unique_id "al4PM7LfyzVz2SrjZpi8ygAAAmk"]
[Mon Jul 20 06:06:11.994412 2026] [security2:error] [pid 796928:tid 796990] [remote 57.141.18.106:41234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PLusTy9vX-htKvPknxAACyj0"]
[Mon Jul 20 06:06:12.047055 2026] [security2:error] [pid 796567:tid 796764] [client 161.30.4.84:43938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.4.30.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/xmlrpc.php"] [unique_id "al4PM7LfyzVz2SrjZpi81AAAAlc"]
[Mon Jul 20 06:06:12.047233 2026] [security2:error] [pid 796567:tid 796764] [client 161.30.4.84:43938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alaraycreative.com"] [uri "/xmlrpc.php"] [unique_id "al4PM7LfyzVz2SrjZpi81AAAAlc"]
[Mon Jul 20 06:06:12.181962 2026] [core:error] [pid 796567:tid 796739] [client 14.225.17.146:51011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:12.181986 2026] [core:error] [pid 796567:tid 796739] [client 14.225.17.146:51011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:12.225333 2026] [security2:error] [pid 796567:tid 796794] [client 57.141.18.22:59468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PLrLfyzVz2SrjZpi7ZAACdUo"]
[Mon Jul 20 06:06:12.554571 2026] [security2:error] [pid 796567:tid 796793] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi87gAAAnQ"]
[Mon Jul 20 06:06:12.767065 2026] [security2:error] [pid 796567:tid 796731] [client 43.172.196.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi9BgAAAjY"]
[Mon Jul 20 06:06:13.159889 2026] [security2:error] [pid 796567:tid 796705] [client 14.225.17.146:61657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8wQAAAhw"], referer: http://whiteoutcb.com/Wordpress
[Mon Jul 20 06:06:13.325486 2026] [security2:error] [pid 796567:tid 796797] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi9NAAAAng"]
[Mon Jul 20 06:06:13.595623 2026] [security2:error] [pid 796567:tid 796704] [client 57.141.18.47:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PL7LfyzVz2SrjZpi7jQACGy4"]
[Mon Jul 20 06:06:13.815448 2026] [security2:error] [pid 796567:tid 796729] [client 185.132.186.101:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/file.php"] [unique_id "al4PNbLfyzVz2SrjZpi9jAAAAjQ"]
[Mon Jul 20 06:06:13.892379 2026] [security2:error] [pid 796567:tid 796710] [client 14.225.17.146:62333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4PNbLfyzVz2SrjZpi9eQAAAiE"], referer: https://north-woods-engineering.com/Wordpress
[Mon Jul 20 06:06:14.122009 2026] [security2:error] [pid 796567:tid 796761] [client 14.225.17.146:63319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi82QAAAlQ"], referer: http://aberballet.co.uk/Wordpress
[Mon Jul 20 06:06:14.129797 2026] [security2:error] [pid 796567:tid 796759] [client 14.225.17.146:55420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4PNrLfyzVz2SrjZpi9pQAAAlI"], referer: http://thefriendlyspreadsheet.com/Wordpress
[Mon Jul 20 06:06:14.261139 2026] [security2:error] [pid 796567:tid 796753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNbLfyzVz2SrjZpi9igAAAkw"]
[Mon Jul 20 06:06:14.350273 2026] [security2:error] [pid 796567:tid 796783] [client 103.141.108.143:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi9xgAAAmo"]
[Mon Jul 20 06:06:14.350411 2026] [security2:error] [pid 796567:tid 796783] [client 103.141.108.143:60490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi9xgAAAmo"]
[Mon Jul 20 06:06:14.547758 2026] [security2:error] [pid 796567:tid 796720] [client 106.192.104.4:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91QAAAis"]
[Mon Jul 20 06:06:14.547886 2026] [security2:error] [pid 796567:tid 796720] [client 106.192.104.4:63353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91QAAAis"]
[Mon Jul 20 06:06:14.587108 2026] [security2:error] [pid 796567:tid 796723] [client 13.215.47.127:47346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91wAAAi4"]
[Mon Jul 20 06:06:14.587273 2026] [security2:error] [pid 796567:tid 796723] [client 13.215.47.127:47346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91wAAAi4"]
[Mon Jul 20 06:06:14.682040 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNrLfyzVz2SrjZpi9zAAAAmY"]
[Mon Jul 20 06:06:14.688629 2026] [security2:error] [pid 796567:tid 796816] [client 57.141.18.40:51344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMLLfyzVz2SrjZpi76AACiww"]
[Mon Jul 20 06:06:15.150263 2026] [security2:error] [pid 796567:tid 796770] [client 150.228.148.150:27650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi9_gAAAl0"]
[Mon Jul 20 06:06:15.154056 2026] [security2:error] [pid 796567:tid 796770] [client 150.228.148.150:27650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi9_gAAAl0"]
[Mon Jul 20 06:06:15.284118 2026] [autoindex:error] [pid 796567:tid 796702] [client 167.86.107.171:57374] AH01276: Cannot serve directory /home4/yjgjjlmy/public_html/omrobuildingcenter/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:06:15.448232 2026] [security2:error] [pid 796567:tid 796613] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IQACJS0"]
[Mon Jul 20 06:06:15.448395 2026] [security2:error] [pid 796567:tid 796714] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IQACJS0"]
[Mon Jul 20 06:06:15.464873 2026] [security2:error] [pid 796567:tid 796822] [client 103.95.123.246:18630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IwAAApE"]
[Mon Jul 20 06:06:15.465573 2026] [security2:error] [pid 796567:tid 796822] [client 103.95.123.246:18630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IwAAApE"]
[Mon Jul 20 06:06:15.490866 2026] [security2:error] [pid 796567:tid 796814] [client 57.141.18.84:55886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMbLfyzVz2SrjZpi8HAACiWw"]
[Mon Jul 20 06:06:15.612311 2026] [security2:error] [pid 796567:tid 796754] [client 57.141.18.78:29644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMbLfyzVz2SrjZpi8KAACTQQ"]
[Mon Jul 20 06:06:15.771156 2026] [security2:error] [pid 796567:tid 796706] [client 185.132.186.78:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "al4PN7LfyzVz2SrjZpi-QgAAAh0"]
[Mon Jul 20 06:06:15.853700 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PN7LfyzVz2SrjZpi-KwAAAmY"]
[Mon Jul 20 06:06:15.891333 2026] [security2:error] [pid 796567:tid 796644] [remote 154.120.133.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.133.120.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4PN7LfyzVz2SrjZpi-TQACREw"]
[Mon Jul 20 06:06:15.940912 2026] [security2:error] [pid 796567:tid 796769] [client 112.213.160.112:31041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-VAAAAlw"]
[Mon Jul 20 06:06:15.941009 2026] [security2:error] [pid 796567:tid 796769] [client 112.213.160.112:31041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-VAAAAlw"]
[Mon Jul 20 06:06:16.203436 2026] [security2:error] [pid 796567:tid 796749] [client 50.116.65.227:40950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4POLLfyzVz2SrjZpi-awAAAkg"]
[Mon Jul 20 06:06:16.214249 2026] [security2:error] [pid 796567:tid 796713] [client 50.116.65.227:40962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4POLLfyzVz2SrjZpi-bgAAAiQ"]
[Mon Jul 20 06:06:16.220149 2026] [security2:error] [pid 796567:tid 796737] [client 57.141.18.113:47536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMrLfyzVz2SrjZpi8VgACPFU"]
[Mon Jul 20 06:06:16.239358 2026] [security2:error] [pid 796567:tid 796709] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PN7LfyzVz2SrjZpi-XwAAAiA"]
[Mon Jul 20 06:06:16.406569 2026] [security2:error] [pid 796567:tid 796819] [client 14.225.17.146:50797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4POLLfyzVz2SrjZpi-cAAAAo4"]
[Mon Jul 20 06:06:16.464065 2026] [security2:error] [pid 796567:tid 796635] [remote 154.120.133.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.133.120.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4POLLfyzVz2SrjZpi-hAACR0M"], referer: https://benbayly.co.nz/wp-login.php
[Mon Jul 20 06:06:16.652511 2026] [security2:error] [pid 796567:tid 796732] [client 158.173.166.181:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4POLLfyzVz2SrjZpi-igAAAjc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:17.025008 2026] [security2:error] [pid 796567:tid 796742] [client 57.141.18.22:59474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8pAACQVY"]
[Mon Jul 20 06:06:17.222434 2026] [security2:error] [pid 796567:tid 796796] [client 115.246.21.170:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-uQAAAnc"]
[Mon Jul 20 06:06:17.224041 2026] [security2:error] [pid 796567:tid 796796] [client 115.246.21.170:1099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-uQAAAnc"]
[Mon Jul 20 06:06:17.345291 2026] [security2:error] [pid 796567:tid 796755] [client 43.173.178.125:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4PObLfyzVz2SrjZpi-vwAAAk4"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.362615 2026] [security2:error] [pid 796567:tid 796806] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PObLfyzVz2SrjZpi-twAAAoE"]
[Mon Jul 20 06:06:17.543319 2026] [security2:error] [pid 796567:tid 796800] [client 57.141.18.89:33588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8zAACe2c"]
[Mon Jul 20 06:06:17.555264 2026] [security2:error] [pid 796567:tid 796793] [client 103.77.203.233:57077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-2QAAAnQ"]
[Mon Jul 20 06:06:17.555824 2026] [security2:error] [pid 796567:tid 796793] [client 103.77.203.233:57077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-2QAAAnQ"]
[Mon Jul 20 06:06:17.680020 2026] [core:error] [pid 796567:tid 796636] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.680044 2026] [core:error] [pid 796567:tid 796636] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.681940 2026] [security2:error] [pid 796567:tid 796753] [client 43.173.182.189:57748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4PObLfyzVz2SrjZpi-5QAAAkw"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.687772 2026] [core:error] [pid 796567:tid 796570] [remote 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.687790 2026] [core:error] [pid 796567:tid 796570] [remote 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.713659 2026] [security2:error] [pid 796567:tid 796729] [client 185.132.186.82:39539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "al4PObLfyzVz2SrjZpi-6wAAAjQ"]
[Mon Jul 20 06:06:17.719540 2026] [security2:error] [pid 796567:tid 796786] [client 43.172.196.174:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4PObLfyzVz2SrjZpi-5wAAAm0"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.728199 2026] [core:error] [pid 796567:tid 796626] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.728496 2026] [core:error] [pid 796567:tid 796626] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.774063 2026] [security2:error] [pid 796567:tid 796646] [remote 103.75.185.95:39606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-8AACYE4"]
[Mon Jul 20 06:06:17.774270 2026] [security2:error] [pid 796567:tid 796773] [client 103.75.185.95:39606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-8AACYE4"]
[Mon Jul 20 06:06:17.777865 2026] [core:error] [pid 796567:tid 796634] [remote 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.777886 2026] [core:error] [pid 796567:tid 796634] [remote 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.819734 2026] [security2:error] [pid 796567:tid 796717] [client 50.116.65.227:11936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4PObLfyzVz2SrjZpi-_AAAAig"]
[Mon Jul 20 06:06:17.835556 2026] [security2:error] [pid 796567:tid 796780] [client 50.116.65.227:40996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4PObLfyzVz2SrjZpi-_QAAAik"]
[Mon Jul 20 06:06:17.956114 2026] [security2:error] [pid 796567:tid 796699] [client 43.173.181.77:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PObLfyzVz2SrjZpi_BwAAAhY"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.969140 2026] [security2:error] [pid 796567:tid 796597] [remote 5.161.225.162:47258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PObLfyzVz2SrjZpi_DwACgR0"]
[Mon Jul 20 06:06:17.982269 2026] [security2:error] [pid 796567:tid 796805] [client 43.173.182.221:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PObLfyzVz2SrjZpi_EAAAAoA"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:18.055446 2026] [security2:error] [pid 796567:tid 796656] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_EwACe1g"]
[Mon Jul 20 06:06:18.055656 2026] [security2:error] [pid 796567:tid 796800] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_EwACe1g"]
[Mon Jul 20 06:06:18.134177 2026] [security2:error] [pid 796567:tid 796747] [client 57.141.18.62:30914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi88QACRmo"]
[Mon Jul 20 06:06:18.213410 2026] [security2:error] [pid 796567:tid 796637] [remote 5.161.225.162:47258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_HQACSEU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:06:18.226244 2026] [security2:error] [pid 796567:tid 796707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PObLfyzVz2SrjZpi-_gAAAh4"]
[Mon Jul 20 06:06:18.312080 2026] [security2:error] [pid 796567:tid 796717] [client 43.173.180.199:57562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4POrLfyzVz2SrjZpi_JgAAAig"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:18.428990 2026] [security2:error] [pid 796567:tid 796587] [remote 124.55.178.99:34162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_NwACfhM"]
[Mon Jul 20 06:06:18.613960 2026] [security2:error] [pid 796567:tid 796767] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4POrLfyzVz2SrjZpi_MgAAAlo"]
[Mon Jul 20 06:06:18.728599 2026] [security2:error] [pid 796567:tid 796771] [client 41.173.37.102:2727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_TQAAAl4"]
[Mon Jul 20 06:06:18.728704 2026] [security2:error] [pid 796567:tid 796771] [client 41.173.37.102:2727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_TQAAAl4"]
[Mon Jul 20 06:06:18.846222 2026] [security2:error] [pid 796567:tid 796725] [client 210.212.97.243:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_XAAAAjA"]
[Mon Jul 20 06:06:18.846382 2026] [security2:error] [pid 796567:tid 796725] [client 210.212.97.243:10448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_XAAAAjA"]
[Mon Jul 20 06:06:18.879784 2026] [security2:error] [pid 796567:tid 796680] [remote 124.55.178.99:34162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_XgACR3A"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:06:18.938858 2026] [security2:error] [pid 796567:tid 796625] [remote 124.55.178.99:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_ZgACiDk"]
[Mon Jul 20 06:06:19.031214 2026] [security2:error] [pid 796567:tid 796717] [client 178.152.178.232:35985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_bgAAAig"]
[Mon Jul 20 06:06:19.031333 2026] [security2:error] [pid 796567:tid 796717] [client 178.152.178.232:35985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_bgAAAig"]
[Mon Jul 20 06:06:19.050695 2026] [security2:error] [pid 796567:tid 796712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4POrLfyzVz2SrjZpi_WwAAAiM"]
[Mon Jul 20 06:06:19.315745 2026] [security2:error] [pid 796567:tid 796609] [remote 5.252.52.249:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PO7LfyzVz2SrjZpi_iwACgyk"]
[Mon Jul 20 06:06:19.366348 2026] [security2:error] [pid 796567:tid 796590] [remote 124.55.178.99:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PO7LfyzVz2SrjZpi_kgACJhY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:19.506774 2026] [security2:error] [pid 796567:tid 796796] [client 27.96.94.195:37763] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_nAAAAnc"]
[Mon Jul 20 06:06:19.506913 2026] [security2:error] [pid 796567:tid 796796] [client 27.96.94.195:37763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_nAAAAnc"]
[Mon Jul 20 06:06:19.512008 2026] [security2:error] [pid 796567:tid 796638] [remote 5.252.52.249:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PO7LfyzVz2SrjZpi_nQACIUY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:19.569303 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_hwAAAmY"]
[Mon Jul 20 06:06:19.657958 2026] [security2:error] [pid 796567:tid 796777] [client 185.132.186.85:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/autoload_classmap.php"] [unique_id "al4PO7LfyzVz2SrjZpi_owAAAmQ"]
[Mon Jul 20 06:06:19.724205 2026] [security2:error] [pid 796567:tid 796760] [client 181.224.94.124:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_pgAAAlM"]
[Mon Jul 20 06:06:19.724377 2026] [security2:error] [pid 796567:tid 796760] [client 181.224.94.124:55672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_pgAAAlM"]
[Mon Jul 20 06:06:19.851911 2026] [security2:error] [pid 796567:tid 796677] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_tgACMG0"]
[Mon Jul 20 06:06:19.852059 2026] [security2:error] [pid 796567:tid 796725] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_tgACMG0"]
[Mon Jul 20 06:06:19.870569 2026] [security2:error] [pid 796567:tid 796704] [client 14.225.17.146:54308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_rAAAAhs"], referer: http://daseighty.net/Wordpress
[Mon Jul 20 06:06:20.215437 2026] [security2:error] [pid 796567:tid 796811] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_qwAAAoY"]
[Mon Jul 20 06:06:20.343822 2026] [proxy:error] [pid 796567:tid 796804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:20.343881 2026] [proxy_http:error] [pid 796567:tid 796804] [client 198.235.24.147:59458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:20.344981 2026] [proxy:error] [pid 796567:tid 796804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:20.345006 2026] [proxy_http:error] [pid 796567:tid 796804] [client 198.235.24.147:59458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:20.354816 2026] [security2:error] [pid 796567:tid 796603] [remote 182.77.62.24:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PPLLfyzVz2SrjZpi_4wACJiM"]
[Mon Jul 20 06:06:20.481050 2026] [security2:error] [pid 796567:tid 796784] [client 57.141.18.17:60240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PNrLfyzVz2SrjZpi96QACa2Q"]
[Mon Jul 20 06:06:20.485154 2026] [core:error] [pid 796567:tid 796643] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:20.485209 2026] [core:error] [pid 796567:tid 796643] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:20.869390 2026] [security2:error] [pid 796567:tid 796809] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PPLLfyzVz2SrjZpi_-QAAAoQ"]
[Mon Jul 20 06:06:20.887465 2026] [security2:error] [pid 796567:tid 796582] [remote 182.77.62.24:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PPLLfyzVz2SrjZpjACgAChw4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:06:21.076819 2026] [security2:error] [pid 796567:tid 796746] [client 86.98.90.58:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PPbLfyzVz2SrjZpjAGgAAAkU"]
[Mon Jul 20 06:06:21.077310 2026] [security2:error] [pid 796567:tid 796746] [client 86.98.90.58:60458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PPbLfyzVz2SrjZpjAGgAAAkU"]
[Mon Jul 20 06:06:21.189676 2026] [security2:error] [pid 796567:tid 796716] [client 43.173.173.32:36020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4PPbLfyzVz2SrjZpjAIwAAAic"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.199425 2026] [security2:error] [pid 796567:tid 796763] [client 43.173.179.57:60554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4PPbLfyzVz2SrjZpjAJAAAAlY"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.370570 2026] [security2:error] [pid 796567:tid 796780] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjAHAAAAmc"]
[Mon Jul 20 06:06:21.515432 2026] [security2:error] [pid 796567:tid 796749] [client 14.225.17.146:50095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjALwAAAkg"], referer: http://sarahsnyder.net/Wordpress
[Mon Jul 20 06:06:21.541728 2026] [security2:error] [pid 796567:tid 796797] [client 43.172.197.103:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PPbLfyzVz2SrjZpjARgAAAng"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.609828 2026] [security2:error] [pid 796567:tid 796784] [client 185.132.186.62:45593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/wp-conflg.php"] [unique_id "al4PPbLfyzVz2SrjZpjAUAAAAms"]
[Mon Jul 20 06:06:21.652131 2026] [security2:error] [pid 796567:tid 796712] [client 43.172.196.207:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4PPbLfyzVz2SrjZpjAVQAAAiM"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.670051 2026] [security2:error] [pid 796567:tid 796597] [remote 192.241.143.148:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PPbLfyzVz2SrjZpjAVwACbh0"]
[Mon Jul 20 06:06:21.701469 2026] [security2:error] [pid 796567:tid 796772] [client 69.171.230.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rentorangegrove.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjARQAAAl8"]
[Mon Jul 20 06:06:21.837061 2026] [security2:error] [pid 796567:tid 796730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjAQgAAAjU"]
[Mon Jul 20 06:06:21.842085 2026] [security2:error] [pid 796567:tid 796651] [remote 192.241.143.148:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PPbLfyzVz2SrjZpjAZgACUFM"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:06:22.498825 2026] [security2:error] [pid 796567:tid 796780] [client 54.244.177.189:30926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4PPrLfyzVz2SrjZpjAlwAAAmc"]
[Mon Jul 20 06:06:22.539848 2026] [security2:error] [pid 796567:tid 796792] [client 14.225.17.146:61637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAjgAAAnM"], referer: https://sarahsnyder.net/Wordpress
[Mon Jul 20 06:06:22.693542 2026] [security2:error] [pid 796567:tid 796742] [client 23.251.146.115:13216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAnQACQU0"]
[Mon Jul 20 06:06:22.697927 2026] [security2:error] [pid 796567:tid 796773] [client 23.251.146.115:58432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAnwACYBQ"]
[Mon Jul 20 06:06:22.802218 2026] [security2:error] [pid 796567:tid 796769] [client 23.251.146.115:13216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjArQACXDk"]
[Mon Jul 20 06:06:22.803663 2026] [security2:error] [pid 796567:tid 796746] [client 23.251.146.115:58432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAsAACRSQ"]
[Mon Jul 20 06:06:22.960939 2026] [security2:error] [pid 796567:tid 796700] [client 57.141.18.2:64692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PObLfyzVz2SrjZpi-sAACF2M"]
[Mon Jul 20 06:06:22.969029 2026] [security2:error] [pid 796567:tid 796821] [client 45.157.112.60:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PPrLfyzVz2SrjZpjAwwAAApA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:23.056889 2026] [security2:error] [pid 796567:tid 796809] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAxAAAAoQ"]
[Mon Jul 20 06:06:23.072382 2026] [security2:error] [pid 796567:tid 796775] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PP7LfyzVz2SrjZpjAyAAAAmI"]
[Mon Jul 20 06:06:23.215883 2026] [security2:error] [pid 796567:tid 796594] [remote 8.217.108.67:57016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PP7LfyzVz2SrjZpjA1gACFho"]
[Mon Jul 20 06:06:23.556346 2026] [security2:error] [pid 796567:tid 796808] [client 185.132.186.99:53309] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "harborhealth.us"] [uri "/wp-admin/theme-editor.php"] [unique_id "al4PP7LfyzVz2SrjZpjA8QAAAoM"]
[Mon Jul 20 06:06:23.925978 2026] [security2:error] [pid 796567:tid 796790] [client 34.31.203.120:12944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PP7LfyzVz2SrjZpjBDgACcUg"]
[Mon Jul 20 06:06:23.926371 2026] [security2:error] [pid 796567:tid 796783] [client 103.153.183.69:1472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//var/www/html/config.php"] [unique_id "al4PP7LfyzVz2SrjZpjBGQAAAmo"], referer: https://twitter.com/
[Mon Jul 20 06:06:24.031226 2026] [security2:error] [pid 796567:tid 796595] [remote 173.249.4.11:21773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBLQACYxs"]
[Mon Jul 20 06:06:24.037145 2026] [security2:error] [pid 796567:tid 796771] [client 34.31.203.120:12944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PP7LfyzVz2SrjZpjBIQACXkk"]
[Mon Jul 20 06:06:24.047275 2026] [security2:error] [pid 796567:tid 796603] [remote 152.228.213.32:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBLgACiSM"]
[Mon Jul 20 06:06:24.067262 2026] [core:error] [pid 796567:tid 796730] [client 8.229.3.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:24.067291 2026] [core:error] [pid 796567:tid 796730] [client 8.229.3.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:24.254092 2026] [security2:error] [pid 796567:tid 796686] [remote 173.249.4.11:21773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBQQACbHY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:06:24.264056 2026] [security2:error] [pid 796567:tid 796607] [remote 152.228.213.32:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBRAACKyc"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:06:24.268046 2026] [security2:error] [pid 796567:tid 796578] [remote 216.73.217.138:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4PQLLfyzVz2SrjZpjBPwACRwo"]
[Mon Jul 20 06:06:24.293019 2026] [security2:error] [pid 796567:tid 796822] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PQLLfyzVz2SrjZpjBPgAAApE"]
[Mon Jul 20 06:06:24.352190 2026] [security2:error] [pid 796567:tid 796593] [remote 8.217.108.67:57016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBUAACMxk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:24.369385 2026] [security2:error] [pid 796567:tid 796639] [remote 152.228.213.32:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBVAACMkc"]
[Mon Jul 20 06:06:24.474988 2026] [security2:error] [pid 796567:tid 796801] [client 8.229.3.76:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.3.229.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "beta.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4PQLLfyzVz2SrjZpjBXQAAAnw"]
[Mon Jul 20 06:06:24.595916 2026] [security2:error] [pid 796567:tid 796664] [remote 152.228.213.32:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBawACKmA"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:06:24.693952 2026] [security2:error] [pid 796567:tid 796769] [client 8.229.3.76:59126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4PQLLfyzVz2SrjZpjBdgAAAlw"]
[Mon Jul 20 06:06:24.701562 2026] [security2:error] [pid 796567:tid 796807] [client 104.234.53.48:62671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PQLLfyzVz2SrjZpjBbgAAAoI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:24.875626 2026] [security2:error] [pid 796567:tid 796788] [client 8.229.3.76:60685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4PQLLfyzVz2SrjZpjBigAAAm8"]
[Mon Jul 20 06:06:25.061158 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBngAAAiA"]
[Mon Jul 20 06:06:25.061468 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:60932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBngAAAiA"]
[Mon Jul 20 06:06:25.077184 2026] [security2:error] [pid 796567:tid 796655] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBmQACKFc"]
[Mon Jul 20 06:06:25.077456 2026] [security2:error] [pid 796567:tid 796717] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBmQACKFc"]
[Mon Jul 20 06:06:25.102641 2026] [security2:error] [pid 796567:tid 796795] [client 8.229.3.76:62023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjBpQAAAnY"]
[Mon Jul 20 06:06:25.114401 2026] [security2:error] [pid 796567:tid 796739] [client 106.192.104.4:63832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBqAAAAj4"]
[Mon Jul 20 06:06:25.114527 2026] [security2:error] [pid 796567:tid 796739] [client 106.192.104.4:63832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBqAAAAj4"]
[Mon Jul 20 06:06:25.143594 2026] [security2:error] [pid 796567:tid 796651] [remote 192.241.143.148:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjBrQACilM"]
[Mon Jul 20 06:06:25.280687 2026] [security2:error] [pid 796567:tid 796718] [client 57.141.18.32:49594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_dAACKXM"]
[Mon Jul 20 06:06:25.301315 2026] [security2:error] [pid 796567:tid 796656] [remote 100.42.189.89:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjBtwACQ1g"]
[Mon Jul 20 06:06:25.304129 2026] [security2:error] [pid 796567:tid 796792] [client 8.229.3.76:56079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjBuAAAAnM"]
[Mon Jul 20 06:06:25.346698 2026] [security2:error] [pid 796567:tid 796657] [remote 192.241.143.148:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjBvgACSVk"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:06:25.456547 2026] [security2:error] [pid 796567:tid 796794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjBpwAAAnU"], referer: 1'"3000
[Mon Jul 20 06:06:25.509666 2026] [security2:error] [pid 796567:tid 796795] [client 185.132.186.53:23007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/abc.php"] [unique_id "al4PQbLfyzVz2SrjZpjB0AAAAnY"]
[Mon Jul 20 06:06:25.523563 2026] [security2:error] [pid 796567:tid 796690] [remote 100.42.189.89:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjB0gACgXo"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 06:06:25.540579 2026] [security2:error] [pid 796567:tid 796779] [client 8.229.3.76:61912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjB1AAAAmY"]
[Mon Jul 20 06:06:25.541199 2026] [security2:error] [pid 796567:tid 796775] [client 40.77.167.79:36379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjBywACYhM"]
[Mon Jul 20 06:06:25.727134 2026] [security2:error] [pid 796567:tid 796730] [client 8.229.3.76:50974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjB7wAAAjU"]
[Mon Jul 20 06:06:25.741951 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:9432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjB8AAAAmA"]
[Mon Jul 20 06:06:25.745610 2026] [security2:error] [pid 796567:tid 796736] [client 104.28.219.194:14358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dev.cira.org"] [uri "/.env"] [unique_id "al4PQbLfyzVz2SrjZpjB9gAAAjs"]
[Mon Jul 20 06:06:25.749741 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:9432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjB8AAAAmA"]
[Mon Jul 20 06:06:25.903564 2026] [security2:error] [pid 796567:tid 796733] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjB5wAAAjg"], referer: 1'"3000
[Mon Jul 20 06:06:25.907604 2026] [security2:error] [pid 796567:tid 796808] [client 8.229.3.76:60002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjCCAAAAoM"]
[Mon Jul 20 06:06:25.950065 2026] [security2:error] [pid 796567:tid 796731] [client 114.119.128.233:42375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/robots.txt"] [unique_id "al4PQbLfyzVz2SrjZpjCDQAAAjY"], referer: http://www.sarakety.com/robots.txt
[Mon Jul 20 06:06:25.969933 2026] [security2:error] [pid 796567:tid 796625] [remote 167.233.114.32:36308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjCDwACKzk"]
[Mon Jul 20 06:06:26.051460 2026] [security2:error] [pid 796567:tid 796613] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCFQACZy0"]
[Mon Jul 20 06:06:26.051637 2026] [security2:error] [pid 796567:tid 796780] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCFQACZy0"]
[Mon Jul 20 06:06:26.070686 2026] [security2:error] [pid 796567:tid 796737] [client 50.116.65.227:19620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PQrLfyzVz2SrjZpjCGAAAAjw"]
[Mon Jul 20 06:06:26.080522 2026] [security2:error] [pid 796567:tid 796819] [client 50.116.65.227:19630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PQrLfyzVz2SrjZpjCGQAAAo4"]
[Mon Jul 20 06:06:26.175839 2026] [security2:error] [pid 796567:tid 796746] [client 8.229.3.76:60488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCMgAAAkU"]
[Mon Jul 20 06:06:26.256498 2026] [security2:error] [pid 796567:tid 796699] [client 188.161.209.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjCDAAAAhY"]
[Mon Jul 20 06:06:26.299458 2026] [security2:error] [pid 796567:tid 796629] [remote 167.233.114.32:36308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCOgACgD0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:06:26.300286 2026] [security2:error] [pid 796567:tid 796600] [remote 84.247.172.23:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCOQACYCA"]
[Mon Jul 20 06:06:26.373212 2026] [security2:error] [pid 796567:tid 796703] [client 8.229.3.76:52225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCRQAAAho"]
[Mon Jul 20 06:06:26.394914 2026] [security2:error] [pid 796567:tid 796807] [client 14.225.17.146:50587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCJgAAAoI"], referer: http://idigress.agency/Wordpress
[Mon Jul 20 06:06:26.414121 2026] [security2:error] [pid 796567:tid 796794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCMwAAAnU"], referer: 1'"3000
[Mon Jul 20 06:06:26.465347 2026] [security2:error] [pid 796567:tid 796590] [remote 95.217.78.234:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCSwACjBY"]
[Mon Jul 20 06:06:26.492331 2026] [security2:error] [pid 796567:tid 796644] [remote 84.247.172.23:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCTgACWEw"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:06:26.533031 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/feed/d1psu8ztljg3.php"] [unique_id "al4PQrLfyzVz2SrjZpjCVQAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:26.541700 2026] [security2:error] [pid 796567:tid 796751] [client 8.229.3.76:64774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCXAAAAko"]
[Mon Jul 20 06:06:26.628979 2026] [security2:error] [pid 796567:tid 796748] [client 103.95.123.246:19128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCZAAAAkc"]
[Mon Jul 20 06:06:26.629125 2026] [security2:error] [pid 796567:tid 796748] [client 103.95.123.246:19128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCZAAAAkc"]
[Mon Jul 20 06:06:26.665619 2026] [security2:error] [pid 796567:tid 796731] [client 112.213.160.112:8289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCaQAAAjY"]
[Mon Jul 20 06:06:26.666333 2026] [security2:error] [pid 796567:tid 796731] [client 112.213.160.112:8289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCaQAAAjY"]
[Mon Jul 20 06:06:26.707665 2026] [security2:error] [pid 796567:tid 796759] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCXgAAAlI"]
[Mon Jul 20 06:06:26.721467 2026] [security2:error] [pid 796567:tid 796653] [remote 95.217.78.234:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCcwACS1U"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:06:26.759795 2026] [security2:error] [pid 796567:tid 796819] [client 104.234.53.48:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCdgAAAo4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:26.822529 2026] [security2:error] [pid 796567:tid 796730] [client 8.229.3.76:55395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCeAAAAjU"]
[Mon Jul 20 06:06:27.014585 2026] [security2:error] [pid 796567:tid 796660] [remote 72.167.132.114:42556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCiwACGlw"]
[Mon Jul 20 06:06:27.044857 2026] [security2:error] [pid 796567:tid 796814] [client 8.229.3.76:59845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4PQ7LfyzVz2SrjZpjCjwAAAok"]
[Mon Jul 20 06:06:27.225353 2026] [security2:error] [pid 796567:tid 796786] [client 57.141.18.63:28832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjAIQACbRE"]
[Mon Jul 20 06:06:27.253604 2026] [security2:error] [pid 796567:tid 796689] [remote 72.167.132.114:42556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCpAACMXk"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:06:27.333218 2026] [security2:error] [pid 796567:tid 796733] [client 77.110.127.138:55690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCVwAAAjg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.422946 2026] [security2:error] [pid 796567:tid 796818] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCYQAAAo0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.428588 2026] [security2:error] [pid 796567:tid 796749] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCbgAAAkg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.561776 2026] [security2:error] [pid 796567:tid 796736] [client 77.110.127.138:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/testimonials/mx47788438ef.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCzwAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.769774 2026] [security2:error] [pid 796567:tid 796708] [client 77.110.127.138:55662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCzQAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.771361 2026] [security2:error] [pid 796567:tid 796709] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC1gAAAiA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.822290 2026] [security2:error] [pid 796567:tid 796790] [client 115.246.21.170:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC5QAAAnE"]
[Mon Jul 20 06:06:27.822383 2026] [security2:error] [pid 796567:tid 796790] [client 115.246.21.170:33234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC5QAAAnE"]
[Mon Jul 20 06:06:27.842639 2026] [security2:error] [pid 796567:tid 796706] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC1AAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.022425 2026] [security2:error] [pid 796567:tid 796791] [client 103.77.203.233:57137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PRLLfyzVz2SrjZpjC-QAAAnI"]
[Mon Jul 20 06:06:28.022537 2026] [security2:error] [pid 796567:tid 796791] [client 103.77.203.233:57137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PRLLfyzVz2SrjZpjC-QAAAnI"]
[Mon Jul 20 06:06:28.270129 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/501/k81p0h0fcv2n.php"] [unique_id "al4PRLLfyzVz2SrjZpjDEQAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.358877 2026] [http2:info] [pid 832668:tid 832668] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:06:28.383969 2026] [security2:error] [pid 796567:tid 796817] [client 158.173.89.95:24119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PRLLfyzVz2SrjZpjDKQAAAow"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:28.487990 2026] [security2:error] [pid 796567:tid 796697] [client 77.110.127.138:55667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDEgAAAhQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.499556 2026] [security2:error] [pid 796567:tid 796728] [client 185.132.186.100:61739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/wonder.php"] [unique_id "al4PRLLfyzVz2SrjZpjDNAAAAjM"]
[Mon Jul 20 06:06:28.550921 2026] [security2:error] [pid 832668:tid 832672] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PRGci6KgEEltqA3C24gAAAQE"]
[Mon Jul 20 06:06:28.551086 2026] [security2:error] [pid 832668:tid 832801] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PRGci6KgEEltqA3C24gAAAQE"]
[Mon Jul 20 06:06:28.725120 2026] [security2:error] [pid 796567:tid 796774] [client 14.225.17.146:56305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDNQAAAmE"], referer: http://windowtx.com/Wordpress
[Mon Jul 20 06:06:28.795124 2026] [security2:error] [pid 796567:tid 796795] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDJwAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.833538 2026] [security2:error] [pid 796567:tid 796821] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDJQAAApA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.950825 2026] [security2:error] [pid 832668:tid 832673] [remote 188.40.28.4:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRGci6KgEEltqA3C27AAAEAI"]
[Mon Jul 20 06:06:29.126897 2026] [security2:error] [pid 832668:tid 832805] [client 27.96.94.195:38281] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C28gAAAAU"]
[Mon Jul 20 06:06:29.127038 2026] [security2:error] [pid 832668:tid 832805] [client 27.96.94.195:38281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C28gAAAAU"]
[Mon Jul 20 06:06:29.157270 2026] [security2:error] [pid 832668:tid 832674] [remote 188.40.28.4:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRWci6KgEEltqA3C29QAALQM"], referer: https://vyx.sbv.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:29.329043 2026] [security2:error] [pid 796567:tid 796765] [client 210.212.97.243:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PRbLfyzVz2SrjZpjDYAAAAlg"]
[Mon Jul 20 06:06:29.329129 2026] [security2:error] [pid 832668:tid 832834] [client 41.173.37.102:3175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C2-AAAACI"]
[Mon Jul 20 06:06:29.329151 2026] [security2:error] [pid 796567:tid 796765] [client 210.212.97.243:10449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PRbLfyzVz2SrjZpjDYAAAAlg"]
[Mon Jul 20 06:06:29.329230 2026] [security2:error] [pid 832668:tid 832834] [client 41.173.37.102:3175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C2-AAAACI"]
[Mon Jul 20 06:06:29.474863 2026] [security2:error] [pid 832668:tid 832848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRWci6KgEEltqA3C29wAAADA"], referer: 1'"3000
[Mon Jul 20 06:06:29.556967 2026] [core:error] [pid 796567:tid 796730] [client 14.225.17.146:54549] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:29.556995 2026] [core:error] [pid 796567:tid 796730] [client 14.225.17.146:54549] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:29.691076 2026] [security2:error] [pid 832668:tid 832853] [client 178.152.178.232:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C3BwAAADU"]
[Mon Jul 20 06:06:29.691196 2026] [security2:error] [pid 832668:tid 832853] [client 178.152.178.232:37589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C3BwAAADU"]
[Mon Jul 20 06:06:29.866878 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRbLfyzVz2SrjZpjDfgAAAl0"], referer: 1'"3000
[Mon Jul 20 06:06:29.926390 2026] [security2:error] [pid 796567:tid 796810] [client 14.225.17.146:52944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCvgAAAoU"], referer: http://fineartsfactory.net/Wordpress
[Mon Jul 20 06:06:30.015264 2026] [security2:error] [pid 796567:tid 796710] [client 57.141.18.124:20412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PQLLfyzVz2SrjZpjBUgACISw"]
[Mon Jul 20 06:06:30.264406 2026] [security2:error] [pid 832668:tid 832909] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3FAAAAG0"], referer: 1'"3000
[Mon Jul 20 06:06:30.295191 2026] [security2:error] [pid 796567:tid 796797] [client 181.224.94.124:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDpAAAAng"]
[Mon Jul 20 06:06:30.295336 2026] [security2:error] [pid 796567:tid 796797] [client 181.224.94.124:10194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDpAAAAng"]
[Mon Jul 20 06:06:30.327900 2026] [security2:error] [pid 832668:tid 832681] [remote 115.79.143.180:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3HAAAXwo"]
[Mon Jul 20 06:06:30.344930 2026] [security2:error] [pid 832668:tid 832922] [client 74.7.227.179:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3GwAAegg"], referer: https://tejasenvironmental.com/p=537057
[Mon Jul 20 06:06:30.375743 2026] [security2:error] [pid 832668:tid 832680] [remote 45.90.123.233:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3IAAAdQk"]
[Mon Jul 20 06:06:30.457420 2026] [security2:error] [pid 796567:tid 796707] [client 185.132.186.82:59625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/wonder.php"] [unique_id "al4PRrLfyzVz2SrjZpjDrQAAAh4"]
[Mon Jul 20 06:06:30.510894 2026] [security2:error] [pid 796567:tid 796667] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDrgACN2M"]
[Mon Jul 20 06:06:30.511087 2026] [security2:error] [pid 796567:tid 796732] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDrgACN2M"]
[Mon Jul 20 06:06:30.587393 2026] [security2:error] [pid 832668:tid 832683] [remote 45.90.123.233:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3KQAAGgw"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:30.753569 2026] [security2:error] [pid 832668:tid 832684] [remote 115.79.143.180:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3LQAAKw0"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:06:30.789271 2026] [security2:error] [pid 832668:tid 832801] [client 14.225.17.146:56295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3KwAAAAE"], referer: http://mtlegnews.gov/Wordpress
[Mon Jul 20 06:06:31.225830 2026] [security2:error] [pid 832668:tid 832840] [client 14.225.17.146:54176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3MAAAACg"], referer: http://webgardensbypaula.com/Wordpress
[Mon Jul 20 06:06:31.265761 2026] [security2:error] [pid 832668:tid 832880] [client 50.116.65.227:25470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/05/IMG_3889.jpeg"] [unique_id "al4PR2ci6KgEEltqA3C3PAAAAE8"]
[Mon Jul 20 06:06:31.787193 2026] [security2:error] [pid 796567:tid 796595] [remote 20.153.140.50:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PR7LfyzVz2SrjZpjD5gACZhs"]
[Mon Jul 20 06:06:31.929955 2026] [security2:error] [pid 796567:tid 796816] [client 104.234.53.47:29661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PR7LfyzVz2SrjZpjD7AAAAos"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:32.221464 2026] [security2:error] [pid 796567:tid 796614] [remote 20.153.140.50:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PSLLfyzVz2SrjZpjD_gACOC4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:06:32.401631 2026] [security2:error] [pid 796567:tid 796821] [client 86.98.90.58:61268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PSLLfyzVz2SrjZpjEBQAAApA"]
[Mon Jul 20 06:06:32.401745 2026] [security2:error] [pid 796567:tid 796821] [client 86.98.90.58:61268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PSLLfyzVz2SrjZpjEBQAAApA"]
[Mon Jul 20 06:06:32.409488 2026] [security2:error] [pid 796567:tid 796740] [client 185.132.186.99:21651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/fix/as.php"] [unique_id "al4PSLLfyzVz2SrjZpjECAAAAj8"]
[Mon Jul 20 06:06:32.469111 2026] [security2:error] [pid 796567:tid 796601] [remote 81.173.115.7:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PSLLfyzVz2SrjZpjECwACkiE"]
[Mon Jul 20 06:06:32.670125 2026] [security2:error] [pid 796567:tid 796659] [remote 81.173.115.7:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PSLLfyzVz2SrjZpjEEQACL1s"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:32.798765 2026] [security2:error] [pid 796567:tid 796812] [client 57.141.18.9:21934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCjAACh3U"]
[Mon Jul 20 06:06:33.017782 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PSLLfyzVz2SrjZpjEGwAAAnI"]
[Mon Jul 20 06:06:33.652318 2026] [security2:error] [pid 832668:tid 832894] [client 34.31.203.120:11712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PSWci6KgEEltqA3C3gwAAXhY"]
[Mon Jul 20 06:06:33.725026 2026] [security2:error] [pid 832668:tid 832896] [client 74.208.214.194:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PSWci6KgEEltqA3C3igAAAGA"]
[Mon Jul 20 06:06:34.358065 2026] [security2:error] [pid 796567:tid 796734] [client 185.132.186.76:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/tox.php"] [unique_id "al4PSrLfyzVz2SrjZpjEWwAAAjk"]
[Mon Jul 20 06:06:34.388150 2026] [security2:error] [pid 832668:tid 832699] [remote 117.0.21.154:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PSmci6KgEEltqA3C3nAAALhw"]
[Mon Jul 20 06:06:34.535688 2026] [security2:error] [pid 796567:tid 796715] [client 114.119.155.96:30633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fkconstructionfunding.com"] [uri "/projects"] [unique_id "al4PSrLfyzVz2SrjZpjEZQAAAiY"], referer: https://fkconstructionfunding.com/latest-news/
[Mon Jul 20 06:06:34.595030 2026] [security2:error] [pid 832668:tid 832702] [remote 72.167.132.114:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PSmci6KgEEltqA3C3qAAAJR8"]
[Mon Jul 20 06:06:34.758291 2026] [security2:error] [pid 832668:tid 832867] [client 34.31.203.120:11712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PSmci6KgEEltqA3C3rAAAQyE"]
[Mon Jul 20 06:06:34.795746 2026] [security2:error] [pid 796567:tid 796658] [remote 157.66.26.183:33546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PSrLfyzVz2SrjZpjEcgACdVo"]
[Mon Jul 20 06:06:34.811534 2026] [security2:error] [pid 832668:tid 832814] [client 196.251.121.187:55385] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.fansarogroup.com"] [uri "/"] [unique_id "al4PSmci6KgEEltqA3C3sgAAAA4"]
[Mon Jul 20 06:06:34.895362 2026] [security2:error] [pid 832668:tid 832890] [client 74.208.214.194:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PSmci6KgEEltqA3C3tgAAAFo"]
[Mon Jul 20 06:06:34.976957 2026] [security2:error] [pid 832668:tid 832707] [remote 72.167.132.114:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PSmci6KgEEltqA3C3uQAAdiQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:06:35.094309 2026] [security2:error] [pid 796567:tid 796709] [client 14.225.17.146:63670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4PSbLfyzVz2SrjZpjELAAAAiA"], referer: http://oldracelimited.com/Wordpress
[Mon Jul 20 06:06:35.209006 2026] [security2:error] [pid 832668:tid 832709] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PS2ci6KgEEltqA3C3xAAAJiY"]
[Mon Jul 20 06:06:35.209157 2026] [security2:error] [pid 832668:tid 832838] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PS2ci6KgEEltqA3C3xAAAJiY"]
[Mon Jul 20 06:06:35.293563 2026] [security2:error] [pid 796567:tid 796609] [remote 157.66.26.183:33546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PS7LfyzVz2SrjZpjEigACFik"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:35.874222 2026] [security2:error] [pid 796567:tid 796760] [client 103.141.108.143:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PS7LfyzVz2SrjZpjEqQAAAlM"]
[Mon Jul 20 06:06:35.874354 2026] [security2:error] [pid 832668:tid 832710] [remote 173.249.4.11:28345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4PS2ci6KgEEltqA3C3zQAAFic"]
[Mon Jul 20 06:06:35.874413 2026] [security2:error] [pid 796567:tid 796760] [client 103.141.108.143:61378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PS7LfyzVz2SrjZpjEqQAAAlM"]
[Mon Jul 20 06:06:36.054737 2026] [security2:error] [pid 796567:tid 796739] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PS7LfyzVz2SrjZpjEtwAAAj4"]
[Mon Jul 20 06:06:36.105816 2026] [security2:error] [pid 796567:tid 796738] [client 106.192.104.4:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjExAAAAj0"]
[Mon Jul 20 06:06:36.105937 2026] [security2:error] [pid 796567:tid 796738] [client 106.192.104.4:64333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjExAAAAj0"]
[Mon Jul 20 06:06:36.106064 2026] [security2:error] [pid 796567:tid 796708] [client 104.234.53.54:45689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PTLLfyzVz2SrjZpjEwQAAAh8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:36.255487 2026] [security2:error] [pid 796567:tid 796695] [remote 162.19.86.63:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PTLLfyzVz2SrjZpjEywACJ38"]
[Mon Jul 20 06:06:36.284916 2026] [lsapi:warn] [pid 796567:tid 796644] [remote 198.143.19.78:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://ali-alghanim.net/
[Mon Jul 20 06:06:36.318328 2026] [security2:error] [pid 796567:tid 796721] [client 185.132.186.92:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/index.php"] [unique_id "al4PTLLfyzVz2SrjZpjEzgAAAiw"]
[Mon Jul 20 06:06:36.375549 2026] [security2:error] [pid 832668:tid 832715] [remote 117.0.21.154:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C32gAAaSw"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:36.445667 2026] [security2:error] [pid 832668:tid 832717] [remote 173.249.4.11:28345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C33gAATy4"], referer: https://bigwormfishing.com/wp-login.php
[Mon Jul 20 06:06:36.446352 2026] [security2:error] [pid 832668:tid 832716] [remote 5.161.225.162:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C33AAAFy0"]
[Mon Jul 20 06:06:36.457791 2026] [security2:error] [pid 796567:tid 796692] [remote 162.19.86.63:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PTLLfyzVz2SrjZpjE1gACenw"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:06:36.501426 2026] [security2:error] [pid 796567:tid 796740] [client 150.228.148.150:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjE2AAAAj8"]
[Mon Jul 20 06:06:36.511662 2026] [security2:error] [pid 796567:tid 796740] [client 150.228.148.150:50898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjE2AAAAj8"]
[Mon Jul 20 06:06:36.653903 2026] [security2:error] [pid 832668:tid 832914] [client 94.154.43.188:20998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rrf.lcd.mybluehost.me"] [uri "/.env"] [unique_id "al4PTGci6KgEEltqA3C35AAAAHI"]
[Mon Jul 20 06:06:36.735251 2026] [security2:error] [pid 832668:tid 832720] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PTGci6KgEEltqA3C35gAAEzE"]
[Mon Jul 20 06:06:36.735429 2026] [security2:error] [pid 832668:tid 832819] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PTGci6KgEEltqA3C35gAAEzE"]
[Mon Jul 20 06:06:36.833530 2026] [security2:error] [pid 832668:tid 832884] [client 104.234.53.51:54135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PTGci6KgEEltqA3C37AAAAFQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:36.903298 2026] [security2:error] [pid 832668:tid 832818] [client 14.225.17.146:65026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4PTGci6KgEEltqA3C36QAAABI"], referer: http://thechancersband.com/Wordpress
[Mon Jul 20 06:06:36.990879 2026] [security2:error] [pid 832668:tid 832721] [remote 5.161.225.162:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C38wAAKDI"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:06:37.094104 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.107:35240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PR2ci6KgEEltqA3C3OwAATnw"]
[Mon Jul 20 06:06:37.257119 2026] [security2:error] [pid 832668:tid 832913] [client 161.118.195.148:49989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-login.php"] [unique_id "al4PTWci6KgEEltqA3C3-AAAAHE"]
[Mon Jul 20 06:06:37.402239 2026] [security2:error] [pid 832668:tid 832899] [client 112.213.160.112:31112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4AQAAAGM"]
[Mon Jul 20 06:06:37.402429 2026] [security2:error] [pid 832668:tid 832899] [client 112.213.160.112:31112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4AQAAAGM"]
[Mon Jul 20 06:06:37.714464 2026] [security2:error] [pid 832668:tid 832902] [client 103.95.123.246:19607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4EwAAAGY"]
[Mon Jul 20 06:06:37.715084 2026] [security2:error] [pid 832668:tid 832902] [client 103.95.123.246:19607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4EwAAAGY"]
[Mon Jul 20 06:06:37.730603 2026] [security2:error] [pid 796567:tid 796736] [client 52.109.124.141:35779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PTbLfyzVz2SrjZpjFCAAAAjs"]
[Mon Jul 20 06:06:37.911281 2026] [security2:error] [pid 796567:tid 796806] [client 52.109.124.141:35779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PTbLfyzVz2SrjZpjFFAAAAoE"]
[Mon Jul 20 06:06:38.051203 2026] [security2:error] [pid 832668:tid 832827] [client 89.124.113.107:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-comments-post.php"] [unique_id "al4PTmci6KgEEltqA3C4GAAAABs"], referer: https://retzkolonglogistics.com/hello-world/
[Mon Jul 20 06:06:38.051324 2026] [security2:error] [pid 832668:tid 832827] [client 89.124.113.107:65335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/wp-comments-post.php"] [unique_id "al4PTmci6KgEEltqA3C4GAAAABs"], referer: https://retzkolonglogistics.com/hello-world/
[Mon Jul 20 06:06:38.133129 2026] [security2:error] [pid 796567:tid 796758] [client 57.141.18.51:42002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PSLLfyzVz2SrjZpjEBgACUWc"]
[Mon Jul 20 06:06:38.299645 2026] [security2:error] [pid 796567:tid 796786] [client 161.118.195.148:50443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PTrLfyzVz2SrjZpjFJAAAAm0"]
[Mon Jul 20 06:06:38.343056 2026] [security2:error] [pid 832668:tid 832878] [client 52.109.16.52:12353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PTmci6KgEEltqA3C4JgAAAE4"]
[Mon Jul 20 06:06:38.392259 2026] [security2:error] [pid 832668:tid 832917] [client 52.109.16.52:12353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PTmci6KgEEltqA3C4KAAAAHU"]
[Mon Jul 20 06:06:38.498547 2026] [security2:error] [pid 832668:tid 832850] [client 115.246.21.170:42116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PTmci6KgEEltqA3C4LQAAADI"]
[Mon Jul 20 06:06:38.498661 2026] [security2:error] [pid 832668:tid 832850] [client 115.246.21.170:42116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PTmci6KgEEltqA3C4LQAAADI"]
[Mon Jul 20 06:06:38.525876 2026] [security2:error] [pid 796567:tid 796702] [client 103.77.203.233:57195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PTrLfyzVz2SrjZpjFOAAAAhk"]
[Mon Jul 20 06:06:38.526138 2026] [security2:error] [pid 796567:tid 796702] [client 103.77.203.233:57195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PTrLfyzVz2SrjZpjFOAAAAhk"]
[Mon Jul 20 06:06:38.558675 2026] [security2:error] [pid 796567:tid 796771] [client 185.132.186.91:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/dist/default.php"] [unique_id "al4PTrLfyzVz2SrjZpjFOgAAAl4"]
[Mon Jul 20 06:06:38.748758 2026] [security2:error] [pid 796567:tid 796777] [client 57.141.18.46:22102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PSLLfyzVz2SrjZpjEHAACZE4"]
[Mon Jul 20 06:06:38.876404 2026] [security2:error] [pid 796567:tid 796721] [client 161.118.195.148:51168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4PTrLfyzVz2SrjZpjFRgAAAiw"]
[Mon Jul 20 06:06:39.061059 2026] [security2:error] [pid 832668:tid 832919] [client 104.234.53.94:55031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PT2ci6KgEEltqA3C4PgAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:39.255740 2026] [security2:error] [pid 796567:tid 796630] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFVgACWj4"]
[Mon Jul 20 06:06:39.255950 2026] [security2:error] [pid 796567:tid 796767] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFVgACWj4"]
[Mon Jul 20 06:06:39.453121 2026] [security2:error] [pid 796567:tid 796822] [client 161.118.195.148:51525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4PT7LfyzVz2SrjZpjFYAAAApE"]
[Mon Jul 20 06:06:39.477191 2026] [security2:error] [pid 832668:tid 832901] [client 57.141.18.56:20926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PSWci6KgEEltqA3C3fAAAZRU"]
[Mon Jul 20 06:06:39.915734 2026] [security2:error] [pid 832668:tid 832891] [client 210.212.97.243:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PT2ci6KgEEltqA3C4XAAAAFs"]
[Mon Jul 20 06:06:39.915846 2026] [security2:error] [pid 832668:tid 832891] [client 210.212.97.243:10450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PT2ci6KgEEltqA3C4XAAAAFs"]
[Mon Jul 20 06:06:39.926179 2026] [security2:error] [pid 796567:tid 796787] [client 41.173.37.102:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFcQAAAm4"]
[Mon Jul 20 06:06:39.926251 2026] [security2:error] [pid 796567:tid 796787] [client 41.173.37.102:3613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFcQAAAm4"]
[Mon Jul 20 06:06:40.203928 2026] [security2:error] [pid 832668:tid 832814] [client 14.225.17.146:52937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4PTmci6KgEEltqA3C4JQAAAA4"], referer: http://narv.co/Wordpress
[Mon Jul 20 06:06:40.294147 2026] [security2:error] [pid 832668:tid 832899] [client 178.152.178.232:37467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PUGci6KgEEltqA3C4bwAAAGM"]
[Mon Jul 20 06:06:40.294316 2026] [security2:error] [pid 832668:tid 832899] [client 178.152.178.232:37467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PUGci6KgEEltqA3C4bwAAAGM"]
[Mon Jul 20 06:06:40.429188 2026] [security2:error] [pid 796567:tid 796801] [client 27.96.94.195:38204] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFgwAAAnw"]
[Mon Jul 20 06:06:40.429310 2026] [security2:error] [pid 796567:tid 796801] [client 27.96.94.195:38204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFgwAAAnw"]
[Mon Jul 20 06:06:40.500239 2026] [security2:error] [pid 796567:tid 796800] [client 185.132.186.65:34745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/tfileman.php"] [unique_id "al4PULLfyzVz2SrjZpjFhgAAAns"]
[Mon Jul 20 06:06:40.745838 2026] [security2:error] [pid 832668:tid 832910] [client 57.141.18.59:36732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PS2ci6KgEEltqA3C3uwAAbiU"]
[Mon Jul 20 06:06:40.818217 2026] [security2:error] [pid 796567:tid 796706] [client 181.224.94.124:60138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFlwAAAh0"]
[Mon Jul 20 06:06:40.818357 2026] [security2:error] [pid 796567:tid 796706] [client 181.224.94.124:60138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFlwAAAh0"]
[Mon Jul 20 06:06:40.831161 2026] [security2:error] [pid 832668:tid 832895] [client 161.118.195.148:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/version.php"] [unique_id "al4PUGci6KgEEltqA3C4iAAAAF8"]
[Mon Jul 20 06:06:40.847783 2026] [security2:error] [pid 832668:tid 832875] [client 14.225.17.146:62998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4PUGci6KgEEltqA3C4hgAAAEs"], referer: http://omenana.com/Wordpress
[Mon Jul 20 06:06:41.159325 2026] [security2:error] [pid 796567:tid 796611] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFrwACNis"]
[Mon Jul 20 06:06:41.159527 2026] [security2:error] [pid 796567:tid 796731] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFrwACNis"]
[Mon Jul 20 06:06:41.199669 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:64089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4PUbLfyzVz2SrjZpjFqAAAAhg"], referer: https://narv.co/Wordpress
[Mon Jul 20 06:06:41.268114 2026] [core:error] [pid 796567:tid 796738] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:41.268154 2026] [core:error] [pid 796567:tid 796738] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:41.343926 2026] [security2:error] [pid 832668:tid 832750] [remote 81.173.115.7:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4PUWci6KgEEltqA3C4lwAAWk8"]
[Mon Jul 20 06:06:41.370199 2026] [security2:error] [pid 796567:tid 796584] [remote 188.138.102.156:33624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFuAAChBA"]
[Mon Jul 20 06:06:41.370349 2026] [security2:error] [pid 796567:tid 796809] [client 188.138.102.156:33624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFuAAChBA"]
[Mon Jul 20 06:06:41.409676 2026] [security2:error] [pid 796567:tid 796772] [client 161.118.195.148:52979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/functions.php"] [unique_id "al4PUbLfyzVz2SrjZpjFugAAAl8"]
[Mon Jul 20 06:06:41.555329 2026] [security2:error] [pid 832668:tid 832751] [remote 81.173.115.7:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4PUWci6KgEEltqA3C4nAAAd1A"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:06:41.680322 2026] [security2:error] [pid 832668:tid 832845] [client 207.46.13.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4PUGci6KgEEltqA3C4dAAAAC0"]
[Mon Jul 20 06:06:41.989852 2026] [security2:error] [pid 796567:tid 796794] [client 161.118.195.148:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4PUbLfyzVz2SrjZpjF0wAAAnU"]
[Mon Jul 20 06:06:42.449829 2026] [security2:error] [pid 832668:tid 832827] [client 185.132.186.77:37871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/tiny.php"] [unique_id "al4PUmci6KgEEltqA3C4sgAAABs"]
[Mon Jul 20 06:06:42.566468 2026] [security2:error] [pid 832668:tid 832866] [client 161.118.195.148:53705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/option.php"] [unique_id "al4PUmci6KgEEltqA3C4uAAAAEI"]
[Mon Jul 20 06:06:42.995881 2026] [security2:error] [pid 832668:tid 832834] [client 104.234.53.77:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PUmci6KgEEltqA3C4zQAAACI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:43.142572 2026] [security2:error] [pid 832668:tid 832813] [client 161.118.195.148:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/post.php"] [unique_id "al4PU2ci6KgEEltqA3C41wAAAA0"]
[Mon Jul 20 06:06:43.244558 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.63:49706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PTWci6KgEEltqA3C4EQAALjk"]
[Mon Jul 20 06:06:43.495875 2026] [security2:error] [pid 832668:tid 832826] [client 86.98.90.58:62082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PU2ci6KgEEltqA3C44QAAABo"]
[Mon Jul 20 06:06:43.496272 2026] [security2:error] [pid 832668:tid 832826] [client 86.98.90.58:62082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PU2ci6KgEEltqA3C44QAAABo"]
[Mon Jul 20 06:06:43.713663 2026] [security2:error] [pid 796567:tid 796796] [client 161.118.195.148:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/user.php"] [unique_id "al4PU7LfyzVz2SrjZpjGEAAAAnc"]
[Mon Jul 20 06:06:44.092816 2026] [security2:error] [pid 832668:tid 832771] [remote 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4PVGci6KgEEltqA3C4-QAAHWQ"]
[Mon Jul 20 06:06:44.302846 2026] [security2:error] [pid 832668:tid 832773] [remote 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4PVGci6KgEEltqA3C5AAAAA2Y"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:06:44.390489 2026] [security2:error] [pid 796567:tid 796778] [client 185.132.186.77:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/autoload_classmap.php"] [unique_id "al4PVLLfyzVz2SrjZpjGJQAAAmU"]
[Mon Jul 20 06:06:44.481347 2026] [security2:error] [pid 796567:tid 796705] [client 14.225.17.146:55155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4PVLLfyzVz2SrjZpjGJwAAAhw"], referer: http://momheadquarters.com/Wordpress
[Mon Jul 20 06:06:45.139648 2026] [security2:error] [pid 832668:tid 832861] [client 57.141.18.2:38486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PT2ci6KgEEltqA3C4TgAAPUQ"]
[Mon Jul 20 06:06:45.722025 2026] [security2:error] [pid 832668:tid 832784] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PVWci6KgEEltqA3C5PQAAIHE"]
[Mon Jul 20 06:06:45.722182 2026] [security2:error] [pid 832668:tid 832832] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PVWci6KgEEltqA3C5PQAAIHE"]
[Mon Jul 20 06:06:46.226759 2026] [security2:error] [pid 796567:tid 796724] [client 14.225.17.146:55274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PVLLfyzVz2SrjZpjGOgAAAi8"]
[Mon Jul 20 06:06:46.347298 2026] [security2:error] [pid 832668:tid 832839] [client 185.132.186.88:45721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/themes.php"] [unique_id "al4PVmci6KgEEltqA3C5TwAAACc"]
[Mon Jul 20 06:06:46.373510 2026] [security2:error] [pid 796567:tid 796648] [remote 72.167.132.114:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PVrLfyzVz2SrjZpjGfAACj1A"]
[Mon Jul 20 06:06:46.499129 2026] [security2:error] [pid 796567:tid 796717] [client 14.225.17.146:58560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4PVrLfyzVz2SrjZpjGcAAAAig"], referer: http://transparentservices.online/Wordpress
[Mon Jul 20 06:06:46.613458 2026] [security2:error] [pid 832668:tid 832905] [client 106.192.104.4:64809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PVmci6KgEEltqA3C5XAAAAGk"]
[Mon Jul 20 06:06:46.613556 2026] [security2:error] [pid 832668:tid 832905] [client 106.192.104.4:64809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PVmci6KgEEltqA3C5XAAAAGk"]
[Mon Jul 20 06:06:46.635188 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:61813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PVrLfyzVz2SrjZpjGigAAAiA"]
[Mon Jul 20 06:06:46.635398 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:61813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PVrLfyzVz2SrjZpjGigAAAiA"]
[Mon Jul 20 06:06:46.641929 2026] [security2:error] [pid 796567:tid 796633] [remote 72.167.132.114:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PVrLfyzVz2SrjZpjGiQACiUE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:46.992007 2026] [security2:error] [pid 832668:tid 832787] [remote 57.141.18.40:61816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4PVmci6KgEEltqA3C5ZAAAenQ"]
[Mon Jul 20 06:06:47.002968 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGngAAAmA"]
[Mon Jul 20 06:06:47.011039 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:35476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGngAAAmA"]
[Mon Jul 20 06:06:47.039972 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:56197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4PVWci6KgEEltqA3C5NgAAAFE"], referer: http://xp-design.co/Wordpress
[Mon Jul 20 06:06:47.224196 2026] [security2:error] [pid 832668:tid 832914] [client 161.118.195.148:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4PV2ci6KgEEltqA3C5bAAAAHI"]
[Mon Jul 20 06:06:47.303268 2026] [security2:error] [pid 832668:tid 832808] [client 14.225.17.146:54644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4PV2ci6KgEEltqA3C5aAAAAAg"], referer: http://floorsourcestock.com/Wordpress
[Mon Jul 20 06:06:47.330066 2026] [security2:error] [pid 832668:tid 832919] [client 14.225.17.146:57724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4PVWci6KgEEltqA3C5OwAAAHc"], referer: http://secretkeynumerology.com/Wordpress
[Mon Jul 20 06:06:47.392041 2026] [security2:error] [pid 796567:tid 796603] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGtwACbSM"]
[Mon Jul 20 06:06:47.392226 2026] [security2:error] [pid 796567:tid 796786] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGtwACbSM"]
[Mon Jul 20 06:06:47.441336 2026] [security2:error] [pid 796567:tid 796769] [client 4.194.217.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/nine2code.php"] [unique_id "al4PV7LfyzVz2SrjZpjGwAAAAlw"]
[Mon Jul 20 06:06:47.505639 2026] [security2:error] [pid 832668:tid 832868] [client 187.16.187.247:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atozgroup.biz"] [uri "/xmlrpc.php"] [unique_id "al4PV2ci6KgEEltqA3C5bwAAAEQ"]
[Mon Jul 20 06:06:47.505833 2026] [security2:error] [pid 832668:tid 832868] [client 187.16.187.247:59554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atozgroup.biz"] [uri "/xmlrpc.php"] [unique_id "al4PV2ci6KgEEltqA3C5bwAAAEQ"]
[Mon Jul 20 06:06:47.591817 2026] [security2:error] [pid 796567:tid 796702] [client 160.30.136.8:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PV7LfyzVz2SrjZpjGyAAAAhk"]
[Mon Jul 20 06:06:47.711702 2026] [security2:error] [pid 832668:tid 832901] [client 57.141.18.19:24758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PUmci6KgEEltqA3C4owAAZVE"]
[Mon Jul 20 06:06:47.922113 2026] [security2:error] [pid 832668:tid 832826] [client 103.153.183.69:32516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../app/.env"] [unique_id "al4PV2ci6KgEEltqA3C5fwAAABo"], referer: https://www.reddit.com/
[Mon Jul 20 06:06:47.982694 2026] [security2:error] [pid 832668:tid 832905] [client 160.30.136.8:64201] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4PV2ci6KgEEltqA3C5hgAAAGk"]
[Mon Jul 20 06:06:48.014411 2026] [security2:error] [pid 796567:tid 796568] [remote 38.242.157.30:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PWLLfyzVz2SrjZpjG2QACHwA"]
[Mon Jul 20 06:06:48.018824 2026] [security2:error] [pid 796567:tid 796719] [client 4.194.217.15:1648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/num.php"] [unique_id "al4PWLLfyzVz2SrjZpjG3AAAAio"]
[Mon Jul 20 06:06:48.125629 2026] [security2:error] [pid 796567:tid 796790] [client 14.225.17.146:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4PVrLfyzVz2SrjZpjGkQAAAnE"], referer: http://cloudspacesgroup.com/Wordpress
[Mon Jul 20 06:06:48.164093 2026] [security2:error] [pid 832668:tid 832902] [client 112.213.160.112:8356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5jAAAAGY"]
[Mon Jul 20 06:06:48.164221 2026] [security2:error] [pid 832668:tid 832902] [client 112.213.160.112:8356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5jAAAAGY"]
[Mon Jul 20 06:06:48.275337 2026] [security2:error] [pid 832668:tid 832819] [client 185.132.186.67:63301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-themes.php"] [unique_id "al4PWGci6KgEEltqA3C5kAAAABM"]
[Mon Jul 20 06:06:48.337735 2026] [security2:error] [pid 832668:tid 832852] [client 14.225.17.146:53809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4PWGci6KgEEltqA3C5jgAAADQ"], referer: https://secretkeynumerology.com/Wordpress
[Mon Jul 20 06:06:48.388846 2026] [security2:error] [pid 832668:tid 832804] [client 160.30.136.8:62767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWGci6KgEEltqA3C5lwAAAAQ"]
[Mon Jul 20 06:06:48.412724 2026] [security2:error] [pid 796567:tid 796615] [remote 38.242.157.30:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PWLLfyzVz2SrjZpjG7gACgi8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:06:48.534363 2026] [security2:error] [pid 832668:tid 832832] [client 103.153.183.69:32516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../srv/.env"] [unique_id "al4PWGci6KgEEltqA3C5oAAAACA"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:06:48.572038 2026] [security2:error] [pid 796567:tid 796808] [client 4.194.217.15:12499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4PWLLfyzVz2SrjZpjG_wAAAoM"]
[Mon Jul 20 06:06:48.621006 2026] [security2:error] [pid 796567:tid 796760] [client 14.225.17.146:58557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4PVrLfyzVz2SrjZpjGcgAAAlM"], referer: http://onewingpictures.com/Wordpress
[Mon Jul 20 06:06:48.621276 2026] [security2:error] [pid 832668:tid 832895] [client 103.95.123.246:20096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5pQAAAF8"]
[Mon Jul 20 06:06:48.621455 2026] [security2:error] [pid 832668:tid 832895] [client 103.95.123.246:20096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5pQAAAF8"]
[Mon Jul 20 06:06:48.654910 2026] [security2:error] [pid 796567:tid 796731] [client 46.110.96.34:13506] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4PWLLfyzVz2SrjZpjHCwAAAjY"]
[Mon Jul 20 06:06:48.798990 2026] [security2:error] [pid 832668:tid 832842] [client 160.30.136.8:64975] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4PWGci6KgEEltqA3C5qwAAACo"]
[Mon Jul 20 06:06:49.003096 2026] [security2:error] [pid 796567:tid 796738] [client 103.77.203.233:57257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHIwAAAj0"]
[Mon Jul 20 06:06:49.003231 2026] [security2:error] [pid 796567:tid 796738] [client 103.77.203.233:57257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHIwAAAj0"]
[Mon Jul 20 06:06:49.058927 2026] [security2:error] [pid 832668:tid 832798] [remote 130.185.118.215:37612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PWWci6KgEEltqA3C5tgAAMX8"]
[Mon Jul 20 06:06:49.110803 2026] [security2:error] [pid 796567:tid 796746] [client 115.246.21.170:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHLgAAAkU"]
[Mon Jul 20 06:06:49.110897 2026] [security2:error] [pid 796567:tid 796746] [client 115.246.21.170:5091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHLgAAAkU"]
[Mon Jul 20 06:06:49.120356 2026] [security2:error] [pid 796567:tid 796726] [client 4.194.217.15:5376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/option.php"] [unique_id "al4PWbLfyzVz2SrjZpjHLwAAAjE"]
[Mon Jul 20 06:06:49.217043 2026] [security2:error] [pid 832668:tid 832836] [client 160.30.136.8:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWWci6KgEEltqA3C5ugAAACQ"]
[Mon Jul 20 06:06:49.298300 2026] [security2:error] [pid 796567:tid 796751] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PWbLfyzVz2SrjZpjHMwAAAko"]
[Mon Jul 20 06:06:49.318887 2026] [security2:error] [pid 832668:tid 832672] [remote 130.185.118.215:37612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PWWci6KgEEltqA3C5vAAASAE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:06:49.633964 2026] [security2:error] [pid 796567:tid 796804] [client 160.30.136.8:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWbLfyzVz2SrjZpjHSAAAAn8"]
[Mon Jul 20 06:06:49.662315 2026] [security2:error] [pid 832668:tid 832890] [client 4.194.217.15:10012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/p.php"] [unique_id "al4PWWci6KgEEltqA3C5ywAAAFo"]
[Mon Jul 20 06:06:49.994020 2026] [security2:error] [pid 832668:tid 832674] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PWWci6KgEEltqA3C53AAADQM"]
[Mon Jul 20 06:06:49.994218 2026] [security2:error] [pid 832668:tid 832813] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PWWci6KgEEltqA3C53AAADQM"]
[Mon Jul 20 06:06:50.037584 2026] [security2:error] [pid 832668:tid 832906] [client 160.30.136.8:64065] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4PWmci6KgEEltqA3C54AAAAGo"]
[Mon Jul 20 06:06:50.151398 2026] [security2:error] [pid 832668:tid 832828] [client 103.153.183.69:23634] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//proc/self/environ"] [unique_id "al4PWmci6KgEEltqA3C54wAAABw"], referer: https://twitter.com/
[Mon Jul 20 06:06:50.207079 2026] [security2:error] [pid 832668:tid 832839] [client 185.132.186.64:22343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sodium_compat/src/index.php"] [unique_id "al4PWmci6KgEEltqA3C55QAAACc"]
[Mon Jul 20 06:06:50.268886 2026] [security2:error] [pid 832668:tid 832841] [client 4.194.217.15:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/past.php"] [unique_id "al4PWmci6KgEEltqA3C56gAAACk"]
[Mon Jul 20 06:06:50.272930 2026] [security2:error] [pid 796567:tid 796782] [client 193.19.109.219:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4PWrLfyzVz2SrjZpjHYQAAAmk"]
[Mon Jul 20 06:06:50.394184 2026] [security2:error] [pid 832668:tid 832679] [remote 20.173.88.122:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4PWmci6KgEEltqA3C57wAAAwg"]
[Mon Jul 20 06:06:50.441897 2026] [security2:error] [pid 796567:tid 796727] [client 210.212.97.243:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHaAAAAjI"]
[Mon Jul 20 06:06:50.442006 2026] [security2:error] [pid 796567:tid 796727] [client 210.212.97.243:10451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHaAAAAjI"]
[Mon Jul 20 06:06:50.490541 2026] [security2:error] [pid 796567:tid 796697] [client 98.159.234.160:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWrLfyzVz2SrjZpjHbgAAAhQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:50.610154 2026] [security2:error] [pid 796567:tid 796716] [client 41.173.37.102:4065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHdAAAAic"]
[Mon Jul 20 06:06:50.610287 2026] [security2:error] [pid 796567:tid 796716] [client 41.173.37.102:4065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHdAAAAic"]
[Mon Jul 20 06:06:50.642395 2026] [security2:error] [pid 796567:tid 796754] [client 14.225.17.146:57433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4PWrLfyzVz2SrjZpjHZQAAAk0"], referer: http://massagelacey.com/Wordpress
[Mon Jul 20 06:06:50.723257 2026] [security2:error] [pid 832668:tid 832678] [remote 20.173.88.122:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4PWmci6KgEEltqA3C6AQAAKwc"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 06:06:50.809884 2026] [security2:error] [pid 832668:tid 832845] [client 4.194.217.15:9820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/php.php"] [unique_id "al4PWmci6KgEEltqA3C6BAAAAC0"]
[Mon Jul 20 06:06:50.810700 2026] [security2:error] [pid 832668:tid 832909] [client 114.119.133.250:33599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/wp-content/uploads/2019/10/6-Presentation-Exterior-Entry-View-2-700x559.jpg"] [unique_id "al4PWmci6KgEEltqA3C6BQAAAG0"], referer: https://mourgroup.com/portfolio/cafe-sevilla/
[Mon Jul 20 06:06:51.011441 2026] [security2:error] [pid 832668:tid 832684] [remote 20.153.140.50:41106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PWmci6KgEEltqA3C6DQAARg0"]
[Mon Jul 20 06:06:51.351936 2026] [security2:error] [pid 796567:tid 796774] [client 181.224.94.124:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PW7LfyzVz2SrjZpjHlQAAAmE"]
[Mon Jul 20 06:06:51.352075 2026] [security2:error] [pid 796567:tid 796774] [client 181.224.94.124:51838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PW7LfyzVz2SrjZpjHlQAAAmE"]
[Mon Jul 20 06:06:51.352233 2026] [security2:error] [pid 796567:tid 796781] [client 4.194.217.15:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/php8.php"] [unique_id "al4PW7LfyzVz2SrjZpjHlAAAAmg"]
[Mon Jul 20 06:06:51.426291 2026] [security2:error] [pid 832668:tid 832689] [remote 20.153.140.50:41106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PW2ci6KgEEltqA3C6GQAAeBI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:06:51.500848 2026] [security2:error] [pid 796567:tid 796808] [client 14.225.17.146:55666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4PW7LfyzVz2SrjZpjHnAAAAoM"], referer: http://travelbyfire.com/Wordpress
[Mon Jul 20 06:06:51.514203 2026] [security2:error] [pid 796567:tid 796796] [client 57.141.18.72:21092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PVbLfyzVz2SrjZpjGWQACdwg"]
[Mon Jul 20 06:06:51.517626 2026] [security2:error] [pid 832668:tid 832922] [client 14.225.17.146:57256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4PWWci6KgEEltqA3C52QAAAHo"], referer: http://ironcitywellness.com/Wordpress
[Mon Jul 20 06:06:51.771959 2026] [security2:error] [pid 832668:tid 832688] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PW2ci6KgEEltqA3C6KwAAaBE"]
[Mon Jul 20 06:06:51.772224 2026] [security2:error] [pid 832668:tid 832904] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PW2ci6KgEEltqA3C6KwAAaBE"]
[Mon Jul 20 06:06:51.859088 2026] [security2:error] [pid 832668:tid 832927] [client 14.225.17.146:55849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4PWmci6KgEEltqA3C57QAAAH8"], referer: http://colinkeyphotography.com/Wordpress
[Mon Jul 20 06:06:51.891310 2026] [security2:error] [pid 796567:tid 796809] [client 4.194.217.15:10037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/phpinfo.php"] [unique_id "al4PW7LfyzVz2SrjZpjHrAAAAoQ"]
[Mon Jul 20 06:06:51.960781 2026] [security2:error] [pid 796567:tid 796760] [client 14.225.17.146:56219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4PWrLfyzVz2SrjZpjHXwAAAlM"], referer: http://superiorcopywriting.com/Wordpress
[Mon Jul 20 06:06:52.100243 2026] [security2:error] [pid 832668:tid 832694] [remote 18.61.192.253:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-login.php"] [unique_id "al4PXGci6KgEEltqA3C6OgAAfBc"]
[Mon Jul 20 06:06:52.167112 2026] [security2:error] [pid 832668:tid 832895] [client 185.132.186.61:48347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/erinyani/asasx.php"] [unique_id "al4PXGci6KgEEltqA3C6PAAAAF8"]
[Mon Jul 20 06:06:52.395465 2026] [security2:error] [pid 796567:tid 796754] [client 14.225.17.146:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4PXLLfyzVz2SrjZpjHuQAAAk0"], referer: https://travelbyfire.com/Wordpress
[Mon Jul 20 06:06:52.482522 2026] [security2:error] [pid 796567:tid 796773] [client 178.152.178.232:36217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PXLLfyzVz2SrjZpjHwQAAAmA"]
[Mon Jul 20 06:06:52.482640 2026] [security2:error] [pid 796567:tid 796773] [client 178.152.178.232:36217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PXLLfyzVz2SrjZpjHwQAAAmA"]
[Mon Jul 20 06:06:52.533421 2026] [security2:error] [pid 832668:tid 832804] [client 14.225.17.146:49158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4PW2ci6KgEEltqA3C6DgAAAAQ"]
[Mon Jul 20 06:06:52.606520 2026] [security2:error] [pid 832668:tid 832759] [remote 18.61.192.253:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-login.php"] [unique_id "al4PXGci6KgEEltqA3C6hwAAflg"], referer: https://retzkolonglogistics.com/wp-login.php
[Mon Jul 20 06:06:52.819811 2026] [security2:error] [pid 796567:tid 796717] [client 50.116.65.227:12064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PXLLfyzVz2SrjZpjH0QAAAig"]
[Mon Jul 20 06:06:52.830067 2026] [security2:error] [pid 796567:tid 796775] [client 50.116.65.227:12076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PXLLfyzVz2SrjZpjH0gAAAmI"]
[Mon Jul 20 06:06:52.862049 2026] [security2:error] [pid 796567:tid 796626] [remote 45.90.123.233:58570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4PXLLfyzVz2SrjZpjH0wACPzo"]
[Mon Jul 20 06:06:53.048008 2026] [security2:error] [pid 796567:tid 796774] [client 193.19.109.226:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4PXbLfyzVz2SrjZpjH2QAAAmE"]
[Mon Jul 20 06:06:53.051841 2026] [security2:error] [pid 796567:tid 796659] [remote 45.90.123.233:58570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4PXbLfyzVz2SrjZpjH2wACLFs"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:06:53.080732 2026] [security2:error] [pid 832668:tid 832910] [client 193.37.33.6:39491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4PXWci6KgEEltqA3C6ngAAAG4"]
[Mon Jul 20 06:06:53.093549 2026] [security2:error] [pid 832668:tid 832890] [client 193.19.109.216:37947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4PXWci6KgEEltqA3C6oQAAAFo"]
[Mon Jul 20 06:06:53.180163 2026] [security2:error] [pid 796567:tid 796808] [client 193.19.109.217:61715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4PXbLfyzVz2SrjZpjH3gAAAoM"]
[Mon Jul 20 06:06:53.289693 2026] [security2:error] [pid 832668:tid 832893] [client 50.116.65.227:12052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4PXGci6KgEEltqA3C6hgAAAF0"]
[Mon Jul 20 06:06:53.302456 2026] [security2:error] [pid 832668:tid 832851] [client 52.140.101.203:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PXWci6KgEEltqA3C6sQAAADM"]
[Mon Jul 20 06:06:53.365420 2026] [security2:error] [pid 832668:tid 832810] [client 50.116.65.227:12094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PXWci6KgEEltqA3C6qAAAAAo"]
[Mon Jul 20 06:06:53.453898 2026] [security2:error] [pid 832668:tid 832826] [client 52.183.195.200:30022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PXWci6KgEEltqA3C6tAAAABo"]
[Mon Jul 20 06:06:53.481088 2026] [security2:error] [pid 832668:tid 832830] [client 52.183.195.200:30022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PXWci6KgEEltqA3C6uwAAAB4"]
[Mon Jul 20 06:06:53.533887 2026] [security2:error] [pid 832668:tid 832889] [client 52.140.101.203:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PXWci6KgEEltqA3C6wAAAAFk"]
[Mon Jul 20 06:06:53.550058 2026] [security2:error] [pid 832668:tid 832858] [client 50.116.65.227:12108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PXWci6KgEEltqA3C6swAAADo"]
[Mon Jul 20 06:06:53.611836 2026] [security2:error] [pid 832668:tid 832864] [client 14.225.17.146:57609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4PXWci6KgEEltqA3C6vQAAAEA"], referer: http://koaconsultants.com/Wordpress
[Mon Jul 20 06:06:53.742982 2026] [security2:error] [pid 832668:tid 832848] [client 4.194.217.15:6586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/post.php"] [unique_id "al4PXWci6KgEEltqA3C6ywAAADA"]
[Mon Jul 20 06:06:53.955910 2026] [security2:error] [pid 796567:tid 796697] [client 50.116.65.227:12106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4PXbLfyzVz2SrjZpjH5gAAAhQ"]
[Mon Jul 20 06:06:54.117486 2026] [security2:error] [pid 796567:tid 796708] [client 185.132.186.83:50815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/mariju.php"] [unique_id "al4PXrLfyzVz2SrjZpjH_QAAAh8"]
[Mon Jul 20 06:06:54.286052 2026] [security2:error] [pid 832668:tid 832811] [client 4.194.217.15:12603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4PXmci6KgEEltqA3C64AAAAAs"]
[Mon Jul 20 06:06:54.408002 2026] [security2:error] [pid 796567:tid 796663] [remote 47.86.33.52:8166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PXrLfyzVz2SrjZpjIDAACgF8"]
[Mon Jul 20 06:06:54.408199 2026] [security2:error] [pid 796567:tid 796805] [client 47.86.33.52:8166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PXrLfyzVz2SrjZpjIDAACgF8"]
[Mon Jul 20 06:06:54.503670 2026] [security2:error] [pid 832668:tid 832922] [client 50.116.65.227:12114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PXmci6KgEEltqA3C65wAAAHo"]
[Mon Jul 20 06:06:54.514300 2026] [security2:error] [pid 832668:tid 832815] [client 50.116.65.227:12116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PXmci6KgEEltqA3C66AAAAA8"]
[Mon Jul 20 06:06:54.591910 2026] [security2:error] [pid 796567:tid 796666] [remote 5.161.225.162:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PXrLfyzVz2SrjZpjIEwACHmI"]
[Mon Jul 20 06:06:54.839359 2026] [security2:error] [pid 796567:tid 796740] [client 4.194.217.15:1443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/public/css.php"] [unique_id "al4PXrLfyzVz2SrjZpjIKAAAAj8"]
[Mon Jul 20 06:06:55.086568 2026] [security2:error] [pid 796567:tid 796721] [client 14.225.17.146:57936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4PXrLfyzVz2SrjZpjILgAAAiw"], referer: http://nextlvlmarketingco.com/Wordpress
[Mon Jul 20 06:06:55.381316 2026] [security2:error] [pid 832668:tid 832823] [client 4.194.217.15:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/r.php"] [unique_id "al4PX2ci6KgEEltqA3C7AQAAABc"]
[Mon Jul 20 06:06:55.504379 2026] [security2:error] [pid 832668:tid 832819] [client 14.225.17.146:57384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C62gAAABM"], referer: http://blaizeaccountingservices.com/Wordpress
[Mon Jul 20 06:06:55.762521 2026] [security2:error] [pid 796567:tid 796767] [client 57.141.18.69:63256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PWbLfyzVz2SrjZpjHOAACWhU"]
[Mon Jul 20 06:06:55.775639 2026] [security2:error] [pid 832668:tid 832873] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PX2ci6KgEEltqA3C7DAAAAEk"]
[Mon Jul 20 06:06:55.953589 2026] [security2:error] [pid 796567:tid 796753] [client 4.194.217.15:12606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/radio.php"] [unique_id "al4PX7LfyzVz2SrjZpjIVwAAAkw"]
[Mon Jul 20 06:06:55.979048 2026] [security2:error] [pid 832668:tid 832794] [remote 42.200.84.61:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4PX2ci6KgEEltqA3C7GgAAd3s"]
[Mon Jul 20 06:06:56.070051 2026] [security2:error] [pid 832668:tid 832841] [client 185.132.186.70:48829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/waf_defender.php"] [unique_id "al4PYGci6KgEEltqA3C7GwAAACk"]
[Mon Jul 20 06:06:56.317703 2026] [security2:error] [pid 832668:tid 832798] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PYGci6KgEEltqA3C7JgAAJ38"]
[Mon Jul 20 06:06:56.317848 2026] [security2:error] [pid 832668:tid 832839] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PYGci6KgEEltqA3C7JgAAJ38"]
[Mon Jul 20 06:06:56.321780 2026] [security2:error] [pid 832668:tid 832842] [client 14.225.17.146:57875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C68gAAACo"], referer: http://alexsandbergmusic.com/Wordpress
[Mon Jul 20 06:06:56.343464 2026] [security2:error] [pid 796567:tid 796771] [client 57.141.18.69:63268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PWbLfyzVz2SrjZpjHWAACXjk"]
[Mon Jul 20 06:06:56.370232 2026] [security2:error] [pid 832668:tid 832672] [remote 42.200.84.61:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4PYGci6KgEEltqA3C7KgAAIQE"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:06:56.387395 2026] [security2:error] [pid 832668:tid 832813] [client 14.225.17.146:57622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C68AAAAA0"], referer: http://nwcarvingacademy.com/Wordpress
[Mon Jul 20 06:06:56.416532 2026] [proxy:error] [pid 796567:tid 796726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:56.416624 2026] [proxy_http:error] [pid 796567:tid 796726] [client 195.96.139.207:53473] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:56.417667 2026] [proxy:error] [pid 796567:tid 796726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:56.417704 2026] [proxy_http:error] [pid 796567:tid 796726] [client 195.96.139.207:53473] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:56.502080 2026] [security2:error] [pid 832668:tid 832907] [client 4.194.217.15:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/randkeyword.php7"] [unique_id "al4PYGci6KgEEltqA3C7LgAAAGs"]
[Mon Jul 20 06:06:57.049112 2026] [security2:error] [pid 832668:tid 832827] [client 14.225.17.146:56510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4PX2ci6KgEEltqA3C7DgAAABs"], referer: http://hammadownenterprises.com/Wordpress
[Mon Jul 20 06:06:57.067584 2026] [security2:error] [pid 796567:tid 796817] [client 4.194.217.15:7433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/readme.php"] [unique_id "al4PYbLfyzVz2SrjZpjIhwAAAow"]
[Mon Jul 20 06:06:57.156743 2026] [security2:error] [pid 832668:tid 832857] [client 57.141.18.103:58100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PWmci6KgEEltqA3C6BgAAOQw"]
[Mon Jul 20 06:06:57.436342 2026] [security2:error] [pid 796567:tid 796779] [client 103.141.108.143:62262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjImgAAAmY"]
[Mon Jul 20 06:06:57.436426 2026] [security2:error] [pid 796567:tid 796779] [client 103.141.108.143:62262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjImgAAAmY"]
[Mon Jul 20 06:06:57.459275 2026] [security2:error] [pid 832668:tid 832815] [client 14.225.17.146:54864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4PYWci6KgEEltqA3C7UwAAAA8"], referer: https://nwcarvingacademy.com/Wordpress
[Mon Jul 20 06:06:57.506620 2026] [security2:error] [pid 796567:tid 796768] [client 14.225.17.146:57670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4PX7LfyzVz2SrjZpjINQAAAls"], referer: http://adastra.love/Wordpress
[Mon Jul 20 06:06:57.593314 2026] [security2:error] [pid 796567:tid 796739] [client 150.228.148.150:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIogAAAj4"]
[Mon Jul 20 06:06:57.595133 2026] [security2:error] [pid 796567:tid 796745] [client 106.192.104.4:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIowAAAkQ"]
[Mon Jul 20 06:06:57.601039 2026] [security2:error] [pid 796567:tid 796739] [client 150.228.148.150:20467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIogAAAj4"]
[Mon Jul 20 06:06:57.604661 2026] [security2:error] [pid 796567:tid 796745] [client 106.192.104.4:65304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIowAAAkQ"]
[Mon Jul 20 06:06:57.610286 2026] [security2:error] [pid 796567:tid 796738] [client 4.194.217.15:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/reze.php"] [unique_id "al4PYbLfyzVz2SrjZpjIpAAAAj0"]
[Mon Jul 20 06:06:57.663494 2026] [security2:error] [pid 796567:tid 796593] [remote 5.252.52.249:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4PYbLfyzVz2SrjZpjIpgACOxk"]
[Mon Jul 20 06:06:57.679503 2026] [security2:error] [pid 796567:tid 796614] [remote 5.161.225.162:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PYbLfyzVz2SrjZpjIqAACGy4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:06:57.755935 2026] [security2:error] [pid 832668:tid 832680] [remote 5.252.52.249:37646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4PYWci6KgEEltqA3C7aAAAJgk"]
[Mon Jul 20 06:06:57.904187 2026] [security2:error] [pid 796567:tid 796694] [remote 5.252.52.249:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4PYbLfyzVz2SrjZpjIrQACLn4"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 06:06:57.976979 2026] [security2:error] [pid 832668:tid 832678] [remote 5.252.52.249:37646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4PYWci6KgEEltqA3C7cQAAPgc"], referer: https://dnsplumbing.com/wp-login.php
[Mon Jul 20 06:06:58.015501 2026] [security2:error] [pid 832668:tid 832827] [client 185.132.186.60:31697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/cong.php"] [unique_id "al4PYmci6KgEEltqA3C7cwAAABs"]
[Mon Jul 20 06:06:58.028283 2026] [security2:error] [pid 832668:tid 832682] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7dQAAZAs"]
[Mon Jul 20 06:06:58.028399 2026] [security2:error] [pid 832668:tid 832900] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7dQAAZAs"]
[Mon Jul 20 06:06:58.036348 2026] [security2:error] [pid 832668:tid 832684] [remote 20.153.140.50:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eframiproperties.com"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7dAAAIw0"]
[Mon Jul 20 06:06:58.101019 2026] [security2:error] [pid 832668:tid 832828] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PYWci6KgEEltqA3C7bAAAABw"]
[Mon Jul 20 06:06:58.154511 2026] [security2:error] [pid 832668:tid 832921] [client 4.194.217.15:4754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/rh.php"] [unique_id "al4PYmci6KgEEltqA3C7gwAAAHk"]
[Mon Jul 20 06:06:58.176869 2026] [access_compat:error] [pid 832668:tid 832816] [client 183.47.107.78:56397] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:58.253462 2026] [security2:error] [pid 832668:tid 832689] [remote 188.40.28.4:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7hQAAGhI"]
[Mon Jul 20 06:06:58.364791 2026] [security2:error] [pid 832668:tid 832800] [client 14.225.17.146:55033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PYmci6KgEEltqA3C7hAAAAAA"], referer: http://fkconstructionfunding.com/Wordpress
[Mon Jul 20 06:06:58.437129 2026] [security2:error] [pid 832668:tid 832686] [remote 20.153.140.50:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eframiproperties.com"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7kAAAHw8"], referer: https://eframiproperties.com/wp-login.php
[Mon Jul 20 06:06:58.463011 2026] [security2:error] [pid 832668:tid 832688] [remote 188.40.28.4:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7kgAAXRE"], referer: https://thslogistics.net/wp-login.php
[Mon Jul 20 06:06:58.464438 2026] [security2:error] [pid 796567:tid 796716] [client 104.234.53.86:22167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PYrLfyzVz2SrjZpjIvQAAAic"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:58.719229 2026] [security2:error] [pid 832668:tid 832894] [client 4.194.217.15:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/rip.php"] [unique_id "al4PYmci6KgEEltqA3C7ngAAAF4"]
[Mon Jul 20 06:06:58.819509 2026] [security2:error] [pid 832668:tid 832911] [client 112.213.160.112:8357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7ogAAAG8"]
[Mon Jul 20 06:06:58.819633 2026] [security2:error] [pid 832668:tid 832911] [client 112.213.160.112:8357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7ogAAAG8"]
[Mon Jul 20 06:06:58.837422 2026] [security2:error] [pid 832668:tid 832825] [client 57.141.18.50:61182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PXGci6KgEEltqA3C6hAAAGVQ"]
[Mon Jul 20 06:06:59.030814 2026] [security2:error] [pid 796567:tid 796764] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PYrLfyzVz2SrjZpjIyAAAAlc"]
[Mon Jul 20 06:06:59.259134 2026] [security2:error] [pid 832668:tid 832826] [client 4.194.217.15:4744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/root.php"] [unique_id "al4PY2ci6KgEEltqA3C7xgAAABo"]
[Mon Jul 20 06:06:59.362336 2026] [security2:error] [pid 796567:tid 796725] [client 103.95.123.246:20591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI4gAAAjA"]
[Mon Jul 20 06:06:59.362439 2026] [security2:error] [pid 796567:tid 796725] [client 103.95.123.246:20591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI4gAAAjA"]
[Mon Jul 20 06:06:59.389253 2026] [security2:error] [pid 796567:tid 796814] [client 14.225.17.146:56625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PY7LfyzVz2SrjZpjI2gAAAok"], referer: https://fkconstructionfunding.com/Wordpress
[Mon Jul 20 06:06:59.464311 2026] [security2:error] [pid 832668:tid 832877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PY2ci6KgEEltqA3C7xAAAAE0"]
[Mon Jul 20 06:06:59.631802 2026] [security2:error] [pid 832668:tid 832807] [client 14.225.17.146:57855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4PY2ci6KgEEltqA3C71wAAAAc"], referer: http://retzkolonglogistics.com/Wordpress
[Mon Jul 20 06:06:59.637251 2026] [security2:error] [pid 832668:tid 832924] [client 103.77.203.233:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PY2ci6KgEEltqA3C73gAAAHw"]
[Mon Jul 20 06:06:59.637493 2026] [security2:error] [pid 832668:tid 832924] [client 103.77.203.233:57316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PY2ci6KgEEltqA3C73gAAAHw"]
[Mon Jul 20 06:06:59.694031 2026] [security2:error] [pid 796567:tid 796815] [client 115.246.21.170:26090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI9gAAAoo"]
[Mon Jul 20 06:06:59.694156 2026] [security2:error] [pid 796567:tid 796815] [client 115.246.21.170:26090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI9gAAAoo"]
[Mon Jul 20 06:06:59.807939 2026] [security2:error] [pid 832668:tid 832866] [client 4.194.217.15:4766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/s.php"] [unique_id "al4PY2ci6KgEEltqA3C75wAAAEI"]
[Mon Jul 20 06:06:59.877979 2026] [security2:error] [pid 796567:tid 796738] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PY7LfyzVz2SrjZpjI7gAAAj0"]
[Mon Jul 20 06:06:59.911494 2026] [access_compat:error] [pid 832668:tid 832850] [client 183.47.125.145:42635] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:59.959962 2026] [security2:error] [pid 796567:tid 796776] [client 185.132.186.92:33693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/av.php"] [unique_id "al4PY7LfyzVz2SrjZpjI_wAAAmM"]
[Mon Jul 20 06:07:00.061843 2026] [security2:error] [pid 832668:tid 832875] [client 54.244.177.189:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4PZGci6KgEEltqA3C78wAAAEs"]
[Mon Jul 20 06:07:00.211089 2026] [security2:error] [pid 832668:tid 832820] [client 45.116.69.230:57773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C7-QAAABQ"]
[Mon Jul 20 06:07:00.211209 2026] [security2:error] [pid 832668:tid 832820] [client 45.116.69.230:57773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C7-QAAABQ"]
[Mon Jul 20 06:07:00.244719 2026] [security2:error] [pid 796567:tid 796697] [client 43.173.182.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canqungarments.com"] [uri "/index.php"] [unique_id "al4PX7LfyzVz2SrjZpjIRQAAAhQ"]
[Mon Jul 20 06:07:00.276105 2026] [security2:error] [pid 832668:tid 832856] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZGci6KgEEltqA3C78gAAADg"]
[Mon Jul 20 06:07:00.342593 2026] [security2:error] [pid 832668:tid 832851] [client 57.141.18.31:43996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C63AAAM3M"]
[Mon Jul 20 06:07:00.350522 2026] [security2:error] [pid 832668:tid 832912] [client 4.194.217.15:4763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sang.php"] [unique_id "al4PZGci6KgEEltqA3C8AgAAAHA"]
[Mon Jul 20 06:07:00.457977 2026] [security2:error] [pid 832668:tid 832862] [client 3.87.179.57:31954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cryptomeaning.com"] [uri "/"] [unique_id "al4PZGci6KgEEltqA3C8BAAAAD4"]
[Mon Jul 20 06:07:00.738043 2026] [security2:error] [pid 832668:tid 832721] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C8GQAACzI"]
[Mon Jul 20 06:07:00.738310 2026] [security2:error] [pid 832668:tid 832811] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C8GQAACzI"]
[Mon Jul 20 06:07:00.764813 2026] [security2:error] [pid 832668:tid 832719] [remote 34.21.244.199:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewritinglair.com"] [uri "/wp-login.php"] [unique_id "al4PZGci6KgEEltqA3C8GgAAMTA"]
[Mon Jul 20 06:07:00.903059 2026] [security2:error] [pid 832668:tid 832913] [client 4.194.217.15:9230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/scxy.php"] [unique_id "al4PZGci6KgEEltqA3C8KQAAAHE"]
[Mon Jul 20 06:07:00.976618 2026] [security2:error] [pid 832668:tid 832867] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZGci6KgEEltqA3C8GAAAAEM"]
[Mon Jul 20 06:07:01.007627 2026] [security2:error] [pid 832668:tid 832848] [client 210.212.97.243:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8LwAAADA"]
[Mon Jul 20 06:07:01.007719 2026] [security2:error] [pid 832668:tid 832848] [client 210.212.97.243:10452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8LwAAADA"]
[Mon Jul 20 06:07:01.134741 2026] [security2:error] [pid 832668:tid 832724] [remote 34.21.244.199:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewritinglair.com"] [uri "/wp-login.php"] [unique_id "al4PZWci6KgEEltqA3C8OgAABzU"], referer: https://thewritinglair.com/wp-login.php
[Mon Jul 20 06:07:01.153116 2026] [security2:error] [pid 832668:tid 832725] [remote 20.153.140.50:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8PQAAAjY"]
[Mon Jul 20 06:07:01.153267 2026] [security2:error] [pid 832668:tid 832802] [client 20.153.140.50:60132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8PQAAAjY"]
[Mon Jul 20 06:07:01.197571 2026] [security2:error] [pid 796567:tid 796719] [client 41.173.37.102:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJNQAAAio"]
[Mon Jul 20 06:07:01.197700 2026] [security2:error] [pid 796567:tid 796719] [client 41.173.37.102:4513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJNQAAAio"]
[Mon Jul 20 06:07:01.253471 2026] [security2:error] [pid 796567:tid 796729] [client 193.37.33.6:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makeupyourskin.nl"] [uri "/wp-login.php"] [unique_id "al4PZbLfyzVz2SrjZpjJNgAAAjQ"]
[Mon Jul 20 06:07:01.267113 2026] [lsapi:warn] [pid 832668:tid 832852] [client 14.225.17.146:57858] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:01.267137 2026] [lsapi:warn] [pid 832668:tid 832852] [client 14.225.17.146:57858] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:01.285605 2026] [security2:error] [pid 796567:tid 796748] [client 193.19.109.213:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makeupyourskin.nl"] [uri "/wp-login.php"] [unique_id "al4PZbLfyzVz2SrjZpjJOAAAAkc"]
[Mon Jul 20 06:07:01.382686 2026] [security2:error] [pid 796567:tid 796667] [remote 47.86.33.52:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJPAACaGM"]
[Mon Jul 20 06:07:01.382887 2026] [security2:error] [pid 796567:tid 796781] [client 47.86.33.52:57000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJPAACaGM"]
[Mon Jul 20 06:07:01.444602 2026] [security2:error] [pid 832668:tid 832903] [client 4.194.217.15:1841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sd.php"] [unique_id "al4PZWci6KgEEltqA3C8UQAAAGc"]
[Mon Jul 20 06:07:01.452390 2026] [security2:error] [pid 832668:tid 832884] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZWci6KgEEltqA3C8QgAAAFQ"]
[Mon Jul 20 06:07:01.514640 2026] [security2:error] [pid 832668:tid 832924] [client 158.173.166.181:45105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PZWci6KgEEltqA3C8VgAAAHw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:01.555936 2026] [security2:error] [pid 796567:tid 796702] [client 14.225.17.146:58731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4PZbLfyzVz2SrjZpjJQAAAAhk"], referer: http://grndl.com/Wordpress
[Mon Jul 20 06:07:01.752773 2026] [security2:error] [pid 796567:tid 796787] [client 193.19.109.229:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4PZbLfyzVz2SrjZpjJSgAAAm4"]
[Mon Jul 20 06:07:01.779871 2026] [security2:error] [pid 832668:tid 832819] [client 193.19.109.227:57739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4PZWci6KgEEltqA3C8YQAAABM"]
[Mon Jul 20 06:07:01.863726 2026] [security2:error] [pid 832668:tid 832735] [remote 157.66.26.183:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8agAAZEA"]
[Mon Jul 20 06:07:01.863909 2026] [security2:error] [pid 832668:tid 832900] [client 157.66.26.183:56604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8agAAZEA"]
[Mon Jul 20 06:07:01.871849 2026] [security2:error] [pid 832668:tid 832868] [client 193.19.109.233:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/wp-login.php"] [unique_id "al4PZWci6KgEEltqA3C8ZAAAAEQ"]
[Mon Jul 20 06:07:01.877516 2026] [security2:error] [pid 796567:tid 796745] [client 181.224.94.124:36297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJTgAAAkQ"]
[Mon Jul 20 06:07:01.877624 2026] [security2:error] [pid 796567:tid 796745] [client 181.224.94.124:36297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJTgAAAkQ"]
[Mon Jul 20 06:07:01.899522 2026] [security2:error] [pid 796567:tid 796782] [client 185.132.186.73:28893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/glex.php"] [unique_id "al4PZbLfyzVz2SrjZpjJTwAAAmk"]
[Mon Jul 20 06:07:01.987504 2026] [security2:error] [pid 832668:tid 832907] [client 4.194.217.15:9229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sf.php"] [unique_id "al4PZWci6KgEEltqA3C8cgAAAGs"]
[Mon Jul 20 06:07:02.065113 2026] [security2:error] [pid 832668:tid 832846] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZWci6KgEEltqA3C8XwAAAC4"]
[Mon Jul 20 06:07:02.150219 2026] [lsapi:warn] [pid 796567:tid 796747] [client 50.116.65.227:53424] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:07:02.150246 2026] [lsapi:warn] [pid 796567:tid 796747] [client 50.116.65.227:53424] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:07:02.163805 2026] [security2:error] [pid 832668:tid 832852] [client 14.225.17.146:57858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4PZGci6KgEEltqA3C8GwAAADQ"], referer: http://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:02.169415 2026] [security2:error] [pid 832668:tid 832910] [client 178.152.178.232:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8dwAAAG4"]
[Mon Jul 20 06:07:02.169544 2026] [security2:error] [pid 832668:tid 832910] [client 178.152.178.232:37860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8dwAAAG4"]
[Mon Jul 20 06:07:02.256692 2026] [security2:error] [pid 832668:tid 832898] [client 57.141.18.5:41892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PX2ci6KgEEltqA3C7GQAAYnc"]
[Mon Jul 20 06:07:02.386881 2026] [security2:error] [pid 832668:tid 832740] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8hAAAKkU"]
[Mon Jul 20 06:07:02.387072 2026] [security2:error] [pid 832668:tid 832842] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8hAAAKkU"]
[Mon Jul 20 06:07:02.539971 2026] [security2:error] [pid 832668:tid 832913] [client 4.194.217.15:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/shell.php"] [unique_id "al4PZmci6KgEEltqA3C8igAAAHE"]
[Mon Jul 20 06:07:02.649833 2026] [security2:error] [pid 832668:tid 832919] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZmci6KgEEltqA3C8ggAAAHc"]
[Mon Jul 20 06:07:02.699466 2026] [security2:error] [pid 832668:tid 832909] [client 14.225.17.146:56642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4PZmci6KgEEltqA3C8iQAAAG0"]
[Mon Jul 20 06:07:02.726620 2026] [security2:error] [pid 796567:tid 796779] [client 104.234.53.54:23575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PZrLfyzVz2SrjZpjJcQAAAmY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:02.926828 2026] [security2:error] [pid 796567:tid 796726] [client 94.154.43.185:36960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gua.yhh.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al4PZrLfyzVz2SrjZpjJegAAAjE"]
[Mon Jul 20 06:07:02.972948 2026] [security2:error] [pid 832668:tid 832868] [client 94.154.43.229:45660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gua.yhh.mybluehost.me"] [uri "/.env"] [unique_id "al4PZmci6KgEEltqA3C8mAAAAEQ"]
[Mon Jul 20 06:07:02.979847 2026] [security2:error] [pid 832668:tid 832888] [client 94.154.43.229:45668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gua.yhh.mybluehost.me"] [uri "/.env"] [unique_id "al4PZmci6KgEEltqA3C8mQAAAFg"]
[Mon Jul 20 06:07:02.996707 2026] [security2:error] [pid 832668:tid 832835] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZmci6KgEEltqA3C8kgAAACM"]
[Mon Jul 20 06:07:03.004520 2026] [lsapi:warn] [pid 796567:tid 796714] [client 14.225.17.146:57242] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:03.004536 2026] [lsapi:warn] [pid 796567:tid 796714] [client 14.225.17.146:57242] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:03.062254 2026] [security2:error] [pid 796567:tid 796714] [client 14.225.17.146:57242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJfAAAAiU"], referer: https://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:03.171918 2026] [security2:error] [pid 796567:tid 796593] [remote 84.247.172.23:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJiwACPhk"]
[Mon Jul 20 06:07:03.356440 2026] [security2:error] [pid 796567:tid 796763] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJiAAAAlY"]
[Mon Jul 20 06:07:03.375265 2026] [security2:error] [pid 832668:tid 832902] [client 50.116.65.227:53436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PZ2ci6KgEEltqA3C8rwAAAGY"]
[Mon Jul 20 06:07:03.385691 2026] [security2:error] [pid 832668:tid 832917] [client 50.116.65.227:53452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PZ2ci6KgEEltqA3C8sAAAAHU"]
[Mon Jul 20 06:07:03.452250 2026] [security2:error] [pid 796567:tid 796615] [remote 84.247.172.23:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJmAACPC8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:07:03.517984 2026] [security2:error] [pid 796567:tid 796762] [client 193.19.109.249:32007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtlegnews.gov"] [uri "/wp-login.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJnQAAAlU"]
[Mon Jul 20 06:07:03.585206 2026] [security2:error] [pid 832668:tid 832898] [client 193.19.109.250:57937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtlegnews.gov"] [uri "/wp-login.php"] [unique_id "al4PZ2ci6KgEEltqA3C8vAAAAGI"]
[Mon Jul 20 06:07:03.754932 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:64854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4PZWci6KgEEltqA3C8VQAAAFE"], referer: http://hilltopnurseryinc.com/Wordpress
[Mon Jul 20 06:07:03.818447 2026] [security2:error] [pid 832668:tid 832848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZ2ci6KgEEltqA3C8vwAAADA"]
[Mon Jul 20 06:07:03.856127 2026] [security2:error] [pid 796567:tid 796708] [client 185.132.186.68:33301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJrwAAAh8"]
[Mon Jul 20 06:07:03.892448 2026] [security2:error] [pid 832668:tid 832826] [client 4.194.217.15:10993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sid3.php"] [unique_id "al4PZ2ci6KgEEltqA3C8ywAAABo"]
[Mon Jul 20 06:07:03.946202 2026] [security2:error] [pid 832668:tid 832901] [client 57.141.18.63:65534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PYWci6KgEEltqA3C7YQAAZQY"]
[Mon Jul 20 06:07:04.261528 2026] [security2:error] [pid 796567:tid 796757] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJtAAAAlA"]
[Mon Jul 20 06:07:04.264765 2026] [access_compat:error] [pid 796567:tid 796700] [client 112.14.1.26:33872] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:07:04.458223 2026] [security2:error] [pid 796567:tid 796809] [client 4.194.217.15:7291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/simple.php"] [unique_id "al4PaLLfyzVz2SrjZpjJzwAAAoQ"]
[Mon Jul 20 06:07:04.568057 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PaLLfyzVz2SrjZpjJywAAAl0"]
[Mon Jul 20 06:07:04.607678 2026] [security2:error] [pid 796567:tid 796656] [remote 188.166.241.141:49760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4PaLLfyzVz2SrjZpjJ0wACXFg"]
[Mon Jul 20 06:07:04.859617 2026] [security2:error] [pid 832668:tid 832817] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PaGci6KgEEltqA3C87AAAABE"]
[Mon Jul 20 06:07:05.000997 2026] [security2:error] [pid 796567:tid 796674] [remote 188.166.241.141:49760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4PabLfyzVz2SrjZpjJ6gACT2o"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:07:05.002095 2026] [security2:error] [pid 796567:tid 796800] [client 4.194.217.15:10984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sitemap.php"] [unique_id "al4PabLfyzVz2SrjZpjJ6wAAAns"]
[Mon Jul 20 06:07:05.171880 2026] [security2:error] [pid 832668:tid 832901] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PaGci6KgEEltqA3C89wAAAGU"]
[Mon Jul 20 06:07:05.551091 2026] [security2:error] [pid 796567:tid 796779] [client 4.194.217.15:10975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/size.php"] [unique_id "al4PabLfyzVz2SrjZpjKAwAAAmY"]
[Mon Jul 20 06:07:05.740205 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PabLfyzVz2SrjZpjKAgAAAiU"]
[Mon Jul 20 06:07:05.802248 2026] [security2:error] [pid 796567:tid 796745] [client 185.132.186.103:44203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Parse/about.php"] [unique_id "al4PabLfyzVz2SrjZpjKFAAAAkQ"]
[Mon Jul 20 06:07:05.967343 2026] [security2:error] [pid 796567:tid 796700] [client 14.225.17.146:65368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4PabLfyzVz2SrjZpjKEgAAAhc"], referer: http://lifeisbetterlakeside.com/Wordpress
[Mon Jul 20 06:07:06.099544 2026] [security2:error] [pid 796567:tid 796746] [client 4.194.217.15:10999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sm.php"] [unique_id "al4ParLfyzVz2SrjZpjKIgAAAkU"]
[Mon Jul 20 06:07:06.225105 2026] [security2:error] [pid 832668:tid 832871] [client 50.116.65.227:28418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4Pamci6KgEEltqA3C9IAAAAEc"]
[Mon Jul 20 06:07:06.237396 2026] [security2:error] [pid 832668:tid 832892] [client 50.116.65.227:53472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4Pamci6KgEEltqA3C9IgAAAGQ"]
[Mon Jul 20 06:07:06.561484 2026] [security2:error] [pid 796567:tid 796817] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ParLfyzVz2SrjZpjKLgAAAow"]
[Mon Jul 20 06:07:06.650170 2026] [security2:error] [pid 796567:tid 796705] [client 4.194.217.15:11003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sql.php"] [unique_id "al4ParLfyzVz2SrjZpjKQQAAAhw"]
[Mon Jul 20 06:07:06.826814 2026] [security2:error] [pid 832668:tid 832751] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pamci6KgEEltqA3C9PQAAS1A"]
[Mon Jul 20 06:07:06.826936 2026] [security2:error] [pid 832668:tid 832875] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pamci6KgEEltqA3C9PQAAS1A"]
[Mon Jul 20 06:07:07.090590 2026] [security2:error] [pid 832668:tid 832907] [client 86.98.90.58:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa2ci6KgEEltqA3C9TQAAAGs"]
[Mon Jul 20 06:07:07.090725 2026] [security2:error] [pid 832668:tid 832907] [client 86.98.90.58:64117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa2ci6KgEEltqA3C9TQAAAGs"]
[Mon Jul 20 06:07:07.147053 2026] [security2:error] [pid 832668:tid 832821] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pamci6KgEEltqA3C9RQAAABU"]
[Mon Jul 20 06:07:07.190469 2026] [security2:error] [pid 832668:tid 832859] [client 4.194.217.15:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/ss.php"] [unique_id "al4Pa2ci6KgEEltqA3C9UQAAADs"]
[Mon Jul 20 06:07:07.250685 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9TAAAAC4"]
[Mon Jul 20 06:07:07.255261 2026] [security2:error] [pid 832668:tid 832811] [client 14.225.17.146:56510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4Pamci6KgEEltqA3C9NwAAAAs"]
[Mon Jul 20 06:07:07.523868 2026] [security2:error] [pid 832668:tid 832888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9VQAAAFg"]
[Mon Jul 20 06:07:07.721132 2026] [security2:error] [pid 796567:tid 796720] [client 84.54.44.19:63768] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "84.54.44.19" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKaQAAAis"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 06:07:07.721304 2026] [security2:error] [pid 796567:tid 796720] [client 84.54.44.19:63768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKaQAAAis"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 06:07:07.748293 2026] [security2:error] [pid 796567:tid 796719] [client 185.132.186.81:24167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKbAAAAio"]
[Mon Jul 20 06:07:07.753649 2026] [security2:error] [pid 832668:tid 832909] [client 4.194.217.15:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/stats.php"] [unique_id "al4Pa2ci6KgEEltqA3C9YwAAAG0"]
[Mon Jul 20 06:07:08.023558 2026] [security2:error] [pid 796567:tid 796721] [client 13.201.64.214:51860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKdQAAAiw"]
[Mon Jul 20 06:07:08.023742 2026] [security2:error] [pid 796567:tid 796721] [client 13.201.64.214:51860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKdQAAAiw"]
[Mon Jul 20 06:07:08.146385 2026] [security2:error] [pid 832668:tid 832877] [client 104.234.53.69:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PbGci6KgEEltqA3C9bwAAAE0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:08.168483 2026] [security2:error] [pid 832668:tid 832858] [client 103.141.108.143:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9cQAAADo"]
[Mon Jul 20 06:07:08.168621 2026] [security2:error] [pid 832668:tid 832858] [client 103.141.108.143:62702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9cQAAADo"]
[Mon Jul 20 06:07:08.207341 2026] [security2:error] [pid 796567:tid 796703] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKagAAAho"]
[Mon Jul 20 06:07:08.244392 2026] [security2:error] [pid 796567:tid 796767] [client 14.225.17.146:56073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4PbLLfyzVz2SrjZpjKegAAAlo"], referer: http://qualitycoatingsinspection.com/Wordpress
[Mon Jul 20 06:07:08.285029 2026] [security2:error] [pid 796567:tid 796710] [client 150.228.148.150:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PbLLfyzVz2SrjZpjKhAAAAiE"]
[Mon Jul 20 06:07:08.285169 2026] [security2:error] [pid 796567:tid 796710] [client 150.228.148.150:49625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PbLLfyzVz2SrjZpjKhAAAAiE"]
[Mon Jul 20 06:07:08.306923 2026] [security2:error] [pid 832668:tid 832913] [client 4.194.217.15:1560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sump1.php"] [unique_id "al4PbGci6KgEEltqA3C9eQAAAHE"]
[Mon Jul 20 06:07:08.376293 2026] [security2:error] [pid 832668:tid 832851] [client 14.225.17.146:63912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4Pamci6KgEEltqA3C9NQAAADM"]
[Mon Jul 20 06:07:08.413156 2026] [security2:error] [pid 832668:tid 832813] [client 43.205.139.3:18754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pa2ci6KgEEltqA3C9ZAAAAA0"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:07:08.704470 2026] [security2:error] [pid 832668:tid 832766] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9jgAAWl8"]
[Mon Jul 20 06:07:08.704697 2026] [security2:error] [pid 832668:tid 832890] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9jgAAWl8"]
[Mon Jul 20 06:07:08.846667 2026] [security2:error] [pid 796567:tid 796730] [client 4.194.217.15:5199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system.php"] [unique_id "al4PbLLfyzVz2SrjZpjKlwAAAjU"]
[Mon Jul 20 06:07:08.868737 2026] [security2:error] [pid 832668:tid 832834] [client 106.192.104.4:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9mAAAACI"]
[Mon Jul 20 06:07:08.868864 2026] [security2:error] [pid 832668:tid 832834] [client 106.192.104.4:49416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9mAAAACI"]
[Mon Jul 20 06:07:09.003868 2026] [security2:error] [pid 832668:tid 832730] [remote 124.55.178.99:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PbGci6KgEEltqA3C9mwAAPDs"]
[Mon Jul 20 06:07:09.069341 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:63909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9XQAAABw"], referer: http://expertcultures.com/Wordpress
[Mon Jul 20 06:07:09.190805 2026] [security2:error] [pid 796567:tid 796776] [client 14.225.17.146:63941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4PbbLfyzVz2SrjZpjKogAAAmM"], referer: https://qualitycoatingsinspection.com/Wordpress
[Mon Jul 20 06:07:09.391801 2026] [security2:error] [pid 796567:tid 796717] [client 4.194.217.15:1543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4PbbLfyzVz2SrjZpjKqgAAAig"]
[Mon Jul 20 06:07:09.579966 2026] [security2:error] [pid 832668:tid 832927] [client 112.213.160.112:8436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9sgAAAH8"]
[Mon Jul 20 06:07:09.580115 2026] [security2:error] [pid 832668:tid 832927] [client 112.213.160.112:8436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9sgAAAH8"]
[Mon Jul 20 06:07:09.610040 2026] [security2:error] [pid 832668:tid 832778] [remote 124.55.178.99:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PbWci6KgEEltqA3C9tAAAEGs"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:07:09.691473 2026] [security2:error] [pid 796567:tid 796817] [client 185.132.186.56:42591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/system_cache.php"] [unique_id "al4PbbLfyzVz2SrjZpjKtAAAAow"]
[Mon Jul 20 06:07:09.724343 2026] [security2:error] [pid 832668:tid 832883] [client 57.141.18.72:26110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PZ2ci6KgEEltqA3C8tgAAUyE"]
[Mon Jul 20 06:07:09.961763 2026] [security2:error] [pid 832668:tid 832837] [client 4.194.217.15:6024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4PbWci6KgEEltqA3C9wwAAACU"]
[Mon Jul 20 06:07:09.977394 2026] [security2:error] [pid 832668:tid 832813] [client 103.77.203.233:57377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9xAAAAA0"]
[Mon Jul 20 06:07:09.977532 2026] [security2:error] [pid 832668:tid 832813] [client 103.77.203.233:57377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9xAAAAA0"]
[Mon Jul 20 06:07:10.180508 2026] [security2:error] [pid 832668:tid 832849] [client 50.116.65.227:36890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Pbmci6KgEEltqA3C9ywAAADE"]
[Mon Jul 20 06:07:10.197123 2026] [security2:error] [pid 832668:tid 832896] [client 50.116.65.227:26854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Pbmci6KgEEltqA3C9zAAAAGA"]
[Mon Jul 20 06:07:10.209530 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PbrLfyzVz2SrjZpjKxQAAAkk"]
[Mon Jul 20 06:07:10.209686 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:17990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PbrLfyzVz2SrjZpjKxQAAAkk"]
[Mon Jul 20 06:07:10.321643 2026] [security2:error] [pid 832668:tid 832886] [client 14.225.17.146:59530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4PbGci6KgEEltqA3C9iAAAAFY"], referer: http://tacticaltreeoperations.com/Wordpress
[Mon Jul 20 06:07:10.344257 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C91QAAAC8"]
[Mon Jul 20 06:07:10.344381 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C91QAAAC8"]
[Mon Jul 20 06:07:10.354245 2026] [security2:error] [pid 832668:tid 832912] [client 34.31.203.120:48448] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.royalart-lb.com"] [uri "/"] [unique_id "al4Pbmci6KgEEltqA3C91gAAAHA"]
[Mon Jul 20 06:07:10.488797 2026] [security2:error] [pid 832668:tid 832920] [client 45.116.69.230:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C92wAAAHg"]
[Mon Jul 20 06:07:10.488904 2026] [security2:error] [pid 832668:tid 832920] [client 45.116.69.230:58440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C92wAAAHg"]
[Mon Jul 20 06:07:10.524602 2026] [security2:error] [pid 832668:tid 832897] [client 4.194.217.15:5237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system_log.php"] [unique_id "al4Pbmci6KgEEltqA3C93QAAAGE"]
[Mon Jul 20 06:07:10.845959 2026] [security2:error] [pid 832668:tid 832785] [remote 192.241.143.148:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Pbmci6KgEEltqA3C97AAAUnI"]
[Mon Jul 20 06:07:10.927947 2026] [security2:error] [pid 796567:tid 796778] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PbrLfyzVz2SrjZpjK3wAAAmU"]
[Mon Jul 20 06:07:10.982522 2026] [security2:error] [pid 832668:tid 832749] [remote 5.161.225.162:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4Pbmci6KgEEltqA3C98QAAR04"]
[Mon Jul 20 06:07:11.030502 2026] [security2:error] [pid 832668:tid 832787] [remote 192.241.143.148:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Pb2ci6KgEEltqA3C99AAAMXQ"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:07:11.120046 2026] [security2:error] [pid 796567:tid 796788] [client 4.194.217.15:5191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/t.php"] [unique_id "al4Pb7LfyzVz2SrjZpjK8QAAAm8"]
[Mon Jul 20 06:07:11.323316 2026] [security2:error] [pid 796567:tid 796669] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjK-wACh2U"]
[Mon Jul 20 06:07:11.323498 2026] [security2:error] [pid 796567:tid 796812] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjK-wACh2U"]
[Mon Jul 20 06:07:11.354771 2026] [security2:error] [pid 832668:tid 832792] [remote 5.161.225.162:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4Pb2ci6KgEEltqA3C9_QAAAHk"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:07:11.375656 2026] [security2:error] [pid 832668:tid 832885] [client 45.157.112.60:30847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Pb2ci6KgEEltqA3C9_gAAAFU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:11.581842 2026] [security2:error] [pid 796567:tid 796751] [client 210.212.97.243:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjLAwAAAko"]
[Mon Jul 20 06:07:11.581947 2026] [security2:error] [pid 796567:tid 796751] [client 210.212.97.243:10453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjLAwAAAko"]
[Mon Jul 20 06:07:11.598115 2026] [security2:error] [pid 796567:tid 796722] [client 185.132.186.85:48835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/sky-pro/js.php"] [unique_id "al4Pb7LfyzVz2SrjZpjLBgAAAi0"]
[Mon Jul 20 06:07:11.696626 2026] [security2:error] [pid 832668:tid 832877] [client 4.194.217.15:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/term.php"] [unique_id "al4Pb2ci6KgEEltqA3C-CwAAAE0"]
[Mon Jul 20 06:07:11.753345 2026] [security2:error] [pid 796567:tid 796731] [client 57.141.18.107:45776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PabLfyzVz2SrjZpjKBQACNiQ"]
[Mon Jul 20 06:07:11.841470 2026] [security2:error] [pid 832668:tid 832804] [client 41.173.37.102:4976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb2ci6KgEEltqA3C-FAAAAAQ"]
[Mon Jul 20 06:07:11.841631 2026] [security2:error] [pid 832668:tid 832804] [client 41.173.37.102:4976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb2ci6KgEEltqA3C-FAAAAAQ"]
[Mon Jul 20 06:07:11.966632 2026] [security2:error] [pid 832668:tid 832815] [client 14.224.227.113:54251] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Pb2ci6KgEEltqA3C-GAAAAA8"]
[Mon Jul 20 06:07:12.237421 2026] [security2:error] [pid 832668:tid 832840] [client 4.194.217.15:5205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/test.php"] [unique_id "al4PcGci6KgEEltqA3C-JQAAACg"]
[Mon Jul 20 06:07:12.459832 2026] [security2:error] [pid 832668:tid 832921] [client 181.224.94.124:43729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PcGci6KgEEltqA3C-NwAAAHk"]
[Mon Jul 20 06:07:12.460031 2026] [security2:error] [pid 832668:tid 832921] [client 181.224.94.124:43729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PcGci6KgEEltqA3C-NwAAAHk"]
[Mon Jul 20 06:07:12.682550 2026] [security2:error] [pid 796567:tid 796753] [client 178.152.178.232:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PcLLfyzVz2SrjZpjLMwAAAkw"]
[Mon Jul 20 06:07:12.682684 2026] [security2:error] [pid 796567:tid 796753] [client 178.152.178.232:36811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PcLLfyzVz2SrjZpjLMwAAAkw"]
[Mon Jul 20 06:07:12.709276 2026] [security2:error] [pid 832668:tid 832804] [client 50.116.65.227:26876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PcGci6KgEEltqA3C-RgAAAAQ"]
[Mon Jul 20 06:07:12.709298 2026] [security2:error] [pid 832668:tid 832854] [client 193.37.33.232:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atozgroup.biz"] [uri "/wp-login.php"] [unique_id "al4PcGci6KgEEltqA3C-QAAAADY"]
[Mon Jul 20 06:07:12.721729 2026] [security2:error] [pid 832668:tid 832889] [client 50.116.65.227:26892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PcGci6KgEEltqA3C-SAAAAFk"]
[Mon Jul 20 06:07:12.777870 2026] [security2:error] [pid 832668:tid 832897] [client 4.194.217.15:6053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/test1.php"] [unique_id "al4PcGci6KgEEltqA3C-TAAAAGE"]
[Mon Jul 20 06:07:12.898219 2026] [security2:error] [pid 796567:tid 796720] [client 14.225.17.146:55651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4PcLLfyzVz2SrjZpjLNwAAAis"], referer: http://ivetstrategies.com/Wordpress
[Mon Jul 20 06:07:12.943643 2026] [security2:error] [pid 832668:tid 832814] [client 43.205.139.3:18764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PcGci6KgEEltqA3C-LgAAAA4"]
[Mon Jul 20 06:07:13.004477 2026] [security2:error] [pid 796567:tid 796633] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PcbLfyzVz2SrjZpjLPgACWkE"]
[Mon Jul 20 06:07:13.004695 2026] [security2:error] [pid 796567:tid 796767] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PcbLfyzVz2SrjZpjLPgACWkE"]
[Mon Jul 20 06:07:13.339376 2026] [security2:error] [pid 832668:tid 832850] [client 4.194.217.15:5235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/tfm.php"] [unique_id "al4PcWci6KgEEltqA3C-ZQAAADI"]
[Mon Jul 20 06:07:13.350682 2026] [security2:error] [pid 832668:tid 832853] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PcGci6KgEEltqA3C-TQAAADU"], referer: http://laceycaraccident.com/identity
[Mon Jul 20 06:07:13.553652 2026] [security2:error] [pid 832668:tid 832862] [client 185.132.186.80:22789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/wp-conflg.php"] [unique_id "al4PcWci6KgEEltqA3C-bQAAAD4"]
[Mon Jul 20 06:07:13.900566 2026] [security2:error] [pid 832668:tid 832842] [client 4.194.217.15:6076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/thebe.php"] [unique_id "al4PcWci6KgEEltqA3C-fwAAACo"]
[Mon Jul 20 06:07:14.067118 2026] [security2:error] [pid 796567:tid 796760] [client 14.225.17.146:49362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4PcLLfyzVz2SrjZpjLIgAAAlM"], referer: http://according2plant.com/Wordpress
[Mon Jul 20 06:07:14.308508 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.10:54144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9aQAATk0"]
[Mon Jul 20 06:07:14.440393 2026] [security2:error] [pid 832668:tid 832911] [client 4.194.217.15:6048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/themes.php"] [unique_id "al4Pcmci6KgEEltqA3C-jgAAAG8"]
[Mon Jul 20 06:07:15.004328 2026] [security2:error] [pid 796567:tid 796725] [client 4.194.217.15:1682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/tiny.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLjQAAAjA"]
[Mon Jul 20 06:07:15.488569 2026] [security2:error] [pid 796567:tid 796598] [remote 57.141.18.45:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4417158"] [unique_id "al4Pc7LfyzVz2SrjZpjLoAACih4"]
[Mon Jul 20 06:07:15.576386 2026] [security2:error] [pid 796567:tid 796756] [client 4.194.217.15:1244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/tmp/byp.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLowAAAk8"]
[Mon Jul 20 06:07:15.957362 2026] [security2:error] [pid 832668:tid 832786] [remote 95.217.78.234:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4Pc2ci6KgEEltqA3C-zwAAbXM"]
[Mon Jul 20 06:07:16.173332 2026] [security2:error] [pid 796567:tid 796795] [client 57.141.18.24:47346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PbbLfyzVz2SrjZpjKuQACdkI"]
[Mon Jul 20 06:07:16.177376 2026] [security2:error] [pid 832668:tid 832711] [remote 95.217.78.234:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4PdGci6KgEEltqA3C-1QAABCg"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 06:07:16.256426 2026] [security2:error] [pid 832668:tid 832847] [client 104.234.53.73:26749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PdGci6KgEEltqA3C-2gAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:16.475502 2026] [security2:error] [pid 832668:tid 832910] [client 158.173.89.95:20035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PdGci6KgEEltqA3C-5gAAAG4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:16.523714 2026] [security2:error] [pid 796567:tid 796731] [client 185.132.186.73:33485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/waf_defender.php"] [unique_id "al4PdLLfyzVz2SrjZpjLyAAAAjY"]
[Mon Jul 20 06:07:16.627855 2026] [security2:error] [pid 832668:tid 832905] [client 14.225.17.146:56572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Pc2ci6KgEEltqA3C-wQAAAGk"]
[Mon Jul 20 06:07:16.702530 2026] [security2:error] [pid 832668:tid 832835] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PdGci6KgEEltqA3C-2wAAACM"]
[Mon Jul 20 06:07:16.882047 2026] [security2:error] [pid 832668:tid 832892] [client 27.96.94.195:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PdGci6KgEEltqA3C-8gAAAFw"]
[Mon Jul 20 06:07:16.882227 2026] [security2:error] [pid 832668:tid 832892] [client 27.96.94.195:37458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PdGci6KgEEltqA3C-8gAAAFw"]
[Mon Jul 20 06:07:17.344889 2026] [security2:error] [pid 832668:tid 832791] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PdWci6KgEEltqA3C_GAAAGXg"]
[Mon Jul 20 06:07:17.345108 2026] [security2:error] [pid 832668:tid 832825] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PdWci6KgEEltqA3C_GAAAGXg"]
[Mon Jul 20 06:07:17.725153 2026] [security2:error] [pid 832668:tid 832895] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PdWci6KgEEltqA3C-_gAAAF8"], referer: http://laceycaraccident.com/sitecore/shell/sitecore.version.xml
[Mon Jul 20 06:07:17.882656 2026] [security2:error] [pid 796567:tid 796782] [client 14.225.17.146:56474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLsgAAAmk"], referer: http://mobilesurvsolutions.com/Wordpress
[Mon Jul 20 06:07:18.035676 2026] [security2:error] [pid 796567:tid 796800] [client 113.160.97.242:50075] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4PdrLfyzVz2SrjZpjMAQAAAns"]
[Mon Jul 20 06:07:18.073313 2026] [core:error] [pid 832668:tid 832812] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.073343 2026] [core:error] [pid 832668:tid 832812] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.077713 2026] [core:error] [pid 832668:tid 832883] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.077731 2026] [core:error] [pid 832668:tid 832883] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.471324 2026] [security2:error] [pid 832668:tid 832824] [client 185.132.186.98:63823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/theme.php"] [unique_id "al4Pdmci6KgEEltqA3C_TgAAABg"]
[Mon Jul 20 06:07:18.729591 2026] [security2:error] [pid 796567:tid 796770] [client 86.98.90.58:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGgAAAl0"]
[Mon Jul 20 06:07:18.735450 2026] [security2:error] [pid 796567:tid 796770] [client 86.98.90.58:64875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGgAAAl0"]
[Mon Jul 20 06:07:18.752509 2026] [security2:error] [pid 796567:tid 796759] [client 57.141.18.24:47362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PcLLfyzVz2SrjZpjLFQACUk0"]
[Mon Jul 20 06:07:18.754423 2026] [security2:error] [pid 796567:tid 796798] [client 103.141.108.143:63134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGwAAAnk"]
[Mon Jul 20 06:07:18.754787 2026] [security2:error] [pid 796567:tid 796798] [client 103.141.108.143:63134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGwAAAnk"]
[Mon Jul 20 06:07:18.834717 2026] [security2:error] [pid 796567:tid 796710] [client 14.225.17.146:64102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4PdLLfyzVz2SrjZpjL3AAAAiE"], referer: http://709fx.com/Wordpress
[Mon Jul 20 06:07:18.970587 2026] [security2:error] [pid 796567:tid 796750] [client 150.228.148.150:62356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMHgAAAkk"]
[Mon Jul 20 06:07:18.972726 2026] [security2:error] [pid 796567:tid 796750] [client 150.228.148.150:62356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMHgAAAkk"]
[Mon Jul 20 06:07:19.299158 2026] [security2:error] [pid 832668:tid 832916] [client 106.192.104.4:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_bgAAAHQ"]
[Mon Jul 20 06:07:19.299274 2026] [security2:error] [pid 832668:tid 832916] [client 106.192.104.4:49897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_bgAAAHQ"]
[Mon Jul 20 06:07:19.315484 2026] [security2:error] [pid 832668:tid 832874] [client 121.229.156.97:43652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/crochet-tips-tutorials/"] [unique_id "al4Pd2ci6KgEEltqA3C_cQAAAEo"]
[Mon Jul 20 06:07:19.315618 2026] [security2:error] [pid 832668:tid 832874] [client 121.229.156.97:43652] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mezzacraft.com"] [uri "/crochet-tips-tutorials/"] [unique_id "al4Pd2ci6KgEEltqA3C_cQAAAEo"]
[Mon Jul 20 06:07:19.365473 2026] [security2:error] [pid 832668:tid 832731] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_dAAAVjw"]
[Mon Jul 20 06:07:19.365713 2026] [security2:error] [pid 832668:tid 832886] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_dAAAVjw"]
[Mon Jul 20 06:07:19.370745 2026] [security2:error] [pid 832668:tid 832879] [client 57.141.18.10:41478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PcGci6KgEEltqA3C-PQAAT2M"]
[Mon Jul 20 06:07:19.413439 2026] [security2:error] [pid 832668:tid 832913] [client 193.37.33.3:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4Pd2ci6KgEEltqA3C_dgAAAHE"]
[Mon Jul 20 06:07:19.425495 2026] [security2:error] [pid 796567:tid 796716] [client 193.19.109.245:60623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4Pd7LfyzVz2SrjZpjMLwAAAic"]
[Mon Jul 20 06:07:19.653368 2026] [security2:error] [pid 832668:tid 832741] [remote 167.233.114.32:33972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_hgAAHEY"]
[Mon Jul 20 06:07:19.653493 2026] [security2:error] [pid 832668:tid 832828] [client 167.233.114.32:33972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_hgAAHEY"]
[Mon Jul 20 06:07:20.271142 2026] [security2:error] [pid 832668:tid 832873] [client 57.141.18.23:64452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PcWci6KgEEltqA3C-aAAASWU"]
[Mon Jul 20 06:07:20.280164 2026] [security2:error] [pid 796567:tid 796742] [client 112.213.160.112:8443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PeLLfyzVz2SrjZpjMTQAAAkE"]
[Mon Jul 20 06:07:20.280333 2026] [security2:error] [pid 796567:tid 796742] [client 112.213.160.112:8443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PeLLfyzVz2SrjZpjMTQAAAkE"]
[Mon Jul 20 06:07:20.419618 2026] [security2:error] [pid 832668:tid 832907] [client 185.132.186.75:37539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/waf_defender.php"] [unique_id "al4PeGci6KgEEltqA3C_ngAAAGs"]
[Mon Jul 20 06:07:20.541824 2026] [security2:error] [pid 832668:tid 832832] [client 103.77.203.233:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_qwAAACA"]
[Mon Jul 20 06:07:20.551296 2026] [security2:error] [pid 832668:tid 832832] [client 103.77.203.233:57436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_qwAAACA"]
[Mon Jul 20 06:07:20.721851 2026] [security2:error] [pid 796567:tid 796748] [client 185.226.198.7:17356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PeLLfyzVz2SrjZpjMSwAAAkc"], referer: http://laceycaraccident.com/js/NewWindow_2_all.js
[Mon Jul 20 06:07:20.849679 2026] [security2:error] [pid 832668:tid 832858] [client 115.246.21.170:24130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_tQAAADo"]
[Mon Jul 20 06:07:20.849826 2026] [security2:error] [pid 832668:tid 832858] [client 115.246.21.170:24130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_tQAAADo"]
[Mon Jul 20 06:07:20.863272 2026] [security2:error] [pid 796567:tid 796653] [remote 130.185.118.215:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4PeLLfyzVz2SrjZpjMZgACgFU"]
[Mon Jul 20 06:07:21.054480 2026] [security2:error] [pid 796567:tid 796606] [remote 130.185.118.215:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4PebLfyzVz2SrjZpjMcAACaCY"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:07:21.216551 2026] [security2:error] [pid 832668:tid 832906] [client 40.77.167.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4PeWci6KgEEltqA3C_ugAAAGo"]
[Mon Jul 20 06:07:21.306188 2026] [security2:error] [pid 796567:tid 796724] [client 50.116.65.227:58520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PebLfyzVz2SrjZpjMewAAAi8"]
[Mon Jul 20 06:07:21.317523 2026] [security2:error] [pid 832668:tid 832909] [client 50.116.65.227:58532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PeWci6KgEEltqA3C_xwAAAG0"]
[Mon Jul 20 06:07:21.636423 2026] [security2:error] [pid 832668:tid 832922] [client 57.141.18.118:31394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pcmci6KgEEltqA3C-nQAAehA"]
[Mon Jul 20 06:07:21.878364 2026] [security2:error] [pid 832668:tid 832900] [client 104.234.53.49:62987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PeWci6KgEEltqA3C_7AAAAGQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:22.030418 2026] [security2:error] [pid 832668:tid 832760] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_8QAAV1k"]
[Mon Jul 20 06:07:22.030592 2026] [security2:error] [pid 832668:tid 832887] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_8QAAV1k"]
[Mon Jul 20 06:07:22.182299 2026] [security2:error] [pid 832668:tid 832913] [client 103.95.123.246:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_9gAAAHE"]
[Mon Jul 20 06:07:22.182422 2026] [security2:error] [pid 832668:tid 832913] [client 103.95.123.246:17568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_9gAAAHE"]
[Mon Jul 20 06:07:22.184302 2026] [security2:error] [pid 796567:tid 796712] [client 45.116.69.230:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMlgAAAiM"]
[Mon Jul 20 06:07:22.184384 2026] [security2:error] [pid 796567:tid 796712] [client 45.116.69.230:58946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMlgAAAiM"]
[Mon Jul 20 06:07:22.188803 2026] [security2:error] [pid 832668:tid 832892] [client 14.225.17.146:53096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4PeWci6KgEEltqA3C_wQAAAFw"], referer: http://intelligentengineeringsolutions.com/Wordpress
[Mon Jul 20 06:07:22.230531 2026] [security2:error] [pid 796567:tid 796766] [client 14.225.17.146:49186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4PebLfyzVz2SrjZpjMbgAAAlk"]
[Mon Jul 20 06:07:22.337488 2026] [security2:error] [pid 832668:tid 832834] [client 185.132.186.67:53247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "al4Pemci6KgEEltqA3C_-wAAACI"]
[Mon Jul 20 06:07:22.356730 2026] [security2:error] [pid 796567:tid 796736] [client 46.201.22.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "memarion.com"] [uri "/wp-login.php"] [unique_id "al4PerLfyzVz2SrjZpjMmgAAAjs"]
[Mon Jul 20 06:07:22.448569 2026] [security2:error] [pid 796567:tid 796743] [client 41.173.37.102:5433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMnwAAAkI"]
[Mon Jul 20 06:07:22.448663 2026] [security2:error] [pid 796567:tid 796743] [client 41.173.37.102:5433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMnwAAAkI"]
[Mon Jul 20 06:07:22.496774 2026] [security2:error] [pid 796567:tid 796776] [client 14.225.17.146:49364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4PebLfyzVz2SrjZpjMkAAAAmM"], referer: http://entuvy.com/Wordpress
[Mon Jul 20 06:07:22.504230 2026] [security2:error] [pid 796567:tid 796784] [client 57.141.18.108:20906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLpAACa34"]
[Mon Jul 20 06:07:22.736605 2026] [security2:error] [pid 832668:tid 832820] [client 193.56.28.190:26571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/wp-login.php/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_9wAAABQ"]
[Mon Jul 20 06:07:22.838412 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAGAAAAGo"]
[Mon Jul 20 06:07:22.838534 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAGAAAAGo"]
[Mon Jul 20 06:07:22.917113 2026] [security2:error] [pid 832668:tid 832827] [client 14.225.17.146:62847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4Pemci6KgEEltqA3DAFAAAABs"], referer: http://jvcmotorsports.com/Wordpress
[Mon Jul 20 06:07:22.972742 2026] [security2:error] [pid 832668:tid 832920] [client 181.224.94.124:29444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAIgAAAHg"]
[Mon Jul 20 06:07:22.972963 2026] [security2:error] [pid 832668:tid 832920] [client 181.224.94.124:29444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAIgAAAHg"]
[Mon Jul 20 06:07:23.095330 2026] [security2:error] [pid 832668:tid 832785] [remote 74.235.96.117:38046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAKwAAa3I"]
[Mon Jul 20 06:07:23.095637 2026] [security2:error] [pid 832668:tid 832907] [client 74.235.96.117:38046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAKwAAa3I"]
[Mon Jul 20 06:07:23.302609 2026] [security2:error] [pid 832668:tid 832909] [client 27.96.94.195:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAPAAAAG0"]
[Mon Jul 20 06:07:23.302741 2026] [security2:error] [pid 832668:tid 832909] [client 27.96.94.195:37504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAPAAAAG0"]
[Mon Jul 20 06:07:23.467012 2026] [security2:error] [pid 796567:tid 796650] [remote 152.228.213.32:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMtwACH1I"]
[Mon Jul 20 06:07:23.467301 2026] [security2:error] [pid 796567:tid 796708] [client 152.228.213.32:40470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMtwACH1I"]
[Mon Jul 20 06:07:23.491929 2026] [security2:error] [pid 796567:tid 796646] [remote 57.141.18.78:28222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4415964"] [unique_id "al4Pe7LfyzVz2SrjZpjMuAACKk4"]
[Mon Jul 20 06:07:23.627956 2026] [security2:error] [pid 832668:tid 832673] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DATwAAQgI"]
[Mon Jul 20 06:07:23.628200 2026] [security2:error] [pid 832668:tid 832866] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DATwAAQgI"]
[Mon Jul 20 06:07:23.831493 2026] [security2:error] [pid 796567:tid 796783] [client 193.56.28.190:53519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/wp-login.php/xmlrpc.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMvQAAAmo"]
[Mon Jul 20 06:07:24.220559 2026] [security2:error] [pid 796567:tid 796740] [client 14.225.17.146:63174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4PfLLfyzVz2SrjZpjMxQAAAj8"], referer: http://collectingrealestate.com/Wordpress
[Mon Jul 20 06:07:24.244483 2026] [security2:error] [pid 832668:tid 832837] [client 104.234.53.69:33121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PfGci6KgEEltqA3DAdQAAACU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:24.248877 2026] [security2:error] [pid 796567:tid 796797] [client 185.226.198.7:17366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMvgAAAng"], referer: http://laceycaraccident.com/index.jsp
[Mon Jul 20 06:07:24.264240 2026] [security2:error] [pid 832668:tid 832817] [client 57.141.18.114:34914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PdWci6KgEEltqA3C_CgAAETg"]
[Mon Jul 20 06:07:24.708799 2026] [security2:error] [pid 832668:tid 832810] [client 193.19.109.239:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4PfGci6KgEEltqA3DAiQAAAAo"]
[Mon Jul 20 06:07:24.888287 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:63120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAPgAAAFE"], referer: http://guidehunting.com/Wordpress
[Mon Jul 20 06:07:24.897677 2026] [security2:error] [pid 832668:tid 832890] [client 14.225.17.146:63002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DALAAAAFo"], referer: http://lelandumc.org/Wordpress
[Mon Jul 20 06:07:24.943874 2026] [security2:error] [pid 796567:tid 796741] [client 193.56.28.190:25703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/wp-login.php/xmlrpc.php"] [unique_id "al4PfLLfyzVz2SrjZpjM2QAAAkA"]
[Mon Jul 20 06:07:25.136655 2026] [security2:error] [pid 832668:tid 832863] [client 57.141.18.28:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pdmci6KgEEltqA3C_QQAAP0U"]
[Mon Jul 20 06:07:25.215794 2026] [security2:error] [pid 832668:tid 832908] [client 50.116.65.227:46618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4PfWci6KgEEltqA3DAnAAAAGw"]
[Mon Jul 20 06:07:25.220352 2026] [security2:error] [pid 796567:tid 796812] [client 14.225.17.146:63302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4PfLLfyzVz2SrjZpjMwwAAAoc"]
[Mon Jul 20 06:07:25.493320 2026] [security2:error] [pid 832668:tid 832812] [client 14.225.17.146:63425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4PfGci6KgEEltqA3DAiAAAAAw"], referer: http://processorstudio.com/Wordpress
[Mon Jul 20 06:07:25.579902 2026] [security2:error] [pid 796567:tid 796745] [client 185.132.186.59:47477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/Simple.php"] [unique_id "al4PfbLfyzVz2SrjZpjM8QAAAkQ"]
[Mon Jul 20 06:07:25.593067 2026] [security2:error] [pid 796567:tid 796608] [remote 31.42.184.154:32900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.184.42.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PfbLfyzVz2SrjZpjM8gACfyg"]
[Mon Jul 20 06:07:25.593445 2026] [security2:error] [pid 796567:tid 796804] [client 31.42.184.154:32900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PfbLfyzVz2SrjZpjM8gACfyg"]
[Mon Jul 20 06:07:25.774718 2026] [security2:error] [pid 832668:tid 832905] [client 14.225.17.146:63824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4PfWci6KgEEltqA3DApQAAAGk"]
[Mon Jul 20 06:07:26.086969 2026] [security2:error] [pid 832668:tid 832910] [client 198.44.157.34:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Pfmci6KgEEltqA3DA1QAAAG4"]
[Mon Jul 20 06:07:26.087115 2026] [security2:error] [pid 832668:tid 832910] [client 198.44.157.34:47120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Pfmci6KgEEltqA3DA1QAAAG4"]
[Mon Jul 20 06:07:26.175854 2026] [security2:error] [pid 796567:tid 796697] [client 14.225.17.146:63917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4PfbLfyzVz2SrjZpjM_AAAAhQ"], referer: https://guidehunting.com/Wordpress
[Mon Jul 20 06:07:26.223462 2026] [security2:error] [pid 832668:tid 832816] [client 14.225.17.146:63620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4PfWci6KgEEltqA3DAmAAAABA"], referer: http://sarahholyfield.com/Wordpress
[Mon Jul 20 06:07:26.322647 2026] [security2:error] [pid 796567:tid 796725] [client 193.19.109.234:60647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floorsourcestock.com"] [uri "/wp-login.php"] [unique_id "al4PfrLfyzVz2SrjZpjNBwAAAjA"]
[Mon Jul 20 06:07:26.331940 2026] [security2:error] [pid 796567:tid 796793] [client 193.37.33.2:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floorsourcestock.com"] [uri "/wp-login.php"] [unique_id "al4PfrLfyzVz2SrjZpjNBgAAAnQ"]
[Mon Jul 20 06:07:26.341908 2026] [security2:error] [pid 832668:tid 832804] [client 193.56.28.190:49329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PfWci6KgEEltqA3DAzwAAAAQ"]
[Mon Jul 20 06:07:26.471408 2026] [security2:error] [pid 832668:tid 832900] [client 43.166.240.231:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.240.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DA-gAAAGQ"]
[Mon Jul 20 06:07:26.471596 2026] [security2:error] [pid 832668:tid 832863] [client 14.225.17.146:64128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DA-QAAAD8"], referer: https://processorstudio.com/Wordpress
[Mon Jul 20 06:07:26.694187 2026] [security2:error] [pid 796567:tid 796812] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../.env"] [unique_id "al4PfrLfyzVz2SrjZpjNHAAAAoc"], referer: https://www.bing.com/search?q=j1ceu7
[Mon Jul 20 06:07:26.836526 2026] [security2:error] [pid 832668:tid 832853] [client 41.140.27.137:24129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DBHwAAADU"]
[Mon Jul 20 06:07:26.858735 2026] [security2:error] [pid 796567:tid 796718] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../var/www/html/.env"] [unique_id "al4PfrLfyzVz2SrjZpjNIQAAAik"], referer: https://t.co/vsuax1xnwx
[Mon Jul 20 06:07:27.242179 2026] [core:error] [pid 832668:tid 832852] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:27.242202 2026] [core:error] [pid 832668:tid 832852] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:27.525366 2026] [security2:error] [pid 832668:tid 832899] [client 185.132.186.102:42695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBiwAAAGM"]
[Mon Jul 20 06:07:27.690516 2026] [security2:error] [pid 796567:tid 796708] [client 193.56.28.190:61175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Pf7LfyzVz2SrjZpjNKQAAAh8"]
[Mon Jul 20 06:07:27.710326 2026] [security2:error] [pid 832668:tid 832867] [client 14.225.17.146:56809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBggAAAEM"], referer: http://worbals.com/Wordpress
[Mon Jul 20 06:07:27.775826 2026] [security2:error] [pid 796567:tid 796817] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pf7LfyzVz2SrjZpjNJwAAAow"], referer: http://laceycaraccident.com/login.do
[Mon Jul 20 06:07:27.809325 2026] [security2:error] [pid 832668:tid 832726] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pf2ci6KgEEltqA3DBmgAAZzc"]
[Mon Jul 20 06:07:27.809489 2026] [security2:error] [pid 832668:tid 832903] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pf2ci6KgEEltqA3DBmgAAZzc"]
[Mon Jul 20 06:07:27.837371 2026] [security2:error] [pid 796567:tid 796739] [client 57.141.18.114:34916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PeLLfyzVz2SrjZpjMYAACPkM"]
[Mon Jul 20 06:07:27.988697 2026] [proxy:error] [pid 832668:tid 832865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:27.988755 2026] [proxy_http:error] [pid 832668:tid 832865] [client 64.79.224.208:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:27.989461 2026] [proxy:error] [pid 832668:tid 832865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:27.989502 2026] [proxy_http:error] [pid 832668:tid 832865] [client 64.79.224.208:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:28.346795 2026] [security2:error] [pid 796567:tid 796715] [client 14.225.17.146:64229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PfrLfyzVz2SrjZpjNHQAAAiY"], referer: http://nurturemarple.co.uk/Wordpress
[Mon Jul 20 06:07:28.392007 2026] [security2:error] [pid 796567:tid 796711] [client 14.225.17.146:52169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4Pf7LfyzVz2SrjZpjNMgAAAiI"], referer: http://partnerselectricalllc.com/Wordpress
[Mon Jul 20 06:07:28.713843 2026] [security2:error] [pid 832668:tid 832883] [client 14.225.17.146:64253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DBIgAAAFM"], referer: http://amalia-capital.com/Wordpress
[Mon Jul 20 06:07:28.777497 2026] [security2:error] [pid 832668:tid 832804] [client 114.119.153.172:26085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nandansonscharitablefoundation.com"] [uri "/2021/08/"] [unique_id "al4PgGci6KgEEltqA3DB3QAAAAQ"], referer: https://nandansonscharitablefoundation.com/2021/02/06/thank-you-from-baps-swaminarayan-santhsa/
[Mon Jul 20 06:07:28.889062 2026] [security2:error] [pid 832668:tid 832892] [client 50.116.65.227:58650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PgGci6KgEEltqA3DBzwAAAFw"]
[Mon Jul 20 06:07:29.043984 2026] [security2:error] [pid 832668:tid 832885] [client 193.56.28.190:35233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PgGci6KgEEltqA3DB1gAAAFU"]
[Mon Jul 20 06:07:29.092438 2026] [security2:error] [pid 796567:tid 796706] [client 50.116.65.227:58674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PgLLfyzVz2SrjZpjNVAAAAh0"]
[Mon Jul 20 06:07:29.166978 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.33:55822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pemci6KgEEltqA3C_8wAATjs"]
[Mon Jul 20 06:07:29.345951 2026] [security2:error] [pid 796567:tid 796801] [client 14.225.17.146:56971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PgbLfyzVz2SrjZpjNWQAAAnw"], referer: https://nurturemarple.co.uk/Wordpress
[Mon Jul 20 06:07:29.441798 2026] [security2:error] [pid 832668:tid 832915] [client 103.141.108.143:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCBAAAAHM"]
[Mon Jul 20 06:07:29.441912 2026] [security2:error] [pid 832668:tid 832915] [client 103.141.108.143:63574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCBAAAAHM"]
[Mon Jul 20 06:07:29.635842 2026] [security2:error] [pid 832668:tid 832882] [client 87.199.196.181:55527] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.196.181" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4PgWci6KgEEltqA3DCDAAAAFI"], referer: https://www.friendlyspreadsheet.com/my-most-used-spreadsheet-contains-no-formulas/
[Mon Jul 20 06:07:29.635915 2026] [security2:error] [pid 832668:tid 832882] [client 87.199.196.181:55527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4PgWci6KgEEltqA3DCDAAAAFI"], referer: https://www.friendlyspreadsheet.com/my-most-used-spreadsheet-contains-no-formulas/
[Mon Jul 20 06:07:29.696414 2026] [security2:error] [pid 832668:tid 832871] [client 150.228.148.150:38329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCDgAAAEc"]
[Mon Jul 20 06:07:29.701504 2026] [security2:error] [pid 832668:tid 832871] [client 150.228.148.150:38329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCDgAAAEc"]
[Mon Jul 20 06:07:29.854949 2026] [security2:error] [pid 832668:tid 832910] [client 106.192.104.4:50363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCFQAAAG4"]
[Mon Jul 20 06:07:29.869511 2026] [security2:error] [pid 832668:tid 832910] [client 106.192.104.4:50363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCFQAAAG4"]
[Mon Jul 20 06:07:30.027618 2026] [security2:error] [pid 832668:tid 832857] [client 14.225.17.146:53397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBmwAAADk"], referer: http://cheesewithjam.com/Wordpress
[Mon Jul 20 06:07:30.087321 2026] [security2:error] [pid 796567:tid 796681] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNcQACaHE"]
[Mon Jul 20 06:07:30.087443 2026] [security2:error] [pid 796567:tid 796781] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNcQACaHE"]
[Mon Jul 20 06:07:30.298767 2026] [security2:error] [pid 832668:tid 832927] [client 57.141.18.84:54020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAQwAAf3o"]
[Mon Jul 20 06:07:30.320988 2026] [core:error] [pid 796567:tid 796725] [client 14.225.17.146:60698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:30.321011 2026] [core:error] [pid 796567:tid 796725] [client 14.225.17.146:60698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:30.354839 2026] [security2:error] [pid 832668:tid 832811] [client 35.209.224.174:39260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCLgAAAAs"]
[Mon Jul 20 06:07:30.470395 2026] [security2:error] [pid 832668:tid 832901] [client 185.226.198.5:35326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCHwAAAGU"], referer: http://laceycaraccident.com/favicon-32x32.png
[Mon Jul 20 06:07:30.486462 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.86:57697] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-admin/1.php"] [unique_id "al4Pgmci6KgEEltqA3DCOAAAAAI"]
[Mon Jul 20 06:07:30.486591 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.86:57697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/1.php"] [unique_id "al4Pgmci6KgEEltqA3DCOAAAAAI"]
[Mon Jul 20 06:07:30.629863 2026] [security2:error] [pid 832668:tid 832920] [client 57.141.18.121:38054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAWQAAeAw"]
[Mon Jul 20 06:07:30.688084 2026] [security2:error] [pid 832668:tid 832834] [client 57.141.18.113:44752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAZAAAIgQ"]
[Mon Jul 20 06:07:30.698506 2026] [security2:error] [pid 796567:tid 796764] [client 193.19.109.220:24951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4PgrLfyzVz2SrjZpjNigAAAlc"]
[Mon Jul 20 06:07:30.885983 2026] [security2:error] [pid 832668:tid 832868] [client 74.7.227.179:54936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCSQAARBY"], referer: https://tejasenvironmental.com/p=3792676
[Mon Jul 20 06:07:30.920877 2026] [security2:error] [pid 796567:tid 796678] [remote 91.142.222.105:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PgrLfyzVz2SrjZpjNjgACeW4"]
[Mon Jul 20 06:07:30.935310 2026] [security2:error] [pid 796567:tid 796761] [client 112.213.160.112:30987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNjwAAAlQ"]
[Mon Jul 20 06:07:30.935447 2026] [security2:error] [pid 796567:tid 796761] [client 112.213.160.112:30987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNjwAAAlQ"]
[Mon Jul 20 06:07:30.991300 2026] [security2:error] [pid 832668:tid 832915] [client 103.77.203.233:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pgmci6KgEEltqA3DCUwAAAHM"]
[Mon Jul 20 06:07:30.991419 2026] [security2:error] [pid 832668:tid 832915] [client 103.77.203.233:57496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pgmci6KgEEltqA3DCUwAAAHM"]
[Mon Jul 20 06:07:31.067121 2026] [security2:error] [pid 796567:tid 796733] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../var/www/.env"] [unique_id "al4Pg7LfyzVz2SrjZpjNkwAAAjg"], referer: https://www.google.com/
[Mon Jul 20 06:07:31.083525 2026] [security2:error] [pid 796567:tid 796717] [client 86.98.90.58:60693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNlAAAAig"]
[Mon Jul 20 06:07:31.083616 2026] [security2:error] [pid 796567:tid 796717] [client 86.98.90.58:60693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNlAAAAig"]
[Mon Jul 20 06:07:31.127449 2026] [security2:error] [pid 796567:tid 796815] [client 50.116.65.227:32680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Pg7LfyzVz2SrjZpjNlgAAAoo"]
[Mon Jul 20 06:07:31.138358 2026] [security2:error] [pid 832668:tid 832885] [client 50.116.65.227:32696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Pg2ci6KgEEltqA3DCYgAAAFU"]
[Mon Jul 20 06:07:31.220634 2026] [security2:error] [pid 796567:tid 796706] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//var/www/html/wp-config.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNlwAAAh0"], referer: https://www.bing.com/search?q=p0vyi4
[Mon Jul 20 06:07:31.423429 2026] [security2:error] [pid 832668:tid 832910] [client 115.246.21.170:55099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg2ci6KgEEltqA3DCdAAAAG4"]
[Mon Jul 20 06:07:31.423559 2026] [security2:error] [pid 832668:tid 832910] [client 115.246.21.170:55099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg2ci6KgEEltqA3DCdAAAAG4"]
[Mon Jul 20 06:07:31.564970 2026] [security2:error] [pid 832668:tid 832810] [client 185.226.198.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pg2ci6KgEEltqA3DCWQAAAAo"], referer: http://laceycaraccident.com/showLogin.cc
[Mon Jul 20 06:07:31.686621 2026] [security2:error] [pid 832668:tid 832886] [client 104.234.53.55:47359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pg2ci6KgEEltqA3DCggAAAFY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:31.872668 2026] [security2:error] [pid 796567:tid 796605] [remote 8.217.108.67:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNqgACGiU"]
[Mon Jul 20 06:07:31.884117 2026] [security2:error] [pid 796567:tid 796765] [client 45.116.69.230:59410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNrAAAAlg"]
[Mon Jul 20 06:07:31.884270 2026] [security2:error] [pid 796567:tid 796765] [client 45.116.69.230:59410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNrAAAAlg"]
[Mon Jul 20 06:07:32.228076 2026] [security2:error] [pid 832668:tid 832755] [remote 15.206.251.117:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCpQAAaVQ"]
[Mon Jul 20 06:07:32.406724 2026] [security2:error] [pid 832668:tid 832699] [remote 91.142.222.105:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCsAAAARw"]
[Mon Jul 20 06:07:32.491530 2026] [security2:error] [pid 832668:tid 832870] [client 185.132.186.78:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/ocean/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCsQAAAEY"]
[Mon Jul 20 06:07:32.666269 2026] [security2:error] [pid 832668:tid 832790] [remote 15.206.251.117:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCwgAAKHc"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:07:32.694520 2026] [security2:error] [pid 832668:tid 832795] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PhGci6KgEEltqA3DCwwAAPnw"]
[Mon Jul 20 06:07:32.694671 2026] [security2:error] [pid 832668:tid 832862] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PhGci6KgEEltqA3DCwwAAPnw"]
[Mon Jul 20 06:07:32.902911 2026] [security2:error] [pid 796567:tid 796606] [remote 8.217.108.67:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PhLLfyzVz2SrjZpjNwAAChyY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:07:32.968033 2026] [security2:error] [pid 796567:tid 796736] [client 57.141.18.113:22964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PfrLfyzVz2SrjZpjM_wACO2g"]
[Mon Jul 20 06:07:33.000131 2026] [security2:error] [pid 832668:tid 832738] [remote 91.142.222.105:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DC2gAAF0M"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:07:33.024391 2026] [security2:error] [pid 796567:tid 796665] [remote 91.142.222.105:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PhbLfyzVz2SrjZpjNwgACQ2E"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:07:33.043121 2026] [security2:error] [pid 832668:tid 832806] [client 46.110.96.34:17651] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4PhWci6KgEEltqA3DC3gAAAAY"]
[Mon Jul 20 06:07:33.043767 2026] [security2:error] [pid 832668:tid 832827] [client 46.110.96.34:38553] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4PhWci6KgEEltqA3DC3wAAABs"]
[Mon Jul 20 06:07:33.146630 2026] [security2:error] [pid 832668:tid 832859] [client 41.173.37.102:5880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC5wAAADs"]
[Mon Jul 20 06:07:33.146725 2026] [security2:error] [pid 832668:tid 832859] [client 41.173.37.102:5880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC5wAAADs"]
[Mon Jul 20 06:07:33.153942 2026] [security2:error] [pid 832668:tid 832747] [remote 220.181.108.146:13299] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4PhWci6KgEEltqA3DC6QAAZUw"]
[Mon Jul 20 06:07:33.342633 2026] [security2:error] [pid 796567:tid 796774] [client 27.96.94.195:37676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNygAAAmE"]
[Mon Jul 20 06:07:33.342731 2026] [security2:error] [pid 796567:tid 796774] [client 27.96.94.195:37676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNygAAAmE"]
[Mon Jul 20 06:07:33.358117 2026] [security2:error] [pid 832668:tid 832842] [client 74.208.214.194:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PhWci6KgEEltqA3DC9AAAACo"]
[Mon Jul 20 06:07:33.530810 2026] [security2:error] [pid 796567:tid 796761] [client 181.224.94.124:57139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNzQAAAlQ"]
[Mon Jul 20 06:07:33.530950 2026] [security2:error] [pid 796567:tid 796761] [client 181.224.94.124:57139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNzQAAAlQ"]
[Mon Jul 20 06:07:33.535860 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC_wAAAGM"]
[Mon Jul 20 06:07:33.536017 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:18423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC_wAAAGM"]
[Mon Jul 20 06:07:33.620134 2026] [security2:error] [pid 832668:tid 832886] [client 178.152.178.232:37353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DDAwAAAFY"]
[Mon Jul 20 06:07:33.620268 2026] [security2:error] [pid 832668:tid 832886] [client 178.152.178.232:37353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DDAwAAAFY"]
[Mon Jul 20 06:07:33.749156 2026] [security2:error] [pid 832668:tid 832908] [client 57.141.18.29:23412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBSAAAbBI"]
[Mon Jul 20 06:07:34.122859 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.115:60678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBfwAAZBs"]
[Mon Jul 20 06:07:34.234970 2026] [security2:error] [pid 796567:tid 796569] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PhrLfyzVz2SrjZpjN3wACegE"]
[Mon Jul 20 06:07:34.235184 2026] [security2:error] [pid 796567:tid 796799] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PhrLfyzVz2SrjZpjN3wACegE"]
[Mon Jul 20 06:07:34.252372 2026] [security2:error] [pid 832668:tid 832782] [remote 119.249.100.50:35717] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4Phmci6KgEEltqA3DDJAAAW28"]
[Mon Jul 20 06:07:34.421287 2026] [security2:error] [pid 832668:tid 832811] [client 104.234.53.90:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Phmci6KgEEltqA3DDLwAAAAs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:34.438680 2026] [security2:error] [pid 832668:tid 832841] [client 185.132.186.77:34629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "al4Phmci6KgEEltqA3DDMAAAACk"]
[Mon Jul 20 06:07:34.644732 2026] [security2:error] [pid 796567:tid 796739] [client 114.119.158.112:38551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.phillipbloch.com"] [uri "/robots.txt"] [unique_id "al4PhrLfyzVz2SrjZpjN7AAAAj4"], referer: http://www.phillipbloch.com/robots.txt
[Mon Jul 20 06:07:34.644844 2026] [security2:error] [pid 832668:tid 832778] [remote 162.19.86.63:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4Phmci6KgEEltqA3DDOQAAQms"]
[Mon Jul 20 06:07:34.758280 2026] [proxy:error] [pid 832668:tid 832753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:34.758318 2026] [proxy_http:error] [pid 832668:tid 832753] [remote 158.222.112.12:56924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:34.759027 2026] [proxy:error] [pid 832668:tid 832753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:34.759052 2026] [proxy_http:error] [pid 832668:tid 832753] [remote 158.222.112.12:56924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:34.843184 2026] [security2:error] [pid 832668:tid 832774] [remote 162.19.86.63:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4Phmci6KgEEltqA3DDSAAAdWc"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:07:34.945072 2026] [security2:error] [pid 832668:tid 832824] [client 185.226.198.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Phmci6KgEEltqA3DDNAAAABg"], referer: http://laceycaraccident.com/solr/#/
[Mon Jul 20 06:07:35.598021 2026] [security2:error] [pid 832668:tid 832814] [client 57.141.18.72:27450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PgGci6KgEEltqA3DB2gAADlw"]
[Mon Jul 20 06:07:35.701902 2026] [security2:error] [pid 832668:tid 832804] [client 14.225.17.146:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4Ph2ci6KgEEltqA3DDbgAAAAQ"], referer: http://betterbonddogtraining.com/Wordpress
[Mon Jul 20 06:07:35.856131 2026] [security2:error] [pid 832668:tid 832802] [client 14.225.17.146:61257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4Phmci6KgEEltqA3DDLgAAAAI"], referer: http://dnsplumbing.com/Wordpress
[Mon Jul 20 06:07:35.859600 2026] [security2:error] [pid 796567:tid 796730] [client 49.13.167.123:7318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4Ph7LfyzVz2SrjZpjODwAAAjU"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:07:35.921797 2026] [security2:error] [pid 796567:tid 796801] [client 14.225.17.146:60054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4PhrLfyzVz2SrjZpjN2AAAAnw"], referer: http://ksands.co.uk/Wordpress
[Mon Jul 20 06:07:36.057371 2026] [security2:error] [pid 796567:tid 796824] [client 114.119.148.169:46035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/crochet-course-farnham-surrey/"] [unique_id "al4PiLLfyzVz2SrjZpjOGwAAApM"], referer: https://www.mezzacraft.com/learn-to-crochet-course-surrey-2020-2
[Mon Jul 20 06:07:36.387485 2026] [security2:error] [pid 832668:tid 832812] [client 185.132.186.102:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/classwithtostring.php"] [unique_id "al4PiGci6KgEEltqA3DDqAAAAAw"]
[Mon Jul 20 06:07:36.469490 2026] [security2:error] [pid 832668:tid 832711] [remote 111.225.214.198:32295] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4PiGci6KgEEltqA3DDrAAANCg"]
[Mon Jul 20 06:07:36.579584 2026] [security2:error] [pid 796567:tid 796757] [client 57.141.18.42:47342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PgbLfyzVz2SrjZpjNaAACUG0"]
[Mon Jul 20 06:07:36.842048 2026] [security2:error] [pid 832668:tid 832862] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PiGci6KgEEltqA3DDwQAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:36.908918 2026] [security2:error] [pid 832668:tid 832821] [client 98.159.234.160:42347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PiGci6KgEEltqA3DD1AAAABU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:37.421349 2026] [security2:error] [pid 832668:tid 832779] [remote 81.173.115.7:40096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4PiWci6KgEEltqA3DEBAAAVGw"]
[Mon Jul 20 06:07:37.447147 2026] [security2:error] [pid 832668:tid 832844] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PiGci6KgEEltqA3DD1wAAACw"], referer: http://laceycaraccident.com/Telerik.Web.UI.WebResource.axd?type=rau
[Mon Jul 20 06:07:37.617546 2026] [security2:error] [pid 832668:tid 832677] [remote 81.173.115.7:40096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4PiWci6KgEEltqA3DEDAAAGQY"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 06:07:37.636369 2026] [security2:error] [pid 832668:tid 832865] [client 57.141.18.91:23556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCQwAAQQs"]
[Mon Jul 20 06:07:37.710467 2026] [security2:error] [pid 832668:tid 832905] [client 14.225.17.146:53327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4PiGci6KgEEltqA3DDnAAAAGk"], referer: http://ghivs.com/Wordpress
[Mon Jul 20 06:07:38.124178 2026] [security2:error] [pid 832668:tid 832816] [client 172.190.117.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4Pimci6KgEEltqA3DEIwAAABA"]
[Mon Jul 20 06:07:38.333471 2026] [security2:error] [pid 832668:tid 832713] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pimci6KgEEltqA3DEOAAARSo"]
[Mon Jul 20 06:07:38.333679 2026] [security2:error] [pid 832668:tid 832869] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pimci6KgEEltqA3DEOAAARSo"]
[Mon Jul 20 06:07:38.335269 2026] [security2:error] [pid 832668:tid 832876] [client 185.132.186.55:23961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/av.php"] [unique_id "al4Pimci6KgEEltqA3DEOQAAAEw"]
[Mon Jul 20 06:07:38.662270 2026] [security2:error] [pid 832668:tid 832892] [client 47.129.222.11:51710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pimci6KgEEltqA3DETgAAAFw"]
[Mon Jul 20 06:07:38.816702 2026] [security2:error] [pid 832668:tid 832820] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pimci6KgEEltqA3DEUAAAABQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:39.228613 2026] [security2:error] [pid 832668:tid 832868] [client 57.141.18.56:44536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pg2ci6KgEEltqA3DCjQAARBc"]
[Mon Jul 20 06:07:39.425090 2026] [security2:error] [pid 832668:tid 832866] [client 185.226.198.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pimci6KgEEltqA3DEYgAAAEI"], referer: http://laceycaraccident.com/api/session/properties
[Mon Jul 20 06:07:39.562932 2026] [security2:error] [pid 832668:tid 832807] [client 13.229.223.11:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pi2ci6KgEEltqA3DEegAAAAc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:07:39.904050 2026] [security2:error] [pid 832668:tid 832871] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pi2ci6KgEEltqA3DEkwAAAEc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:40.228147 2026] [security2:error] [pid 832668:tid 832884] [client 103.141.108.143:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DErAAAAFQ"]
[Mon Jul 20 06:07:40.228843 2026] [security2:error] [pid 832668:tid 832884] [client 103.141.108.143:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DErAAAAFQ"]
[Mon Jul 20 06:07:40.289293 2026] [security2:error] [pid 796567:tid 796724] [client 185.132.186.89:32743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/waf_defender.php"] [unique_id "al4PjLLfyzVz2SrjZpjOeAAAAi8"]
[Mon Jul 20 06:07:40.298840 2026] [autoindex:error] [pid 796567:tid 796774] [client 141.98.11.42:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Ahi/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Mon Jul 20 06:07:40.471380 2026] [security2:error] [pid 832668:tid 832910] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PjGci6KgEEltqA3DEtAAAAG4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:40.522585 2026] [security2:error] [pid 832668:tid 832894] [client 106.192.104.4:50859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DEuQAAAF4"]
[Mon Jul 20 06:07:40.527213 2026] [security2:error] [pid 832668:tid 832894] [client 106.192.104.4:50859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DEuQAAAF4"]
[Mon Jul 20 06:07:40.556544 2026] [security2:error] [pid 832668:tid 832899] [client 50.116.65.227:15098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PjGci6KgEEltqA3DEvQAAAGM"]
[Mon Jul 20 06:07:40.559042 2026] [security2:error] [pid 832668:tid 832879] [client 57.141.18.18:50988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PhWci6KgEEltqA3DC4QAATx8"]
[Mon Jul 20 06:07:40.565508 2026] [security2:error] [pid 832668:tid 832892] [client 50.116.65.227:15114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PjGci6KgEEltqA3DEwgAAAFw"]
[Mon Jul 20 06:07:40.639390 2026] [core:error] [pid 796567:tid 796822] [client 198.235.24.58:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:40.639418 2026] [core:error] [pid 796567:tid 796822] [client 198.235.24.58:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:40.738901 2026] [security2:error] [pid 832668:tid 832793] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE0gAAJ3o"]
[Mon Jul 20 06:07:40.739068 2026] [security2:error] [pid 832668:tid 832839] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE0gAAJ3o"]
[Mon Jul 20 06:07:40.748542 2026] [security2:error] [pid 832668:tid 832835] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PjGci6KgEEltqA3DEzwAAACM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:40.787917 2026] [security2:error] [pid 832668:tid 832803] [client 116.179.33.83:23038] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4PjGci6KgEEltqA3DE2AAAAAM"]
[Mon Jul 20 06:07:40.837506 2026] [security2:error] [pid 832668:tid 832877] [client 14.225.17.146:53638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Pimci6KgEEltqA3DEQQAAAE0"], referer: http://healthylifegourmet.org/Wordpress
[Mon Jul 20 06:07:40.848358 2026] [security2:error] [pid 832668:tid 832811] [client 31.50.30.70:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.30.50.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE2gAAAAs"]
[Mon Jul 20 06:07:40.848513 2026] [security2:error] [pid 832668:tid 832811] [client 31.50.30.70:58556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE2gAAAAs"]
[Mon Jul 20 06:07:41.227274 2026] [security2:error] [pid 832668:tid 832894] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PjWci6KgEEltqA3DE9QAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:41.293674 2026] [security2:error] [pid 832668:tid 832837] [client 50.116.65.227:15148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/03/IMG_3040-1.jpeg"] [unique_id "al4PjWci6KgEEltqA3DFCAAAAEo"]
[Mon Jul 20 06:07:41.358274 2026] [security2:error] [pid 832668:tid 832907] [client 57.141.18.16:55106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PhWci6KgEEltqA3DDGAAAa1Y"]
[Mon Jul 20 06:07:41.440221 2026] [security2:error] [pid 832668:tid 832857] [client 103.77.203.233:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFEwAAADk"]
[Mon Jul 20 06:07:41.440394 2026] [security2:error] [pid 832668:tid 832857] [client 103.77.203.233:57556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFEwAAADk"]
[Mon Jul 20 06:07:41.481036 2026] [security2:error] [pid 832668:tid 832858] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PjWci6KgEEltqA3DFEgAAADo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:41.686822 2026] [security2:error] [pid 832668:tid 832882] [client 112.213.160.112:8507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFKgAAAFI"]
[Mon Jul 20 06:07:41.687608 2026] [security2:error] [pid 832668:tid 832882] [client 112.213.160.112:8507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFKgAAAFI"]
[Mon Jul 20 06:07:41.845373 2026] [security2:error] [pid 832668:tid 832690] [remote 45.90.123.233:38104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFNAAAXxM"]
[Mon Jul 20 06:07:41.845495 2026] [security2:error] [pid 832668:tid 832895] [client 45.90.123.233:38104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFNAAAXxM"]
[Mon Jul 20 06:07:42.001035 2026] [security2:error] [pid 832668:tid 832803] [client 115.246.21.170:8618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFOAAAAAM"]
[Mon Jul 20 06:07:42.001149 2026] [security2:error] [pid 832668:tid 832803] [client 115.246.21.170:8618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFOAAAAAM"]
[Mon Jul 20 06:07:42.198995 2026] [security2:error] [pid 796567:tid 796783] [client 202.50.55.150:61871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/.env"] [unique_id "al4PjrLfyzVz2SrjZpjOpwAAAmo"]
[Mon Jul 20 06:07:42.223955 2026] [security2:error] [pid 832668:tid 832911] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DFLQAAAG8"], referer: http://laceycaraccident.com/zabbix/favicon.ico
[Mon Jul 20 06:07:42.232176 2026] [security2:error] [pid 796567:tid 796732] [client 185.132.186.95:52105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Cache/upfile.php"] [unique_id "al4PjrLfyzVz2SrjZpjOqQAAAjc"]
[Mon Jul 20 06:07:42.242169 2026] [security2:error] [pid 832668:tid 832885] [client 57.141.18.0:29892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Phmci6KgEEltqA3DDIwAAVWg"]
[Mon Jul 20 06:07:42.400298 2026] [security2:error] [pid 832668:tid 832823] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pjmci6KgEEltqA3DFWgAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:42.516031 2026] [security2:error] [pid 832668:tid 832869] [client 14.225.17.146:50004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DE7gAAAEU"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/Wordpress
[Mon Jul 20 06:07:42.517149 2026] [security2:error] [pid 832668:tid 832806] [client 202.50.55.150:61889] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/conf/.env"] [unique_id "al4Pjmci6KgEEltqA3DFZgAAAAY"]
[Mon Jul 20 06:07:42.578041 2026] [security2:error] [pid 832668:tid 832913] [client 45.116.69.230:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFaQAAAHE"]
[Mon Jul 20 06:07:42.578147 2026] [security2:error] [pid 832668:tid 832913] [client 45.116.69.230:59858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFaQAAAHE"]
[Mon Jul 20 06:07:42.835012 2026] [security2:error] [pid 832668:tid 832834] [client 202.50.55.150:61907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/wp-content/.env"] [unique_id "al4Pjmci6KgEEltqA3DFcQAAACI"]
[Mon Jul 20 06:07:42.864295 2026] [security2:error] [pid 832668:tid 832919] [client 57.141.18.105:59626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ph2ci6KgEEltqA3DDbwAAd10"]
[Mon Jul 20 06:07:43.084800 2026] [security2:error] [pid 832668:tid 832819] [client 14.225.17.146:49972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DFDwAAABM"], referer: http://bnb-engineering.com/Wordpress
[Mon Jul 20 06:07:43.146203 2026] [security2:error] [pid 832668:tid 832912] [client 202.50.55.150:61925] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/wp-admin/.env"] [unique_id "al4Pj2ci6KgEEltqA3DFjwAAAHA"]
[Mon Jul 20 06:07:43.386314 2026] [security2:error] [pid 832668:tid 832689] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFmQAATxI"]
[Mon Jul 20 06:07:43.386453 2026] [security2:error] [pid 832668:tid 832879] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFmQAATxI"]
[Mon Jul 20 06:07:43.456334 2026] [security2:error] [pid 796567:tid 796730] [client 202.50.55.150:61937] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/library/.env"] [unique_id "al4Pj7LfyzVz2SrjZpjOywAAAjU"]
[Mon Jul 20 06:07:43.526085 2026] [security2:error] [pid 832668:tid 832760] [remote 217.61.143.92:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Pj2ci6KgEEltqA3DFogAAVFk"]
[Mon Jul 20 06:07:43.526903 2026] [security2:error] [pid 832668:tid 832831] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFoAAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:43.636836 2026] [security2:error] [pid 796567:tid 796590] [remote 45.90.123.233:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pj7LfyzVz2SrjZpjO0QACKBY"]
[Mon Jul 20 06:07:43.639474 2026] [proxy:error] [pid 796567:tid 796764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:43.639533 2026] [proxy_http:error] [pid 796567:tid 796764] [client 178.73.242.130:27447] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:43.640241 2026] [proxy:error] [pid 796567:tid 796764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:43.640268 2026] [proxy_http:error] [pid 796567:tid 796764] [client 178.73.242.130:27447] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:43.718601 2026] [security2:error] [pid 796567:tid 796821] [client 57.141.18.46:62838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PiLLfyzVz2SrjZpjOJAACkE4"]
[Mon Jul 20 06:07:43.752072 2026] [security2:error] [pid 832668:tid 832816] [client 41.173.37.102:6432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFrAAAABA"]
[Mon Jul 20 06:07:43.752183 2026] [security2:error] [pid 832668:tid 832816] [client 41.173.37.102:6432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFrAAAABA"]
[Mon Jul 20 06:07:43.752759 2026] [security2:error] [pid 832668:tid 832852] [client 14.225.17.146:49739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFowAAADQ"], referer: http://mezzacraft.com/Wordpress
[Mon Jul 20 06:07:43.765993 2026] [security2:error] [pid 832668:tid 832864] [client 202.50.55.150:61945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/new/.env"] [unique_id "al4Pj2ci6KgEEltqA3DFsQAAAEA"]
[Mon Jul 20 06:07:43.783623 2026] [autoindex:error] [pid 796567:tid 796765] [client 49.234.192.248:0] AH01276: Cannot serve directory /home3/elemeqg5/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.elementalkneads.com
[Mon Jul 20 06:07:43.835346 2026] [security2:error] [pid 796567:tid 796573] [remote 45.90.123.233:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pj7LfyzVz2SrjZpjO3QACXQU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:07:43.865372 2026] [security2:error] [pid 832668:tid 832698] [remote 156.59.198.136:47252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nurturemarple.co.uk"] [uri "/wp-content/uploads/2016/02/Nurture-Newsletter_Preschool-Room_Apr16.pdf"] [unique_id "al4Pj2ci6KgEEltqA3DFvAAAOBs"]
[Mon Jul 20 06:07:43.884799 2026] [security2:error] [pid 832668:tid 832737] [remote 217.61.143.92:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Pj2ci6KgEEltqA3DFvwAAFkI"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:07:43.918063 2026] [security2:error] [pid 832668:tid 832834] [client 14.225.17.146:59180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFuQAAACI"], referer: http://katsklar.com/Wordpress
[Mon Jul 20 06:07:44.051001 2026] [security2:error] [pid 832668:tid 832876] [client 181.224.94.124:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PkGci6KgEEltqA3DFxQAAAEw"]
[Mon Jul 20 06:07:44.051124 2026] [security2:error] [pid 832668:tid 832876] [client 181.224.94.124:2202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PkGci6KgEEltqA3DFxQAAAEw"]
[Mon Jul 20 06:07:44.077241 2026] [security2:error] [pid 796567:tid 796798] [client 202.50.55.150:61959] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/vendor/.env"] [unique_id "al4PkLLfyzVz2SrjZpjO5AAAAnk"]
[Mon Jul 20 06:07:44.144787 2026] [security2:error] [pid 796567:tid 796805] [client 74.208.214.194:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PkLLfyzVz2SrjZpjO5wAAAoA"]
[Mon Jul 20 06:07:44.211082 2026] [security2:error] [pid 796567:tid 796585] [remote 217.61.143.92:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4PkLLfyzVz2SrjZpjO6gACkxE"]
[Mon Jul 20 06:07:44.388043 2026] [security2:error] [pid 796567:tid 796752] [client 202.50.55.150:61973] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/old/.env"] [unique_id "al4PkLLfyzVz2SrjZpjO8AAAAks"]
[Mon Jul 20 06:07:44.412295 2026] [security2:error] [pid 832668:tid 832774] [remote 57.141.18.107:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5916983"] [unique_id "al4PkGci6KgEEltqA3DF0wAAYGc"]
[Mon Jul 20 06:07:44.427995 2026] [security2:error] [pid 796567:tid 796741] [client 57.141.18.109:31976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PibLfyzVz2SrjZpjOMAACQE8"]
[Mon Jul 20 06:07:44.446093 2026] [security2:error] [pid 796567:tid 796660] [remote 217.61.143.92:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4PkLLfyzVz2SrjZpjO-AACZVw"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 06:07:44.698404 2026] [security2:error] [pid 796567:tid 796716] [client 202.50.55.150:61981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/local/.env"] [unique_id "al4PkLLfyzVz2SrjZpjPBAAAAic"]
[Mon Jul 20 06:07:44.708790 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PkGci6KgEEltqA3DF2wAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:44.797733 2026] [security2:error] [pid 796567:tid 796621] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPCQACUTU"]
[Mon Jul 20 06:07:44.797954 2026] [security2:error] [pid 796567:tid 796758] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPCQACUTU"]
[Mon Jul 20 06:07:44.954298 2026] [security2:error] [pid 796567:tid 796711] [client 103.95.123.246:18971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPEAAAAiI"]
[Mon Jul 20 06:07:44.954407 2026] [security2:error] [pid 796567:tid 796711] [client 103.95.123.246:18971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPEAAAAiI"]
[Mon Jul 20 06:07:45.016899 2026] [security2:error] [pid 796567:tid 796781] [client 202.50.55.150:61994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/api/.env"] [unique_id "al4PkbLfyzVz2SrjZpjPEgAAAmg"]
[Mon Jul 20 06:07:45.018971 2026] [security2:error] [pid 832668:tid 832807] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PkGci6KgEEltqA3DF8QAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:45.019430 2026] [security2:error] [pid 832668:tid 832925] [client 94.154.43.188:48308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al4PkWci6KgEEltqA3DF9wAAAH0"]
[Mon Jul 20 06:07:45.199877 2026] [security2:error] [pid 832668:tid 832895] [client 185.132.186.81:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/small.php"] [unique_id "al4PkWci6KgEEltqA3DF_AAAAF8"]
[Mon Jul 20 06:07:45.322369 2026] [security2:error] [pid 796567:tid 796769] [client 94.154.43.184:19772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.scoophouse.com"] [uri "/.env"] [unique_id "al4PkbLfyzVz2SrjZpjPFwAAAlw"]
[Mon Jul 20 06:07:45.342992 2026] [security2:error] [pid 796567:tid 796714] [client 202.50.55.150:62004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/blog/.env"] [unique_id "al4PkbLfyzVz2SrjZpjPGAAAAiU"]
[Mon Jul 20 06:07:45.382293 2026] [security2:error] [pid 832668:tid 832903] [client 172.225.80.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFjAAAAGc"]
[Mon Jul 20 06:07:45.543136 2026] [security2:error] [pid 832668:tid 832829] [client 14.225.17.146:59209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFkgAAAB0"], referer: http://securingmemories.com/Wordpress
[Mon Jul 20 06:07:45.675999 2026] [security2:error] [pid 832668:tid 832906] [client 202.50.55.150:62015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/crm/.env"] [unique_id "al4PkWci6KgEEltqA3DGFgAAAGo"]
[Mon Jul 20 06:07:45.955608 2026] [core:error] [pid 832668:tid 832819] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:45.955633 2026] [core:error] [pid 832668:tid 832819] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:46.011770 2026] [security2:error] [pid 832668:tid 832914] [client 57.141.18.53:34602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pi2ci6KgEEltqA3DEZQAAcho"]
[Mon Jul 20 06:07:46.077291 2026] [security2:error] [pid 832668:tid 832844] [client 57.141.18.44:27008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pi2ci6KgEEltqA3DEZgAALCU"]
[Mon Jul 20 06:07:46.313225 2026] [security2:error] [pid 832668:tid 832909] [client 185.226.198.5:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PkWci6KgEEltqA3DGGQAAAG0"], referer: http://laceycaraccident.com/static/historypage.js
[Mon Jul 20 06:07:46.337714 2026] [security2:error] [pid 832668:tid 832921] [client 202.50.55.150:62039] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/laravel/.env"] [unique_id "al4Pkmci6KgEEltqA3DGPAAAAHk"]
[Mon Jul 20 06:07:46.566071 2026] [security2:error] [pid 796567:tid 796715] [client 14.225.17.146:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4PkLLfyzVz2SrjZpjPDwAAAiY"], referer: http://margaretspeckogawa.com/Wordpress
[Mon Jul 20 06:07:46.602437 2026] [security2:error] [pid 832668:tid 832888] [client 116.204.96.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGSwAAWFY"], referer: https://www.aleishapenny.ca/listing/page/560?paged=560&view=grid
[Mon Jul 20 06:07:46.648465 2026] [security2:error] [pid 832668:tid 832822] [client 202.50.55.150:62053] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/app/.env"] [unique_id "al4Pkmci6KgEEltqA3DGWAAAABY"]
[Mon Jul 20 06:07:46.958225 2026] [security2:error] [pid 796567:tid 796799] [client 202.50.55.150:62064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/app/config/.env"] [unique_id "al4PkrLfyzVz2SrjZpjPPwAAAno"]
[Mon Jul 20 06:07:47.141721 2026] [security2:error] [pid 832668:tid 832898] [client 185.132.186.54:50243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/about.php"] [unique_id "al4Pk2ci6KgEEltqA3DGfQAAAGI"]
[Mon Jul 20 06:07:47.284696 2026] [security2:error] [pid 832668:tid 832896] [client 202.50.55.150:62076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/apps/.env"] [unique_id "al4Pk2ci6KgEEltqA3DGgwAAAGA"]
[Mon Jul 20 06:07:47.407965 2026] [security2:error] [pid 796567:tid 796779] [client 14.225.17.146:53751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPRAAAAmY"], referer: http://adultdaycarereno.com/Wordpress
[Mon Jul 20 06:07:47.513847 2026] [security2:error] [pid 832668:tid 832899] [client 158.173.166.181:59469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Pk2ci6KgEEltqA3DGlAAAAGM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:47.590293 2026] [security2:error] [pid 832668:tid 832824] [client 57.141.18.113:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjGci6KgEEltqA3DE0AAAGAE"]
[Mon Jul 20 06:07:47.611067 2026] [security2:error] [pid 796567:tid 796786] [client 202.50.55.150:62087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/audio/.env"] [unique_id "al4Pk7LfyzVz2SrjZpjPSwAAAm0"]
[Mon Jul 20 06:07:47.814218 2026] [security2:error] [pid 832668:tid 832909] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pk2ci6KgEEltqA3DGngAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:47.817974 2026] [security2:error] [pid 832668:tid 832804] [client 57.141.18.26:28808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjGci6KgEEltqA3DE2wAABCI"]
[Mon Jul 20 06:07:47.843836 2026] [security2:error] [pid 796567:tid 796817] [client 8.229.3.76:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.3.229.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/xmlrpc.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPUQAAAow"]
[Mon Jul 20 06:07:47.843962 2026] [security2:error] [pid 796567:tid 796817] [client 8.229.3.76:56252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "betterbonddogtraining.com"] [uri "/xmlrpc.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPUQAAAow"]
[Mon Jul 20 06:07:47.921857 2026] [security2:error] [pid 832668:tid 832896] [client 202.50.55.150:62101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/cgi-bin/.env"] [unique_id "al4Pk2ci6KgEEltqA3DGsAAAAGA"]
[Mon Jul 20 06:07:47.983103 2026] [proxy:error] [pid 832668:tid 832834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:47.983207 2026] [proxy_http:error] [pid 832668:tid 832834] [client 24.144.83.208:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:47.984298 2026] [proxy:error] [pid 832668:tid 832834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:47.984349 2026] [proxy_http:error] [pid 832668:tid 832834] [client 24.144.83.208:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:48.072130 2026] [security2:error] [pid 832668:tid 832820] [client 46.110.96.34:59705] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4PlGci6KgEEltqA3DGvAAAABQ"]
[Mon Jul 20 06:07:48.107045 2026] [proxy:error] [pid 832668:tid 832889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:48.107128 2026] [proxy_http:error] [pid 832668:tid 832889] [client 24.144.83.208:56100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:48.107794 2026] [proxy:error] [pid 832668:tid 832889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:48.107824 2026] [proxy_http:error] [pid 832668:tid 832889] [client 24.144.83.208:56100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:48.239854 2026] [security2:error] [pid 832668:tid 832925] [client 202.50.55.150:62114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/backend/.env"] [unique_id "al4PlGci6KgEEltqA3DGyAAAAH0"]
[Mon Jul 20 06:07:48.273403 2026] [security2:error] [pid 832668:tid 832903] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PlGci6KgEEltqA3DGxAAAAGc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:48.277910 2026] [security2:error] [pid 832668:tid 832855] [client 14.225.17.146:59391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGXwAAADc"], referer: http://reosportsboats.com/Wordpress
[Mon Jul 20 06:07:48.296222 2026] [security2:error] [pid 832668:tid 832828] [client 57.141.18.14:33782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DE9AAAHAQ"]
[Mon Jul 20 06:07:48.349394 2026] [security2:error] [pid 832668:tid 832813] [client 193.19.109.224:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PlGci6KgEEltqA3DGzQAAAA0"]
[Mon Jul 20 06:07:48.365706 2026] [security2:error] [pid 832668:tid 832836] [client 193.19.109.247:28721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PlGci6KgEEltqA3DG0AAAACQ"]
[Mon Jul 20 06:07:48.395248 2026] [security2:error] [pid 832668:tid 832908] [client 14.225.17.146:58713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Pk2ci6KgEEltqA3DGkgAAAGw"], referer: http://headachescarpaltunnelfibromyalgia.com/Wordpress
[Mon Jul 20 06:07:48.412826 2026] [core:error] [pid 832668:tid 832878] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:48.412852 2026] [core:error] [pid 832668:tid 832878] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:48.505077 2026] [security2:error] [pid 832668:tid 832847] [client 14.225.17.146:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4PlGci6KgEEltqA3DG2wAAAC8"], referer: https://adultdaycarereno.com/Wordpress
[Mon Jul 20 06:07:48.516111 2026] [security2:error] [pid 832668:tid 832891] [client 57.141.18.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Pk2ci6KgEEltqA3DGqgAAAFs"]
[Mon Jul 20 06:07:48.557326 2026] [security2:error] [pid 796567:tid 796721] [client 202.50.55.150:62130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/src/.env"] [unique_id "al4PlLLfyzVz2SrjZpjPYAAAAiw"]
[Mon Jul 20 06:07:48.626196 2026] [security2:error] [pid 796567:tid 796571] [remote 72.167.132.114:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PlLLfyzVz2SrjZpjPYgACWgM"]
[Mon Jul 20 06:07:48.827967 2026] [security2:error] [pid 796567:tid 796598] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PlLLfyzVz2SrjZpjPZgACZR4"]
[Mon Jul 20 06:07:48.828187 2026] [security2:error] [pid 796567:tid 796778] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PlLLfyzVz2SrjZpjPZgACZR4"]
[Mon Jul 20 06:07:48.837198 2026] [security2:error] [pid 796567:tid 796569] [remote 72.167.132.114:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PlLLfyzVz2SrjZpjPaAACSwE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:07:48.868635 2026] [security2:error] [pid 832668:tid 832863] [client 202.50.55.150:62141] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/base/.env"] [unique_id "al4PlGci6KgEEltqA3DG7AAAAD8"]
[Mon Jul 20 06:07:48.900666 2026] [security2:error] [pid 796567:tid 796771] [client 14.225.17.146:49684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPRQAAAl4"], referer: http://tntcatholic.com/Wordpress
[Mon Jul 20 06:07:48.994627 2026] [security2:error] [pid 832668:tid 832694] [remote 124.55.178.99:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4PlGci6KgEEltqA3DG9QAAXxc"]
[Mon Jul 20 06:07:49.172476 2026] [security2:error] [pid 832668:tid 832692] [remote 47.128.122.53:27440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/omenana-submissions/embed/"] [unique_id "al4PlWci6KgEEltqA3DG-wAAahU"], referer: https://iapwe.org/
[Mon Jul 20 06:07:49.179607 2026] [security2:error] [pid 832668:tid 832816] [client 202.50.55.150:62154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/core/.env"] [unique_id "al4PlWci6KgEEltqA3DG_AAAABA"]
[Mon Jul 20 06:07:49.210493 2026] [security2:error] [pid 832668:tid 832858] [client 14.225.17.146:59380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4Pk2ci6KgEEltqA3DGrQAAADo"], referer: http://keywayconstructionclt.com/Wordpress
[Mon Jul 20 06:07:49.332036 2026] [security2:error] [pid 796567:tid 796774] [client 14.225.17.146:51886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4PlbLfyzVz2SrjZpjPdAAAAmE"], referer: https://reosportsboats.com/Wordpress
[Mon Jul 20 06:07:49.428472 2026] [security2:error] [pid 832668:tid 832773] [remote 124.55.178.99:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4PlWci6KgEEltqA3DHCgAAaGY"], referer: https://hammadownenterprises.com/wp-login.php
[Mon Jul 20 06:07:49.492380 2026] [security2:error] [pid 832668:tid 832849] [client 202.50.55.150:62167] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/vendor/laravel/.env"] [unique_id "al4PlWci6KgEEltqA3DHEAAAADE"]
[Mon Jul 20 06:07:49.564630 2026] [security2:error] [pid 796567:tid 796757] [client 57.141.18.49:47584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjrLfyzVz2SrjZpjOqAACUBQ"]
[Mon Jul 20 06:07:49.609858 2026] [security2:error] [pid 796567:tid 796711] [client 50.116.65.227:11128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PlbLfyzVz2SrjZpjPgQAAAiI"]
[Mon Jul 20 06:07:49.620559 2026] [security2:error] [pid 796567:tid 796814] [client 50.116.65.227:11142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PlbLfyzVz2SrjZpjPggAAAok"]
[Mon Jul 20 06:07:49.802380 2026] [security2:error] [pid 796567:tid 796818] [client 202.50.55.150:62185] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/storage/.env"] [unique_id "al4PlbLfyzVz2SrjZpjPhQAAAo0"]
[Mon Jul 20 06:07:49.988620 2026] [security2:error] [pid 796567:tid 796764] [client 47.128.42.240:42150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nurturemarple.co.uk"] [uri "/robots.txt"] [unique_id "al4PlbLfyzVz2SrjZpjPjQAAAlc"]
[Mon Jul 20 06:07:50.112109 2026] [security2:error] [pid 832668:tid 832848] [client 202.50.55.150:62201] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/protected/.env"] [unique_id "al4Plmci6KgEEltqA3DHMwAAADA"]
[Mon Jul 20 06:07:50.194037 2026] [security2:error] [pid 832668:tid 832924] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Plmci6KgEEltqA3DHLAAAAHw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:50.232914 2026] [security2:error] [pid 832668:tid 832901] [client 14.225.17.146:51392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4Plmci6KgEEltqA3DHOQAAAGU"], referer: https://keywayconstructionclt.com/Wordpress
[Mon Jul 20 06:07:50.280967 2026] [security2:error] [pid 796567:tid 796769] [client 14.225.17.146:51373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4PlrLfyzVz2SrjZpjPjgAAAlw"], referer: http://taskidsvirginia.com/Wordpress
[Mon Jul 20 06:07:50.301573 2026] [core:error] [pid 832668:tid 832810] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:50.301600 2026] [core:error] [pid 832668:tid 832810] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:50.303681 2026] [security2:error] [pid 832668:tid 832879] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PlWci6KgEEltqA3DHIgAAAE8"], referer: http://laceycaraccident.com/cgi-bin/authLogin.cgi
[Mon Jul 20 06:07:50.410519 2026] [security2:error] [pid 832668:tid 832832] [client 185.132.186.87:50103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/NewFile.php"] [unique_id "al4Plmci6KgEEltqA3DHRAAAACA"]
[Mon Jul 20 06:07:50.422866 2026] [security2:error] [pid 832668:tid 832887] [client 202.50.55.150:62215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/newsite/.env"] [unique_id "al4Plmci6KgEEltqA3DHRwAAAFc"]
[Mon Jul 20 06:07:50.589044 2026] [security2:error] [pid 796567:tid 796767] [client 216.73.216.229:31918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PlrLfyzVz2SrjZpjPlgACWlE"]
[Mon Jul 20 06:07:50.650349 2026] [security2:error] [pid 832668:tid 832814] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Plmci6KgEEltqA3DHUAAAAA4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:50.741149 2026] [security2:error] [pid 796567:tid 796741] [client 202.50.55.150:62231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/www/.env"] [unique_id "al4PlrLfyzVz2SrjZpjPmwAAAkA"]
[Mon Jul 20 06:07:50.794456 2026] [security2:error] [pid 796567:tid 796804] [client 216.73.216.229:31918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PlrLfyzVz2SrjZpjPmAACfzE"], referer: https://www.iagdevelopments.com/sitemap.xml
[Mon Jul 20 06:07:50.856434 2026] [security2:error] [pid 832668:tid 832925] [client 103.141.108.143:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Plmci6KgEEltqA3DHWAAAAH0"]
[Mon Jul 20 06:07:50.856602 2026] [security2:error] [pid 832668:tid 832925] [client 103.141.108.143:64474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Plmci6KgEEltqA3DHWAAAAH0"]
[Mon Jul 20 06:07:51.072690 2026] [security2:error] [pid 832668:tid 832822] [client 202.50.55.150:62253] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/sites/all/libraries/mailchimp/.env"] [unique_id "al4Pl2ci6KgEEltqA3DHbAAAABY"]
[Mon Jul 20 06:07:51.100359 2026] [security2:error] [pid 832668:tid 832833] [client 57.141.18.24:38582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFpwAAIVc"]
[Mon Jul 20 06:07:51.309174 2026] [security2:error] [pid 832668:tid 832828] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pl2ci6KgEEltqA3DHcwAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:51.375589 2026] [security2:error] [pid 832668:tid 832693] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pl2ci6KgEEltqA3DHgQAAYxY"]
[Mon Jul 20 06:07:51.375711 2026] [security2:error] [pid 832668:tid 832899] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pl2ci6KgEEltqA3DHgQAAYxY"]
[Mon Jul 20 06:07:51.405516 2026] [security2:error] [pid 832668:tid 832814] [client 202.50.55.150:62275] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/database/.env"] [unique_id "al4Pl2ci6KgEEltqA3DHgwAAAA4"]
[Mon Jul 20 06:07:51.723827 2026] [security2:error] [pid 832668:tid 832834] [client 202.50.55.150:62294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/public/.env"] [unique_id "al4Pl2ci6KgEEltqA3DHmAAAACI"]
[Mon Jul 20 06:07:51.994539 2026] [security2:error] [pid 796567:tid 796785] [client 50.116.65.227:56902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4Pl7LfyzVz2SrjZpjPvwAAAmw"]
[Mon Jul 20 06:07:52.007677 2026] [security2:error] [pid 796567:tid 796813] [client 50.116.65.227:11188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4PmLLfyzVz2SrjZpjPwAAAAog"]
[Mon Jul 20 06:07:52.011629 2026] [security2:error] [pid 796567:tid 796711] [client 103.77.203.233:57615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPwQAAAiI"]
[Mon Jul 20 06:07:52.011770 2026] [security2:error] [pid 796567:tid 796711] [client 103.77.203.233:57615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPwQAAAiI"]
[Mon Jul 20 06:07:52.035418 2026] [security2:error] [pid 796567:tid 796788] [client 57.141.18.38:27138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PkLLfyzVz2SrjZpjO7QACb0g"]
[Mon Jul 20 06:07:52.045588 2026] [security2:error] [pid 832668:tid 832909] [client 106.192.104.4:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHqQAAAG0"]
[Mon Jul 20 06:07:52.045682 2026] [security2:error] [pid 832668:tid 832909] [client 106.192.104.4:31835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHqQAAAG0"]
[Mon Jul 20 06:07:52.206850 2026] [security2:error] [pid 832668:tid 832857] [client 202.50.55.150:62325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/108-179-215-73.unifiedlayer.com/.env"] [unique_id "al4PmGci6KgEEltqA3DHsQAAADk"]
[Mon Jul 20 06:07:52.359021 2026] [security2:error] [pid 796567:tid 796787] [client 112.213.160.112:8478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPxwAAAm4"]
[Mon Jul 20 06:07:52.359173 2026] [security2:error] [pid 796567:tid 796787] [client 112.213.160.112:8478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPxwAAAm4"]
[Mon Jul 20 06:07:52.360142 2026] [security2:error] [pid 832668:tid 832882] [client 185.132.186.59:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/index.php"] [unique_id "al4PmGci6KgEEltqA3DHtgAAAFI"]
[Mon Jul 20 06:07:52.475896 2026] [security2:error] [pid 832668:tid 832709] [remote 40.77.167.28:58287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4PmGci6KgEEltqA3DHwgAAfCY"]
[Mon Jul 20 06:07:52.495685 2026] [security2:error] [pid 832668:tid 832912] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PmGci6KgEEltqA3DHvQAAAHA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:52.581478 2026] [security2:error] [pid 832668:tid 832828] [client 115.246.21.170:7724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHyQAAABw"]
[Mon Jul 20 06:07:52.581617 2026] [security2:error] [pid 832668:tid 832828] [client 115.246.21.170:7724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHyQAAABw"]
[Mon Jul 20 06:07:52.732046 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.105:49272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PkWci6KgEEltqA3DF-QAAZGE"]
[Mon Jul 20 06:07:52.857542 2026] [security2:error] [pid 832668:tid 832840] [client 202.50.55.150:62366] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "108.179.215.73"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al4PmGci6KgEEltqA3DH2QAAACg"]
[Mon Jul 20 06:07:53.211804 2026] [security2:error] [pid 832668:tid 832829] [client 14.225.17.146:52185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4PmGci6KgEEltqA3DHzgAAAB0"], referer: http://thesoloceos.com/Wordpress
[Mon Jul 20 06:07:53.255305 2026] [security2:error] [pid 832668:tid 832906] [client 45.116.69.230:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PmWci6KgEEltqA3DH9AAAAGo"]
[Mon Jul 20 06:07:53.255421 2026] [security2:error] [pid 832668:tid 832906] [client 45.116.69.230:60326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PmWci6KgEEltqA3DH9AAAAGo"]
[Mon Jul 20 06:07:53.344425 2026] [security2:error] [pid 832668:tid 832902] [client 57.141.18.70:27192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PkWci6KgEEltqA3DGFQAAZjg"]
[Mon Jul 20 06:07:53.700339 2026] [security2:error] [pid 832668:tid 832863] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PmWci6KgEEltqA3DIAgAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:53.711471 2026] [security2:error] [pid 832668:tid 832887] [client 14.225.17.146:53250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4Pl2ci6KgEEltqA3DHhwAAAFc"], referer: http://soloceos.com/Wordpress
[Mon Jul 20 06:07:53.782651 2026] [security2:error] [pid 796567:tid 796801] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PmbLfyzVz2SrjZpjP5QAAAnw"], referer: http://laceycaraccident.com/WebInterface/
[Mon Jul 20 06:07:53.881033 2026] [security2:error] [pid 832668:tid 832867] [client 57.141.18.112:62454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGQAAAQ00"]
[Mon Jul 20 06:07:54.182836 2026] [security2:error] [pid 832668:tid 832770] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIJwAANmM"]
[Mon Jul 20 06:07:54.183024 2026] [security2:error] [pid 832668:tid 832854] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIJwAANmM"]
[Mon Jul 20 06:07:54.229165 2026] [security2:error] [pid 832668:tid 832846] [client 103.153.183.69:34824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../srv/.env"] [unique_id "al4Pmmci6KgEEltqA3DIKQAAAC4"], referer: https://www.google.com/search?q=9gecwx
[Mon Jul 20 06:07:54.287391 2026] [security2:error] [pid 796567:tid 796743] [client 185.132.186.99:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/error.php"] [unique_id "al4PmrLfyzVz2SrjZpjQAAAAAkI"]
[Mon Jul 20 06:07:54.359703 2026] [security2:error] [pid 796567:tid 796777] [client 14.225.17.146:51725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4PmrLfyzVz2SrjZpjP9gAAAmQ"], referer: http://grecruit.online/Wordpress
[Mon Jul 20 06:07:54.386043 2026] [security2:error] [pid 796567:tid 796703] [client 41.173.37.102:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PmrLfyzVz2SrjZpjQAwAAAho"]
[Mon Jul 20 06:07:54.386178 2026] [security2:error] [pid 796567:tid 796703] [client 41.173.37.102:7077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PmrLfyzVz2SrjZpjQAwAAAho"]
[Mon Jul 20 06:07:54.420267 2026] [security2:error] [pid 796567:tid 796722] [client 14.225.17.146:59442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4PmrLfyzVz2SrjZpjP_wAAAi0"], referer: https://thesoloceos.com/Wordpress
[Mon Jul 20 06:07:54.452536 2026] [security2:error] [pid 832668:tid 832834] [client 14.239.11.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4Pmmci6KgEEltqA3DIJAAAACI"]
[Mon Jul 20 06:07:54.579652 2026] [security2:error] [pid 832668:tid 832894] [client 57.141.18.125:40362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGdAAAXhE"]
[Mon Jul 20 06:07:54.595130 2026] [security2:error] [pid 832668:tid 832872] [client 181.224.94.124:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIOwAAAEg"]
[Mon Jul 20 06:07:54.595262 2026] [security2:error] [pid 832668:tid 832872] [client 181.224.94.124:51750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIOwAAAEg"]
[Mon Jul 20 06:07:55.005419 2026] [security2:error] [pid 832668:tid 832806] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Pmmci6KgEEltqA3DITAAABmQ"], referer: http://aleishapenny.ca/Wordpress
[Mon Jul 20 06:07:55.298170 2026] [security2:error] [pid 832668:tid 832869] [client 178.152.178.232:36671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pm2ci6KgEEltqA3DIYgAAAEU"]
[Mon Jul 20 06:07:55.298268 2026] [security2:error] [pid 832668:tid 832869] [client 178.152.178.232:36671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pm2ci6KgEEltqA3DIYgAAAEU"]
[Mon Jul 20 06:07:55.422232 2026] [security2:error] [pid 796567:tid 796683] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pm7LfyzVz2SrjZpjQGwACJnM"]
[Mon Jul 20 06:07:55.422452 2026] [security2:error] [pid 796567:tid 796715] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pm7LfyzVz2SrjZpjQGwACJnM"]
[Mon Jul 20 06:07:55.468674 2026] [security2:error] [pid 832668:tid 832872] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pm2ci6KgEEltqA3DIZQAAAEg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:55.594123 2026] [security2:error] [pid 832668:tid 832911] [client 14.225.17.146:53302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4Pmmci6KgEEltqA3DIKAAAAG8"], referer: http://goyalsatyam.com/Wordpress
[Mon Jul 20 06:07:55.772092 2026] [security2:error] [pid 796567:tid 796765] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Pm7LfyzVz2SrjZpjQJAACWE0"], referer: https://aleishapenny.ca/Wordpress
[Mon Jul 20 06:07:55.942579 2026] [security2:error] [pid 832668:tid 832922] [client 103.153.183.69:34824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../home/.env"] [unique_id "al4Pm2ci6KgEEltqA3DIcQAAAHo"], referer: https://www.bing.com/search?q=fgtkq3
[Mon Jul 20 06:07:55.959207 2026] [security2:error] [pid 832668:tid 832781] [remote 188.166.241.141:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4Pm2ci6KgEEltqA3DIcwAAV24"]
[Mon Jul 20 06:07:56.053315 2026] [security2:error] [pid 832668:tid 832840] [client 163.172.182.64:51036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5016.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PnGci6KgEEltqA3DIegAAACg"]
[Mon Jul 20 06:07:56.189914 2026] [security2:error] [pid 832668:tid 832808] [client 57.141.18.27:26488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PlGci6KgEEltqA3DG1AAACEw"]
[Mon Jul 20 06:07:56.238209 2026] [security2:error] [pid 796567:tid 796706] [client 185.132.186.97:60205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/admin-footer.php"] [unique_id "al4PnLLfyzVz2SrjZpjQLwAAAh0"]
[Mon Jul 20 06:07:56.309192 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:19489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PnGci6KgEEltqA3DIkgAAAGM"]
[Mon Jul 20 06:07:56.309298 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:19489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PnGci6KgEEltqA3DIkgAAAGM"]
[Mon Jul 20 06:07:56.352777 2026] [security2:error] [pid 832668:tid 832796] [remote 188.166.241.141:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4PnGci6KgEEltqA3DIlgAAGX0"], referer: https://gescontrols.com/wp-login.php
[Mon Jul 20 06:07:56.564223 2026] [security2:error] [pid 832668:tid 832897] [client 14.225.17.146:51287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIgwAAAGE"], referer: http://areitoproducciones.com/Wordpress
[Mon Jul 20 06:07:56.603484 2026] [security2:error] [pid 832668:tid 832814] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIhAAAAA4"], referer: http://laceycaraccident.com/console
[Mon Jul 20 06:07:56.713948 2026] [security2:error] [pid 832668:tid 832835] [client 57.141.18.61:55536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PlGci6KgEEltqA3DG5wAAIxA"]
[Mon Jul 20 06:07:56.951227 2026] [security2:error] [pid 832668:tid 832802] [client 50.116.65.227:11268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIrwAAAAI"]
[Mon Jul 20 06:07:57.148827 2026] [security2:error] [pid 832668:tid 832820] [client 50.116.65.227:11282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIvQAAABQ"]
[Mon Jul 20 06:07:57.345404 2026] [security2:error] [pid 832668:tid 832866] [client 57.141.18.108:36330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PlWci6KgEEltqA3DHAQAAQhs"]
[Mon Jul 20 06:07:57.515143 2026] [security2:error] [pid 832668:tid 832724] [remote 45.150.79.142:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PnWci6KgEEltqA3DI3AAABTU"]
[Mon Jul 20 06:07:57.539904 2026] [security2:error] [pid 832668:tid 832856] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PnWci6KgEEltqA3DI2gAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:57.679887 2026] [security2:error] [pid 832668:tid 832710] [remote 45.150.79.142:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PnWci6KgEEltqA3DI4QAADCc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:07:58.180939 2026] [security2:error] [pid 832668:tid 832864] [client 185.132.186.64:64523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-search-function.php"] [unique_id "al4Pnmci6KgEEltqA3DI9QAAAEA"]
[Mon Jul 20 06:07:58.527638 2026] [security2:error] [pid 832668:tid 832907] [client 14.225.17.146:51342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4PnWci6KgEEltqA3DIyQAAAGs"], referer: http://detroitcsc.com/Wordpress
[Mon Jul 20 06:07:58.640681 2026] [security2:error] [pid 796567:tid 796708] [client 50.116.65.227:11346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PnrLfyzVz2SrjZpjQZQAAAh8"]
[Mon Jul 20 06:07:58.652134 2026] [security2:error] [pid 796567:tid 796824] [client 50.116.65.227:11356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PnrLfyzVz2SrjZpjQZgAAApM"]
[Mon Jul 20 06:07:58.791070 2026] [security2:error] [pid 832668:tid 832889] [client 14.225.17.146:51463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4PnWci6KgEEltqA3DI2QAAAFk"], referer: http://northbrookcpa.ca/Wordpress
[Mon Jul 20 06:07:59.438081 2026] [security2:error] [pid 832668:tid 832731] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pn2ci6KgEEltqA3DJKAAAcDw"]
[Mon Jul 20 06:07:59.438222 2026] [security2:error] [pid 832668:tid 832912] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pn2ci6KgEEltqA3DJKAAAcDw"]
[Mon Jul 20 06:07:59.740317 2026] [security2:error] [pid 832668:tid 832718] [remote 130.51.180.8:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Pn2ci6KgEEltqA3DJOwAAby8"]
[Mon Jul 20 06:07:59.867798 2026] [security2:error] [pid 796567:tid 796742] [client 45.157.112.60:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Pn7LfyzVz2SrjZpjQiAAAAkE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:00.017117 2026] [security2:error] [pid 832668:tid 832694] [remote 130.51.180.8:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PoGci6KgEEltqA3DJRAAAVRc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:08:00.033898 2026] [security2:error] [pid 832668:tid 832851] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pn2ci6KgEEltqA3DJQQAAADM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:00.041543 2026] [security2:error] [pid 832668:tid 832906] [client 185.226.198.4:16108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "al4PoGci6KgEEltqA3DJRQAAAGo"]
[Mon Jul 20 06:08:00.128641 2026] [security2:error] [pid 832668:tid 832840] [client 185.132.186.58:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/themes/index.php"] [unique_id "al4PoGci6KgEEltqA3DJTAAAACg"]
[Mon Jul 20 06:08:00.171954 2026] [security2:error] [pid 832668:tid 832887] [client 114.119.155.185:63825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "securingmemories.com"] [uri "/index.php/privacy-policy/"] [unique_id "al4PoGci6KgEEltqA3DJTQAAAFc"], referer: https://securingmemories.com/index.php/2020/11/02/i-know-what-youre-thinking
[Mon Jul 20 06:08:00.241203 2026] [core:error] [pid 832668:tid 832905] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:00.241222 2026] [core:error] [pid 832668:tid 832905] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:00.654470 2026] [security2:error] [pid 796567:tid 796750] [client 57.141.18.35:25154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PmLLfyzVz2SrjZpjP2wACSSQ"]
[Mon Jul 20 06:08:00.778356 2026] [security2:error] [pid 832668:tid 832892] [client 14.225.17.146:64320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4Pn2ci6KgEEltqA3DJNgAAAFw"], referer: http://mcg.homes/Wordpress
[Mon Jul 20 06:08:00.785809 2026] [security2:error] [pid 832668:tid 832765] [remote 103.28.36.200:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PoGci6KgEEltqA3DJcAAAG14"]
[Mon Jul 20 06:08:00.806740 2026] [security2:error] [pid 832668:tid 832914] [client 14.225.17.146:51465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4Pn2ci6KgEEltqA3DJPwAAAHI"], referer: http://idigress.studio/Wordpress
[Mon Jul 20 06:08:01.228809 2026] [security2:error] [pid 832668:tid 832781] [remote 103.28.36.200:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PoWci6KgEEltqA3DJkAAAOG4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:08:01.324033 2026] [security2:error] [pid 796567:tid 796697] [client 114.119.135.199:46315] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emil.manasyan.uk"] [uri "/robots.txt"] [unique_id "al4PobLfyzVz2SrjZpjQrwAAAhQ"], referer: https://emil.manasyan.uk/robots.txt
[Mon Jul 20 06:08:01.347966 2026] [security2:error] [pid 832668:tid 832895] [client 57.141.18.92:27516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PmWci6KgEEltqA3DICgAAX10"]
[Mon Jul 20 06:08:01.450414 2026] [security2:error] [pid 832668:tid 832859] [client 103.141.108.143:64931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PoWci6KgEEltqA3DJlAAAADs"]
[Mon Jul 20 06:08:01.450537 2026] [security2:error] [pid 832668:tid 832859] [client 103.141.108.143:64931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PoWci6KgEEltqA3DJlAAAADs"]
[Mon Jul 20 06:08:01.696475 2026] [security2:error] [pid 832668:tid 832784] [remote 8.217.108.67:25900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PoWci6KgEEltqA3DJowAARHE"]
[Mon Jul 20 06:08:01.843485 2026] [security2:error] [pid 832668:tid 832822] [client 185.226.198.5:42512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "al4PoWci6KgEEltqA3DJqAAAABY"]
[Mon Jul 20 06:08:02.047767 2026] [security2:error] [pid 796567:tid 796682] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PorLfyzVz2SrjZpjQwwACfHI"]
[Mon Jul 20 06:08:02.047911 2026] [security2:error] [pid 796567:tid 796801] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PorLfyzVz2SrjZpjQwwACfHI"]
[Mon Jul 20 06:08:02.052660 2026] [core:error] [pid 796567:tid 796775] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:02.052676 2026] [core:error] [pid 796567:tid 796775] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:02.074128 2026] [security2:error] [pid 832668:tid 832866] [client 185.132.186.87:49957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-files.php"] [unique_id "al4Pomci6KgEEltqA3DJuAAAAEI"]
[Mon Jul 20 06:08:02.259608 2026] [security2:error] [pid 832668:tid 832711] [remote 152.228.213.32:42934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4Pomci6KgEEltqA3DJwwAAbig"]
[Mon Jul 20 06:08:02.473989 2026] [security2:error] [pid 832668:tid 832680] [remote 152.228.213.32:42934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4Pomci6KgEEltqA3DJygAAOQk"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 06:08:02.476726 2026] [security2:error] [pid 832668:tid 832825] [client 103.77.203.233:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJzAAAABk"]
[Mon Jul 20 06:08:02.478031 2026] [security2:error] [pid 832668:tid 832825] [client 103.77.203.233:57677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJzAAAABk"]
[Mon Jul 20 06:08:02.506545 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:60425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4Pomci6KgEEltqA3DJxwAAAFQ"], referer: http://adirondackengineering.com/Wordpress
[Mon Jul 20 06:08:02.507937 2026] [security2:error] [pid 832668:tid 832684] [remote 8.217.108.67:25900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Pomci6KgEEltqA3DJ0AAAIg0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:08:02.618284 2026] [security2:error] [pid 832668:tid 832804] [client 106.192.104.4:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJ2QAAAAQ"]
[Mon Jul 20 06:08:02.618460 2026] [security2:error] [pid 832668:tid 832804] [client 106.192.104.4:52138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJ2QAAAAQ"]
[Mon Jul 20 06:08:02.665147 2026] [proxy:error] [pid 832668:tid 832806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.665201 2026] [proxy_http:error] [pid 832668:tid 832806] [client 94.154.43.186:43400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.666548 2026] [proxy:error] [pid 832668:tid 832806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.666602 2026] [proxy_http:error] [pid 832668:tid 832806] [client 94.154.43.186:43400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.670118 2026] [security2:error] [pid 832668:tid 832889] [client 94.154.43.188:24122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.samueldcohen.com"] [uri "/.env"] [unique_id "al4Pomci6KgEEltqA3DJ4wAAAFk"]
[Mon Jul 20 06:08:02.821129 2026] [proxy:error] [pid 832668:tid 832840] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.821212 2026] [proxy_http:error] [pid 832668:tid 832840] [client 94.154.43.183:43890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.822037 2026] [proxy:error] [pid 832668:tid 832840] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.822089 2026] [proxy_http:error] [pid 832668:tid 832840] [client 94.154.43.183:43890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.918405 2026] [security2:error] [pid 832668:tid 832894] [client 14.225.17.146:60538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Pomci6KgEEltqA3DJ5wAAAF4"], referer: http://savilerowtravel.com/Wordpress
[Mon Jul 20 06:08:03.102525 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Po2ci6KgEEltqA3DJ9gAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:03.102638 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Po2ci6KgEEltqA3DJ9gAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:03.133062 2026] [security2:error] [pid 832668:tid 832891] [client 112.213.160.112:31226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Po2ci6KgEEltqA3DJ-QAAAFs"]
[Mon Jul 20 06:08:03.133215 2026] [security2:error] [pid 832668:tid 832891] [client 112.213.160.112:31226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Po2ci6KgEEltqA3DJ-QAAAFs"]
[Mon Jul 20 06:08:03.138686 2026] [security2:error] [pid 796567:tid 796750] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PorLfyzVz2SrjZpjQ0AACSTY"], referer: http://ali-alghanim.net/Wordpress
[Mon Jul 20 06:08:03.199635 2026] [security2:error] [pid 832668:tid 832907] [client 14.225.17.146:61522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJqwAAAGs"], referer: http://mazzucelli.com/Wordpress
[Mon Jul 20 06:08:03.299849 2026] [security2:error] [pid 796567:tid 796769] [client 115.246.21.170:4147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ3QAAAlw"]
[Mon Jul 20 06:08:03.299947 2026] [security2:error] [pid 796567:tid 796769] [client 115.246.21.170:4147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ3QAAAlw"]
[Mon Jul 20 06:08:03.441231 2026] [security2:error] [pid 832668:tid 832824] [client 185.226.198.5:42518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "al4Po2ci6KgEEltqA3DKCgAAABg"]
[Mon Jul 20 06:08:03.852172 2026] [security2:error] [pid 796567:tid 796793] [client 45.116.69.230:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ6AAAAnQ"]
[Mon Jul 20 06:08:03.852305 2026] [security2:error] [pid 796567:tid 796793] [client 45.116.69.230:60783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ6AAAAnQ"]
[Mon Jul 20 06:08:04.006719 2026] [security2:error] [pid 832668:tid 832824] [client 47.128.52.93:18870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/news/"] [unique_id "al4PpGci6KgEEltqA3DKOgAAABg"]
[Mon Jul 20 06:08:04.023104 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.59:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/functions.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ6QAAAis"]
[Mon Jul 20 06:08:04.138639 2026] [security2:error] [pid 832668:tid 832822] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PpGci6KgEEltqA3DKQgAAABY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:04.192667 2026] [security2:error] [pid 832668:tid 832811] [client 14.225.17.146:61305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Po2ci6KgEEltqA3DKOAAAAAs"], referer: https://savilerowtravel.com/Wordpress
[Mon Jul 20 06:08:04.265953 2026] [security2:error] [pid 796567:tid 796804] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ7AAAAn8"]
[Mon Jul 20 06:08:04.281827 2026] [security2:error] [pid 796567:tid 796772] [client 57.141.18.108:60290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PnbLfyzVz2SrjZpjQPAACXys"]
[Mon Jul 20 06:08:04.353270 2026] [security2:error] [pid 796567:tid 796634] [remote 45.90.123.233:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ-AACYUI"]
[Mon Jul 20 06:08:04.363307 2026] [security2:error] [pid 832668:tid 832832] [client 14.225.17.146:61532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJrgAAACA"], referer: http://dollpassionista.com/Wordpress
[Mon Jul 20 06:08:04.391268 2026] [security2:error] [pid 796567:tid 796742] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ9AAAAkE"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:04.559251 2026] [security2:error] [pid 796567:tid 796602] [remote 45.90.123.233:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PpLLfyzVz2SrjZpjRAAACkSI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:08:04.580248 2026] [security2:error] [pid 832668:tid 832731] [remote 103.94.134.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.134.94.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKXwAAETw"]
[Mon Jul 20 06:08:04.580410 2026] [security2:error] [pid 832668:tid 832817] [client 103.94.134.160:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ashleystrain.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKXwAAETw"]
[Mon Jul 20 06:08:04.624952 2026] [security2:error] [pid 796567:tid 796747] [client 15.204.254.129:53040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "thewritinglair.com"] [uri "/"] [unique_id "al4PpLLfyzVz2SrjZpjRBQAAAkY"]
[Mon Jul 20 06:08:04.769663 2026] [security2:error] [pid 796567:tid 796781] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjRCQAAAmg"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:04.964446 2026] [security2:error] [pid 832668:tid 832873] [client 41.173.37.102:7542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKeAAAAEk"]
[Mon Jul 20 06:08:04.964592 2026] [security2:error] [pid 832668:tid 832873] [client 41.173.37.102:7542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKeAAAAEk"]
[Mon Jul 20 06:08:05.081703 2026] [security2:error] [pid 832668:tid 832694] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKgAAAAhc"]
[Mon Jul 20 06:08:05.081894 2026] [security2:error] [pid 832668:tid 832802] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKgAAAAhc"]
[Mon Jul 20 06:08:05.082924 2026] [security2:error] [pid 832668:tid 832869] [client 57.141.18.121:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PnWci6KgEEltqA3DI6QAARSA"]
[Mon Jul 20 06:08:05.094667 2026] [security2:error] [pid 832668:tid 832914] [client 181.224.94.124:58132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKggAAAHI"]
[Mon Jul 20 06:08:05.094786 2026] [security2:error] [pid 832668:tid 832914] [client 181.224.94.124:58132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKggAAAHI"]
[Mon Jul 20 06:08:05.199205 2026] [security2:error] [pid 832668:tid 832924] [client 158.173.89.95:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PpWci6KgEEltqA3DKhwAAAHw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:05.449932 2026] [security2:error] [pid 832668:tid 832872] [client 14.225.17.146:61144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4PpWci6KgEEltqA3DKjAAAAEg"], referer: https://dollpassionista.com/Wordpress
[Mon Jul 20 06:08:05.462372 2026] [security2:error] [pid 796567:tid 796795] [client 14.225.17.146:61589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ_AAAAnY"]
[Mon Jul 20 06:08:05.980564 2026] [security2:error] [pid 832668:tid 832858] [client 185.132.186.98:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Canonical.php"] [unique_id "al4PpWci6KgEEltqA3DKsQAAADo"]
[Mon Jul 20 06:08:05.986830 2026] [security2:error] [pid 832668:tid 832769] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKsgAAT2I"]
[Mon Jul 20 06:08:05.987037 2026] [security2:error] [pid 832668:tid 832879] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKsgAAT2I"]
[Mon Jul 20 06:08:06.035239 2026] [security2:error] [pid 796567:tid 796711] [client 185.226.198.5:30040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al4PprLfyzVz2SrjZpjRGAAAAiI"]
[Mon Jul 20 06:08:06.079442 2026] [security2:error] [pid 796567:tid 796700] [client 14.225.17.146:61087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ-wAAAhc"], referer: http://maplerespiteservices.com/Wordpress
[Mon Jul 20 06:08:06.246397 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ppmci6KgEEltqA3DKyAAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:06.368689 2026] [core:error] [pid 796567:tid 796802] [client 14.225.17.146:62657] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:06.368714 2026] [core:error] [pid 796567:tid 796802] [client 14.225.17.146:62657] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:06.455224 2026] [security2:error] [pid 832668:tid 832777] [remote 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Ppmci6KgEEltqA3DK1QAAFGo"]
[Mon Jul 20 06:08:06.455420 2026] [security2:error] [pid 832668:tid 832820] [client 5.161.225.162:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Ppmci6KgEEltqA3DK1QAAFGo"]
[Mon Jul 20 06:08:06.475167 2026] [security2:error] [pid 832668:tid 832922] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Ppmci6KgEEltqA3DK0QAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:06.575380 2026] [security2:error] [pid 796567:tid 796618] [remote 154.66.198.148:31076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PprLfyzVz2SrjZpjRJQACeTI"]
[Mon Jul 20 06:08:06.672844 2026] [security2:error] [pid 832668:tid 832855] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ppmci6KgEEltqA3DK3wAAADc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:06.927693 2026] [security2:error] [pid 832668:tid 832891] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Ppmci6KgEEltqA3DK7wAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:07.287458 2026] [security2:error] [pid 832668:tid 832735] [remote 57.141.18.72:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4Pp2ci6KgEEltqA3DK_wAASEA"]
[Mon Jul 20 06:08:07.337410 2026] [security2:error] [pid 832668:tid 832882] [client 185.226.198.7:23652] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "al4Pp2ci6KgEEltqA3DLAwAAAFI"]
[Mon Jul 20 06:08:07.394325 2026] [security2:error] [pid 796567:tid 796637] [remote 154.66.198.148:31076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRPgACV0U"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:08:07.577453 2026] [security2:error] [pid 796567:tid 796679] [remote 188.166.241.141:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRQAACaW8"]
[Mon Jul 20 06:08:07.726886 2026] [security2:error] [pid 832668:tid 832883] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pp2ci6KgEEltqA3DLFAAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:07.773046 2026] [security2:error] [pid 796567:tid 796806] [client 103.95.123.246:20010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRQgAAAoE"]
[Mon Jul 20 06:08:07.773184 2026] [security2:error] [pid 796567:tid 796806] [client 103.95.123.246:20010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRQgAAAoE"]
[Mon Jul 20 06:08:07.898299 2026] [security2:error] [pid 832668:tid 832894] [client 50.116.65.227:15882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Pp2ci6KgEEltqA3DLHgAAAF4"]
[Mon Jul 20 06:08:07.909065 2026] [security2:error] [pid 832668:tid 832838] [client 50.116.65.227:15896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Pp2ci6KgEEltqA3DLIAAAACY"]
[Mon Jul 20 06:08:07.920816 2026] [security2:error] [pid 796567:tid 796741] [client 185.132.186.70:57273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/autoload_classmap.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRSgAAAkA"]
[Mon Jul 20 06:08:07.984408 2026] [security2:error] [pid 796567:tid 796662] [remote 188.166.241.141:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRTwACS14"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:08:08.014137 2026] [security2:error] [pid 796567:tid 796726] [client 14.225.17.146:64623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4PprLfyzVz2SrjZpjRIwAAAjE"], referer: http://inspirespublishing.com/Wordpress
[Mon Jul 20 06:08:08.082833 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.124:44994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJmwAAZHI"]
[Mon Jul 20 06:08:08.140155 2026] [security2:error] [pid 832668:tid 832831] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PqGci6KgEEltqA3DLKgAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:08.387586 2026] [security2:error] [pid 832668:tid 832876] [client 57.141.18.108:41602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJpgAATD4"]
[Mon Jul 20 06:08:08.670543 2026] [security2:error] [pid 832668:tid 832839] [client 185.226.198.7:23662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLVgAAACc"]
[Mon Jul 20 06:08:08.670636 2026] [security2:error] [pid 832668:tid 832828] [client 185.226.198.6:22080] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLVwAAABw"]
[Mon Jul 20 06:08:08.679337 2026] [security2:error] [pid 832668:tid 832850] [client 185.226.198.4:14724] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLWAAAADI"]
[Mon Jul 20 06:08:08.686879 2026] [security2:error] [pid 796567:tid 796810] [client 185.226.198.7:23668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRXwAAAoU"]
[Mon Jul 20 06:08:08.687801 2026] [security2:error] [pid 832668:tid 832901] [client 185.226.198.5:30056] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLWwAAAGU"]
[Mon Jul 20 06:08:08.696802 2026] [security2:error] [pid 832668:tid 832810] [client 185.226.198.5:30072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXQAAAAo"]
[Mon Jul 20 06:08:08.696803 2026] [security2:error] [pid 832668:tid 832816] [client 185.226.198.6:22092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXAAAABA"]
[Mon Jul 20 06:08:08.700381 2026] [security2:error] [pid 832668:tid 832900] [client 185.226.198.5:30074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXgAAAGQ"]
[Mon Jul 20 06:08:08.703242 2026] [security2:error] [pid 796567:tid 796707] [client 185.226.198.6:22094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYAAAAh4"]
[Mon Jul 20 06:08:08.711427 2026] [security2:error] [pid 832668:tid 832888] [client 185.226.198.4:14738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXwAAAFg"]
[Mon Jul 20 06:08:08.714297 2026] [security2:error] [pid 796567:tid 796761] [client 185.226.198.5:30086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYQAAAlQ"]
[Mon Jul 20 06:08:08.716219 2026] [security2:error] [pid 796567:tid 796804] [client 185.226.198.7:23676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYgAAAn8"]
[Mon Jul 20 06:08:08.720518 2026] [security2:error] [pid 796567:tid 796791] [client 185.226.198.4:14754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYwAAAnI"]
[Mon Jul 20 06:08:08.720987 2026] [security2:error] [pid 796567:tid 796709] [client 185.226.198.7:23678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZAAAAiA"]
[Mon Jul 20 06:08:08.721876 2026] [security2:error] [pid 796567:tid 796699] [client 185.226.198.4:14762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZQAAAhY"]
[Mon Jul 20 06:08:08.724266 2026] [security2:error] [pid 796567:tid 796815] [client 185.226.198.4:14766] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZgAAAoo"]
[Mon Jul 20 06:08:08.724619 2026] [security2:error] [pid 796567:tid 796772] [client 185.226.198.6:22098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZwAAAl8"]
[Mon Jul 20 06:08:08.727804 2026] [security2:error] [pid 796567:tid 796746] [client 185.226.198.7:23688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRaAAAAkU"]
[Mon Jul 20 06:08:08.728920 2026] [security2:error] [pid 796567:tid 796774] [client 185.226.198.6:22108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRaQAAAmE"]
[Mon Jul 20 06:08:08.732236 2026] [security2:error] [pid 796567:tid 796801] [client 185.226.198.7:23692] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRagAAAnw"]
[Mon Jul 20 06:08:08.734831 2026] [security2:error] [pid 796567:tid 796714] [client 185.226.198.4:14778] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRawAAAiU"]
[Mon Jul 20 06:08:08.734930 2026] [security2:error] [pid 796567:tid 796742] [client 185.226.198.5:30100] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbAAAAkE"]
[Mon Jul 20 06:08:08.740010 2026] [security2:error] [pid 796567:tid 796735] [client 185.226.198.7:23708] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbQAAAjo"]
[Mon Jul 20 06:08:08.740667 2026] [security2:error] [pid 832668:tid 832877] [client 185.226.198.5:30106] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYAAAAE0"]
[Mon Jul 20 06:08:08.741589 2026] [security2:error] [pid 832668:tid 832831] [client 185.226.198.6:22110] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYQAAAB8"]
[Mon Jul 20 06:08:08.743397 2026] [security2:error] [pid 796567:tid 796779] [client 185.226.198.7:23724] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbgAAAmY"]
[Mon Jul 20 06:08:08.744131 2026] [security2:error] [pid 796567:tid 796805] [client 185.226.198.7:23730] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbwAAAoA"]
[Mon Jul 20 06:08:08.745304 2026] [security2:error] [pid 796567:tid 796771] [client 185.226.198.4:14790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcAAAAl4"]
[Mon Jul 20 06:08:08.745354 2026] [security2:error] [pid 796567:tid 796783] [client 185.226.198.6:22126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcQAAAmo"]
[Mon Jul 20 06:08:08.745811 2026] [security2:error] [pid 832668:tid 832867] [client 185.226.198.6:22134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYgAAAEM"]
[Mon Jul 20 06:08:08.750912 2026] [security2:error] [pid 796567:tid 796706] [client 185.226.198.7:23736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcgAAAh0"]
[Mon Jul 20 06:08:08.751437 2026] [security2:error] [pid 796567:tid 796730] [client 185.226.198.4:14798] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcwAAAjU"]
[Mon Jul 20 06:08:08.754362 2026] [security2:error] [pid 796567:tid 796708] [client 185.226.198.6:22142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdAAAAh8"]
[Mon Jul 20 06:08:08.755235 2026] [security2:error] [pid 832668:tid 832854] [client 185.226.198.4:14814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYwAAADY"]
[Mon Jul 20 06:08:08.755944 2026] [security2:error] [pid 796567:tid 796756] [client 185.226.198.5:30120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdQAAAk8"]
[Mon Jul 20 06:08:08.759801 2026] [security2:error] [pid 796567:tid 796797] [client 185.226.198.4:14824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdgAAAng"]
[Mon Jul 20 06:08:08.760357 2026] [security2:error] [pid 796567:tid 796757] [client 185.226.198.5:30132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdwAAAlA"]
[Mon Jul 20 06:08:08.761855 2026] [security2:error] [pid 832668:tid 832801] [client 185.226.198.5:30142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLZQAAAAE"]
[Mon Jul 20 06:08:08.762667 2026] [security2:error] [pid 832668:tid 832837] [client 185.226.198.4:14830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLZgAAACU"]
[Mon Jul 20 06:08:08.763513 2026] [security2:error] [pid 796567:tid 796823] [client 185.226.198.6:22152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjReQAAApI"]
[Mon Jul 20 06:08:08.770587 2026] [security2:error] [pid 796567:tid 796824] [client 185.226.198.6:22170] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRewAAApM"]
[Mon Jul 20 06:08:08.770605 2026] [security2:error] [pid 796567:tid 796813] [client 185.226.198.6:22158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRegAAAog"]
[Mon Jul 20 06:08:08.770666 2026] [security2:error] [pid 796567:tid 796739] [client 185.226.198.5:30146] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRfAAAAj4"]
[Mon Jul 20 06:08:08.772294 2026] [security2:error] [pid 832668:tid 832879] [client 185.226.198.5:30150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLZwAAAE8"]
[Mon Jul 20 06:08:08.772422 2026] [security2:error] [pid 796567:tid 796818] [client 185.226.198.7:23742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRfQAAAo0"]
[Mon Jul 20 06:08:08.772957 2026] [security2:error] [pid 796567:tid 796765] [client 185.226.198.5:30152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRfgAAAlg"]
[Mon Jul 20 06:08:08.788252 2026] [security2:error] [pid 832668:tid 832893] [client 185.226.198.7:23746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLagAAAF0"]
[Mon Jul 20 06:08:08.797874 2026] [security2:error] [pid 832668:tid 832824] [client 185.226.198.6:22186] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLawAAABg"]
[Mon Jul 20 06:08:09.099852 2026] [security2:error] [pid 832668:tid 832869] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLgAAAAEU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:09.139955 2026] [security2:error] [pid 832668:tid 832823] [client 57.141.18.110:38182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pomci6KgEEltqA3DJ6AAAFww"]
[Mon Jul 20 06:08:09.408228 2026] [security2:error] [pid 832668:tid 832690] [remote 78.46.157.202:33658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLmAAAEBM"]
[Mon Jul 20 06:08:09.547805 2026] [security2:error] [pid 832668:tid 832807] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLoAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:09.547930 2026] [security2:error] [pid 832668:tid 832807] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLoAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:09.615062 2026] [security2:error] [pid 832668:tid 832704] [remote 78.46.157.202:33658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLowAAKSE"], referer: https://thedoctorscuisine.com/wp-login.php
[Mon Jul 20 06:08:09.722125 2026] [security2:error] [pid 796567:tid 796775] [client 106.49.57.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRNAACYgQ"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91singularity-studio-escala-1-4-malenia/
[Mon Jul 20 06:08:09.875950 2026] [security2:error] [pid 832668:tid 832839] [client 185.132.186.54:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/aks.php"] [unique_id "al4PqWci6KgEEltqA3DLvAAAACc"]
[Mon Jul 20 06:08:09.922728 2026] [security2:error] [pid 832668:tid 832671] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PqWci6KgEEltqA3DLwAAAEgA"]
[Mon Jul 20 06:08:09.922928 2026] [security2:error] [pid 832668:tid 832818] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PqWci6KgEEltqA3DLwAAAEgA"]
[Mon Jul 20 06:08:10.010395 2026] [security2:error] [pid 832668:tid 832896] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PqWci6KgEEltqA3DLwQAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:10.056832 2026] [security2:error] [pid 796567:tid 796734] [client 185.226.198.6:22198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "al4PqrLfyzVz2SrjZpjRjwAAAjk"]
[Mon Jul 20 06:08:10.354639 2026] [security2:error] [pid 832668:tid 832870] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pqmci6KgEEltqA3DL4wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:10.801835 2026] [security2:error] [pid 832668:tid 832826] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Pqmci6KgEEltqA3DL8QAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:10.901474 2026] [security2:error] [pid 832668:tid 832847] [client 57.141.18.100:30524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PpGci6KgEEltqA3DKYAAALy0"]
[Mon Jul 20 06:08:10.965208 2026] [security2:error] [pid 832668:tid 832825] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pqmci6KgEEltqA3DL_QAAABk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:11.008408 2026] [security2:error] [pid 796567:tid 796676] [remote 173.212.252.15:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PqrLfyzVz2SrjZpjRpgACIGw"]
[Mon Jul 20 06:08:11.008579 2026] [security2:error] [pid 796567:tid 796709] [client 173.212.252.15:39102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PqrLfyzVz2SrjZpjRpgACIGw"]
[Mon Jul 20 06:08:11.200782 2026] [security2:error] [pid 832668:tid 832836] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Pq2ci6KgEEltqA3DMCgAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:11.341587 2026] [security2:error] [pid 832668:tid 832730] [remote 194.164.192.228:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pq2ci6KgEEltqA3DMFwAAeTs"]
[Mon Jul 20 06:08:11.540919 2026] [security2:error] [pid 832668:tid 832769] [remote 194.164.192.228:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pq2ci6KgEEltqA3DMIgAALWI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:08:11.738696 2026] [security2:error] [pid 796567:tid 796809] [client 57.141.18.9:21914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PpbLfyzVz2SrjZpjRFAAChDQ"]
[Mon Jul 20 06:08:11.750883 2026] [security2:error] [pid 796567:tid 796710] [client 185.226.198.7:23754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "al4Pq7LfyzVz2SrjZpjRuwAAAiE"]
[Mon Jul 20 06:08:11.820109 2026] [security2:error] [pid 832668:tid 832810] [client 185.132.186.58:39759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/litespeed.php"] [unique_id "al4Pq2ci6KgEEltqA3DMNgAAAAo"]
[Mon Jul 20 06:08:12.077712 2026] [security2:error] [pid 832668:tid 832865] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PrGci6KgEEltqA3DMPgAAAEE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:12.266343 2026] [security2:error] [pid 796567:tid 796794] [client 57.141.18.122:23716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PprLfyzVz2SrjZpjRHgACdWs"]
[Mon Jul 20 06:08:12.382489 2026] [security2:error] [pid 832668:tid 832814] [client 103.141.108.143:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMSAAAAA4"]
[Mon Jul 20 06:08:12.382579 2026] [security2:error] [pid 832668:tid 832814] [client 103.141.108.143:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMSAAAAA4"]
[Mon Jul 20 06:08:12.422638 2026] [security2:error] [pid 832668:tid 832875] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PrGci6KgEEltqA3DMRgAAAEs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:12.753072 2026] [security2:error] [pid 832668:tid 832914] [client 14.225.17.146:56485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DLzQAAAHI"], referer: http://nextlevelpressurewashing.com/Wordpress
[Mon Jul 20 06:08:12.843544 2026] [security2:error] [pid 832668:tid 832752] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZQAAPFE"]
[Mon Jul 20 06:08:12.843674 2026] [security2:error] [pid 832668:tid 832860] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZQAAPFE"]
[Mon Jul 20 06:08:12.852460 2026] [security2:error] [pid 832668:tid 832922] [client 106.192.104.4:34190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZgAAAHo"]
[Mon Jul 20 06:08:12.852553 2026] [security2:error] [pid 832668:tid 832922] [client 106.192.104.4:34190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZgAAAHo"]
[Mon Jul 20 06:08:13.019961 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.26:63546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pp2ci6KgEEltqA3DK9AAALn0"]
[Mon Jul 20 06:08:13.036143 2026] [security2:error] [pid 832668:tid 832863] [client 103.77.203.233:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMcAAAAD8"]
[Mon Jul 20 06:08:13.036335 2026] [security2:error] [pid 832668:tid 832863] [client 103.77.203.233:57738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMcAAAAD8"]
[Mon Jul 20 06:08:13.230857 2026] [security2:error] [pid 796567:tid 796770] [client 57.141.18.52:20802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRNQACXWI"]
[Mon Jul 20 06:08:13.425449 2026] [security2:error] [pid 832668:tid 832758] [remote 209.42.18.223:41614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMgwAAQ1c"]
[Mon Jul 20 06:08:13.425661 2026] [security2:error] [pid 832668:tid 832867] [client 209.42.18.223:41614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMgwAAQ1c"]
[Mon Jul 20 06:08:13.773464 2026] [security2:error] [pid 832668:tid 832834] [client 185.132.186.77:40441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/img/about.php"] [unique_id "al4PrWci6KgEEltqA3DMoAAAACI"]
[Mon Jul 20 06:08:13.885139 2026] [security2:error] [pid 796567:tid 796771] [client 112.213.160.112:30756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PrbLfyzVz2SrjZpjR7gAAAl4"]
[Mon Jul 20 06:08:13.885275 2026] [security2:error] [pid 796567:tid 796771] [client 112.213.160.112:30756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PrbLfyzVz2SrjZpjR7gAAAl4"]
[Mon Jul 20 06:08:13.920261 2026] [security2:error] [pid 832668:tid 832876] [client 115.246.21.170:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMpgAAAEw"]
[Mon Jul 20 06:08:13.920394 2026] [security2:error] [pid 832668:tid 832876] [client 115.246.21.170:46438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMpgAAAEw"]
[Mon Jul 20 06:08:13.985902 2026] [security2:error] [pid 796567:tid 796747] [client 35.209.224.174:39182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4PrbLfyzVz2SrjZpjR7wAAAkY"]
[Mon Jul 20 06:08:14.039726 2026] [security2:error] [pid 832668:tid 832823] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Prmci6KgEEltqA3DMrwAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:14.278686 2026] [security2:error] [pid 832668:tid 832910] [client 185.226.198.4:14836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "al4Prmci6KgEEltqA3DMwAAAAG4"]
[Mon Jul 20 06:08:14.515903 2026] [security2:error] [pid 796567:tid 796614] [remote 45.90.123.233:33370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4PrrLfyzVz2SrjZpjSAwACNC4"]
[Mon Jul 20 06:08:14.653962 2026] [security2:error] [pid 796567:tid 796722] [client 45.116.69.230:61248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PrrLfyzVz2SrjZpjSCAAAAi0"]
[Mon Jul 20 06:08:14.654077 2026] [security2:error] [pid 796567:tid 796722] [client 45.116.69.230:61248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PrrLfyzVz2SrjZpjSCAAAAi0"]
[Mon Jul 20 06:08:14.739500 2026] [security2:error] [pid 796567:tid 796628] [remote 45.90.123.233:33370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4PrrLfyzVz2SrjZpjSDAAChjw"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:08:14.955547 2026] [security2:error] [pid 832668:tid 832870] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Prmci6KgEEltqA3DM3wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:14.955714 2026] [security2:error] [pid 832668:tid 832870] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Prmci6KgEEltqA3DM3wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:15.171566 2026] [security2:error] [pid 796567:tid 796726] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PrrLfyzVz2SrjZpjSEAACMR4"]
[Mon Jul 20 06:08:15.171595 2026] [security2:error] [pid 796567:tid 796726] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PrrLfyzVz2SrjZpjSEAACMR4"]
[Mon Jul 20 06:08:15.324266 2026] [security2:error] [pid 832668:tid 832921] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pr2ci6KgEEltqA3DM8QAAAHk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:15.511870 2026] [security2:error] [pid 796567:tid 796725] [client 41.173.37.102:7989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSIAAAAjA"]
[Mon Jul 20 06:08:15.511980 2026] [security2:error] [pid 796567:tid 796725] [client 41.173.37.102:7989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSIAAAAjA"]
[Mon Jul 20 06:08:15.620841 2026] [security2:error] [pid 832668:tid 832847] [client 181.224.94.124:61330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNBwAAAC8"]
[Mon Jul 20 06:08:15.620975 2026] [security2:error] [pid 832668:tid 832847] [client 181.224.94.124:61330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNBwAAAC8"]
[Mon Jul 20 06:08:15.703844 2026] [security2:error] [pid 832668:tid 832927] [client 185.132.186.78:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-feed-index.php"] [unique_id "al4Pr2ci6KgEEltqA3DNDQAAAH8"]
[Mon Jul 20 06:08:15.736912 2026] [security2:error] [pid 832668:tid 832871] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pr2ci6KgEEltqA3DNDwAAAEc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:15.800490 2026] [security2:error] [pid 832668:tid 832707] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNFgAAPyQ"]
[Mon Jul 20 06:08:15.800623 2026] [security2:error] [pid 832668:tid 832863] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNFgAAPyQ"]
[Mon Jul 20 06:08:15.950585 2026] [security2:error] [pid 832668:tid 832907] [client 178.152.178.232:37150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNHAAAAGs"]
[Mon Jul 20 06:08:15.955299 2026] [security2:error] [pid 832668:tid 832907] [client 178.152.178.232:37150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNHAAAAGs"]
[Mon Jul 20 06:08:16.005453 2026] [security2:error] [pid 832668:tid 832864] [client 57.141.18.49:56942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PqWci6KgEEltqA3DLuAAAQEk"]
[Mon Jul 20 06:08:16.065422 2026] [security2:error] [pid 832668:tid 832840] [client 185.226.198.7:35850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "al4PsGci6KgEEltqA3DNJQAAACg"]
[Mon Jul 20 06:08:16.162696 2026] [security2:error] [pid 832668:tid 832821] [client 34.138.198.0:27450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNIwAAABU"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.276823 2026] [security2:error] [pid 832668:tid 832857] [client 14.225.17.146:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4Prmci6KgEEltqA3DM3gAAADk"], referer: http://elitetax-mi.com/Wordpress
[Mon Jul 20 06:08:16.281678 2026] [security2:error] [pid 796567:tid 796622] [remote 20.153.140.50:43254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PsLLfyzVz2SrjZpjSNwACajY"]
[Mon Jul 20 06:08:16.295038 2026] [security2:error] [pid 832668:tid 832811] [client 57.141.18.107:22562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DL3wAACzo"]
[Mon Jul 20 06:08:16.348731 2026] [security2:error] [pid 832668:tid 832910] [client 34.138.198.0:27498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.198.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/wp-config.php"] [unique_id "al4PsGci6KgEEltqA3DNOgAAAG4"]
[Mon Jul 20 06:08:16.377871 2026] [security2:error] [pid 796567:tid 796768] [client 34.138.198.0:27516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSNgAAAls"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.406774 2026] [security2:error] [pid 832668:tid 832917] [client 34.138.198.0:27456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env"] [unique_id "al4PsGci6KgEEltqA3DNQAAAAHU"]
[Mon Jul 20 06:08:16.423508 2026] [security2:error] [pid 796567:tid 796708] [client 34.138.198.0:27528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSOgAAAh8"]
[Mon Jul 20 06:08:16.428309 2026] [security2:error] [pid 832668:tid 832852] [client 34.138.198.0:27530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNNwAAADQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.448073 2026] [security2:error] [pid 832668:tid 832888] [client 34.138.198.0:27536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNOAAAAFg"]
[Mon Jul 20 06:08:16.453420 2026] [security2:error] [pid 832668:tid 832815] [client 34.138.198.0:27548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNPQAAAA8"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.516701 2026] [security2:error] [pid 796567:tid 796806] [client 158.173.241.141:51185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSOQACgQo"]
[Mon Jul 20 06:08:16.518220 2026] [security2:error] [pid 796567:tid 796813] [client 34.138.198.0:27464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.backup"] [unique_id "al4PsLLfyzVz2SrjZpjSQQAAAog"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.528038 2026] [security2:error] [pid 796567:tid 796756] [client 34.138.198.0:27560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.bak"] [unique_id "al4PsLLfyzVz2SrjZpjSRAAAAk8"]
[Mon Jul 20 06:08:16.532739 2026] [security2:error] [pid 832668:tid 832713] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PsGci6KgEEltqA3DNRwAAVyo"]
[Mon Jul 20 06:08:16.532936 2026] [security2:error] [pid 832668:tid 832887] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PsGci6KgEEltqA3DNRwAAVyo"]
[Mon Jul 20 06:08:16.546614 2026] [security2:error] [pid 832668:tid 832802] [client 57.141.18.33:45432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DL5wAAAlA"]
[Mon Jul 20 06:08:16.555161 2026] [security2:error] [pid 832668:tid 832905] [client 34.138.198.0:27506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNQgAAAGk"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.624051 2026] [security2:error] [pid 796567:tid 796784] [client 34.138.198.0:27466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSQgAAAms"]
[Mon Jul 20 06:08:16.625161 2026] [security2:error] [pid 796567:tid 796809] [client 34.138.198.0:27482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSQwAAAoQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.656171 2026] [security2:error] [pid 832668:tid 832915] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PsGci6KgEEltqA3DNSgAAAHM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:16.658781 2026] [security2:error] [pid 796567:tid 796691] [remote 20.153.140.50:43254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PsLLfyzVz2SrjZpjSRgACd3s"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:08:16.695371 2026] [security2:error] [pid 832668:tid 832908] [client 57.141.18.45:57218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DL9gAAbBc"]
[Mon Jul 20 06:08:16.811865 2026] [security2:error] [pid 796567:tid 796820] [client 34.138.198.0:27590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/wp-config.php.bak"] [unique_id "al4PsLLfyzVz2SrjZpjSTAAAAo8"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.860045 2026] [security2:error] [pid 796567:tid 796741] [client 14.225.17.146:62009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSEgAAAkA"], referer: http://outlookturf.com/Wordpress
[Mon Jul 20 06:08:16.894600 2026] [security2:error] [pid 832668:tid 832819] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PsGci6KgEEltqA3DNVwAAABM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:17.117298 2026] [security2:error] [pid 832668:tid 832926] [client 34.138.198.0:27574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsWci6KgEEltqA3DNXwAAAH4"]
[Mon Jul 20 06:08:17.118818 2026] [security2:error] [pid 796567:tid 796777] [client 34.138.198.0:27596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsbLfyzVz2SrjZpjSUgAAAmQ"]
[Mon Jul 20 06:08:17.198697 2026] [security2:error] [pid 832668:tid 832852] [client 50.116.65.227:45494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4PsWci6KgEEltqA3DNbQAAADQ"]
[Mon Jul 20 06:08:17.201381 2026] [security2:error] [pid 832668:tid 832865] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PsWci6KgEEltqA3DNZwAAAEE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:17.211878 2026] [security2:error] [pid 796567:tid 796720] [client 50.116.65.227:29592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4PsbLfyzVz2SrjZpjSVAAAAis"]
[Mon Jul 20 06:08:17.375016 2026] [security2:error] [pid 796567:tid 796726] [client 52.47.76.32:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PsbLfyzVz2SrjZpjSXAAAAjE"]
[Mon Jul 20 06:08:17.375204 2026] [security2:error] [pid 796567:tid 796726] [client 52.47.76.32:13650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PsbLfyzVz2SrjZpjSXAAAAjE"]
[Mon Jul 20 06:08:17.432148 2026] [security2:error] [pid 832668:tid 832806] [client 50.116.65.227:29606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PsWci6KgEEltqA3DNegAAAAY"]
[Mon Jul 20 06:08:17.443521 2026] [security2:error] [pid 832668:tid 832838] [client 50.116.65.227:29618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PsWci6KgEEltqA3DNewAAACY"]
[Mon Jul 20 06:08:17.464454 2026] [security2:error] [pid 832668:tid 832915] [client 185.226.198.6:20536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "al4PsWci6KgEEltqA3DNfgAAAHM"]
[Mon Jul 20 06:08:17.477899 2026] [security2:error] [pid 796567:tid 796753] [client 34.138.198.0:27610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsbLfyzVz2SrjZpjSXQAAAkw"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:17.607612 2026] [security2:error] [pid 832668:tid 832901] [client 185.132.186.77:34461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wpn.php"] [unique_id "al4PsWci6KgEEltqA3DNgwAAAGU"]
[Mon Jul 20 06:08:17.999614 2026] [security2:error] [pid 832668:tid 832896] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PsWci6KgEEltqA3DNnAAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:18.082847 2026] [security2:error] [pid 832668:tid 832855] [client 74.208.214.194:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Psmci6KgEEltqA3DNoQAAADc"]
[Mon Jul 20 06:08:18.305436 2026] [security2:error] [pid 796567:tid 796782] [client 164.100.212.184:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PsrLfyzVz2SrjZpjSbgAAAmk"]
[Mon Jul 20 06:08:18.305555 2026] [security2:error] [pid 796567:tid 796782] [client 164.100.212.184:61410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PsrLfyzVz2SrjZpjSbgAAAmk"]
[Mon Jul 20 06:08:18.344300 2026] [security2:error] [pid 832668:tid 832858] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Psmci6KgEEltqA3DNrQAAADo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:18.497813 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.60:46378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PrbLfyzVz2SrjZpjR3wACcgg"]
[Mon Jul 20 06:08:18.813845 2026] [security2:error] [pid 832668:tid 832845] [client 103.95.123.246:20539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Psmci6KgEEltqA3DNyAAAAC0"]
[Mon Jul 20 06:08:18.813997 2026] [security2:error] [pid 832668:tid 832845] [client 103.95.123.246:20539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Psmci6KgEEltqA3DNyAAAAC0"]
[Mon Jul 20 06:08:18.884180 2026] [security2:error] [pid 832668:tid 832921] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Psmci6KgEEltqA3DNxQAAAHk"]
[Mon Jul 20 06:08:18.997328 2026] [security2:error] [pid 832668:tid 832871] [client 14.225.17.146:50343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4Psmci6KgEEltqA3DNtgAAAEc"], referer: http://carolinapressurewashers.com/Wordpress
[Mon Jul 20 06:08:19.175388 2026] [security2:error] [pid 832668:tid 832906] [client 57.141.18.12:33718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PrWci6KgEEltqA3DMkgAAag0"]
[Mon Jul 20 06:08:19.260848 2026] [security2:error] [pid 832668:tid 832862] [client 114.119.157.24:61703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elementconstruction.co.uk"] [uri "/609-2/"] [unique_id "al4Ps2ci6KgEEltqA3DN6QAAAD4"], referer: https://elementconstruction.co.uk/shop
[Mon Jul 20 06:08:19.287624 2026] [security2:error] [pid 832668:tid 832864] [client 50.116.65.227:30172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Ps2ci6KgEEltqA3DN6wAAAEA"]
[Mon Jul 20 06:08:19.300377 2026] [security2:error] [pid 832668:tid 832908] [client 50.116.65.227:30836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Ps2ci6KgEEltqA3DN7QAAAGw"]
[Mon Jul 20 06:08:19.363434 2026] [security2:error] [pid 832668:tid 832847] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Ps2ci6KgEEltqA3DN6AAAAC8"]
[Mon Jul 20 06:08:19.501679 2026] [security2:error] [pid 832668:tid 832911] [client 103.153.183.69:10494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4Ps2ci6KgEEltqA3DN9wAAAG8"], referer: https://www.google.com/search?q=1pagch
[Mon Jul 20 06:08:19.556813 2026] [security2:error] [pid 832668:tid 832816] [client 185.226.198.6:20538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "al4Ps2ci6KgEEltqA3DN-wAAABA"]
[Mon Jul 20 06:08:19.732989 2026] [security2:error] [pid 832668:tid 832818] [client 34.138.198.0:27640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Ps2ci6KgEEltqA3DN_QAAABI"]
[Mon Jul 20 06:08:19.735039 2026] [security2:error] [pid 832668:tid 832917] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ps2ci6KgEEltqA3DN_wAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:19.744401 2026] [security2:error] [pid 796567:tid 796745] [client 34.138.198.0:27614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Ps7LfyzVz2SrjZpjSkQAAAkQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:19.911308 2026] [security2:error] [pid 832668:tid 832888] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ps2ci6KgEEltqA3DOCQAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:19.911475 2026] [security2:error] [pid 832668:tid 832888] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ps2ci6KgEEltqA3DOCQAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:20.045709 2026] [security2:error] [pid 796567:tid 796761] [client 34.138.198.0:27634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Ps7LfyzVz2SrjZpjSnQAAAlQ"]
[Mon Jul 20 06:08:20.231619 2026] [security2:error] [pid 796567:tid 796751] [client 14.225.17.146:62053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4PsrLfyzVz2SrjZpjSdgAAAko"], referer: http://samdothan.org/Wordpress
[Mon Jul 20 06:08:20.232647 2026] [security2:error] [pid 832668:tid 832869] [client 34.138.198.0:27618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtGci6KgEEltqA3DOFAAAAEU"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:20.237037 2026] [security2:error] [pid 796567:tid 796747] [client 34.138.198.0:27680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtLLfyzVz2SrjZpjSpgAAAkY"]
[Mon Jul 20 06:08:20.298474 2026] [security2:error] [pid 796567:tid 796712] [client 34.138.198.0:27670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtLLfyzVz2SrjZpjSqQAAAiM"]
[Mon Jul 20 06:08:20.299610 2026] [security2:error] [pid 832668:tid 832723] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.bak"] [unique_id "al4PtGci6KgEEltqA3DOHwAAfjQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:20.354606 2026] [security2:error] [pid 832668:tid 832835] [client 34.138.198.0:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.old"] [unique_id "al4PtGci6KgEEltqA3DOIgAAACM"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:20.383955 2026] [security2:error] [pid 832668:tid 832860] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PtGci6KgEEltqA3DOIAAAADw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:20.459781 2026] [security2:error] [pid 832668:tid 832876] [client 57.141.18.54:47198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Prmci6KgEEltqA3DM2QAATCY"]
[Mon Jul 20 06:08:20.474347 2026] [security2:error] [pid 832668:tid 832678] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PtGci6KgEEltqA3DOJwAAPQc"]
[Mon Jul 20 06:08:20.474494 2026] [security2:error] [pid 832668:tid 832861] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PtGci6KgEEltqA3DOJwAAPQc"]
[Mon Jul 20 06:08:20.510150 2026] [security2:error] [pid 832668:tid 832883] [client 34.138.198.0:27642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtGci6KgEEltqA3DOJQAAAFM"]
[Mon Jul 20 06:08:20.688270 2026] [security2:error] [pid 832668:tid 832924] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PtGci6KgEEltqA3DONwAAAHw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:20.854245 2026] [security2:error] [pid 832668:tid 832903] [client 103.153.183.69:10494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4PtGci6KgEEltqA3DOPgAAAGc"], referer: https://twitter.com/
[Mon Jul 20 06:08:20.866630 2026] [security2:error] [pid 796567:tid 796780] [client 57.141.18.110:56434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSHAACZ1s"]
[Mon Jul 20 06:08:20.878466 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.82:57996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSHQACY2A"]
[Mon Jul 20 06:08:21.316355 2026] [security2:error] [pid 796567:tid 796779] [client 185.226.198.6:20548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "al4PtbLfyzVz2SrjZpjS1QAAAmY"]
[Mon Jul 20 06:08:21.651025 2026] [security2:error] [pid 796567:tid 796751] [client 185.132.186.90:30581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/classwithtostring.php"] [unique_id "al4PtbLfyzVz2SrjZpjS3gAAAko"]
[Mon Jul 20 06:08:21.686277 2026] [security2:error] [pid 832668:tid 832803] [client 14.225.17.146:50396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4PtGci6KgEEltqA3DOHAAAAAM"], referer: http://slutilities.com/Wordpress
[Mon Jul 20 06:08:21.797069 2026] [security2:error] [pid 832668:tid 832868] [client 57.141.18.14:48876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNSwAARDw"]
[Mon Jul 20 06:08:21.970286 2026] [security2:error] [pid 796567:tid 796733] [client 103.178.3.191:40654] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PtbLfyzVz2SrjZpjS6QAAAjg"]
[Mon Jul 20 06:08:22.008177 2026] [security2:error] [pid 796567:tid 796697] [client 14.225.17.146:57977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PtbLfyzVz2SrjZpjS6gAAAhQ"], referer: http://iagdevelopments.com/Wordpress
[Mon Jul 20 06:08:22.111926 2026] [security2:error] [pid 796567:tid 796733] [client 103.178.3.191:40654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PtbLfyzVz2SrjZpjS6QAAAjg"]
[Mon Jul 20 06:08:22.316969 2026] [security2:error] [pid 832668:tid 832920] [client 57.141.18.61:33076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PsWci6KgEEltqA3DNZQAAeFQ"]
[Mon Jul 20 06:08:22.991571 2026] [security2:error] [pid 832668:tid 832870] [client 103.141.108.143:49443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ptmci6KgEEltqA3DOlAAAAEY"]
[Mon Jul 20 06:08:22.992969 2026] [security2:error] [pid 832668:tid 832870] [client 103.141.108.143:49443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ptmci6KgEEltqA3DOlAAAAEY"]
[Mon Jul 20 06:08:23.026536 2026] [security2:error] [pid 796567:tid 796715] [client 14.225.17.146:57126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PtrLfyzVz2SrjZpjTBwAAAiY"], referer: https://iagdevelopments.com/Wordpress
[Mon Jul 20 06:08:23.099590 2026] [security2:error] [pid 832668:tid 832826] [client 185.226.198.4:44612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "al4Pt2ci6KgEEltqA3DOmwAAABo"]
[Mon Jul 20 06:08:23.373142 2026] [security2:error] [pid 832668:tid 832901] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Pt2ci6KgEEltqA3DOqQAAAGU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:23.390684 2026] [security2:error] [pid 832668:tid 832718] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOrQAAQS8"]
[Mon Jul 20 06:08:23.390856 2026] [security2:error] [pid 832668:tid 832865] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOrQAAQS8"]
[Mon Jul 20 06:08:23.522619 2026] [security2:error] [pid 832668:tid 832873] [client 103.77.203.233:57827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOtgAAAEk"]
[Mon Jul 20 06:08:23.522761 2026] [security2:error] [pid 832668:tid 832873] [client 103.77.203.233:57827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOtgAAAEk"]
[Mon Jul 20 06:08:23.639868 2026] [security2:error] [pid 832668:tid 832694] [remote 91.142.222.105:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Pt2ci6KgEEltqA3DOvAAANxc"]
[Mon Jul 20 06:08:23.696791 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4Ptmci6KgEEltqA3DObwAAVB0"], referer: http://ardhalwafaa.com/Wordpress
[Mon Jul 20 06:08:23.752432 2026] [security2:error] [pid 832668:tid 832893] [client 103.178.3.191:40703] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pt2ci6KgEEltqA3DOwQAAAF0"]
[Mon Jul 20 06:08:23.876662 2026] [security2:error] [pid 832668:tid 832893] [client 103.178.3.191:40703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pt2ci6KgEEltqA3DOwQAAAF0"]
[Mon Jul 20 06:08:23.992384 2026] [security2:error] [pid 832668:tid 832761] [remote 91.142.222.105:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Pt2ci6KgEEltqA3DOzAAABVo"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:08:23.995553 2026] [security2:error] [pid 796567:tid 796801] [client 106.192.104.4:53178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt7LfyzVz2SrjZpjTKgAAAnw"]
[Mon Jul 20 06:08:23.995669 2026] [security2:error] [pid 796567:tid 796801] [client 106.192.104.4:53178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt7LfyzVz2SrjZpjTKgAAAnw"]
[Mon Jul 20 06:08:23.995719 2026] [security2:error] [pid 832668:tid 832922] [client 57.141.18.41:46272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Psmci6KgEEltqA3DNzQAAeiU"]
[Mon Jul 20 06:08:24.132540 2026] [security2:error] [pid 832668:tid 832822] [client 98.159.234.160:40461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PuGci6KgEEltqA3DO1AAAABY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:24.339238 2026] [security2:error] [pid 796567:tid 796744] [client 57.141.18.87:33890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ps7LfyzVz2SrjZpjSfgACQ2Y"]
[Mon Jul 20 06:08:24.378277 2026] [security2:error] [pid 832668:tid 832860] [client 115.246.21.170:6282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PuGci6KgEEltqA3DO4QAAADw"]
[Mon Jul 20 06:08:24.378390 2026] [security2:error] [pid 832668:tid 832860] [client 115.246.21.170:6282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PuGci6KgEEltqA3DO4QAAADw"]
[Mon Jul 20 06:08:24.443113 2026] [security2:error] [pid 832668:tid 832858] [client 14.225.17.146:60297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pt2ci6KgEEltqA3DOyAAAADo"], referer: http://laceycaraccident.com/Wordpress
[Mon Jul 20 06:08:24.481969 2026] [security2:error] [pid 796567:tid 796822] [client 112.213.160.112:30745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PuLLfyzVz2SrjZpjTOQAAApE"]
[Mon Jul 20 06:08:24.482084 2026] [security2:error] [pid 796567:tid 796822] [client 112.213.160.112:30745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PuLLfyzVz2SrjZpjTOQAAApE"]
[Mon Jul 20 06:08:24.520517 2026] [security2:error] [pid 832668:tid 832898] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PuGci6KgEEltqA3DO6wAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.109509 2026] [security2:error] [pid 832668:tid 832887] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PuWci6KgEEltqA3DPBQAAAFc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.194869 2026] [security2:error] [pid 832668:tid 832882] [client 57.141.18.23:53056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ps2ci6KgEEltqA3DOCwAAUho"]
[Mon Jul 20 06:08:25.225702 2026] [security2:error] [pid 796567:tid 796707] [client 185.226.198.6:29430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PuLLfyzVz2SrjZpjTQAAAAh4"], referer: http://laceycaraccident.com/sugar_version.json
[Mon Jul 20 06:08:25.238262 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:60291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4Pt2ci6KgEEltqA3DOywAAABw"], referer: http://39ishlife.com/Wordpress
[Mon Jul 20 06:08:25.242382 2026] [core:error] [pid 832668:tid 832816] [client 14.225.17.146:55556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wordpress
[Mon Jul 20 06:08:25.242406 2026] [core:error] [pid 832668:tid 832816] [client 14.225.17.146:55556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wordpress
[Mon Jul 20 06:08:25.290668 2026] [security2:error] [pid 832668:tid 832817] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PuWci6KgEEltqA3DPGAAAABE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.312046 2026] [security2:error] [pid 832668:tid 832805] [client 45.116.69.230:61707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PuWci6KgEEltqA3DPGwAAAAU"]
[Mon Jul 20 06:08:25.313036 2026] [security2:error] [pid 832668:tid 832805] [client 45.116.69.230:61707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PuWci6KgEEltqA3DPGwAAAAU"]
[Mon Jul 20 06:08:25.466782 2026] [security2:error] [pid 832668:tid 832884] [client 103.178.3.191:40743] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PuWci6KgEEltqA3DPJQAAAFQ"]
[Mon Jul 20 06:08:25.617338 2026] [security2:error] [pid 832668:tid 832884] [client 103.178.3.191:40743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PuWci6KgEEltqA3DPJQAAAFQ"]
[Mon Jul 20 06:08:25.618889 2026] [security2:error] [pid 832668:tid 832847] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PuWci6KgEEltqA3DPKwAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.999551 2026] [security2:error] [pid 796567:tid 796709] [client 14.225.17.146:55453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4PubLfyzVz2SrjZpjTWwAAAiA"], referer: http://longevityperformanceclinic.com/Wordpress
[Mon Jul 20 06:08:26.146680 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:8438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PurLfyzVz2SrjZpjTZgAAAmo"]
[Mon Jul 20 06:08:26.146758 2026] [security2:error] [pid 832668:tid 832913] [client 181.224.94.124:39321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPRwAAAHE"]
[Mon Jul 20 06:08:26.146807 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:8438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PurLfyzVz2SrjZpjTZgAAAmo"]
[Mon Jul 20 06:08:26.146867 2026] [security2:error] [pid 832668:tid 832913] [client 181.224.94.124:39321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPRwAAAHE"]
[Mon Jul 20 06:08:26.304269 2026] [security2:error] [pid 832668:tid 832817] [client 14.225.17.146:55775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4Pumci6KgEEltqA3DPRAAAABE"]
[Mon Jul 20 06:08:26.340902 2026] [security2:error] [pid 796567:tid 796806] [client 14.225.17.146:58035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4PurLfyzVz2SrjZpjTawAAAoE"], referer: https://39ishlife.com/Wordpress
[Mon Jul 20 06:08:26.379714 2026] [security2:error] [pid 832668:tid 832869] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pumci6KgEEltqA3DPVQAAAEU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:26.446148 2026] [security2:error] [pid 796567:tid 796770] [client 57.141.18.42:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PtbLfyzVz2SrjZpjS0AACXSk"]
[Mon Jul 20 06:08:26.503124 2026] [security2:error] [pid 832668:tid 832796] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPWgAAEn0"]
[Mon Jul 20 06:08:26.503300 2026] [security2:error] [pid 832668:tid 832818] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPWgAAEn0"]
[Mon Jul 20 06:08:26.566264 2026] [security2:error] [pid 832668:tid 832918] [client 178.152.178.232:36018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPXAAAAHY"]
[Mon Jul 20 06:08:26.566407 2026] [security2:error] [pid 832668:tid 832918] [client 178.152.178.232:36018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPXAAAAHY"]
[Mon Jul 20 06:08:26.612230 2026] [security2:error] [pid 796567:tid 796777] [client 185.132.186.60:37791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/iR7SzrsOUEP.php"] [unique_id "al4PurLfyzVz2SrjZpjTfQAAAmQ"]
[Mon Jul 20 06:08:26.757922 2026] [security2:error] [pid 796567:tid 796708] [client 57.141.18.51:60748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PtbLfyzVz2SrjZpjS4gACH0M"]
[Mon Jul 20 06:08:26.792327 2026] [security2:error] [pid 796567:tid 796701] [client 103.178.3.191:40783] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PurLfyzVz2SrjZpjThgAAAhg"]
[Mon Jul 20 06:08:26.915276 2026] [security2:error] [pid 796567:tid 796701] [client 103.178.3.191:40783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PurLfyzVz2SrjZpjThgAAAhg"]
[Mon Jul 20 06:08:27.176385 2026] [security2:error] [pid 832668:tid 832684] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdAAAfg0"]
[Mon Jul 20 06:08:27.176530 2026] [security2:error] [pid 832668:tid 832926] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdAAAfg0"]
[Mon Jul 20 06:08:27.223852 2026] [security2:error] [pid 832668:tid 832856] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdwAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:27.223972 2026] [security2:error] [pid 832668:tid 832856] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdwAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:27.579924 2026] [security2:error] [pid 832668:tid 832849] [client 50.116.65.227:30942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Pu2ci6KgEEltqA3DPggAAADE"]
[Mon Jul 20 06:08:27.589924 2026] [security2:error] [pid 832668:tid 832815] [client 50.116.65.227:30944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Pu2ci6KgEEltqA3DPgwAAAA8"]
[Mon Jul 20 06:08:27.872513 2026] [security2:error] [pid 832668:tid 832916] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPkAAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:27.896879 2026] [security2:error] [pid 832668:tid 832899] [client 34.138.198.0:62096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.backup"] [unique_id "al4Pu2ci6KgEEltqA3DPlgAAAGM"]
[Mon Jul 20 06:08:27.898460 2026] [security2:error] [pid 832668:tid 832892] [client 34.138.198.0:62106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env"] [unique_id "al4Pu2ci6KgEEltqA3DPmQAAAFw"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:27.906199 2026] [security2:error] [pid 832668:tid 832836] [client 34.138.198.0:62174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.rtkenergypartners.com"] [uri "/wp-config.php.bak"] [unique_id "al4Pu2ci6KgEEltqA3DPoAAAACQ"]
[Mon Jul 20 06:08:27.994745 2026] [security2:error] [pid 832668:tid 832911] [client 34.138.198.0:62160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.198.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rtkenergypartners.com"] [uri "/wp-config.php"] [unique_id "al4Pu2ci6KgEEltqA3DPqAAAAG8"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.033954 2026] [security2:error] [pid 832668:tid 832876] [client 34.138.198.0:62222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.bak"] [unique_id "al4PvGci6KgEEltqA3DPqQAAAEw"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.040156 2026] [security2:error] [pid 832668:tid 832845] [client 34.138.198.0:62130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPlwAAAC0"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.042577 2026] [security2:error] [pid 832668:tid 832921] [client 34.138.198.0:62112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPmgAAAHk"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.043432 2026] [security2:error] [pid 832668:tid 832807] [client 34.138.198.0:62186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPnQAAAAc"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.043834 2026] [security2:error] [pid 832668:tid 832868] [client 34.138.198.0:62132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPmwAAAEQ"]
[Mon Jul 20 06:08:28.048078 2026] [security2:error] [pid 832668:tid 832814] [client 34.138.198.0:62154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPnAAAAA4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.057938 2026] [security2:error] [pid 832668:tid 832918] [client 34.138.198.0:62126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPmAAAAHY"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.133958 2026] [security2:error] [pid 832668:tid 832850] [client 34.138.198.0:62230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpQAAADI"]
[Mon Jul 20 06:08:28.135413 2026] [security2:error] [pid 832668:tid 832866] [client 34.138.198.0:62258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpgAAAEI"]
[Mon Jul 20 06:08:28.135728 2026] [security2:error] [pid 832668:tid 832846] [client 34.138.198.0:62246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpwAAAC4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.136120 2026] [security2:error] [pid 832668:tid 832894] [client 34.138.198.0:62198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpAAAAF4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.140400 2026] [security2:error] [pid 796567:tid 796756] [client 34.138.198.0:62236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu7LfyzVz2SrjZpjTtwAAAk8"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.175280 2026] [security2:error] [pid 832668:tid 832812] [client 34.138.198.0:62210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvGci6KgEEltqA3DPrgAAAAw"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.330851 2026] [security2:error] [pid 796567:tid 796811] [client 14.225.17.146:55452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4PurLfyzVz2SrjZpjTjQAAAoY"], referer: http://scott-assist.com/Wordpress
[Mon Jul 20 06:08:28.337771 2026] [security2:error] [pid 796567:tid 796742] [client 103.178.3.191:40816] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvLLfyzVz2SrjZpjTxwAAAkE"]
[Mon Jul 20 06:08:28.480115 2026] [security2:error] [pid 796567:tid 796742] [client 103.178.3.191:40816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvLLfyzVz2SrjZpjTxwAAAkE"]
[Mon Jul 20 06:08:28.502213 2026] [security2:error] [pid 832668:tid 832825] [client 185.132.186.93:34557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section-boolean.php"] [unique_id "al4PvGci6KgEEltqA3DPxAAAABk"]
[Mon Jul 20 06:08:28.521815 2026] [security2:error] [pid 832668:tid 832888] [client 185.61.219.192:28311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "oohlovely.com"] [uri "/xmlrpc.php"] [unique_id "al4Pu2ci6KgEEltqA3DPgQAAWBY"]
[Mon Jul 20 06:08:28.546200 2026] [security2:error] [pid 796567:tid 796612] [remote 57.141.18.37:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3187007"] [unique_id "al4PvLLfyzVz2SrjZpjT0AACYSw"]
[Mon Jul 20 06:08:28.643545 2026] [security2:error] [pid 796567:tid 796728] [client 164.100.212.184:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PvLLfyzVz2SrjZpjT1AAAAjM"]
[Mon Jul 20 06:08:28.643671 2026] [security2:error] [pid 796567:tid 796728] [client 164.100.212.184:59198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PvLLfyzVz2SrjZpjT1AAAAjM"]
[Mon Jul 20 06:08:29.175798 2026] [core:error] [pid 832668:tid 832850] [client 14.225.17.146:53942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wordpress
[Mon Jul 20 06:08:29.175826 2026] [core:error] [pid 832668:tid 832850] [client 14.225.17.146:53942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wordpress
[Mon Jul 20 06:08:29.219478 2026] [security2:error] [pid 832668:tid 832877] [client 57.141.18.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP4gAAAE0"]
[Mon Jul 20 06:08:29.232027 2026] [security2:error] [pid 832668:tid 832803] [client 57.141.18.18:32486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PuGci6KgEEltqA3DOzwAAA18"]
[Mon Jul 20 06:08:29.321275 2026] [security2:error] [pid 832668:tid 832904] [client 34.138.198.0:62272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP6AAAAGg"], referer: https://www.rtkenergypartners.com/.env.local
[Mon Jul 20 06:08:29.334502 2026] [security2:error] [pid 832668:tid 832811] [client 34.138.198.0:62294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP6QAAAAs"], referer: https://www.rtkenergypartners.com/.env.sample
[Mon Jul 20 06:08:29.405039 2026] [security2:error] [pid 832668:tid 832906] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PvWci6KgEEltqA3DP8QAAAGo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:29.511479 2026] [security2:error] [pid 832668:tid 832901] [client 34.138.198.0:62352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP8AAAAGU"], referer: https://www.rtkenergypartners.com/.env.save
[Mon Jul 20 06:08:29.549435 2026] [security2:error] [pid 796567:tid 796810] [client 34.138.198.0:62400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjT9wAAAoU"], referer: https://www.rtkenergypartners.com/.dev.vars
[Mon Jul 20 06:08:29.610956 2026] [security2:error] [pid 832668:tid 832862] [client 57.141.18.25:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PuGci6KgEEltqA3DO4wAAPmQ"]
[Mon Jul 20 06:08:29.614358 2026] [security2:error] [pid 796567:tid 796738] [client 34.138.198.0:62410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjT_AAAAj0"], referer: https://www.rtkenergypartners.com/config.yaml
[Mon Jul 20 06:08:29.621840 2026] [security2:error] [pid 832668:tid 832853] [client 34.138.198.0:62362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP_QAAADU"], referer: https://www.rtkenergypartners.com/api/config
[Mon Jul 20 06:08:29.624291 2026] [security2:error] [pid 832668:tid 832842] [client 34.138.198.0:62306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP-gAAACo"], referer: https://www.rtkenergypartners.com/.env.test
[Mon Jul 20 06:08:29.644759 2026] [security2:error] [pid 832668:tid 832825] [client 34.138.198.0:62278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DQAAAAABk"], referer: https://www.rtkenergypartners.com/.npmrc
[Mon Jul 20 06:08:29.747842 2026] [ssl:error] [pid 832668:tid 832883] [client 104.48.69.105:58172] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:08:29.750457 2026] [security2:error] [pid 832668:tid 832916] [client 34.138.198.0:62378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DQAQAAAHQ"], referer: https://www.rtkenergypartners.com/.env.production
[Mon Jul 20 06:08:29.804577 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PvWci6KgEEltqA3DQBAAAAC8"]
[Mon Jul 20 06:08:29.804707 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PvWci6KgEEltqA3DQBAAAAC8"]
[Mon Jul 20 06:08:29.875887 2026] [security2:error] [pid 832668:tid 832892] [client 103.178.3.191:40880] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvWci6KgEEltqA3DQCQAAAFw"]
[Mon Jul 20 06:08:29.917850 2026] [security2:error] [pid 796567:tid 796731] [client 34.138.198.0:62336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjUAwAAAjY"], referer: https://www.rtkenergypartners.com/.git/config
[Mon Jul 20 06:08:29.924928 2026] [security2:error] [pid 796567:tid 796794] [client 34.138.198.0:62320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjUBAAAAnU"], referer: https://www.rtkenergypartners.com/.aws/credentials
[Mon Jul 20 06:08:29.974179 2026] [security2:error] [pid 832668:tid 832878] [client 34.138.198.0:62388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DQCgAAAE4"], referer: https://www.rtkenergypartners.com/.git/HEAD
[Mon Jul 20 06:08:29.980569 2026] [security2:error] [pid 832668:tid 832812] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PvWci6KgEEltqA3DQCwAAAAw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:30.001921 2026] [security2:error] [pid 832668:tid 832892] [client 103.178.3.191:40880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvWci6KgEEltqA3DQCQAAAFw"]
[Mon Jul 20 06:08:30.129081 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:57063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4Pvmci6KgEEltqA3DQFgAAAAg"]
[Mon Jul 20 06:08:30.129309 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:57063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4Pvmci6KgEEltqA3DQFgAAAAg"]
[Mon Jul 20 06:08:30.270690 2026] [security2:error] [pid 796567:tid 796719] [client 14.225.17.146:63351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4PvrLfyzVz2SrjZpjUEgAAAio"], referer: http://dasmarque.com/Wordpress
[Mon Jul 20 06:08:30.379432 2026] [security2:error] [pid 832668:tid 832866] [client 27.96.94.195:37687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQIQAAAEI"]
[Mon Jul 20 06:08:30.379539 2026] [security2:error] [pid 832668:tid 832866] [client 27.96.94.195:37687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQIQAAAEI"]
[Mon Jul 20 06:08:30.412879 2026] [security2:error] [pid 796567:tid 796727] [client 57.141.18.69:22328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PubLfyzVz2SrjZpjTRwACMiQ"]
[Mon Jul 20 06:08:30.484632 2026] [security2:error] [pid 832668:tid 832922] [client 185.132.186.87:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/functions.php"] [unique_id "al4Pvmci6KgEEltqA3DQIwAAAHo"]
[Mon Jul 20 06:08:30.631500 2026] [security2:error] [pid 832668:tid 832834] [client 54.196.52.99:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.52.196.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQNAAAACI"]
[Mon Jul 20 06:08:30.631649 2026] [security2:error] [pid 832668:tid 832834] [client 54.196.52.99:16666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQNAAAACI"]
[Mon Jul 20 06:08:30.889700 2026] [security2:error] [pid 832668:tid 832691] [remote 162.19.86.63:57145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Pvmci6KgEEltqA3DQPwAANRQ"]
[Mon Jul 20 06:08:30.955470 2026] [security2:error] [pid 796567:tid 796709] [client 191.237.250.106:29814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4PvrLfyzVz2SrjZpjUMAAAAiA"]
[Mon Jul 20 06:08:30.955597 2026] [security2:error] [pid 796567:tid 796709] [client 191.237.250.106:29814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4PvrLfyzVz2SrjZpjUMAAAAiA"]
[Mon Jul 20 06:08:30.995289 2026] [security2:error] [pid 796567:tid 796627] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PvrLfyzVz2SrjZpjUNAACaTs"]
[Mon Jul 20 06:08:30.995449 2026] [security2:error] [pid 796567:tid 796782] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PvrLfyzVz2SrjZpjUNAACaTs"]
[Mon Jul 20 06:08:30.998282 2026] [security2:error] [pid 796567:tid 796817] [client 57.141.18.102:57882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PubLfyzVz2SrjZpjTVwACjC8"]
[Mon Jul 20 06:08:31.127621 2026] [security2:error] [pid 832668:tid 832701] [remote 162.19.86.63:57145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Pv2ci6KgEEltqA3DQSAAAYR4"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:08:31.440855 2026] [security2:error] [pid 796567:tid 796814] [client 103.178.3.191:40916] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUQwAAAok"]
[Mon Jul 20 06:08:31.447530 2026] [security2:error] [pid 832668:tid 832810] [client 14.225.17.146:53154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4Pvmci6KgEEltqA3DQEQAAAAo"], referer: http://dadanetnet.net/Wordpress
[Mon Jul 20 06:08:31.559884 2026] [security2:error] [pid 796567:tid 796814] [client 103.178.3.191:40916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUQwAAAok"]
[Mon Jul 20 06:08:31.665501 2026] [security2:error] [pid 832668:tid 832852] [client 57.141.18.35:31448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pumci6KgEEltqA3DPVwAANEo"]
[Mon Jul 20 06:08:31.689013 2026] [security2:error] [pid 832668:tid 832883] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pv2ci6KgEEltqA3DQVwAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:31.810949 2026] [security2:error] [pid 796567:tid 796808] [client 193.19.109.251:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUWAAAAoM"]
[Mon Jul 20 06:08:31.830690 2026] [security2:error] [pid 796567:tid 796798] [client 193.19.109.231:44089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUVwAAAnk"]
[Mon Jul 20 06:08:31.986595 2026] [security2:error] [pid 832668:tid 832831] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Pv2ci6KgEEltqA3DQXgAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:32.204902 2026] [security2:error] [pid 796567:tid 796736] [client 191.237.250.106:37593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/x.php"] [unique_id "al4PwLLfyzVz2SrjZpjUZgAAAjs"]
[Mon Jul 20 06:08:32.205008 2026] [security2:error] [pid 796567:tid 796736] [client 191.237.250.106:37593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/x.php"] [unique_id "al4PwLLfyzVz2SrjZpjUZgAAAjs"]
[Mon Jul 20 06:08:32.370775 2026] [security2:error] [pid 832668:tid 832803] [client 74.208.214.194:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PwGci6KgEEltqA3DQcwAAAAM"]
[Mon Jul 20 06:08:32.480734 2026] [security2:error] [pid 796567:tid 796704] [client 185.132.186.66:31567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/db.php"] [unique_id "al4PwLLfyzVz2SrjZpjUcQAAAhs"]
[Mon Jul 20 06:08:32.730999 2026] [security2:error] [pid 832668:tid 832898] [client 34.138.198.0:62424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQewAAAGI"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:32.827602 2026] [security2:error] [pid 796567:tid 796819] [client 34.138.198.0:62430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwLLfyzVz2SrjZpjUfgAAAo4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:32.865387 2026] [security2:error] [pid 796567:tid 796799] [client 191.237.250.106:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/mgrr.php"] [unique_id "al4PwLLfyzVz2SrjZpjUhgAAAno"]
[Mon Jul 20 06:08:32.865487 2026] [security2:error] [pid 796567:tid 796799] [client 191.237.250.106:16320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/mgrr.php"] [unique_id "al4PwLLfyzVz2SrjZpjUhgAAAno"]
[Mon Jul 20 06:08:32.963919 2026] [security2:error] [pid 796567:tid 796651] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.bak"] [unique_id "al4PwLLfyzVz2SrjZpjUiQACFFM"]
[Mon Jul 20 06:08:33.124869 2026] [security2:error] [pid 832668:tid 832840] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQhgAAKAU"]
[Mon Jul 20 06:08:33.124906 2026] [security2:error] [pid 832668:tid 832840] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQhgAAKAU"]
[Mon Jul 20 06:08:33.251764 2026] [security2:error] [pid 832668:tid 832891] [client 34.138.198.0:62434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwWci6KgEEltqA3DQjwAAAFs"]
[Mon Jul 20 06:08:33.381826 2026] [security2:error] [pid 832668:tid 832805] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PwWci6KgEEltqA3DQnQAAAAU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:33.504830 2026] [security2:error] [pid 832668:tid 832854] [client 14.224.227.113:58323] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4PwWci6KgEEltqA3DQpQAAADY"]
[Mon Jul 20 06:08:33.568479 2026] [security2:error] [pid 832668:tid 832924] [client 103.178.3.191:40957] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PwWci6KgEEltqA3DQqgAAAHw"]
[Mon Jul 20 06:08:33.675091 2026] [security2:error] [pid 832668:tid 832919] [client 103.141.108.143:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PwWci6KgEEltqA3DQsAAAAHc"]
[Mon Jul 20 06:08:33.675304 2026] [security2:error] [pid 832668:tid 832919] [client 103.141.108.143:49892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PwWci6KgEEltqA3DQsAAAAHc"]
[Mon Jul 20 06:08:33.691033 2026] [security2:error] [pid 832668:tid 832905] [client 34.138.198.0:62456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwWci6KgEEltqA3DQqwAAAGk"], referer: https://www.rtkenergypartners.com/.pypirc
[Mon Jul 20 06:08:33.720490 2026] [security2:error] [pid 832668:tid 832924] [client 103.178.3.191:40957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PwWci6KgEEltqA3DQqgAAAHw"]
[Mon Jul 20 06:08:33.742424 2026] [security2:error] [pid 796567:tid 796745] [client 158.173.166.181:57887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PwbLfyzVz2SrjZpjUsgAAAkQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:33.781589 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/stdin.php"] [unique_id "al4PwWci6KgEEltqA3DQwQAAAHk"]
[Mon Jul 20 06:08:33.781685 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/stdin.php"] [unique_id "al4PwWci6KgEEltqA3DQwQAAAHk"]
[Mon Jul 20 06:08:33.957489 2026] [security2:error] [pid 832668:tid 832899] [client 34.138.198.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PwWci6KgEEltqA3DQyAAAAGM"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:34.028545 2026] [security2:error] [pid 796567:tid 796710] [client 34.138.198.0:62440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwbLfyzVz2SrjZpjUuQAAAiE"], referer: https://www.rtkenergypartners.com/.env.dist
[Mon Jul 20 06:08:34.047332 2026] [security2:error] [pid 796567:tid 796707] [client 103.77.203.233:57913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjUvAAAAh4"]
[Mon Jul 20 06:08:34.047831 2026] [security2:error] [pid 796567:tid 796707] [client 103.77.203.233:57913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjUvAAAAh4"]
[Mon Jul 20 06:08:34.082653 2026] [security2:error] [pid 832668:tid 832761] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pwmci6KgEEltqA3DQ0AAAVVo"]
[Mon Jul 20 06:08:34.082803 2026] [security2:error] [pid 832668:tid 832885] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pwmci6KgEEltqA3DQ0AAAVVo"]
[Mon Jul 20 06:08:34.254198 2026] [security2:error] [pid 832668:tid 832888] [client 173.239.254.42:48029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Pwmci6KgEEltqA3DQ1wAAAFg"]
[Mon Jul 20 06:08:34.265044 2026] [security2:error] [pid 796567:tid 796709] [client 193.19.109.227:52869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4PwrLfyzVz2SrjZpjU0AAAAiA"]
[Mon Jul 20 06:08:34.312323 2026] [security2:error] [pid 796567:tid 796737] [client 193.19.109.241:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4PwrLfyzVz2SrjZpjU0QAAAjw"]
[Mon Jul 20 06:08:34.368827 2026] [security2:error] [pid 832668:tid 832874] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ2AAAAEo"]
[Mon Jul 20 06:08:34.400368 2026] [security2:error] [pid 832668:tid 832826] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Pwmci6KgEEltqA3DQ3gAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:34.415701 2026] [security2:error] [pid 796567:tid 796813] [client 14.225.17.146:62264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4PwLLfyzVz2SrjZpjUgQAAAog"], referer: http://eframiproperties.com/Wordpress
[Mon Jul 20 06:08:34.420836 2026] [security2:error] [pid 832668:tid 832840] [client 34.138.198.0:62462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ2wAAACg"]
[Mon Jul 20 06:08:34.478009 2026] [security2:error] [pid 832668:tid 832854] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ3wAAADY"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:34.627981 2026] [security2:error] [pid 796567:tid 796697] [client 34.138.198.0:62476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.old"] [unique_id "al4PwrLfyzVz2SrjZpjU4AAAAhQ"]
[Mon Jul 20 06:08:34.630606 2026] [security2:error] [pid 832668:tid 832903] [client 34.138.198.0:62464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ7AAAAGc"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:34.744553 2026] [security2:error] [pid 832668:tid 832900] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ-AAAAGQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:34.789722 2026] [security2:error] [pid 796567:tid 796717] [client 34.138.198.0:62490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU5AAAAig"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:34.875306 2026] [security2:error] [pid 796567:tid 796784] [client 34.138.198.0:62498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU5wAAAms"], referer: https://www.rtkenergypartners.com/.netrc
[Mon Jul 20 06:08:34.938581 2026] [security2:error] [pid 796567:tid 796812] [client 57.141.18.26:63154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PvrLfyzVz2SrjZpjUFQACh24"]
[Mon Jul 20 06:08:34.968910 2026] [security2:error] [pid 832668:tid 832924] [client 34.138.198.0:62504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DRBAAAAHw"]
[Mon Jul 20 06:08:34.976829 2026] [security2:error] [pid 796567:tid 796722] [client 115.246.21.170:46841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjU8wAAAi0"]
[Mon Jul 20 06:08:34.976983 2026] [security2:error] [pid 796567:tid 796722] [client 115.246.21.170:46841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjU8wAAAi0"]
[Mon Jul 20 06:08:34.991138 2026] [security2:error] [pid 796567:tid 796791] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU7wAAAnI"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:35.054946 2026] [security2:error] [pid 796567:tid 796701] [client 57.141.18.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU7gAAAhg"]
[Mon Jul 20 06:08:35.082886 2026] [security2:error] [pid 832668:tid 832833] [client 103.178.3.191:41029] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pw2ci6KgEEltqA3DREwAAACE"]
[Mon Jul 20 06:08:35.122018 2026] [security2:error] [pid 796567:tid 796706] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pw7LfyzVz2SrjZpjU9gAAAh0"]
[Mon Jul 20 06:08:35.164449 2026] [security2:error] [pid 832668:tid 832861] [client 112.213.160.112:30730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRGQAAAD0"]
[Mon Jul 20 06:08:35.164602 2026] [security2:error] [pid 832668:tid 832861] [client 112.213.160.112:30730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRGQAAAD0"]
[Mon Jul 20 06:08:35.166009 2026] [security2:error] [pid 796567:tid 796789] [client 191.237.250.106:29792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/BDKR28.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVAQAAAnA"]
[Mon Jul 20 06:08:35.166170 2026] [security2:error] [pid 796567:tid 796789] [client 191.237.250.106:29792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/BDKR28.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVAQAAAnA"]
[Mon Jul 20 06:08:35.236488 2026] [security2:error] [pid 796567:tid 796797] [client 193.19.109.249:44413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVBQAAAng"]
[Mon Jul 20 06:08:35.239128 2026] [security2:error] [pid 832668:tid 832833] [client 103.178.3.191:41029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pw2ci6KgEEltqA3DREwAAACE"]
[Mon Jul 20 06:08:35.581416 2026] [security2:error] [pid 832668:tid 832923] [client 57.141.18.10:32936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pvmci6KgEEltqA3DQRAAAe3o"]
[Mon Jul 20 06:08:35.622802 2026] [security2:error] [pid 796567:tid 796795] [client 34.138.198.0:62520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVEAAAAnY"], referer: https://www.rtkenergypartners.com/.env.production.local
[Mon Jul 20 06:08:35.778504 2026] [security2:error] [pid 832668:tid 832815] [client 44.245.170.32:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Pw2ci6KgEEltqA3DRQAAAAA8"]
[Mon Jul 20 06:08:35.787212 2026] [security2:error] [pid 796567:tid 796757] [client 52.109.124.141:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Pw7LfyzVz2SrjZpjVFwAAAlA"]
[Mon Jul 20 06:08:35.910761 2026] [security2:error] [pid 832668:tid 832916] [client 45.116.69.230:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRSAAAAHQ"]
[Mon Jul 20 06:08:35.910861 2026] [security2:error] [pid 832668:tid 832916] [client 45.116.69.230:62187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRSAAAAHQ"]
[Mon Jul 20 06:08:35.935626 2026] [security2:error] [pid 796567:tid 796785] [client 185.132.186.85:25717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-dependency-float.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVHAAAAmw"]
[Mon Jul 20 06:08:35.974797 2026] [security2:error] [pid 796567:tid 796779] [client 52.109.124.141:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Pw7LfyzVz2SrjZpjVHgAAAmY"]
[Mon Jul 20 06:08:36.208887 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.105:59812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUTAACY1U"]
[Mon Jul 20 06:08:36.227380 2026] [security2:error] [pid 796567:tid 796700] [client 34.138.198.0:56802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PxLLfyzVz2SrjZpjVJgAAAhc"], referer: https://www.rtkenergypartners.com/.env.development.local
[Mon Jul 20 06:08:36.250602 2026] [security2:error] [pid 796567:tid 796777] [client 34.138.198.0:56808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PxLLfyzVz2SrjZpjVJwAAAmQ"], referer: https://www.rtkenergypartners.com/secrets.yaml
[Mon Jul 20 06:08:36.520124 2026] [security2:error] [pid 832668:tid 832844] [client 74.7.227.179:48664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRXQAALH0"], referer: https://tejasenvironmental.com/p=617389
[Mon Jul 20 06:08:36.541982 2026] [security2:error] [pid 832668:tid 832833] [client 104.234.53.91:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PxGci6KgEEltqA3DRbQAAACE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:36.564889 2026] [security2:error] [pid 796567:tid 796805] [client 104.28.219.194:51160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/.env"] [unique_id "al4PxLLfyzVz2SrjZpjVOQAAAoA"]
[Mon Jul 20 06:08:36.678939 2026] [security2:error] [pid 832668:tid 832889] [client 104.28.219.194:51163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRcgAAAFk"]
[Mon Jul 20 06:08:36.679661 2026] [security2:error] [pid 832668:tid 832924] [client 104.28.219.194:51168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRcAAAAHw"]
[Mon Jul 20 06:08:36.683343 2026] [security2:error] [pid 832668:tid 832883] [client 104.28.219.194:51172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRcwAAAFM"]
[Mon Jul 20 06:08:36.688551 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:44878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRdgAAAA0"]
[Mon Jul 20 06:08:36.688643 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:44878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRdgAAAA0"]
[Mon Jul 20 06:08:36.711962 2026] [security2:error] [pid 796567:tid 796740] [client 43.205.139.3:22992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVHwAAAj8"]
[Mon Jul 20 06:08:36.716637 2026] [security2:error] [pid 796567:tid 796701] [client 104.28.219.194:51160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxLLfyzVz2SrjZpjVPAAAAhg"]
[Mon Jul 20 06:08:36.808557 2026] [security2:error] [pid 832668:tid 832922] [client 34.138.198.0:56816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DReAAAAHo"], referer: https://www.rtkenergypartners.com/config.yml
[Mon Jul 20 06:08:36.818363 2026] [security2:error] [pid 832668:tid 832812] [client 41.173.37.102:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRfQAAAAw"]
[Mon Jul 20 06:08:36.818478 2026] [security2:error] [pid 832668:tid 832812] [client 41.173.37.102:8879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRfQAAAAw"]
[Mon Jul 20 06:08:36.885893 2026] [security2:error] [pid 832668:tid 832684] [remote 68.178.160.25:39016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4PxGci6KgEEltqA3DRgQAAew0"]
[Mon Jul 20 06:08:37.099416 2026] [security2:error] [pid 796567:tid 796635] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVVgACdUM"]
[Mon Jul 20 06:08:37.099609 2026] [security2:error] [pid 796567:tid 796794] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVVgACdUM"]
[Mon Jul 20 06:08:37.196152 2026] [security2:error] [pid 796567:tid 796803] [client 52.109.44.112:35147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PxbLfyzVz2SrjZpjVXAAAAn4"]
[Mon Jul 20 06:08:37.225144 2026] [security2:error] [pid 796567:tid 796806] [client 13.229.223.11:61478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4PxbLfyzVz2SrjZpjVYAAAAoE"]
[Mon Jul 20 06:08:37.308847 2026] [security2:error] [pid 832668:tid 832926] [client 191.237.250.106:11259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/001.php"] [unique_id "al4PxWci6KgEEltqA3DRiAAAAH4"]
[Mon Jul 20 06:08:37.309001 2026] [security2:error] [pid 832668:tid 832926] [client 191.237.250.106:11259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/001.php"] [unique_id "al4PxWci6KgEEltqA3DRiAAAAH4"]
[Mon Jul 20 06:08:37.335600 2026] [security2:error] [pid 796567:tid 796746] [client 52.109.44.112:35147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PxbLfyzVz2SrjZpjVawAAAkU"]
[Mon Jul 20 06:08:37.375658 2026] [ssl:error] [pid 796567:tid 796753] [client 104.48.69.105:58180] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:08:37.411396 2026] [security2:error] [pid 832668:tid 832792] [remote 68.178.160.25:39016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4PxWci6KgEEltqA3DRjgAAcXk"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 06:08:37.428906 2026] [security2:error] [pid 796567:tid 796763] [client 114.119.134.3:53667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "recruitinginsight.us"] [uri "/page/28/"] [unique_id "al4PxbLfyzVz2SrjZpjVcQAAAlY"], referer: https://recruitinginsight.us/page/28/?et_blog
[Mon Jul 20 06:08:37.491830 2026] [ssl:error] [pid 796567:tid 796792] [client 104.48.69.105:58186] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:08:37.555404 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.105:59822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQhQAALmg"]
[Mon Jul 20 06:08:37.671532 2026] [security2:error] [pid 832668:tid 832839] [client 13.201.64.214:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PxWci6KgEEltqA3DRlwAAACc"]
[Mon Jul 20 06:08:37.671723 2026] [security2:error] [pid 832668:tid 832839] [client 13.201.64.214:36090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PxWci6KgEEltqA3DRlwAAACc"]
[Mon Jul 20 06:08:37.743003 2026] [security2:error] [pid 796567:tid 796767] [client 178.152.178.232:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVfAAAAlo"]
[Mon Jul 20 06:08:37.743131 2026] [security2:error] [pid 796567:tid 796767] [client 178.152.178.232:37354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVfAAAAlo"]
[Mon Jul 20 06:08:37.832118 2026] [security2:error] [pid 796567:tid 796677] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVgAACKW0"]
[Mon Jul 20 06:08:37.832250 2026] [security2:error] [pid 796567:tid 796718] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVgAACKW0"]
[Mon Jul 20 06:08:38.009868 2026] [security2:error] [pid 796567:tid 796761] [client 57.141.18.93:60042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PwbLfyzVz2SrjZpjUnAACVAc"]
[Mon Jul 20 06:08:38.488643 2026] [security2:error] [pid 832668:tid 832845] [client 13.229.223.11:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pxmci6KgEEltqA3DRuQAAAC0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:08:39.183727 2026] [security2:error] [pid 796567:tid 796820] [client 57.141.18.53:39178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU1wACjzA"]
[Mon Jul 20 06:08:39.260898 2026] [security2:error] [pid 832668:tid 832887] [client 193.19.109.242:31961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4Px2ci6KgEEltqA3DRzQAAAFc"]
[Mon Jul 20 06:08:39.291067 2026] [security2:error] [pid 832668:tid 832894] [client 164.100.212.184:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Px2ci6KgEEltqA3DR0AAAAF4"]
[Mon Jul 20 06:08:39.291164 2026] [security2:error] [pid 832668:tid 832894] [client 164.100.212.184:63041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Px2ci6KgEEltqA3DR0AAAAF4"]
[Mon Jul 20 06:08:40.062206 2026] [security2:error] [pid 832668:tid 832892] [client 191.237.250.106:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/dZ3wP5.php"] [unique_id "al4PyGci6KgEEltqA3DR9gAAAFw"]
[Mon Jul 20 06:08:40.062308 2026] [security2:error] [pid 832668:tid 832892] [client 191.237.250.106:59139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/dZ3wP5.php"] [unique_id "al4PyGci6KgEEltqA3DR9gAAAFw"]
[Mon Jul 20 06:08:40.680790 2026] [security2:error] [pid 832668:tid 832889] [client 103.95.123.246:17460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PyGci6KgEEltqA3DSDQAAAFk"]
[Mon Jul 20 06:08:40.683422 2026] [security2:error] [pid 832668:tid 832889] [client 103.95.123.246:17460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PyGci6KgEEltqA3DSDQAAAFk"]
[Mon Jul 20 06:08:40.688037 2026] [security2:error] [pid 832668:tid 832685] [remote 152.228.213.32:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4PyGci6KgEEltqA3DSDAAAFQ4"]
[Mon Jul 20 06:08:40.927918 2026] [security2:error] [pid 796567:tid 796778] [client 57.141.18.89:49720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVHQACZS8"]
[Mon Jul 20 06:08:41.086815 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yup.php"] [unique_id "al4PyWci6KgEEltqA3DSGAAAAHk"]
[Mon Jul 20 06:08:41.086947 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yup.php"] [unique_id "al4PyWci6KgEEltqA3DSGAAAAHk"]
[Mon Jul 20 06:08:41.120135 2026] [proxy:error] [pid 796567:tid 796783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:41.120205 2026] [proxy_http:error] [pid 796567:tid 796783] [client 185.247.137.40:37661] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:41.120702 2026] [proxy:error] [pid 796567:tid 796783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:41.120736 2026] [proxy_http:error] [pid 796567:tid 796783] [client 185.247.137.40:37661] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:41.208452 2026] [security2:error] [pid 796567:tid 796702] [client 216.144.249.201:37698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/"] [unique_id "al4PybLfyzVz2SrjZpjV_gAAAhk"]
[Mon Jul 20 06:08:41.208564 2026] [security2:error] [pid 796567:tid 796702] [client 216.144.249.201:37698] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/"] [unique_id "al4PybLfyzVz2SrjZpjV_gAAAhk"]
[Mon Jul 20 06:08:41.257626 2026] [security2:error] [pid 832668:tid 832701] [remote 120.46.94.180:44522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.94.46.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PyWci6KgEEltqA3DSHwAAQx4"]
[Mon Jul 20 06:08:41.308966 2026] [security2:error] [pid 796567:tid 796766] [client 15.237.142.234:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWAgAAAlk"]
[Mon Jul 20 06:08:41.309089 2026] [security2:error] [pid 796567:tid 796766] [client 15.237.142.234:54884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWAgAAAlk"]
[Mon Jul 20 06:08:41.480835 2026] [security2:error] [pid 796567:tid 796693] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWDwACJn0"]
[Mon Jul 20 06:08:41.480968 2026] [security2:error] [pid 796567:tid 796715] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWDwACJn0"]
[Mon Jul 20 06:08:41.483471 2026] [security2:error] [pid 796567:tid 796699] [client 216.144.249.201:37700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env"] [unique_id "al4PybLfyzVz2SrjZpjWEAAAAhY"]
[Mon Jul 20 06:08:41.667390 2026] [security2:error] [pid 832668:tid 832682] [remote 152.228.213.32:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4PyWci6KgEEltqA3DSOgAAdAs"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:08:41.725082 2026] [security2:error] [pid 832668:tid 832909] [client 191.237.250.106:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/X.php"] [unique_id "al4PyWci6KgEEltqA3DSOwAAAG0"]
[Mon Jul 20 06:08:41.725191 2026] [security2:error] [pid 832668:tid 832909] [client 191.237.250.106:19436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/X.php"] [unique_id "al4PyWci6KgEEltqA3DSOwAAAG0"]
[Mon Jul 20 06:08:41.821405 2026] [security2:error] [pid 832668:tid 832702] [remote 95.217.78.234:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4PyWci6KgEEltqA3DSPAAAER8"]
[Mon Jul 20 06:08:42.048301 2026] [security2:error] [pid 832668:tid 832731] [remote 95.217.78.234:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Pymci6KgEEltqA3DSRgAASjw"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:08:42.183878 2026] [security2:error] [pid 832668:tid 832801] [client 191.237.250.106:29770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/1polka.php"] [unique_id "al4Pymci6KgEEltqA3DSTQAAAAE"]
[Mon Jul 20 06:08:42.183998 2026] [security2:error] [pid 832668:tid 832801] [client 191.237.250.106:29770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/1polka.php"] [unique_id "al4Pymci6KgEEltqA3DSTQAAAAE"]
[Mon Jul 20 06:08:42.251090 2026] [security2:error] [pid 832668:tid 832829] [client 216.144.249.201:37770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/app/.env"] [unique_id "al4Pymci6KgEEltqA3DSUwAAAB0"]
[Mon Jul 20 06:08:42.252352 2026] [security2:error] [pid 832668:tid 832878] [client 216.144.249.201:37728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env.bak"] [unique_id "al4Pymci6KgEEltqA3DSVQAAAE4"]
[Mon Jul 20 06:08:42.253940 2026] [security2:error] [pid 796567:tid 796785] [client 216.144.249.201:37736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env.backup"] [unique_id "al4PyrLfyzVz2SrjZpjWMAAAAmw"]
[Mon Jul 20 06:08:42.254179 2026] [security2:error] [pid 796567:tid 796752] [client 216.144.249.201:37820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/wp/.env"] [unique_id "al4PyrLfyzVz2SrjZpjWMQAAAks"]
[Mon Jul 20 06:08:42.269444 2026] [security2:error] [pid 832668:tid 832854] [client 216.144.249.201:37990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4Pymci6KgEEltqA3DSXQAAADY"]
[Mon Jul 20 06:08:42.269575 2026] [security2:error] [pid 832668:tid 832854] [client 216.144.249.201:37990] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4Pymci6KgEEltqA3DSXQAAADY"]
[Mon Jul 20 06:08:42.326206 2026] [security2:error] [pid 832668:tid 832818] [client 216.144.249.201:37962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/key.json"] [unique_id "al4Pymci6KgEEltqA3DSYgAAABI"]
[Mon Jul 20 06:08:42.326445 2026] [security2:error] [pid 796567:tid 796776] [client 216.144.249.201:37792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/api/.env"] [unique_id "al4PyrLfyzVz2SrjZpjWNgAAAmM"]
[Mon Jul 20 06:08:42.326586 2026] [security2:error] [pid 832668:tid 832818] [client 216.144.249.201:37962] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/key.json"] [unique_id "al4Pymci6KgEEltqA3DSYgAAABI"]
[Mon Jul 20 06:08:42.329170 2026] [security2:error] [pid 832668:tid 832834] [client 216.144.249.201:37808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/public/.env"] [unique_id "al4Pymci6KgEEltqA3DSYwAAACI"]
[Mon Jul 20 06:08:42.329876 2026] [security2:error] [pid 832668:tid 832912] [client 216.144.249.201:37892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/api/config"] [unique_id "al4Pymci6KgEEltqA3DSZQAAAHA"]
[Mon Jul 20 06:08:42.329977 2026] [security2:error] [pid 832668:tid 832912] [client 216.144.249.201:37892] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/api/config"] [unique_id "al4Pymci6KgEEltqA3DSZQAAAHA"]
[Mon Jul 20 06:08:42.331230 2026] [security2:error] [pid 832668:tid 832806] [client 216.144.249.201:38068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "scarlettshirt.com"] [uri "/wp-config.php.bak"] [unique_id "al4Pymci6KgEEltqA3DSZwAAAAY"]
[Mon Jul 20 06:08:42.333026 2026] [security2:error] [pid 832668:tid 832861] [client 216.144.249.201:37984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/token.json"] [unique_id "al4Pymci6KgEEltqA3DSaQAAAD0"]
[Mon Jul 20 06:08:42.333116 2026] [security2:error] [pid 832668:tid 832861] [client 216.144.249.201:37984] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/token.json"] [unique_id "al4Pymci6KgEEltqA3DSaQAAAD0"]
[Mon Jul 20 06:08:42.356080 2026] [security2:error] [pid 832668:tid 832841] [client 216.144.249.201:37812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/laravel/.env"] [unique_id "al4Pymci6KgEEltqA3DSbwAAACk"]
[Mon Jul 20 06:08:42.356082 2026] [security2:error] [pid 832668:tid 832839] [client 216.144.249.201:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/backend/.env"] [unique_id "al4Pymci6KgEEltqA3DSbgAAACc"]
[Mon Jul 20 06:08:42.384192 2026] [security2:error] [pid 832668:tid 832690] [remote 120.46.94.180:44522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.94.46.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Pymci6KgEEltqA3DSdAAAFBM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:08:42.401663 2026] [security2:error] [pid 796567:tid 796645] [remote 57.141.18.31:23666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PxbLfyzVz2SrjZpjVZAACVU0"]
[Mon Jul 20 06:08:42.407864 2026] [security2:error] [pid 796567:tid 796700] [client 216.144.249.201:38066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.249.144.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "scarlettshirt.com"] [uri "/wp-config.php"] [unique_id "al4PyrLfyzVz2SrjZpjWQwAAAhc"]
[Mon Jul 20 06:08:42.471482 2026] [security2:error] [pid 796567:tid 796741] [client 14.225.17.146:65244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4PyLLfyzVz2SrjZpjV4gAAAkA"], referer: http://itdynamix.com/Wordpress
[Mon Jul 20 06:08:42.485859 2026] [security2:error] [pid 796567:tid 796724] [client 216.144.249.201:37942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/credentials.json"] [unique_id "al4PyrLfyzVz2SrjZpjWRgAAAi8"]
[Mon Jul 20 06:08:42.485951 2026] [security2:error] [pid 796567:tid 796724] [client 216.144.249.201:37942] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/credentials.json"] [unique_id "al4PyrLfyzVz2SrjZpjWRgAAAi8"]
[Mon Jul 20 06:08:42.487170 2026] [security2:error] [pid 796567:tid 796709] [client 216.144.249.201:38076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/web.config"] [unique_id "al4PyrLfyzVz2SrjZpjWRAAAAiA"]
[Mon Jul 20 06:08:42.491865 2026] [security2:error] [pid 796567:tid 796760] [client 216.144.249.201:37752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env.old"] [unique_id "al4PyrLfyzVz2SrjZpjWSQAAAlM"]
[Mon Jul 20 06:08:42.508650 2026] [security2:error] [pid 832668:tid 832873] [client 216.144.249.201:38080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/.env.development"] [unique_id "al4Pymci6KgEEltqA3DSigAAAEk"]
[Mon Jul 20 06:08:42.508741 2026] [security2:error] [pid 832668:tid 832873] [client 216.144.249.201:38080] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/.env.development"] [unique_id "al4Pymci6KgEEltqA3DSigAAAEk"]
[Mon Jul 20 06:08:42.990246 2026] [security2:error] [pid 832668:tid 832822] [client 191.237.250.106:29804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/gec.php"] [unique_id "al4Pymci6KgEEltqA3DStgAAABY"]
[Mon Jul 20 06:08:42.990359 2026] [security2:error] [pid 832668:tid 832822] [client 191.237.250.106:29804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/gec.php"] [unique_id "al4Pymci6KgEEltqA3DStgAAABY"]
[Mon Jul 20 06:08:43.080090 2026] [security2:error] [pid 832668:tid 832726] [remote 156.59.198.136:19074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bigwormfishing.com"] [uri "/wp-content/uploads/css/CheapFishingTackletheSmartWay.pdf"] [unique_id "al4Py2ci6KgEEltqA3DSwgAAMjc"]
[Mon Jul 20 06:08:43.486087 2026] [security2:error] [pid 832668:tid 832917] [client 14.225.17.146:50677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DS0gAAAHU"], referer: https://itdynamix.com/Wordpress
[Mon Jul 20 06:08:43.772042 2026] [security2:error] [pid 832668:tid 832903] [client 57.141.18.4:45238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pxmci6KgEEltqA3DRtwAAZ3I"]
[Mon Jul 20 06:08:44.137393 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:29769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sky.php"] [unique_id "al4PzGci6KgEEltqA3DTHgAAADI"]
[Mon Jul 20 06:08:44.137551 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:29769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sky.php"] [unique_id "al4PzGci6KgEEltqA3DTHgAAADI"]
[Mon Jul 20 06:08:44.310027 2026] [security2:error] [pid 832668:tid 832829] [client 103.141.108.143:50340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTMAAAAB0"]
[Mon Jul 20 06:08:44.310230 2026] [security2:error] [pid 832668:tid 832829] [client 103.141.108.143:50340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTMAAAAB0"]
[Mon Jul 20 06:08:44.585774 2026] [security2:error] [pid 832668:tid 832911] [client 103.77.203.233:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTSQAAAG8"]
[Mon Jul 20 06:08:44.585988 2026] [security2:error] [pid 832668:tid 832911] [client 103.77.203.233:57974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTSQAAAG8"]
[Mon Jul 20 06:08:44.660055 2026] [security2:error] [pid 832668:tid 832802] [client 14.225.17.146:65334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DS0QAAAAI"], referer: http://effingweirdmuseums.com/Wordpress
[Mon Jul 20 06:08:44.719627 2026] [security2:error] [pid 832668:tid 832873] [client 193.19.109.251:40583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTVgAAAEk"]
[Mon Jul 20 06:08:44.756782 2026] [security2:error] [pid 832668:tid 832825] [client 193.19.109.226:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTWAAAABk"]
[Mon Jul 20 06:08:44.765580 2026] [security2:error] [pid 832668:tid 832801] [client 193.19.109.228:20857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTVQAAAAE"]
[Mon Jul 20 06:08:44.835037 2026] [security2:error] [pid 832668:tid 832885] [client 193.19.109.243:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTXgAAAFU"]
[Mon Jul 20 06:08:44.899368 2026] [security2:error] [pid 832668:tid 832860] [client 57.141.18.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "uninursity.com"] [uri "/index.php"] [unique_id "al4PyWci6KgEEltqA3DSKQAAADw"]
[Mon Jul 20 06:08:44.933168 2026] [security2:error] [pid 832668:tid 832775] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTaQAAemg"]
[Mon Jul 20 06:08:44.933303 2026] [security2:error] [pid 832668:tid 832922] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTaQAAemg"]
[Mon Jul 20 06:08:45.005721 2026] [security2:error] [pid 832668:tid 832849] [client 185.132.186.68:59847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/PHPMailer/index.php"] [unique_id "al4PzWci6KgEEltqA3DTdAAAADE"]
[Mon Jul 20 06:08:45.119417 2026] [security2:error] [pid 832668:tid 832904] [client 14.225.17.146:65364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DS8QAAAGg"], referer: http://cephasnext.com/Wordpress
[Mon Jul 20 06:08:45.235481 2026] [security2:error] [pid 832668:tid 832918] [client 14.225.17.146:52951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4PzGci6KgEEltqA3DTLwAAAHY"], referer: http://techtradeinc.com/Wordpress
[Mon Jul 20 06:08:45.301378 2026] [security2:error] [pid 832668:tid 832838] [client 14.225.17.146:64995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DTCAAAACY"], referer: http://chestermonty.com/Wordpress
[Mon Jul 20 06:08:45.306379 2026] [security2:error] [pid 832668:tid 832821] [client 191.237.250.106:37599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fffm.php"] [unique_id "al4PzWci6KgEEltqA3DTkQAAABU"]
[Mon Jul 20 06:08:45.306542 2026] [security2:error] [pid 832668:tid 832821] [client 191.237.250.106:37599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fffm.php"] [unique_id "al4PzWci6KgEEltqA3DTkQAAABU"]
[Mon Jul 20 06:08:45.567494 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:64992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4Py2ci6KgEEltqA3DTCwAAAFQ"], referer: http://dereckcastellon.com/Wordpress
[Mon Jul 20 06:08:45.647256 2026] [security2:error] [pid 832668:tid 832815] [client 14.225.17.146:50691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTrQAAAA8"], referer: https://effingweirdmuseums.com/Wordpress
[Mon Jul 20 06:08:45.695137 2026] [security2:error] [pid 832668:tid 832888] [client 115.246.21.170:14443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DTugAAAFg"]
[Mon Jul 20 06:08:45.695248 2026] [security2:error] [pid 832668:tid 832888] [client 115.246.21.170:14443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DTugAAAFg"]
[Mon Jul 20 06:08:45.760247 2026] [security2:error] [pid 832668:tid 832885] [client 14.191.253.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTjAAAAFU"]
[Mon Jul 20 06:08:45.766516 2026] [security2:error] [pid 832668:tid 832787] [remote 152.228.213.32:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4PzWci6KgEEltqA3DTwQAADnQ"]
[Mon Jul 20 06:08:45.901196 2026] [security2:error] [pid 832668:tid 832908] [client 112.213.160.112:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DT0QAAAGw"]
[Mon Jul 20 06:08:45.901307 2026] [security2:error] [pid 832668:tid 832908] [client 112.213.160.112:8220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DT0QAAAGw"]
[Mon Jul 20 06:08:46.020100 2026] [security2:error] [pid 832668:tid 832850] [client 52.109.56.130:2371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Pzmci6KgEEltqA3DT3AAAADI"]
[Mon Jul 20 06:08:46.093822 2026] [security2:error] [pid 832668:tid 832874] [client 94.154.43.187:31266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4Pzmci6KgEEltqA3DT5AAAAEo"]
[Mon Jul 20 06:08:46.105315 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:23512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sixxis.php"] [unique_id "al4Pzmci6KgEEltqA3DT5gAAAF8"]
[Mon Jul 20 06:08:46.105421 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:23512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sixxis.php"] [unique_id "al4Pzmci6KgEEltqA3DT5gAAAF8"]
[Mon Jul 20 06:08:46.168874 2026] [security2:error] [pid 832668:tid 832824] [client 106.192.104.4:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DT8AAAABg"]
[Mon Jul 20 06:08:46.169003 2026] [security2:error] [pid 832668:tid 832824] [client 106.192.104.4:54192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DT8AAAABg"]
[Mon Jul 20 06:08:46.197687 2026] [security2:error] [pid 832668:tid 832854] [client 179.127.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4PzGci6KgEEltqA3DTUgAAADY"]
[Mon Jul 20 06:08:46.251531 2026] [security2:error] [pid 832668:tid 832819] [client 52.109.56.130:2371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Pzmci6KgEEltqA3DT9wAAABM"]
[Mon Jul 20 06:08:46.337783 2026] [security2:error] [pid 832668:tid 832918] [client 14.225.17.146:56058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4Pzmci6KgEEltqA3DT9AAAAHY"], referer: https://chestermonty.com/Wordpress
[Mon Jul 20 06:08:46.522043 2026] [security2:error] [pid 832668:tid 832853] [client 14.225.17.146:50695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4PzGci6KgEEltqA3DTSgAAADU"], referer: http://nomorewetsheets.net/Wordpress
[Mon Jul 20 06:08:46.624648 2026] [security2:error] [pid 832668:tid 832836] [client 191.237.250.106:37629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yj09.php"] [unique_id "al4Pzmci6KgEEltqA3DUEAAAACQ"]
[Mon Jul 20 06:08:46.624764 2026] [security2:error] [pid 832668:tid 832836] [client 191.237.250.106:37629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yj09.php"] [unique_id "al4Pzmci6KgEEltqA3DUEAAAACQ"]
[Mon Jul 20 06:08:46.649823 2026] [security2:error] [pid 832668:tid 832876] [client 45.116.69.230:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DUFQAAAEw"]
[Mon Jul 20 06:08:46.649955 2026] [security2:error] [pid 832668:tid 832876] [client 45.116.69.230:62668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DUFQAAAEw"]
[Mon Jul 20 06:08:46.840433 2026] [security2:error] [pid 832668:tid 832919] [client 57.141.18.61:42744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pymci6KgEEltqA3DSSgAAd2w"]
[Mon Jul 20 06:08:47.011120 2026] [security2:error] [pid 832668:tid 832859] [client 185.132.186.94:21611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/PHPMailer/purna.php"] [unique_id "al4Pz2ci6KgEEltqA3DULAAAADs"]
[Mon Jul 20 06:08:47.069912 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/f900.php"] [unique_id "al4Pz2ci6KgEEltqA3DUMQAAACg"]
[Mon Jul 20 06:08:47.070050 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:28764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/f900.php"] [unique_id "al4Pz2ci6KgEEltqA3DUMQAAACg"]
[Mon Jul 20 06:08:47.078942 2026] [security2:error] [pid 832668:tid 832812] [client 52.109.4.7:33538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Pz2ci6KgEEltqA3DUMgAAAAw"]
[Mon Jul 20 06:08:47.083551 2026] [security2:error] [pid 832668:tid 832892] [client 173.239.254.42:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colt-innovate.com"] [uri "/wp-login.php"] [unique_id "al4Pz2ci6KgEEltqA3DUNgAAAFw"]
[Mon Jul 20 06:08:47.140918 2026] [security2:error] [pid 832668:tid 832819] [client 52.109.4.7:33538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Pz2ci6KgEEltqA3DUPAAAABM"]
[Mon Jul 20 06:08:47.221003 2026] [security2:error] [pid 832668:tid 832874] [client 181.224.94.124:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUSAAAAEo"]
[Mon Jul 20 06:08:47.221172 2026] [security2:error] [pid 832668:tid 832874] [client 181.224.94.124:50874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUSAAAAEo"]
[Mon Jul 20 06:08:47.547357 2026] [security2:error] [pid 832668:tid 832877] [client 41.173.37.102:9329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUawAAAE0"]
[Mon Jul 20 06:08:47.547477 2026] [security2:error] [pid 832668:tid 832877] [client 41.173.37.102:9329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUawAAAE0"]
[Mon Jul 20 06:08:47.755058 2026] [security2:error] [pid 832668:tid 832722] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUewAAMzM"]
[Mon Jul 20 06:08:47.755258 2026] [security2:error] [pid 832668:tid 832851] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUewAAMzM"]
[Mon Jul 20 06:08:47.913998 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ups.php"] [unique_id "al4Pz2ci6KgEEltqA3DUkgAAAC4"]
[Mon Jul 20 06:08:47.914088 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:50656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ups.php"] [unique_id "al4Pz2ci6KgEEltqA3DUkgAAAC4"]
[Mon Jul 20 06:08:47.923497 2026] [security2:error] [pid 832668:tid 832818] [client 57.141.18.80:61010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DSywAAEiM"]
[Mon Jul 20 06:08:47.925308 2026] [security2:error] [pid 832668:tid 832907] [client 50.116.65.227:11510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4Pz2ci6KgEEltqA3DUlQAAAGs"]
[Mon Jul 20 06:08:47.928913 2026] [security2:error] [pid 832668:tid 832833] [client 14.225.17.146:56083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4Pzmci6KgEEltqA3DT-wAAACE"], referer: http://recruitinginsight.us/Wordpress
[Mon Jul 20 06:08:47.931800 2026] [security2:error] [pid 832668:tid 832894] [client 14.225.17.146:65280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Pzmci6KgEEltqA3DUJAAAAF4"], referer: http://ncsynchro.com/Wordpress
[Mon Jul 20 06:08:47.965393 2026] [security2:error] [pid 832668:tid 832821] [client 178.152.178.232:36093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUmAAAABU"]
[Mon Jul 20 06:08:47.969135 2026] [security2:error] [pid 832668:tid 832821] [client 178.152.178.232:36093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUmAAAABU"]
[Mon Jul 20 06:08:48.070317 2026] [security2:error] [pid 832668:tid 832868] [client 42.60.14.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4Pz2ci6KgEEltqA3DUjwAAAEQ"]
[Mon Jul 20 06:08:48.074856 2026] [security2:error] [pid 832668:tid 832835] [client 191.37.45.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DT1QAAACM"]
[Mon Jul 20 06:08:48.357040 2026] [security2:error] [pid 832668:tid 832767] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DUrgAAeGA"]
[Mon Jul 20 06:08:48.357192 2026] [security2:error] [pid 832668:tid 832920] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DUrgAAeGA"]
[Mon Jul 20 06:08:48.404323 2026] [security2:error] [pid 832668:tid 832884] [client 191.237.250.106:57045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k.php"] [unique_id "al4P0Gci6KgEEltqA3DUswAAAFQ"]
[Mon Jul 20 06:08:48.404515 2026] [security2:error] [pid 832668:tid 832884] [client 191.237.250.106:57045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k.php"] [unique_id "al4P0Gci6KgEEltqA3DUswAAAFQ"]
[Mon Jul 20 06:08:48.445634 2026] [security2:error] [pid 832668:tid 832903] [client 45.157.112.60:39947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P0Gci6KgEEltqA3DUtgAAAGc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:48.551651 2026] [security2:error] [pid 832668:tid 832862] [client 14.225.17.146:55203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4Pz2ci6KgEEltqA3DUUAAAAD4"], referer: http://lutheranphilosopher.com/Wordpress
[Mon Jul 20 06:08:48.873148 2026] [security2:error] [pid 832668:tid 832859] [client 191.237.250.106:50439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k2.php"] [unique_id "al4P0Gci6KgEEltqA3DU2QAAADs"]
[Mon Jul 20 06:08:48.873249 2026] [security2:error] [pid 832668:tid 832859] [client 191.237.250.106:50439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k2.php"] [unique_id "al4P0Gci6KgEEltqA3DU2QAAADs"]
[Mon Jul 20 06:08:48.976277 2026] [security2:error] [pid 832668:tid 832813] [client 66.249.73.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4P0Gci6KgEEltqA3DU2gAAAA0"]
[Mon Jul 20 06:08:48.995676 2026] [security2:error] [pid 832668:tid 832734] [remote 5.161.225.162:38062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DU5gAATD8"]
[Mon Jul 20 06:08:48.995856 2026] [security2:error] [pid 832668:tid 832876] [client 5.161.225.162:38062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DU5gAATD8"]
[Mon Jul 20 06:08:49.016901 2026] [security2:error] [pid 832668:tid 832872] [client 185.132.186.86:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/interactivity-api/interactivity-api-class.php"] [unique_id "al4P0Wci6KgEEltqA3DU6AAAAEg"]
[Mon Jul 20 06:08:49.033408 2026] [security2:error] [pid 832668:tid 832915] [client 57.141.18.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4P0Gci6KgEEltqA3DU1wAAAHM"]
[Mon Jul 20 06:08:49.212336 2026] [security2:error] [pid 832668:tid 832886] [client 114.119.145.225:55401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4P0Wci6KgEEltqA3DU-gAAAFY"], referer: https://www.new-menus.com/index.php?action=stats%3Bcollapse%3D201209
[Mon Jul 20 06:08:49.267036 2026] [security2:error] [pid 832668:tid 832922] [client 191.237.250.106:27205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w.php"] [unique_id "al4P0Wci6KgEEltqA3DU_QAAAHo"]
[Mon Jul 20 06:08:49.267131 2026] [security2:error] [pid 832668:tid 832922] [client 191.237.250.106:27205] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w.php"] [unique_id "al4P0Wci6KgEEltqA3DU_QAAAHo"]
[Mon Jul 20 06:08:49.411811 2026] [security2:error] [pid 832668:tid 832677] [remote 152.228.213.32:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4P0Wci6KgEEltqA3DVFwAAJAY"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 06:08:49.534740 2026] [security2:error] [pid 832668:tid 832848] [client 103.153.183.69:22040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../root/.ssh/id_rsa"] [unique_id "al4P0Wci6KgEEltqA3DVIwAAADA"], referer: https://www.bing.com/search?q=abk46k
[Mon Jul 20 06:08:49.685706 2026] [security2:error] [pid 832668:tid 832866] [client 104.194.200.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4P0Wci6KgEEltqA3DU_gAAAEI"]
[Mon Jul 20 06:08:49.809476 2026] [security2:error] [pid 832668:tid 832832] [client 191.237.250.106:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fpwch.php"] [unique_id "al4P0Wci6KgEEltqA3DVNwAAACA"]
[Mon Jul 20 06:08:49.809625 2026] [security2:error] [pid 832668:tid 832832] [client 191.237.250.106:57025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fpwch.php"] [unique_id "al4P0Wci6KgEEltqA3DVNwAAACA"]
[Mon Jul 20 06:08:49.910631 2026] [security2:error] [pid 832668:tid 832908] [client 164.100.212.184:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P0Wci6KgEEltqA3DVPgAAAGw"]
[Mon Jul 20 06:08:49.910722 2026] [security2:error] [pid 832668:tid 832908] [client 164.100.212.184:50462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P0Wci6KgEEltqA3DVPgAAAGw"]
[Mon Jul 20 06:08:50.135880 2026] [security2:error] [pid 832668:tid 832896] [client 27.96.94.195:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P0mci6KgEEltqA3DVUwAAAGA"]
[Mon Jul 20 06:08:50.135999 2026] [security2:error] [pid 832668:tid 832896] [client 27.96.94.195:37885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P0mci6KgEEltqA3DVUwAAAGA"]
[Mon Jul 20 06:08:50.159207 2026] [security2:error] [pid 832668:tid 832871] [client 57.141.18.111:52652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTsQAARzU"]
[Mon Jul 20 06:08:50.198218 2026] [security2:error] [pid 832668:tid 832849] [client 3.109.4.218:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4P0mci6KgEEltqA3DVWQAAADE"]
[Mon Jul 20 06:08:50.354177 2026] [security2:error] [pid 832668:tid 832913] [client 57.141.18.19:25698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTvAAAcR4"]
[Mon Jul 20 06:08:50.368340 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:32065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w2025.php"] [unique_id "al4P0mci6KgEEltqA3DVYgAAACg"]
[Mon Jul 20 06:08:50.368444 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:32065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w2025.php"] [unique_id "al4P0mci6KgEEltqA3DVYgAAACg"]
[Mon Jul 20 06:08:51.018857 2026] [security2:error] [pid 832668:tid 832859] [client 185.132.186.64:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/class-wp-widddget-pages.php"] [unique_id "al4P02ci6KgEEltqA3DVkQAAADs"]
[Mon Jul 20 06:08:51.218703 2026] [security2:error] [pid 832668:tid 832871] [client 43.205.139.3:48980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4P02ci6KgEEltqA3DVmgAAAEc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:08:51.477025 2026] [security2:error] [pid 832668:tid 832918] [client 191.237.250.106:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/FWAZ.php"] [unique_id "al4P02ci6KgEEltqA3DVvAAAAHY"]
[Mon Jul 20 06:08:51.477109 2026] [security2:error] [pid 832668:tid 832918] [client 191.237.250.106:50645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/FWAZ.php"] [unique_id "al4P02ci6KgEEltqA3DVvAAAAHY"]
[Mon Jul 20 06:08:51.639434 2026] [security2:error] [pid 832668:tid 832827] [client 103.95.123.246:18239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DVxwAAABs"]
[Mon Jul 20 06:08:51.639555 2026] [security2:error] [pid 832668:tid 832827] [client 103.95.123.246:18239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DVxwAAABs"]
[Mon Jul 20 06:08:51.945205 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:21410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/qterm.php"] [unique_id "al4P02ci6KgEEltqA3DV2gAAAF8"]
[Mon Jul 20 06:08:51.945312 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:21410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/qterm.php"] [unique_id "al4P02ci6KgEEltqA3DV2gAAAF8"]
[Mon Jul 20 06:08:52.004446 2026] [security2:error] [pid 832668:tid 832756] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DV3QAANlU"]
[Mon Jul 20 06:08:52.004682 2026] [security2:error] [pid 832668:tid 832854] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DV3QAANlU"]
[Mon Jul 20 06:08:52.125891 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.65:42488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pz2ci6KgEEltqA3DUaAAATjs"]
[Mon Jul 20 06:08:52.537431 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/blurbs.php"] [unique_id "al4P1Gci6KgEEltqA3DWCQAAAEI"]
[Mon Jul 20 06:08:52.537523 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:11248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/blurbs.php"] [unique_id "al4P1Gci6KgEEltqA3DWCQAAAEI"]
[Mon Jul 20 06:08:52.612204 2026] [security2:error] [pid 832668:tid 832819] [client 57.141.18.111:52658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P0Gci6KgEEltqA3DUmgAAE24"]
[Mon Jul 20 06:08:52.753905 2026] [security2:error] [pid 832668:tid 832900] [client 104.234.53.74:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4P1Gci6KgEEltqA3DWFwAAAGQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:52.890491 2026] [security2:error] [pid 832668:tid 832735] [remote 57.141.18.16:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4339893"] [unique_id "al4P1Gci6KgEEltqA3DWKAAAMEA"]
[Mon Jul 20 06:08:52.982380 2026] [security2:error] [pid 832668:tid 832831] [client 57.141.18.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4P1Gci6KgEEltqA3DWJwAAAB8"]
[Mon Jul 20 06:08:53.001567 2026] [security2:error] [pid 832668:tid 832854] [client 185.132.186.56:29189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al4P1Wci6KgEEltqA3DWMQAAADY"]
[Mon Jul 20 06:08:53.122755 2026] [security2:error] [pid 832668:tid 832806] [client 193.19.109.220:40817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "truthmedicalaesthetics.com"] [uri "/wp-login.php"] [unique_id "al4P1Wci6KgEEltqA3DWOgAAAAY"]
[Mon Jul 20 06:08:53.182956 2026] [security2:error] [pid 832668:tid 832868] [client 86.98.90.58:7867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P1Wci6KgEEltqA3DWRQAAAEQ"]
[Mon Jul 20 06:08:53.183148 2026] [security2:error] [pid 832668:tid 832868] [client 86.98.90.58:7867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P1Wci6KgEEltqA3DWRQAAAEQ"]
[Mon Jul 20 06:08:53.373359 2026] [security2:error] [pid 832668:tid 832902] [client 191.237.250.106:30130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/v543.php"] [unique_id "al4P1Wci6KgEEltqA3DWTwAAAGY"]
[Mon Jul 20 06:08:53.373457 2026] [security2:error] [pid 832668:tid 832902] [client 191.237.250.106:30130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/v543.php"] [unique_id "al4P1Wci6KgEEltqA3DWTwAAAGY"]
[Mon Jul 20 06:08:53.600677 2026] [security2:error] [pid 832668:tid 832808] [client 142.250.32.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "memarion.com"] [uri "/index.php"] [unique_id "al4P0Wci6KgEEltqA3DVJgAACEE"]
[Mon Jul 20 06:08:53.736288 2026] [core:error] [pid 832668:tid 832805] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:53.736311 2026] [core:error] [pid 832668:tid 832805] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:54.269798 2026] [security2:error] [pid 832668:tid 832817] [client 193.19.109.219:30363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4P1mci6KgEEltqA3DWkgAAABE"]
[Mon Jul 20 06:08:54.317830 2026] [security2:error] [pid 832668:tid 832896] [client 50.116.65.227:55158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4P1mci6KgEEltqA3DWmQAAAGA"]
[Mon Jul 20 06:08:54.327942 2026] [security2:error] [pid 832668:tid 832858] [client 50.116.65.227:55164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4P1mci6KgEEltqA3DWmwAAADo"]
[Mon Jul 20 06:08:54.455054 2026] [security2:error] [pid 832668:tid 832831] [client 38.20.252.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4P1mci6KgEEltqA3DWjAAAHwA"]
[Mon Jul 20 06:08:54.708126 2026] [security2:error] [pid 832668:tid 832920] [client 14.225.17.146:53814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4P1Gci6KgEEltqA3DWGAAAAHg"], referer: http://www.justinagrayman.com/Wordpress
[Mon Jul 20 06:08:55.080838 2026] [security2:error] [pid 832668:tid 832887] [client 103.77.203.233:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW1gAAAFc"]
[Mon Jul 20 06:08:55.080963 2026] [security2:error] [pid 832668:tid 832887] [client 103.77.203.233:58034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW1gAAAFc"]
[Mon Jul 20 06:08:55.142991 2026] [security2:error] [pid 832668:tid 832901] [client 38.68.180.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4P1mci6KgEEltqA3DW0AAAZRc"]
[Mon Jul 20 06:08:55.187409 2026] [security2:error] [pid 832668:tid 832906] [client 103.141.108.143:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW4gAAAGo"]
[Mon Jul 20 06:08:55.187798 2026] [security2:error] [pid 832668:tid 832906] [client 103.141.108.143:50788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW4gAAAGo"]
[Mon Jul 20 06:08:55.486743 2026] [security2:error] [pid 832668:tid 832809] [client 191.237.250.106:29315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w3lls.php"] [unique_id "al4P12ci6KgEEltqA3DW-QAAAAk"]
[Mon Jul 20 06:08:55.486844 2026] [security2:error] [pid 832668:tid 832809] [client 191.237.250.106:29315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w3lls.php"] [unique_id "al4P12ci6KgEEltqA3DW-QAAAAk"]
[Mon Jul 20 06:08:55.536777 2026] [security2:error] [pid 832668:tid 832902] [client 158.173.89.95:58121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P12ci6KgEEltqA3DXAAAAAGY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:55.643532 2026] [security2:error] [pid 832668:tid 832765] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DXCAAAXF4"]
[Mon Jul 20 06:08:55.643706 2026] [security2:error] [pid 832668:tid 832892] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DXCAAAXF4"]
[Mon Jul 20 06:08:55.797621 2026] [core:error] [pid 832668:tid 832822] [client 14.225.17.146:57815] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wordpress
[Mon Jul 20 06:08:55.797647 2026] [core:error] [pid 832668:tid 832822] [client 14.225.17.146:57815] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wordpress
[Mon Jul 20 06:08:56.020874 2026] [security2:error] [pid 832668:tid 832849] [client 106.192.104.4:54637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXIgAAADE"]
[Mon Jul 20 06:08:56.020981 2026] [security2:error] [pid 832668:tid 832849] [client 106.192.104.4:54637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXIgAAADE"]
[Mon Jul 20 06:08:56.065041 2026] [security2:error] [pid 832668:tid 832924] [client 103.162.57.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4P1Wci6KgEEltqA3DWSQAAAHw"]
[Mon Jul 20 06:08:56.329764 2026] [security2:error] [pid 832668:tid 832923] [client 43.205.139.3:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4P2Gci6KgEEltqA3DXLQAAAHs"]
[Mon Jul 20 06:08:56.348376 2026] [security2:error] [pid 832668:tid 832840] [client 115.246.21.170:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXPgAAACg"]
[Mon Jul 20 06:08:56.348481 2026] [security2:error] [pid 832668:tid 832840] [client 115.246.21.170:65466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXPgAAACg"]
[Mon Jul 20 06:08:56.428970 2026] [security2:error] [pid 832668:tid 832803] [client 185.132.186.87:28897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/colors.min.php"] [unique_id "al4P2Gci6KgEEltqA3DXSQAAAAM"]
[Mon Jul 20 06:08:56.626146 2026] [security2:error] [pid 832668:tid 832907] [client 112.213.160.112:2971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXWwAAAGs"]
[Mon Jul 20 06:08:56.626264 2026] [security2:error] [pid 832668:tid 832907] [client 112.213.160.112:2971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXWwAAAGs"]
[Mon Jul 20 06:08:56.820160 2026] [proxy:error] [pid 832668:tid 832876] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.820200 2026] [proxy_http:error] [pid 832668:tid 832876] [client 94.154.43.187:53178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:56.820896 2026] [proxy:error] [pid 832668:tid 832876] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.820930 2026] [proxy_http:error] [pid 832668:tid 832876] [client 94.154.43.187:53178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:56.831879 2026] [proxy:error] [pid 832668:tid 832833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.831938 2026] [proxy_http:error] [pid 832668:tid 832833] [client 94.154.43.177:55514] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:56.832499 2026] [proxy:error] [pid 832668:tid 832833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.832536 2026] [proxy_http:error] [pid 832668:tid 832833] [client 94.154.43.177:55514] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:57.132982 2026] [security2:error] [pid 832668:tid 832825] [client 14.225.17.146:57452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4P12ci6KgEEltqA3DW_gAAABk"], referer: http://olearyplumbingllc.com/Wordpress
[Mon Jul 20 06:08:57.173462 2026] [security2:error] [pid 832668:tid 832836] [client 57.141.18.22:42772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P1Gci6KgEEltqA3DWLAAAJA4"]
[Mon Jul 20 06:08:57.261210 2026] [security2:error] [pid 832668:tid 832854] [client 45.116.69.230:63148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXmgAAADY"]
[Mon Jul 20 06:08:57.261311 2026] [security2:error] [pid 832668:tid 832854] [client 45.116.69.230:63148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXmgAAADY"]
[Mon Jul 20 06:08:57.313150 2026] [security2:error] [pid 832668:tid 832801] [client 104.234.53.85:26069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4P2Wci6KgEEltqA3DXnQAAAAE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:57.626576 2026] [security2:error] [pid 832668:tid 832872] [client 191.237.250.106:11234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-ws68.php"] [unique_id "al4P2Wci6KgEEltqA3DXuAAAAEg"]
[Mon Jul 20 06:08:57.626683 2026] [security2:error] [pid 832668:tid 832872] [client 191.237.250.106:11234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-ws68.php"] [unique_id "al4P2Wci6KgEEltqA3DXuAAAAEg"]
[Mon Jul 20 06:08:57.749713 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXyAAAAA0"]
[Mon Jul 20 06:08:57.749837 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:53459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXyAAAAA0"]
[Mon Jul 20 06:08:57.866419 2026] [security2:error] [pid 832668:tid 832909] [client 103.153.183.69:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..%ef%bc%8fvar/www/html/config.php"] [unique_id "al4P2Wci6KgEEltqA3DXygAAAG0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:08:58.124968 2026] [core:error] [pid 832668:tid 832879] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.124990 2026] [core:error] [pid 832668:tid 832879] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.168026 2026] [security2:error] [pid 832668:tid 832911] [client 41.173.37.102:9769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DX5AAAAG8"]
[Mon Jul 20 06:08:58.168127 2026] [security2:error] [pid 832668:tid 832911] [client 41.173.37.102:9769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DX5AAAAG8"]
[Mon Jul 20 06:08:58.286612 2026] [core:error] [pid 832668:tid 832863] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.286643 2026] [core:error] [pid 832668:tid 832863] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.287462 2026] [core:error] [pid 832668:tid 832892] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.287480 2026] [core:error] [pid 832668:tid 832892] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.406875 2026] [security2:error] [pid 832668:tid 832896] [client 185.132.186.81:24127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control-repository.php"] [unique_id "al4P2mci6KgEEltqA3DYBgAAAGA"]
[Mon Jul 20 06:08:58.441487 2026] [security2:error] [pid 832668:tid 832797] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYCwAAB34"]
[Mon Jul 20 06:08:58.441744 2026] [security2:error] [pid 832668:tid 832807] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYCwAAB34"]
[Mon Jul 20 06:08:58.475072 2026] [security2:error] [pid 832668:tid 832872] [client 178.152.178.232:37689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYDQAAAEg"]
[Mon Jul 20 06:08:58.475234 2026] [security2:error] [pid 832668:tid 832872] [client 178.152.178.232:37689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYDQAAAEg"]
[Mon Jul 20 06:08:58.503247 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:58242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/xyn.php"] [unique_id "al4P2mci6KgEEltqA3DYDgAAADI"]
[Mon Jul 20 06:08:58.503336 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:58242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/xyn.php"] [unique_id "al4P2mci6KgEEltqA3DYDgAAADI"]
[Mon Jul 20 06:08:58.649195 2026] [security2:error] [pid 832668:tid 832855] [client 193.19.109.230:45465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "steadfastwolfproductions.com"] [uri "/wp-login.php"] [unique_id "al4P2mci6KgEEltqA3DYFQAAADc"]
[Mon Jul 20 06:08:58.856286 2026] [security2:error] [pid 832668:tid 832785] [remote 192.241.143.148:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYIQAAaXI"]
[Mon Jul 20 06:08:58.856447 2026] [security2:error] [pid 832668:tid 832905] [client 192.241.143.148:54886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYIQAAaXI"]
[Mon Jul 20 06:08:58.972014 2026] [security2:error] [pid 832668:tid 832770] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYLwAAPWM"]
[Mon Jul 20 06:08:58.972197 2026] [security2:error] [pid 832668:tid 832861] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYLwAAPWM"]
[Mon Jul 20 06:08:58.979866 2026] [security2:error] [pid 832668:tid 832872] [client 14.224.227.113:61767] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4P2mci6KgEEltqA3DYMAAAAEg"]
[Mon Jul 20 06:08:59.235813 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:57397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4P22ci6KgEEltqA3DYPAAAABw"], referer: http://musichaven.info/Wordpress
[Mon Jul 20 06:08:59.871393 2026] [security2:error] [pid 832668:tid 832835] [client 103.153.183.69:52892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../etc/nginx/nginx.conf"] [unique_id "al4P22ci6KgEEltqA3DYdwAAACM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:09:00.008122 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:21419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/green3.php"] [unique_id "al4P3Gci6KgEEltqA3DYgwAAAEI"]
[Mon Jul 20 06:09:00.008232 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:21419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/green3.php"] [unique_id "al4P3Gci6KgEEltqA3DYgwAAAEI"]
[Mon Jul 20 06:09:00.021380 2026] [security2:error] [pid 832668:tid 832872] [client 103.153.183.69:52892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../etc/apache2/apache2.conf"] [unique_id "al4P3Gci6KgEEltqA3DYhQAAAEg"], referer: https://www.google.com/
[Mon Jul 20 06:09:00.159024 2026] [security2:error] [pid 832668:tid 832813] [client 193.19.109.243:33125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYjQAAAA0"]
[Mon Jul 20 06:09:00.178567 2026] [security2:error] [pid 832668:tid 832824] [client 193.19.109.247:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYkAAAABg"]
[Mon Jul 20 06:09:00.358707 2026] [security2:error] [pid 832668:tid 832832] [client 14.225.17.146:57709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4P3Gci6KgEEltqA3DYlQAAACA"], referer: https://musichaven.info/Wordpress
[Mon Jul 20 06:09:00.434033 2026] [security2:error] [pid 832668:tid 832747] [remote 103.161.172.221:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYnwAANUw"]
[Mon Jul 20 06:09:00.539378 2026] [security2:error] [pid 832668:tid 832890] [client 164.100.212.184:58342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Gci6KgEEltqA3DYqAAAAFo"]
[Mon Jul 20 06:09:00.539530 2026] [security2:error] [pid 832668:tid 832890] [client 164.100.212.184:58342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Gci6KgEEltqA3DYqAAAAFo"]
[Mon Jul 20 06:09:00.631947 2026] [access_compat:error] [pid 832668:tid 832807] [client 112.90.2.210:52179] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:09:00.806120 2026] [security2:error] [pid 832668:tid 832833] [client 14.225.17.146:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4P22ci6KgEEltqA3DYNgAAACE"], referer: http://bigwormfishing.com/Wordpress
[Mon Jul 20 06:09:00.819499 2026] [security2:error] [pid 832668:tid 832719] [remote 103.161.172.221:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYxQAADzA"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:09:00.955950 2026] [security2:error] [pid 832668:tid 832902] [client 185.132.186.75:36285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-react-refresh-runtime.min-soap.php"] [unique_id "al4P3Gci6KgEEltqA3DY0wAAAGY"]
[Mon Jul 20 06:09:01.569599 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:29318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ccc.php"] [unique_id "al4P3Wci6KgEEltqA3DY_QAAAC4"]
[Mon Jul 20 06:09:01.569759 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:29318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ccc.php"] [unique_id "al4P3Wci6KgEEltqA3DY_QAAAC4"]
[Mon Jul 20 06:09:01.703281 2026] [security2:error] [pid 832668:tid 832812] [client 27.96.94.195:38041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Wci6KgEEltqA3DZCgAAAAw"]
[Mon Jul 20 06:09:01.703414 2026] [security2:error] [pid 832668:tid 832812] [client 27.96.94.195:38041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Wci6KgEEltqA3DZCgAAAAw"]
[Mon Jul 20 06:09:01.774633 2026] [security2:error] [pid 832668:tid 832702] [remote 57.141.18.38:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3966302"] [unique_id "al4P3Wci6KgEEltqA3DZDAAAIR8"]
[Mon Jul 20 06:09:01.801985 2026] [security2:error] [pid 832668:tid 832914] [client 14.225.17.146:55884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4P3Wci6KgEEltqA3DZCAAAAHI"], referer: https://bigwormfishing.com/Wordpress
[Mon Jul 20 06:09:01.885220 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.101:34934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2Wci6KgEEltqA3DXngAAZGE"]
[Mon Jul 20 06:09:02.078178 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/get.php"] [unique_id "al4P3mci6KgEEltqA3DZKwAAAAg"]
[Mon Jul 20 06:09:02.078312 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:19406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/get.php"] [unique_id "al4P3mci6KgEEltqA3DZKwAAAAg"]
[Mon Jul 20 06:09:02.482727 2026] [security2:error] [pid 832668:tid 832871] [client 191.237.250.106:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/images.php"] [unique_id "al4P3mci6KgEEltqA3DZYwAAAEc"]
[Mon Jul 20 06:09:02.482878 2026] [security2:error] [pid 832668:tid 832871] [client 191.237.250.106:62286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/images.php"] [unique_id "al4P3mci6KgEEltqA3DZYwAAAEc"]
[Mon Jul 20 06:09:02.499999 2026] [security2:error] [pid 832668:tid 832866] [client 103.95.123.246:18805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZQAAAEI"]
[Mon Jul 20 06:09:02.500129 2026] [security2:error] [pid 832668:tid 832866] [client 103.95.123.246:18805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZQAAAEI"]
[Mon Jul 20 06:09:02.511404 2026] [security2:error] [pid 832668:tid 832706] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZwAAISM"]
[Mon Jul 20 06:09:02.511559 2026] [security2:error] [pid 832668:tid 832833] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZwAAISM"]
[Mon Jul 20 06:09:02.590855 2026] [security2:error] [pid 832668:tid 832764] [remote 188.40.28.4:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZbQAAAV0"]
[Mon Jul 20 06:09:02.591127 2026] [security2:error] [pid 832668:tid 832801] [client 188.40.28.4:33822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZbQAAAV0"]
[Mon Jul 20 06:09:02.636137 2026] [security2:error] [pid 832668:tid 832809] [client 57.141.18.0:57614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2Wci6KgEEltqA3DX2QAACSQ"]
[Mon Jul 20 06:09:02.819241 2026] [access_compat:error] [pid 832668:tid 832922] [client 183.47.107.119:47159] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:09:02.945820 2026] [security2:error] [pid 832668:tid 832846] [client 66.249.66.200:64747] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "50.116.64.39"] [uri "/robots.txt"] [unique_id "al4P3mci6KgEEltqA3DZjgAAAC4"]
[Mon Jul 20 06:09:02.993154 2026] [security2:error] [pid 832668:tid 832924] [client 185.132.186.73:56161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/module.audio-video.riff-set.php"] [unique_id "al4P3mci6KgEEltqA3DZkAAAAHw"]
[Mon Jul 20 06:09:03.223999 2026] [security2:error] [pid 832668:tid 832903] [client 57.141.18.22:38052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2mci6KgEEltqA3DYDwAAZzc"]
[Mon Jul 20 06:09:03.340306 2026] [security2:error] [pid 832668:tid 832913] [client 193.37.33.232:21819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4P32ci6KgEEltqA3DZsAAAAHE"]
[Mon Jul 20 06:09:03.496378 2026] [security2:error] [pid 832668:tid 832911] [client 104.234.53.93:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4P32ci6KgEEltqA3DZvgAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:03.581683 2026] [security2:error] [pid 832668:tid 832846] [client 50.116.65.227:16836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZtwAAAC4"]
[Mon Jul 20 06:09:03.615456 2026] [security2:error] [pid 832668:tid 832834] [client 57.141.18.19:60852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2mci6KgEEltqA3DYMQAAIi0"]
[Mon Jul 20 06:09:03.627119 2026] [security2:error] [pid 832668:tid 832854] [client 191.237.250.106:50465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/alls.php"] [unique_id "al4P32ci6KgEEltqA3DZzgAAADY"]
[Mon Jul 20 06:09:03.627287 2026] [security2:error] [pid 832668:tid 832854] [client 191.237.250.106:50465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/alls.php"] [unique_id "al4P32ci6KgEEltqA3DZzgAAADY"]
[Mon Jul 20 06:09:03.671782 2026] [security2:error] [pid 832668:tid 832808] [client 14.225.17.146:55713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZxAAAAAg"]
[Mon Jul 20 06:09:03.740002 2026] [proxy:error] [pid 832668:tid 832892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:03.740074 2026] [proxy_http:error] [pid 832668:tid 832892] [client 20.74.45.95:56323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:03.740930 2026] [proxy:error] [pid 832668:tid 832892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:03.740980 2026] [proxy_http:error] [pid 832668:tid 832892] [client 20.74.45.95:56323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:03.770943 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:52574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZ1AAAAFQ"], referer: http://claysharecon.com/Wordpress
[Mon Jul 20 06:09:03.779577 2026] [security2:error] [pid 832668:tid 832920] [client 50.116.65.227:16838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZywAAAHg"]
[Mon Jul 20 06:09:04.153735 2026] [security2:error] [pid 832668:tid 832820] [client 57.141.18.49:36126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P22ci6KgEEltqA3DYZwAAFBo"]
[Mon Jul 20 06:09:04.362064 2026] [security2:error] [pid 832668:tid 832687] [remote 188.166.241.141:57774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4P4Gci6KgEEltqA3DaBQAAThA"]
[Mon Jul 20 06:09:04.411816 2026] [security2:error] [pid 832668:tid 832918] [client 14.225.17.146:55174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4P3Wci6KgEEltqA3DZFwAAAHY"], referer: http://bruceledewitz.com/Wordpress
[Mon Jul 20 06:09:04.777396 2026] [security2:error] [pid 832668:tid 832870] [client 57.141.18.21:35170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P3Gci6KgEEltqA3DYowAARns"]
[Mon Jul 20 06:09:04.850437 2026] [security2:error] [pid 832668:tid 832720] [remote 188.166.241.141:57774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4P4Gci6KgEEltqA3DaLAAATTE"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:09:05.236419 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:8692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaVQAAABg"]
[Mon Jul 20 06:09:05.236531 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:8692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaVQAAABg"]
[Mon Jul 20 06:09:05.505176 2026] [security2:error] [pid 832668:tid 832858] [client 191.237.250.106:50653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/coffexium.php"] [unique_id "al4P4Wci6KgEEltqA3DaaAAAADo"]
[Mon Jul 20 06:09:05.505285 2026] [security2:error] [pid 832668:tid 832858] [client 191.237.250.106:50653] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/coffexium.php"] [unique_id "al4P4Wci6KgEEltqA3DaaAAAADo"]
[Mon Jul 20 06:09:05.551212 2026] [security2:error] [pid 832668:tid 832867] [client 103.77.203.233:58097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DabQAAAEM"]
[Mon Jul 20 06:09:05.560731 2026] [security2:error] [pid 832668:tid 832867] [client 103.77.203.233:58097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DabQAAAEM"]
[Mon Jul 20 06:09:05.671860 2026] [security2:error] [pid 832668:tid 832758] [remote 5.56.58.49:48492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P4Wci6KgEEltqA3DacQAAPVc"]
[Mon Jul 20 06:09:05.834209 2026] [security2:error] [pid 832668:tid 832808] [client 103.141.108.143:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaggAAAAg"]
[Mon Jul 20 06:09:05.834313 2026] [security2:error] [pid 832668:tid 832808] [client 103.141.108.143:51240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaggAAAAg"]
[Mon Jul 20 06:09:05.889341 2026] [security2:error] [pid 832668:tid 832703] [remote 5.56.58.49:48492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P4Wci6KgEEltqA3DahgAAIiA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:06.091944 2026] [security2:error] [pid 832668:tid 832805] [client 57.141.18.113:44506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P3Wci6KgEEltqA3DZDgAABXE"]
[Mon Jul 20 06:09:06.161451 2026] [security2:error] [pid 832668:tid 832728] [remote 152.228.213.32:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3DanAAAcjk"]
[Mon Jul 20 06:09:06.252034 2026] [fcgid:warn] [pid 832668:tid 832909] (70014)End of file found: [client 185.247.137.38:35479] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:06.264823 2026] [security2:error] [pid 832668:tid 832846] [client 50.116.65.227:59418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4P4mci6KgEEltqA3DaqQAAAC4"]
[Mon Jul 20 06:09:06.276634 2026] [security2:error] [pid 832668:tid 832872] [client 50.116.65.227:16882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4P4mci6KgEEltqA3DaqwAAABw"]
[Mon Jul 20 06:09:06.316594 2026] [security2:error] [pid 832668:tid 832706] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3DasQAALCM"]
[Mon Jul 20 06:09:06.316776 2026] [security2:error] [pid 832668:tid 832844] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3DasQAALCM"]
[Mon Jul 20 06:09:06.461467 2026] [security2:error] [pid 832668:tid 832764] [remote 152.228.213.32:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3DavAAADV0"], referer: https://mail.gpm.vvo.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:06.562534 2026] [security2:error] [pid 832668:tid 832825] [client 104.234.53.70:33109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4P4mci6KgEEltqA3DaxwAAABk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:06.638345 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.98:40451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/tinymce/utils/license.php"] [unique_id "al4P4mci6KgEEltqA3DazAAAAAI"]
[Mon Jul 20 06:09:06.806755 2026] [security2:error] [pid 832668:tid 832675] [remote 20.173.88.122:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3Da4QAADAQ"]
[Mon Jul 20 06:09:06.833495 2026] [security2:error] [pid 832668:tid 832741] [remote 194.164.192.228:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3Da5QAAF0Y"]
[Mon Jul 20 06:09:06.833714 2026] [security2:error] [pid 832668:tid 832808] [client 115.246.21.170:18242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3Da5AAAAAg"]
[Mon Jul 20 06:09:06.833909 2026] [security2:error] [pid 832668:tid 832808] [client 115.246.21.170:18242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3Da5AAAAAg"]
[Mon Jul 20 06:09:06.872389 2026] [fcgid:warn] [pid 832668:tid 832892] (70014)End of file found: [client 66.132.195.123:9602] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:06.916510 2026] [security2:error] [pid 832668:tid 832853] [client 57.141.18.29:45828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P3mci6KgEEltqA3DZdAAANW8"]
[Mon Jul 20 06:09:06.917450 2026] [security2:error] [pid 832668:tid 832763] [remote 162.19.86.63:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3Da6AAAPlw"]
[Mon Jul 20 06:09:07.027140 2026] [security2:error] [pid 832668:tid 832740] [remote 194.164.192.228:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3Da8wAAXkU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:07.093341 2026] [security2:error] [pid 832668:tid 832817] [client 14.225.17.146:58816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3Da7wAAABE"], referer: http://omrobuildingcenter.com/Wordpress
[Mon Jul 20 06:09:07.136422 2026] [security2:error] [pid 832668:tid 832796] [remote 20.173.88.122:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3Da-wAACn0"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:09:07.150739 2026] [security2:error] [pid 832668:tid 832860] [client 94.154.43.186:52224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "holistichealthmassagenz.com"] [uri "/.env"] [unique_id "al4P42ci6KgEEltqA3Da_AAAADw"]
[Mon Jul 20 06:09:07.157450 2026] [security2:error] [pid 832668:tid 832708] [remote 162.19.86.63:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3Da_QAANyU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:09:07.159311 2026] [proxy:error] [pid 832668:tid 832852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:07.159342 2026] [proxy_http:error] [pid 832668:tid 832852] [client 94.154.43.185:28640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:07.159782 2026] [proxy:error] [pid 832668:tid 832852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:07.159802 2026] [proxy_http:error] [pid 832668:tid 832852] [client 94.154.43.185:28640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:07.189783 2026] [security2:error] [pid 832668:tid 832868] [client 106.192.104.4:55129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbAgAAAEQ"]
[Mon Jul 20 06:09:07.189884 2026] [security2:error] [pid 832668:tid 832868] [client 106.192.104.4:55129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbAgAAAEQ"]
[Mon Jul 20 06:09:07.248744 2026] [security2:error] [pid 832668:tid 832781] [remote 57.141.18.94:46856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2968118"] [unique_id "al4P42ci6KgEEltqA3DbBwAAPW4"]
[Mon Jul 20 06:09:07.328153 2026] [security2:error] [pid 832668:tid 832827] [client 112.213.160.112:30945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbEAAAABs"]
[Mon Jul 20 06:09:07.328316 2026] [security2:error] [pid 832668:tid 832827] [client 112.213.160.112:30945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbEAAAABs"]
[Mon Jul 20 06:09:07.373372 2026] [security2:error] [pid 832668:tid 832906] [client 14.225.17.146:65435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4P42ci6KgEEltqA3Da-gAAAGo"], referer: http://latiendadejorge.com.gt/Wordpress
[Mon Jul 20 06:09:07.407006 2026] [security2:error] [pid 832668:tid 832806] [client 104.234.53.52:23179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4P42ci6KgEEltqA3DbDAAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:07.684574 2026] [security2:error] [pid 832668:tid 832850] [client 14.225.17.146:54609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3DaqAAAADI"], referer: http://mollycahill.com/Wordpress
[Mon Jul 20 06:09:07.958659 2026] [security2:error] [pid 832668:tid 832903] [client 45.116.69.230:63626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbQgAAAGc"]
[Mon Jul 20 06:09:07.958768 2026] [security2:error] [pid 832668:tid 832903] [client 45.116.69.230:63626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbQgAAAGc"]
[Mon Jul 20 06:09:08.008213 2026] [security2:error] [pid 832668:tid 832904] [client 104.234.53.52:23179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3DbQQAAAGg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:08.327794 2026] [security2:error] [pid 832668:tid 832801] [client 57.141.18.108:39586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4Gci6KgEEltqA3DZ7wAAAQo"]
[Mon Jul 20 06:09:08.382174 2026] [security2:error] [pid 832668:tid 832896] [client 57.141.18.31:55664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4Gci6KgEEltqA3DZ8wAAYA8"]
[Mon Jul 20 06:09:08.678763 2026] [security2:error] [pid 832668:tid 832923] [client 181.224.94.124:14435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbfgAAAHs"]
[Mon Jul 20 06:09:08.678922 2026] [security2:error] [pid 832668:tid 832923] [client 181.224.94.124:14435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbfgAAAHs"]
[Mon Jul 20 06:09:08.745643 2026] [security2:error] [pid 832668:tid 832820] [client 41.173.37.102:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbggAAABQ"]
[Mon Jul 20 06:09:08.745789 2026] [security2:error] [pid 832668:tid 832820] [client 41.173.37.102:10209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbggAAABQ"]
[Mon Jul 20 06:09:08.998478 2026] [security2:error] [pid 832668:tid 832809] [client 178.152.178.232:35905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbkwAAAAk"]
[Mon Jul 20 06:09:08.998597 2026] [security2:error] [pid 832668:tid 832809] [client 178.152.178.232:35905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbkwAAAAk"]
[Mon Jul 20 06:09:09.049195 2026] [security2:error] [pid 832668:tid 832895] [client 14.225.17.146:64888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P5Gci6KgEEltqA3DbiwAAAF8"], referer: http://sesamegreenbeans.com/Wordpress
[Mon Jul 20 06:09:09.187759 2026] [security2:error] [pid 832668:tid 832742] [remote 217.61.143.92:38510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3DbmgAAIkc"]
[Mon Jul 20 06:09:09.193947 2026] [security2:error] [pid 832668:tid 832755] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3DbmwAAOFQ"]
[Mon Jul 20 06:09:09.194091 2026] [security2:error] [pid 832668:tid 832856] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3DbmwAAOFQ"]
[Mon Jul 20 06:09:09.216203 2026] [security2:error] [pid 832668:tid 832797] [remote 124.55.178.99:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3DbngAAan4"]
[Mon Jul 20 06:09:09.555897 2026] [security2:error] [pid 832668:tid 832784] [remote 217.61.143.92:38510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3DbzQAAcHE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:09:09.606443 2026] [security2:error] [pid 832668:tid 832750] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3Db1QAABE8"]
[Mon Jul 20 06:09:09.606585 2026] [security2:error] [pid 832668:tid 832804] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3Db1QAABE8"]
[Mon Jul 20 06:09:09.684393 2026] [security2:error] [pid 832668:tid 832728] [remote 124.55.178.99:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3Db2gAAejk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:09.685115 2026] [security2:error] [pid 832668:tid 832878] [client 185.132.186.97:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/options.php"] [unique_id "al4P5Wci6KgEEltqA3Db2wAAAE4"]
[Mon Jul 20 06:09:10.057251 2026] [security2:error] [pid 832668:tid 832910] [client 66.249.64.6:61397] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "umatha.art"] [uri "/robots.txt"] [unique_id "al4P5mci6KgEEltqA3Db_wAAAG4"]
[Mon Jul 20 06:09:10.110489 2026] [security2:error] [pid 832668:tid 832848] [client 14.225.17.146:58633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P5Wci6KgEEltqA3Db8wAAADA"], referer: https://sesamegreenbeans.com/Wordpress
[Mon Jul 20 06:09:10.604070 2026] [security2:error] [pid 832668:tid 832890] [client 14.225.17.146:58598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4P5mci6KgEEltqA3DcFgAAAFo"], referer: http://myspineworld.com/Wordpress
[Mon Jul 20 06:09:10.635176 2026] [security2:error] [pid 832668:tid 832911] [client 57.141.18.108:39600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3DatAAAb0M"]
[Mon Jul 20 06:09:10.832508 2026] [security2:error] [pid 832668:tid 832833] [client 57.141.18.106:36536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3DaxAAAIT0"]
[Mon Jul 20 06:09:11.173205 2026] [security2:error] [pid 832668:tid 832919] [client 164.100.212.184:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P52ci6KgEEltqA3DcUwAAAHc"]
[Mon Jul 20 06:09:11.173310 2026] [security2:error] [pid 832668:tid 832919] [client 164.100.212.184:53455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P52ci6KgEEltqA3DcUwAAAHc"]
[Mon Jul 20 06:09:11.354778 2026] [security2:error] [pid 832668:tid 832922] [client 50.116.65.227:58842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2025/02/IMG_9124.jpeg"] [unique_id "al4P52ci6KgEEltqA3DcYwAAADU"]
[Mon Jul 20 06:09:11.546085 2026] [security2:error] [pid 832668:tid 832920] [client 57.141.18.53:65386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P42ci6KgEEltqA3DbEwAAeCc"]
[Mon Jul 20 06:09:11.561023 2026] [security2:error] [pid 832668:tid 832905] [client 193.19.109.240:21861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4P52ci6KgEEltqA3DceQAAAGk"]
[Mon Jul 20 06:09:11.573797 2026] [security2:error] [pid 832668:tid 832916] [client 14.225.17.146:57349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DcbQAAAHQ"], referer: https://myspineworld.com/Wordpress
[Mon Jul 20 06:09:11.591184 2026] [security2:error] [pid 832668:tid 832891] [client 193.19.109.244:49669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4P52ci6KgEEltqA3DcegAAAFs"]
[Mon Jul 20 06:09:11.872684 2026] [security2:error] [pid 832668:tid 832863] [client 85.254.64.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DcjwAAAD8"]
[Mon Jul 20 06:09:12.346658 2026] [security2:error] [pid 832668:tid 832868] [client 104.234.53.86:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4P6Gci6KgEEltqA3DcrwAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:12.542062 2026] [security2:error] [pid 832668:tid 832853] [client 98.159.234.160:50671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P6Gci6KgEEltqA3DcyAAAADU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:12.662085 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.101:27197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/wp-load.php"] [unique_id "al4P6Gci6KgEEltqA3DcygAAAAI"]
[Mon Jul 20 06:09:12.820532 2026] [security2:error] [pid 832668:tid 832907] [client 57.141.18.83:55766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P5Gci6KgEEltqA3DbdQAAazQ"]
[Mon Jul 20 06:09:12.873582 2026] [security2:error] [pid 832668:tid 832865] [client 57.141.18.60:65448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P5Gci6KgEEltqA3DbgQAAQQ4"]
[Mon Jul 20 06:09:13.011383 2026] [security2:error] [pid 832668:tid 832704] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3Dc5AAAcCE"]
[Mon Jul 20 06:09:13.011518 2026] [security2:error] [pid 832668:tid 832912] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3Dc5AAAcCE"]
[Mon Jul 20 06:09:13.174398 2026] [security2:error] [pid 832668:tid 832840] [client 57.141.18.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc5QAAACg"]
[Mon Jul 20 06:09:13.200314 2026] [security2:error] [pid 832668:tid 832875] [client 14.225.17.146:65508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc6wAAAEs"], referer: http://friendlyspreadsheet.com/Wordpress
[Mon Jul 20 06:09:13.555662 2026] [core:error] [pid 832668:tid 832912] [client 205.210.31.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:13.555684 2026] [core:error] [pid 832668:tid 832912] [client 205.210.31.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:13.559410 2026] [security2:error] [pid 832668:tid 832851] [client 103.95.123.246:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3DdEAAAADM"]
[Mon Jul 20 06:09:13.559493 2026] [security2:error] [pid 832668:tid 832851] [client 103.95.123.246:19279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3DdEAAAADM"]
[Mon Jul 20 06:09:13.827808 2026] [security2:error] [pid 832668:tid 832867] [client 193.19.109.247:25885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cathyspeed.org"] [uri "/wp-login.php"] [unique_id "al4P6Wci6KgEEltqA3DdKAAAAEM"]
[Mon Jul 20 06:09:14.192239 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:65471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc6AAAAFE"], referer: http://getgarrison.com/Wordpress
[Mon Jul 20 06:09:14.224902 2026] [security2:error] [pid 832668:tid 832911] [client 14.225.17.146:65476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdQAAAAG8"], referer: https://friendlyspreadsheet.com/Wordpress
[Mon Jul 20 06:09:14.586211 2026] [security2:error] [pid 832668:tid 832855] [client 57.141.18.45:58174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P5mci6KgEEltqA3DcKAAAN0o"]
[Mon Jul 20 06:09:14.641818 2026] [security2:error] [pid 832668:tid 832825] [client 185.132.186.71:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/cc.php"] [unique_id "al4P6mci6KgEEltqA3DdYAAAABk"]
[Mon Jul 20 06:09:14.697507 2026] [security2:error] [pid 832668:tid 832921] [client 193.19.109.215:41583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4P6mci6KgEEltqA3DdYwAAAHk"]
[Mon Jul 20 06:09:15.023838 2026] [security2:error] [pid 832668:tid 832674] [remote 103.82.22.235:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P62ci6KgEEltqA3DdgQAAFQM"]
[Mon Jul 20 06:09:15.343445 2026] [security2:error] [pid 832668:tid 832890] [client 57.141.18.33:41158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DcWgAAWhY"]
[Mon Jul 20 06:09:15.950247 2026] [security2:error] [pid 832668:tid 832698] [remote 154.66.198.148:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4P62ci6KgEEltqA3DdtwAAKBs"]
[Mon Jul 20 06:09:15.988662 2026] [security2:error] [pid 832668:tid 832829] [client 103.77.203.233:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P62ci6KgEEltqA3DdvAAAAB0"]
[Mon Jul 20 06:09:15.989142 2026] [security2:error] [pid 832668:tid 832829] [client 103.77.203.233:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P62ci6KgEEltqA3DdvAAAAB0"]
[Mon Jul 20 06:09:16.168839 2026] [security2:error] [pid 832668:tid 832813] [client 57.141.18.20:39132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DckAAADT4"]
[Mon Jul 20 06:09:16.217275 2026] [security2:error] [pid 832668:tid 832888] [client 86.98.90.58:9495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3DdygAAAFg"]
[Mon Jul 20 06:09:16.217527 2026] [security2:error] [pid 832668:tid 832888] [client 86.98.90.58:9495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3DdygAAAFg"]
[Mon Jul 20 06:09:16.243401 2026] [security2:error] [pid 832668:tid 832807] [client 14.225.17.146:65484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdXQAAAAc"], referer: http://swafforddetailing.com/Wordpress
[Mon Jul 20 06:09:16.366197 2026] [security2:error] [pid 832668:tid 832744] [remote 103.82.22.235:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P7Gci6KgEEltqA3Dd0wAAPEk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:09:16.659790 2026] [security2:error] [pid 832668:tid 832847] [client 185.132.186.55:26455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/aahana/worksec.php"] [unique_id "al4P7Gci6KgEEltqA3Dd5gAAAC8"]
[Mon Jul 20 06:09:16.664431 2026] [security2:error] [pid 832668:tid 832823] [client 103.141.108.143:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3Dd5wAAABc"]
[Mon Jul 20 06:09:16.665202 2026] [security2:error] [pid 832668:tid 832823] [client 103.141.108.143:51692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3Dd5wAAABc"]
[Mon Jul 20 06:09:16.731958 2026] [security2:error] [pid 832668:tid 832803] [client 57.141.18.119:50310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6Gci6KgEEltqA3DctwAAAzU"]
[Mon Jul 20 06:09:16.970599 2026] [security2:error] [pid 832668:tid 832909] [client 104.234.53.65:45107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4P7Gci6KgEEltqA3DeAgAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:17.102932 2026] [security2:error] [pid 832668:tid 832797] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeEAAAAX4"]
[Mon Jul 20 06:09:17.103063 2026] [security2:error] [pid 832668:tid 832801] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeEAAAAX4"]
[Mon Jul 20 06:09:17.174335 2026] [security2:error] [pid 832668:tid 832758] [remote 154.66.198.148:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4P7Wci6KgEEltqA3DeFwAAQlc"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:09:17.518848 2026] [security2:error] [pid 832668:tid 832700] [remote 20.153.140.50:40874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeLQAAHx0"]
[Mon Jul 20 06:09:17.519062 2026] [security2:error] [pid 832668:tid 832831] [client 20.153.140.50:40874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeLQAAHx0"]
[Mon Jul 20 06:09:17.565429 2026] [security2:error] [pid 832668:tid 832805] [client 115.246.21.170:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeMwAAAAU"]
[Mon Jul 20 06:09:17.565539 2026] [security2:error] [pid 832668:tid 832805] [client 115.246.21.170:19416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeMwAAAAU"]
[Mon Jul 20 06:09:17.601787 2026] [security2:error] [pid 832668:tid 832902] [client 106.192.104.4:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeOAAAAGY"]
[Mon Jul 20 06:09:17.601934 2026] [security2:error] [pid 832668:tid 832902] [client 106.192.104.4:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeOAAAAGY"]
[Mon Jul 20 06:09:17.679406 2026] [security2:error] [pid 832668:tid 832806] [client 57.141.18.26:35700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc9QAABnI"]
[Mon Jul 20 06:09:17.714435 2026] [security2:error] [pid 832668:tid 832832] [client 27.96.94.195:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeQgAAACA"]
[Mon Jul 20 06:09:17.714554 2026] [security2:error] [pid 832668:tid 832832] [client 27.96.94.195:37310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeQgAAACA"]
[Mon Jul 20 06:09:18.066683 2026] [security2:error] [pid 832668:tid 832834] [client 112.213.160.112:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeWwAAACI"]
[Mon Jul 20 06:09:18.066841 2026] [security2:error] [pid 832668:tid 832834] [client 112.213.160.112:8193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeWwAAACI"]
[Mon Jul 20 06:09:18.149254 2026] [security2:error] [pid 832668:tid 832773] [remote 162.19.86.63:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DeYQAAMGY"]
[Mon Jul 20 06:09:18.190128 2026] [security2:error] [pid 832668:tid 832730] [remote 217.61.143.92:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DeZwAAbDs"]
[Mon Jul 20 06:09:18.398019 2026] [security2:error] [pid 832668:tid 832695] [remote 162.19.86.63:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DedQAANhg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:18.517098 2026] [security2:error] [pid 832668:tid 832684] [remote 217.61.143.92:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DegQAADg0"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:09:18.603023 2026] [security2:error] [pid 832668:tid 832915] [client 45.116.69.230:64114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeiAAAAHM"]
[Mon Jul 20 06:09:18.603202 2026] [security2:error] [pid 832668:tid 832915] [client 45.116.69.230:64114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeiAAAAHM"]
[Mon Jul 20 06:09:18.712081 2026] [security2:error] [pid 832668:tid 832863] [client 185.132.186.73:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DejwAAAD8"]
[Mon Jul 20 06:09:18.770951 2026] [security2:error] [pid 832668:tid 832893] [client 57.141.18.117:42570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdUAAAXTM"]
[Mon Jul 20 06:09:18.835230 2026] [security2:error] [pid 832668:tid 832805] [client 181.224.94.124:40478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DemwAAAAU"]
[Mon Jul 20 06:09:18.835315 2026] [security2:error] [pid 832668:tid 832805] [client 181.224.94.124:40478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DemwAAAAU"]
[Mon Jul 20 06:09:19.068465 2026] [security2:error] [pid 832668:tid 832856] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4P72ci6KgEEltqA3DerwAAADg"], referer: https://twitter.com/
[Mon Jul 20 06:09:19.198624 2026] [security2:error] [pid 832668:tid 832912] [client 57.141.18.85:51094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdagAAcFw"]
[Mon Jul 20 06:09:19.392079 2026] [security2:error] [pid 832668:tid 832802] [client 41.173.37.102:10643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P72ci6KgEEltqA3DeygAAAAI"]
[Mon Jul 20 06:09:19.392191 2026] [security2:error] [pid 832668:tid 832802] [client 41.173.37.102:10643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P72ci6KgEEltqA3DeygAAAAI"]
[Mon Jul 20 06:09:19.614122 2026] [security2:error] [pid 832668:tid 832853] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4P72ci6KgEEltqA3De2wAAADU"], referer: https://duckduckgo.com/?q=aqc7m
[Mon Jul 20 06:09:20.093843 2026] [security2:error] [pid 832668:tid 832676] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3De_wAAeQU"]
[Mon Jul 20 06:09:20.094005 2026] [security2:error] [pid 832668:tid 832921] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3De_wAAeQU"]
[Mon Jul 20 06:09:20.228144 2026] [security2:error] [pid 832668:tid 832701] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfCAAALB4"]
[Mon Jul 20 06:09:20.228290 2026] [security2:error] [pid 832668:tid 832844] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfCAAALB4"]
[Mon Jul 20 06:09:20.268024 2026] [security2:error] [pid 832668:tid 832819] [client 103.153.183.69:40772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../etc/ssh/sshd_config"] [unique_id "al4P8Gci6KgEEltqA3DfDAAAABM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:09:20.312723 2026] [security2:error] [pid 832668:tid 832828] [client 178.152.178.232:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfEQAAABw"]
[Mon Jul 20 06:09:20.312838 2026] [security2:error] [pid 832668:tid 832828] [client 178.152.178.232:37574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfEQAAABw"]
[Mon Jul 20 06:09:20.342307 2026] [security2:error] [pid 832668:tid 832862] [client 158.173.166.181:60671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P8Gci6KgEEltqA3DfGAAAAD4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:20.353497 2026] [security2:error] [pid 832668:tid 832913] [client 104.234.53.92:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4P8Gci6KgEEltqA3DfFwAAAHE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:20.538185 2026] [security2:error] [pid 832668:tid 832809] [client 57.141.18.10:59568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P7Gci6KgEEltqA3Dd1gAACQs"]
[Mon Jul 20 06:09:21.364646 2026] [security2:error] [pid 832668:tid 832824] [client 57.141.18.119:50312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P7Wci6KgEEltqA3DeIwAAGDg"]
[Mon Jul 20 06:09:21.510431 2026] [security2:error] [pid 832668:tid 832907] [client 103.153.183.69:40772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../root/.ssh/id_rsa"] [unique_id "al4P8Wci6KgEEltqA3DfcQAAAGs"], referer: https://www.facebook.com/
[Mon Jul 20 06:09:21.733200 2026] [security2:error] [pid 832668:tid 832916] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4P8Wci6KgEEltqA3DfeQAAAHQ"], referer: https://t.co/u468s1ncte
[Mon Jul 20 06:09:21.752841 2026] [security2:error] [pid 832668:tid 832829] [client 164.100.212.184:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Wci6KgEEltqA3DfewAAAB0"]
[Mon Jul 20 06:09:21.752927 2026] [security2:error] [pid 832668:tid 832829] [client 164.100.212.184:59899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Wci6KgEEltqA3DfewAAAB0"]
[Mon Jul 20 06:09:21.766927 2026] [security2:error] [pid 832668:tid 832689] [remote 47.86.33.52:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P8Wci6KgEEltqA3DfegAATRI"]
[Mon Jul 20 06:09:22.209606 2026] [security2:error] [pid 832668:tid 832861] [client 57.141.18.85:51108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P7mci6KgEEltqA3DeYgAAPWY"]
[Mon Jul 20 06:09:22.257763 2026] [security2:error] [pid 832668:tid 832890] [client 185.132.186.55:58779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/class_api.php"] [unique_id "al4P8mci6KgEEltqA3DfpwAAAFo"]
[Mon Jul 20 06:09:22.272258 2026] [security2:error] [pid 832668:tid 832842] [client 104.234.53.57:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4P8mci6KgEEltqA3DfqQAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:22.435138 2026] [security2:error] [pid 832668:tid 832775] [remote 154.66.198.148:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4P8mci6KgEEltqA3DftQAALWg"]
[Mon Jul 20 06:09:22.503999 2026] [security2:error] [pid 832668:tid 832922] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4P8mci6KgEEltqA3DfvQAAAHo"], referer: https://duckduckgo.com/?q=yesgu
[Mon Jul 20 06:09:23.096414 2026] [security2:error] [pid 832668:tid 832899] [client 57.141.18.5:49984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P72ci6KgEEltqA3DetQAAY0w"]
[Mon Jul 20 06:09:23.264658 2026] [security2:error] [pid 832668:tid 832710] [remote 154.66.198.148:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3Df7gAAYic"], referer: https://claysharecon.com/wp-login.php
[Mon Jul 20 06:09:23.281610 2026] [security2:error] [pid 832668:tid 832908] [client 50.116.65.227:54968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4P82ci6KgEEltqA3Df8gAAAGw"]
[Mon Jul 20 06:09:23.292321 2026] [security2:error] [pid 832668:tid 832927] [client 50.116.65.227:54976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4P82ci6KgEEltqA3Df8wAAAH8"]
[Mon Jul 20 06:09:23.419109 2026] [security2:error] [pid 832668:tid 832731] [remote 47.86.33.52:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3Df-gAAQDw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:23.486563 2026] [security2:error] [pid 832668:tid 832863] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4P82ci6KgEEltqA3DgBAAAAD8"], referer: https://duckduckgo.com/?q=wre76
[Mon Jul 20 06:09:23.525599 2026] [security2:error] [pid 832668:tid 832691] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P82ci6KgEEltqA3DgBgAALhQ"]
[Mon Jul 20 06:09:23.525800 2026] [security2:error] [pid 832668:tid 832846] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P82ci6KgEEltqA3DgBgAALhQ"]
[Mon Jul 20 06:09:23.718901 2026] [security2:error] [pid 832668:tid 832697] [remote 100.42.189.89:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3DgGwAANBo"]
[Mon Jul 20 06:09:23.916245 2026] [security2:error] [pid 832668:tid 832768] [remote 100.42.189.89:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3DgLwAAP2E"], referer: https://uninursity.com/wp-login.php
[Mon Jul 20 06:09:23.963778 2026] [security2:error] [pid 832668:tid 832849] [client 74.208.214.194:46506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4P82ci6KgEEltqA3DgNQAAADE"]
[Mon Jul 20 06:09:24.206419 2026] [security2:error] [pid 832668:tid 832920] [client 185.132.186.88:62541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4P9Gci6KgEEltqA3DgSgAAAHg"]
[Mon Jul 20 06:09:24.266478 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.6:49400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8Gci6KgEEltqA3DfAAAATjU"]
[Mon Jul 20 06:09:24.636364 2026] [security2:error] [pid 832668:tid 832810] [client 103.95.123.246:19766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P9Gci6KgEEltqA3DgZQAAAAo"]
[Mon Jul 20 06:09:24.636550 2026] [security2:error] [pid 832668:tid 832810] [client 103.95.123.246:19766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P9Gci6KgEEltqA3DgZQAAAAo"]
[Mon Jul 20 06:09:25.469988 2026] [security2:error] [pid 832668:tid 832813] [client 57.141.18.76:30334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8Wci6KgEEltqA3DfXwAADS8"]
[Mon Jul 20 06:09:26.158053 2026] [security2:error] [pid 832668:tid 832814] [client 185.132.186.88:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/class-core-upgrader-first.php"] [unique_id "al4P9mci6KgEEltqA3Dg3AAAAA4"]
[Mon Jul 20 06:09:26.471149 2026] [security2:error] [pid 832668:tid 832888] [client 103.77.203.233:58643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3Dg8wAAAFg"]
[Mon Jul 20 06:09:26.471427 2026] [security2:error] [pid 832668:tid 832888] [client 103.77.203.233:58643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3Dg8wAAAFg"]
[Mon Jul 20 06:09:26.837864 2026] [security2:error] [pid 832668:tid 832846] [client 5.161.194.92:44506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4P9mci6KgEEltqA3Dg8AAAAC4"], referer: https://windowtx.com
[Mon Jul 20 06:09:26.838782 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:10201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3DhFwAAABg"]
[Mon Jul 20 06:09:26.838888 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:10201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3DhFwAAABg"]
[Mon Jul 20 06:09:27.073301 2026] [security2:error] [pid 832668:tid 832818] [client 57.141.18.9:48908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8mci6KgEEltqA3DfwQAAEjM"]
[Mon Jul 20 06:09:27.088812 2026] [security2:error] [pid 832668:tid 832914] [client 57.141.18.52:38428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8mci6KgEEltqA3DfwgAAcmI"]
[Mon Jul 20 06:09:27.376137 2026] [security2:error] [pid 832668:tid 832918] [client 103.141.108.143:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhOQAAAHY"]
[Mon Jul 20 06:09:27.376980 2026] [security2:error] [pid 832668:tid 832918] [client 103.141.108.143:52152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhOQAAAHY"]
[Mon Jul 20 06:09:27.622979 2026] [security2:error] [pid 832668:tid 832815] [client 57.141.18.44:50600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P82ci6KgEEltqA3Df6AAAD2o"]
[Mon Jul 20 06:09:27.956948 2026] [security2:error] [pid 832668:tid 832682] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhagAAMgs"]
[Mon Jul 20 06:09:27.957052 2026] [security2:error] [pid 832668:tid 832850] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhagAAMgs"]
[Mon Jul 20 06:09:28.106572 2026] [security2:error] [pid 832668:tid 832919] [client 115.246.21.170:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhdwAAAHc"]
[Mon Jul 20 06:09:28.106709 2026] [security2:error] [pid 832668:tid 832919] [client 115.246.21.170:26368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhdwAAAHc"]
[Mon Jul 20 06:09:28.108861 2026] [security2:error] [pid 832668:tid 832901] [client 185.132.186.55:22361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/wp-css.php"] [unique_id "al4P-Gci6KgEEltqA3DheAAAAGU"]
[Mon Jul 20 06:09:28.122836 2026] [security2:error] [pid 832668:tid 832810] [client 182.189.46.35:41927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4P-Gci6KgEEltqA3DhcgAAAAo"]
[Mon Jul 20 06:09:28.679418 2026] [security2:error] [pid 832668:tid 832864] [client 106.192.104.4:43648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhogAAAEA"]
[Mon Jul 20 06:09:28.679528 2026] [security2:error] [pid 832668:tid 832864] [client 106.192.104.4:43648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhogAAAEA"]
[Mon Jul 20 06:09:28.786437 2026] [security2:error] [pid 832668:tid 832870] [client 112.213.160.112:8523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhqwAAAEY"]
[Mon Jul 20 06:09:28.786537 2026] [security2:error] [pid 832668:tid 832870] [client 112.213.160.112:8523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhqwAAAEY"]
[Mon Jul 20 06:09:29.089228 2026] [security2:error] [pid 832668:tid 832917] [client 57.141.18.111:24496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P9Gci6KgEEltqA3DgegAAdXI"]
[Mon Jul 20 06:09:29.221133 2026] [security2:error] [pid 832668:tid 832888] [client 45.116.69.230:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DhxwAAAFg"]
[Mon Jul 20 06:09:29.221232 2026] [security2:error] [pid 832668:tid 832888] [client 45.116.69.230:64601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DhxwAAAFg"]
[Mon Jul 20 06:09:29.361297 2026] [security2:error] [pid 832668:tid 832849] [client 181.224.94.124:47554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3Dh1QAAADE"]
[Mon Jul 20 06:09:29.361412 2026] [security2:error] [pid 832668:tid 832849] [client 181.224.94.124:47554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3Dh1QAAADE"]
[Mon Jul 20 06:09:29.393783 2026] [security2:error] [pid 832668:tid 832689] [remote 51.158.61.221:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh1gAAJBI"]
[Mon Jul 20 06:09:29.424681 2026] [security2:error] [pid 832668:tid 832694] [remote 217.61.143.92:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh2QAAHRc"]
[Mon Jul 20 06:09:29.591890 2026] [security2:error] [pid 832668:tid 832783] [remote 51.158.61.221:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh4AAAPHA"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 06:09:29.649454 2026] [security2:error] [pid 832668:tid 832766] [remote 217.61.143.92:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh5QAADF8"], referer: https://thesoloceos.com/wp-login.php
[Mon Jul 20 06:09:29.941408 2026] [security2:error] [pid 832668:tid 832924] [client 41.173.37.102:11076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DiAAAAAHw"]
[Mon Jul 20 06:09:29.941565 2026] [security2:error] [pid 832668:tid 832924] [client 41.173.37.102:11076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DiAAAAAHw"]
[Mon Jul 20 06:09:30.058322 2026] [security2:error] [pid 832668:tid 832849] [client 185.132.186.81:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/goto.php"] [unique_id "al4P-mci6KgEEltqA3DiCwAAADE"]
[Mon Jul 20 06:09:30.177492 2026] [security2:error] [pid 832668:tid 832767] [remote 216.73.216.55:37554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4P-mci6KgEEltqA3DiEQAAPmA"]
[Mon Jul 20 06:09:30.376373 2026] [security2:error] [pid 832668:tid 832868] [client 57.141.18.113:51540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P9mci6KgEEltqA3Dg2QAARAk"]
[Mon Jul 20 06:09:30.400228 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiKAAAAGo"]
[Mon Jul 20 06:09:30.400317 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiKAAAAGo"]
[Mon Jul 20 06:09:30.496051 2026] [security2:error] [pid 832668:tid 832834] [client 103.153.183.69:64028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/passwd"] [unique_id "al4P-mci6KgEEltqA3DiLwAAACI"], referer: https://www.google.com/
[Mon Jul 20 06:09:30.523976 2026] [security2:error] [pid 832668:tid 832876] [client 103.153.183.69:64028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/shadow"] [unique_id "al4P-mci6KgEEltqA3DiMgAAAEw"], referer: https://twitter.com/
[Mon Jul 20 06:09:30.605833 2026] [security2:error] [pid 832668:tid 832838] [client 57.141.18.46:49176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P9mci6KgEEltqA3Dg7gAAJgM"]
[Mon Jul 20 06:09:30.644564 2026] [security2:error] [pid 832668:tid 832747] [remote 104.131.116.82:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4P-mci6KgEEltqA3DiNQAAYkw"]
[Mon Jul 20 06:09:30.752871 2026] [security2:error] [pid 832668:tid 832705] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiQQAAOyI"]
[Mon Jul 20 06:09:30.753108 2026] [security2:error] [pid 832668:tid 832859] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiQQAAOyI"]
[Mon Jul 20 06:09:30.856906 2026] [security2:error] [pid 832668:tid 832786] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiSwAAJHM"]
[Mon Jul 20 06:09:30.857130 2026] [security2:error] [pid 832668:tid 832836] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiSwAAJHM"]
[Mon Jul 20 06:09:30.883458 2026] [security2:error] [pid 832668:tid 832722] [remote 104.131.116.82:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4P-mci6KgEEltqA3DiTgAAWjM"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:09:31.664969 2026] [security2:error] [pid 832668:tid 832816] [client 57.141.18.90:41418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P92ci6KgEEltqA3DhMwAAEAc"]
[Mon Jul 20 06:09:31.669051 2026] [security2:error] [pid 832668:tid 832914] [client 103.153.183.69:64028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/hosts"] [unique_id "al4P-2ci6KgEEltqA3DiiwAAAHI"], referer: https://duckduckgo.com/?q=soo1z
[Mon Jul 20 06:09:31.716725 2026] [security2:error] [pid 832668:tid 832819] [client 103.153.183.69:64028] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//....//proc/self/environ"] [unique_id "al4P-2ci6KgEEltqA3DikAAAABM"], referer: https://twitter.com/
[Mon Jul 20 06:09:31.824071 2026] [security2:error] [pid 832668:tid 832922] [client 50.116.65.227:52166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4P-2ci6KgEEltqA3DilwAAAHo"]
[Mon Jul 20 06:09:31.835408 2026] [security2:error] [pid 832668:tid 832866] [client 50.116.65.227:52178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4P-2ci6KgEEltqA3DimAAAAEI"]
[Mon Jul 20 06:09:31.976476 2026] [security2:error] [pid 832668:tid 832871] [client 185.132.186.72:27071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/xboom.php"] [unique_id "al4P-2ci6KgEEltqA3DioAAAAEc"]
[Mon Jul 20 06:09:32.345465 2026] [security2:error] [pid 832668:tid 832826] [client 164.100.212.184:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Gci6KgEEltqA3DivQAAABo"]
[Mon Jul 20 06:09:32.345590 2026] [security2:error] [pid 832668:tid 832826] [client 164.100.212.184:64043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Gci6KgEEltqA3DivQAAABo"]
[Mon Jul 20 06:09:32.472927 2026] [security2:error] [pid 832668:tid 832910] [client 14.225.17.146:63818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4P_Gci6KgEEltqA3DitgAAAG4"], referer: http://inspirespublishing.com/WORDPRESS
[Mon Jul 20 06:09:32.488953 2026] [security2:error] [pid 832668:tid 832858] [client 57.141.18.27:42202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P92ci6KgEEltqA3DhZwAAOlM"]
[Mon Jul 20 06:09:32.570813 2026] [security2:error] [pid 832668:tid 832869] [client 192.236.168.43:55216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.tntcatholic.com"] [uri "/"] [unique_id "al4P_Gci6KgEEltqA3Di0wAAAEU"]
[Mon Jul 20 06:09:33.059381 2026] [security2:error] [pid 832668:tid 832896] [client 57.141.18.15:41554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P-Gci6KgEEltqA3DhjgAAYFY"]
[Mon Jul 20 06:09:33.073571 2026] [security2:error] [pid 832668:tid 832872] [client 74.208.214.194:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4P_Wci6KgEEltqA3Di_gAAAEg"]
[Mon Jul 20 06:09:33.692040 2026] [security2:error] [pid 832668:tid 832760] [remote 188.166.241.141:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P_Wci6KgEEltqA3DjMQAAH1k"]
[Mon Jul 20 06:09:33.892801 2026] [security2:error] [pid 832668:tid 832861] [client 27.96.94.195:37615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Wci6KgEEltqA3DjPgAAAD0"]
[Mon Jul 20 06:09:33.892913 2026] [security2:error] [pid 832668:tid 832861] [client 27.96.94.195:37615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Wci6KgEEltqA3DjPgAAAD0"]
[Mon Jul 20 06:09:33.937594 2026] [security2:error] [pid 832668:tid 832890] [client 185.132.186.70:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "al4P_Wci6KgEEltqA3DjQAAAAFo"]
[Mon Jul 20 06:09:34.001227 2026] [security2:error] [pid 832668:tid 832849] [client 14.225.17.146:49860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P_Wci6KgEEltqA3DjOQAAADE"], referer: http://sesamegreenbeans.com/WORDPRESS
[Mon Jul 20 06:09:34.031692 2026] [security2:error] [pid 832668:tid 832903] [client 57.141.18.65:26928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P-Wci6KgEEltqA3Dh2gAAZy8"]
[Mon Jul 20 06:09:34.086129 2026] [security2:error] [pid 832668:tid 832709] [remote 188.166.241.141:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P_mci6KgEEltqA3DjUgAALSY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:34.100870 2026] [security2:error] [pid 832668:tid 832675] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P_mci6KgEEltqA3DjUwAAVgQ"]
[Mon Jul 20 06:09:34.100998 2026] [security2:error] [pid 832668:tid 832886] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P_mci6KgEEltqA3DjUwAAVgQ"]
[Mon Jul 20 06:09:34.644856 2026] [security2:error] [pid 832668:tid 832903] [client 94.154.43.186:24594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samueldcohen.com"] [uri "/.env"] [unique_id "al4P_mci6KgEEltqA3DjeAAAAGc"]
[Mon Jul 20 06:09:35.008979 2026] [security2:error] [pid 832668:tid 832862] [client 14.225.17.146:53391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P_mci6KgEEltqA3DjiAAAAD4"], referer: https://sesamegreenbeans.com/WORDPRESS
[Mon Jul 20 06:09:35.523796 2026] [security2:error] [pid 832668:tid 832914] [client 103.153.183.69:12042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../home/ubuntu/.ssh/id_rsa"] [unique_id "al4P_2ci6KgEEltqA3DjwgAAAHI"], referer: https://www.google.com/search?q=z3ycm4
[Mon Jul 20 06:09:35.572981 2026] [security2:error] [pid 832668:tid 832890] [client 14.225.17.146:56553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4P_2ci6KgEEltqA3DjuQAAAFo"], referer: http://talknutritionwithlesley.com/WORDPRESS
[Mon Jul 20 06:09:35.731668 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P_2ci6KgEEltqA3Dj0wAAAGM"]
[Mon Jul 20 06:09:35.731788 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:20252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P_2ci6KgEEltqA3Dj0wAAAGM"]
[Mon Jul 20 06:09:35.889786 2026] [security2:error] [pid 832668:tid 832877] [client 185.132.186.93:44297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/Sanskrit.php"] [unique_id "al4P_2ci6KgEEltqA3Dj4QAAAE0"]
[Mon Jul 20 06:09:36.162529 2026] [security2:error] [pid 832668:tid 832690] [remote 152.228.213.32:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QAGci6KgEEltqA3Dj8wAAfhM"]
[Mon Jul 20 06:09:36.217396 2026] [security2:error] [pid 832668:tid 832901] [client 14.225.17.146:64476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4QAGci6KgEEltqA3Dj9AAAAGU"], referer: http://techtradeinc.com/WORDPRESS
[Mon Jul 20 06:09:36.289249 2026] [security2:error] [pid 832668:tid 832789] [remote 157.180.59.124:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.59.180.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3Dj_QAAFHY"]
[Mon Jul 20 06:09:36.289496 2026] [security2:error] [pid 832668:tid 832820] [client 157.180.59.124:59044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3Dj_QAAFHY"]
[Mon Jul 20 06:09:36.346800 2026] [security2:error] [pid 832668:tid 832801] [client 57.141.18.13:63352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P-2ci6KgEEltqA3DihwAAATY"]
[Mon Jul 20 06:09:36.384441 2026] [security2:error] [pid 832668:tid 832729] [remote 152.228.213.32:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QAGci6KgEEltqA3DkCAAAZzo"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:09:36.776858 2026] [security2:error] [pid 832668:tid 832904] [client 57.141.18.58:35286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_Gci6KgEEltqA3DirgAAaEE"]
[Mon Jul 20 06:09:36.808194 2026] [security2:error] [pid 832668:tid 832802] [client 14.225.17.146:59321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4P_2ci6KgEEltqA3DjzAAAAAI"], referer: http://mourgroup.com/WORDPRESS
[Mon Jul 20 06:09:36.934303 2026] [security2:error] [pid 832668:tid 832909] [client 103.77.203.233:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3DkMwAAAG0"]
[Mon Jul 20 06:09:36.934433 2026] [security2:error] [pid 832668:tid 832909] [client 103.77.203.233:59371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3DkMwAAAG0"]
[Mon Jul 20 06:09:37.394823 2026] [security2:error] [pid 832668:tid 832836] [client 57.141.18.64:36610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_Gci6KgEEltqA3Di4wAAJDU"]
[Mon Jul 20 06:09:37.409985 2026] [security2:error] [pid 832668:tid 832883] [client 145.239.10.137:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "howtoacecollegeandmasterlife.com"] [uri "/vb_cache.php"] [unique_id "al4QAWci6KgEEltqA3DkWQAAAFM"], referer: http://howtoacecollegeandmasterlife.com/vb_cache.php
[Mon Jul 20 06:09:37.763228 2026] [security2:error] [pid 832668:tid 832805] [client 182.189.46.35:33028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ccsdifference.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al4QAWci6KgEEltqA3DkbwAAAAU"]
[Mon Jul 20 06:09:37.817732 2026] [security2:error] [pid 832668:tid 832843] [client 86.98.90.58:11029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAWci6KgEEltqA3DkcwAAACs"]
[Mon Jul 20 06:09:37.817868 2026] [security2:error] [pid 832668:tid 832843] [client 86.98.90.58:11029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAWci6KgEEltqA3DkcwAAACs"]
[Mon Jul 20 06:09:37.834373 2026] [security2:error] [pid 832668:tid 832829] [client 185.132.186.73:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-fmfile.php"] [unique_id "al4QAWci6KgEEltqA3DkdAAAAB0"]
[Mon Jul 20 06:09:38.167843 2026] [security2:error] [pid 832668:tid 832876] [client 57.141.18.29:59796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_Wci6KgEEltqA3DjHwAATDk"]
[Mon Jul 20 06:09:38.241475 2026] [security2:error] [pid 832668:tid 832927] [client 103.141.108.143:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkkAAAAH8"]
[Mon Jul 20 06:09:38.241679 2026] [security2:error] [pid 832668:tid 832927] [client 103.141.108.143:52601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkkAAAAH8"]
[Mon Jul 20 06:09:38.687070 2026] [security2:error] [pid 832668:tid 832816] [client 50.116.65.227:12760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4QAmci6KgEEltqA3DkuAAAABA"]
[Mon Jul 20 06:09:38.698691 2026] [security2:error] [pid 832668:tid 832801] [client 50.116.65.227:52252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4QAmci6KgEEltqA3DkugAAAAE"]
[Mon Jul 20 06:09:38.737052 2026] [security2:error] [pid 832668:tid 832822] [client 115.246.21.170:37965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkvgAAABY"]
[Mon Jul 20 06:09:38.738635 2026] [security2:error] [pid 832668:tid 832822] [client 115.246.21.170:37965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkvgAAABY"]
[Mon Jul 20 06:09:38.876556 2026] [security2:error] [pid 832668:tid 832848] [client 14.225.17.146:52888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4QAmci6KgEEltqA3DktwAAADA"], referer: http://thesoloceos.com/WORDPRESS
[Mon Jul 20 06:09:39.066890 2026] [security2:error] [pid 832668:tid 832827] [client 57.141.18.114:26780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_mci6KgEEltqA3DjcgAAG20"]
[Mon Jul 20 06:09:39.172909 2026] [security2:error] [pid 832668:tid 832693] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk2QAAHxY"]
[Mon Jul 20 06:09:39.173169 2026] [security2:error] [pid 832668:tid 832831] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk2QAAHxY"]
[Mon Jul 20 06:09:39.178888 2026] [security2:error] [pid 832668:tid 832910] [client 143.110.169.139:54900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4QAmci6KgEEltqA3DkygAAAG4"], referer: https://hilltopnurseryinc.com/
[Mon Jul 20 06:09:39.197543 2026] [security2:error] [pid 832668:tid 832913] [client 14.225.17.146:62956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4QAWci6KgEEltqA3DkOQAAAHE"], referer: http://younutrition.gr/WORDPRESS
[Mon Jul 20 06:09:39.284127 2026] [security2:error] [pid 832668:tid 832712] [remote 57.141.18.33:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4QA2ci6KgEEltqA3Dk5QAAeyk"]
[Mon Jul 20 06:09:39.352906 2026] [security2:error] [pid 832668:tid 832875] [client 14.225.17.146:61004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4QA2ci6KgEEltqA3Dk3AAAAEs"], referer: http://ghivs.com/WORDPRESS
[Mon Jul 20 06:09:39.380989 2026] [security2:error] [pid 832668:tid 832902] [client 57.141.18.53:58714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_mci6KgEEltqA3DjmAAAZi0"]
[Mon Jul 20 06:09:39.475281 2026] [security2:error] [pid 832668:tid 832904] [client 112.213.160.112:8419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk9QAAAGg"]
[Mon Jul 20 06:09:39.475381 2026] [security2:error] [pid 832668:tid 832904] [client 112.213.160.112:8419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk9QAAAGg"]
[Mon Jul 20 06:09:39.535653 2026] [security2:error] [pid 832668:tid 832817] [client 45.157.112.60:21593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QA2ci6KgEEltqA3Dk-gAAABE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:39.715881 2026] [security2:error] [pid 832668:tid 832900] [client 113.161.215.49:32996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4QA2ci6KgEEltqA3DlAQAAAGQ"], referer: https://thewelloiledlife.com/
[Mon Jul 20 06:09:39.778115 2026] [security2:error] [pid 832668:tid 832918] [client 106.192.104.4:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlFwAAAHY"]
[Mon Jul 20 06:09:39.778224 2026] [security2:error] [pid 832668:tid 832918] [client 106.192.104.4:56556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlFwAAAHY"]
[Mon Jul 20 06:09:39.792264 2026] [security2:error] [pid 832668:tid 832898] [client 35.90.38.209:11686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlFAAAAGI"]
[Mon Jul 20 06:09:39.888721 2026] [security2:error] [pid 832668:tid 832848] [client 14.225.17.146:62146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4QA2ci6KgEEltqA3DlDwAAADA"], referer: https://thesoloceos.com/WORDPRESS
[Mon Jul 20 06:09:39.911103 2026] [security2:error] [pid 832668:tid 832897] [client 45.116.69.230:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIQAAAGE"]
[Mon Jul 20 06:09:39.911201 2026] [security2:error] [pid 832668:tid 832897] [client 45.116.69.230:65080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIQAAAGE"]
[Mon Jul 20 06:09:39.921146 2026] [security2:error] [pid 832668:tid 832865] [client 181.224.94.124:8758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIwAAAEE"]
[Mon Jul 20 06:09:39.921255 2026] [security2:error] [pid 832668:tid 832865] [client 181.224.94.124:8758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIwAAAEE"]
[Mon Jul 20 06:09:40.089981 2026] [security2:error] [pid 832668:tid 832813] [client 182.189.46.35:33030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QA2ci6KgEEltqA3DlDgAAAA0"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:40.507286 2026] [security2:error] [pid 832668:tid 832815] [client 74.7.227.179:49448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QBGci6KgEEltqA3DlPgAAD3Y"], referer: https://tejasenvironmental.com/p=3328864
[Mon Jul 20 06:09:40.554783 2026] [security2:error] [pid 832668:tid 832831] [client 41.173.37.102:11527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QBGci6KgEEltqA3DlSgAAAB8"]
[Mon Jul 20 06:09:40.554915 2026] [security2:error] [pid 832668:tid 832831] [client 41.173.37.102:11527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QBGci6KgEEltqA3DlSgAAAB8"]
[Mon Jul 20 06:09:40.981194 2026] [security2:error] [pid 832668:tid 832838] [client 35.90.38.209:11700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4QBGci6KgEEltqA3DldAAAACY"]
[Mon Jul 20 06:09:41.276431 2026] [security2:error] [pid 832668:tid 832785] [remote 188.40.28.4:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QBWci6KgEEltqA3DliQAAD3I"]
[Mon Jul 20 06:09:41.338048 2026] [security2:error] [pid 832668:tid 832882] [client 185.132.186.100:52759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.trash7309/index.php"] [unique_id "al4QBWci6KgEEltqA3DlkAAAAFI"]
[Mon Jul 20 06:09:41.437995 2026] [security2:error] [pid 832668:tid 832791] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmgAAVXg"]
[Mon Jul 20 06:09:41.438179 2026] [security2:error] [pid 832668:tid 832885] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmgAAVXg"]
[Mon Jul 20 06:09:41.447209 2026] [security2:error] [pid 832668:tid 832753] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmwAARVI"]
[Mon Jul 20 06:09:41.447362 2026] [security2:error] [pid 832668:tid 832869] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmwAARVI"]
[Mon Jul 20 06:09:41.486114 2026] [security2:error] [pid 832668:tid 832778] [remote 188.40.28.4:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QBWci6KgEEltqA3DlngAAWWs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:41.500392 2026] [security2:error] [pid 832668:tid 832849] [client 173.239.224.21:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "partnerselectricalllc.com"] [uri "/wp-login.php"] [unique_id "al4QBWci6KgEEltqA3DlnAAAADE"]
[Mon Jul 20 06:09:41.607620 2026] [security2:error] [pid 832668:tid 832888] [client 57.141.18.121:35194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QAWci6KgEEltqA3DkYAAAWHw"]
[Mon Jul 20 06:09:41.818278 2026] [security2:error] [pid 832668:tid 832819] [client 44.245.170.32:11612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4QBWci6KgEEltqA3DlswAAABM"]
[Mon Jul 20 06:09:42.353125 2026] [security2:error] [pid 832668:tid 832862] [client 35.90.38.209:47682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4QBmci6KgEEltqA3Dl1gAAAD4"]
[Mon Jul 20 06:09:42.572482 2026] [security2:error] [pid 832668:tid 832858] [client 50.116.65.227:22780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QBmci6KgEEltqA3Dl6gAAADo"]
[Mon Jul 20 06:09:42.582993 2026] [security2:error] [pid 832668:tid 832861] [client 50.116.65.227:22784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QBmci6KgEEltqA3Dl6wAAAD0"]
[Mon Jul 20 06:09:42.616056 2026] [security2:error] [pid 832668:tid 832893] [client 57.141.18.20:24962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QAmci6KgEEltqA3DkrAAAXW8"]
[Mon Jul 20 06:09:42.745683 2026] [core:error] [pid 832668:tid 832911] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:42.745709 2026] [core:error] [pid 832668:tid 832911] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:42.936959 2026] [security2:error] [pid 832668:tid 832836] [client 164.100.212.184:64634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QBmci6KgEEltqA3DmCwAAACQ"]
[Mon Jul 20 06:09:42.937085 2026] [security2:error] [pid 832668:tid 832836] [client 164.100.212.184:64634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QBmci6KgEEltqA3DmCwAAACQ"]
[Mon Jul 20 06:09:42.942864 2026] [security2:error] [pid 832668:tid 832825] [client 44.245.170.32:11618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4QBmci6KgEEltqA3DmDQAAABk"]
[Mon Jul 20 06:09:43.069288 2026] [security2:error] [pid 832668:tid 832818] [client 14.225.17.146:50787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4QBWci6KgEEltqA3DlpQAAABI"], referer: http://guidehunting.com/WORDPRESS
[Mon Jul 20 06:09:43.095700 2026] [security2:error] [pid 832668:tid 832826] [client 182.189.46.35:33032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QBmci6KgEEltqA3DmCgAAABo"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:43.286488 2026] [security2:error] [pid 832668:tid 832870] [client 185.132.186.54:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmKwAAAEY"]
[Mon Jul 20 06:09:43.493519 2026] [security2:error] [pid 832668:tid 832886] [client 44.245.170.32:11620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4QB2ci6KgEEltqA3DmQAAAAFY"]
[Mon Jul 20 06:09:43.534143 2026] [security2:error] [pid 832668:tid 832698] [remote 217.61.143.92:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4QB2ci6KgEEltqA3DmRQAAVBs"]
[Mon Jul 20 06:09:43.597303 2026] [security2:error] [pid 832668:tid 832738] [remote 57.141.18.58:23700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4409190"] [unique_id "al4QB2ci6KgEEltqA3DmSgAAWUM"]
[Mon Jul 20 06:09:43.845922 2026] [security2:error] [pid 832668:tid 832787] [remote 217.61.143.92:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4QB2ci6KgEEltqA3DmYgAAIHQ"], referer: https://file.learnthissecret.com/wp-login.php
[Mon Jul 20 06:09:44.011512 2026] [security2:error] [pid 832668:tid 832919] [client 57.141.18.35:57514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBGci6KgEEltqA3DlJwAAdx8"]
[Mon Jul 20 06:09:44.126991 2026] [security2:error] [pid 832668:tid 832874] [client 14.225.17.146:49272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmZAAAAEo"], referer: https://guidehunting.com/WORDPRESS
[Mon Jul 20 06:09:44.190633 2026] [security2:error] [pid 832668:tid 832861] [client 14.232.238.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmaQAAAD0"]
[Mon Jul 20 06:09:44.297260 2026] [security2:error] [pid 832668:tid 832802] [client 44.245.170.32:11628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4QCGci6KgEEltqA3DmfwAAAAI"]
[Mon Jul 20 06:09:44.465605 2026] [security2:error] [pid 832668:tid 832672] [remote 47.86.33.52:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4QCGci6KgEEltqA3DmkQAATwE"]
[Mon Jul 20 06:09:44.613463 2026] [security2:error] [pid 832668:tid 832754] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QCGci6KgEEltqA3DmnQAAGVM"]
[Mon Jul 20 06:09:44.613660 2026] [security2:error] [pid 832668:tid 832825] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QCGci6KgEEltqA3DmnQAAGVM"]
[Mon Jul 20 06:09:44.771493 2026] [security2:error] [pid 832668:tid 832891] [client 57.141.18.80:49664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBGci6KgEEltqA3DlZwAAWwY"]
[Mon Jul 20 06:09:45.170975 2026] [security2:error] [pid 832668:tid 832791] [remote 47.86.33.52:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4QCWci6KgEEltqA3DmxwAAV3g"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:09:45.234222 2026] [security2:error] [pid 832668:tid 832891] [client 185.132.186.89:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ioxi/ioxi/dropdown.php"] [unique_id "al4QCWci6KgEEltqA3DmzAAAAFs"]
[Mon Jul 20 06:09:45.265610 2026] [security2:error] [pid 832668:tid 832900] [client 104.168.114.154:45064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tntcatholic.com"] [uri "/"] [unique_id "al4QCWci6KgEEltqA3Dm0QAAAGQ"]
[Mon Jul 20 06:09:45.469636 2026] [security2:error] [pid 832668:tid 832845] [client 182.189.46.35:33034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QCWci6KgEEltqA3Dm0wAAAC0"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:45.715937 2026] [security2:error] [pid 832668:tid 832926] [client 104.234.53.54:41525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QCWci6KgEEltqA3Dm_AAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:45.778504 2026] [security2:error] [pid 832668:tid 832914] [client 57.141.18.9:46556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBWci6KgEEltqA3DltQAAcno"]
[Mon Jul 20 06:09:45.783888 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.58:20494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBWci6KgEEltqA3DluwAATkY"]
[Mon Jul 20 06:09:45.933901 2026] [security2:error] [pid 832668:tid 832831] [client 57.141.18.87:36004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBmci6KgEEltqA3DlvwAAHzk"]
[Mon Jul 20 06:09:46.462720 2026] [security2:error] [pid 832668:tid 832919] [client 14.225.17.146:50001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4QCWci6KgEEltqA3Dm8gAAAHc"], referer: http://kromosenergy.com/WORDPRESS
[Mon Jul 20 06:09:46.770521 2026] [security2:error] [pid 832668:tid 832835] [client 14.225.17.146:50128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnVAAAACM"], referer: http://keywayconstructionclt.com/WORDPRESS
[Mon Jul 20 06:09:47.248245 2026] [security2:error] [pid 832668:tid 832926] [client 192.236.168.43:58734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.tntcatholic.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnhQAAAH4"]
[Mon Jul 20 06:09:47.274465 2026] [security2:error] [pid 832668:tid 832823] [client 103.95.123.246:20763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnigAAABc"]
[Mon Jul 20 06:09:47.274575 2026] [security2:error] [pid 832668:tid 832823] [client 103.95.123.246:20763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnigAAABc"]
[Mon Jul 20 06:09:47.300351 2026] [security2:error] [pid 832668:tid 832920] [client 104.168.114.154:45580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.website-66dd6fc3.nextlvlmarketingco.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnjQAAAHg"]
[Mon Jul 20 06:09:47.428209 2026] [security2:error] [pid 832668:tid 832845] [client 192.236.168.43:58794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-66dd6fc3.nextlvlmarketingco.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnlwAAAC0"]
[Mon Jul 20 06:09:47.492233 2026] [security2:error] [pid 832668:tid 832899] [client 57.141.18.112:26820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmVwAAYz4"]
[Mon Jul 20 06:09:47.528927 2026] [security2:error] [pid 832668:tid 832894] [client 103.77.203.233:59911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnngAAAF4"]
[Mon Jul 20 06:09:47.529067 2026] [security2:error] [pid 832668:tid 832894] [client 103.77.203.233:59911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnngAAAF4"]
[Mon Jul 20 06:09:47.643468 2026] [security2:error] [pid 832668:tid 832917] [client 192.236.168.43:58838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.poopscoopuniversity.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnpQAAAHU"]
[Mon Jul 20 06:09:47.645545 2026] [security2:error] [pid 832668:tid 832831] [client 14.225.17.146:59545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4QC2ci6KgEEltqA3DnogAAAB8"], referer: https://keywayconstructionclt.com/WORDPRESS
[Mon Jul 20 06:09:47.693668 2026] [security2:error] [pid 832668:tid 832916] [client 14.225.17.146:53716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnJwAAAHQ"], referer: http://colinkeyphotography.com/WORDPRESS
[Mon Jul 20 06:09:47.700467 2026] [security2:error] [pid 832668:tid 832876] [client 104.234.53.74:52323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QC2ci6KgEEltqA3DnqQAAAEw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:47.741082 2026] [security2:error] [pid 832668:tid 832801] [client 185.132.186.67:63473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/memberfuns.php"] [unique_id "al4QC2ci6KgEEltqA3DnsQAAAAE"]
[Mon Jul 20 06:09:47.762085 2026] [security2:error] [pid 832668:tid 832874] [client 14.225.17.146:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnMwAAAEo"], referer: http://hammadownenterprises.com/WORDPRESS
[Mon Jul 20 06:09:47.798516 2026] [security2:error] [pid 832668:tid 832924] [client 158.173.89.95:35067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QC2ci6KgEEltqA3DnugAAAHw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:48.006594 2026] [security2:error] [pid 832668:tid 832887] [client 182.189.46.35:33035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QC2ci6KgEEltqA3DnuwAAAFc"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:48.262879 2026] [security2:error] [pid 832668:tid 832847] [client 14.225.17.146:50113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnUwAAAC8"], referer: http://careysheatingandcooling.com/WORDPRESS
[Mon Jul 20 06:09:48.900635 2026] [security2:error] [pid 832668:tid 832920] [client 103.141.108.143:53060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDGci6KgEEltqA3DoGgAAAHg"]
[Mon Jul 20 06:09:48.901230 2026] [security2:error] [pid 832668:tid 832920] [client 103.141.108.143:53060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDGci6KgEEltqA3DoGgAAAHg"]
[Mon Jul 20 06:09:48.933866 2026] [security2:error] [pid 832668:tid 832818] [client 14.225.17.146:49717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4QDGci6KgEEltqA3Dn-gAAABI"], referer: http://securingmemories.com/WORDPRESS
[Mon Jul 20 06:09:49.051236 2026] [security2:error] [pid 832668:tid 832893] [client 57.141.18.63:45348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QCWci6KgEEltqA3Dm9wAAXS8"]
[Mon Jul 20 06:09:49.216063 2026] [security2:error] [pid 832668:tid 832811] [client 14.225.17.146:59588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4QDWci6KgEEltqA3DoIwAAAAs"], referer: http://goyalsatyam.com/WORDPRESS
[Mon Jul 20 06:09:49.425118 2026] [security2:error] [pid 832668:tid 832883] [client 115.246.21.170:21310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoPgAAAFM"]
[Mon Jul 20 06:09:49.425205 2026] [security2:error] [pid 832668:tid 832883] [client 115.246.21.170:21310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoPgAAAFM"]
[Mon Jul 20 06:09:49.451137 2026] [security2:error] [pid 832668:tid 832810] [client 86.98.90.58:11726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoQAAAAAo"]
[Mon Jul 20 06:09:49.451362 2026] [security2:error] [pid 832668:tid 832810] [client 86.98.90.58:11726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoQAAAAAo"]
[Mon Jul 20 06:09:49.698990 2026] [security2:error] [pid 832668:tid 832809] [client 185.132.186.83:44831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/infos.php"] [unique_id "al4QDWci6KgEEltqA3DoTgAAAAk"]
[Mon Jul 20 06:09:49.788770 2026] [security2:error] [pid 832668:tid 832709] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoWAAAJiY"]
[Mon Jul 20 06:09:49.788923 2026] [security2:error] [pid 832668:tid 832838] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoWAAAJiY"]
[Mon Jul 20 06:09:49.878275 2026] [security2:error] [pid 832668:tid 832839] [client 57.141.18.122:50920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnUAAAJyI"]
[Mon Jul 20 06:09:49.933270 2026] [security2:error] [pid 832668:tid 832828] [client 104.234.53.66:50353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QDWci6KgEEltqA3DoYwAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:50.168467 2026] [security2:error] [pid 832668:tid 832801] [client 112.213.160.112:30983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DodgAAAAE"]
[Mon Jul 20 06:09:50.168611 2026] [security2:error] [pid 832668:tid 832801] [client 112.213.160.112:30983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DodgAAAAE"]
[Mon Jul 20 06:09:50.385869 2026] [security2:error] [pid 832668:tid 832891] [client 14.225.17.146:60254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DodAAAAFs"], referer: http://recruitinginsight.us/WORDPRESS
[Mon Jul 20 06:09:50.403578 2026] [security2:error] [pid 832668:tid 832827] [client 14.225.17.146:58708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DoiQAAABs"], referer: http://friendlyspreadsheet.com/WORDPRESS
[Mon Jul 20 06:09:50.432518 2026] [security2:error] [pid 832668:tid 832871] [client 181.224.94.124:65176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DokAAAAEc"]
[Mon Jul 20 06:09:50.432637 2026] [security2:error] [pid 832668:tid 832871] [client 181.224.94.124:65176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DokAAAAEc"]
[Mon Jul 20 06:09:50.459360 2026] [security2:error] [pid 832668:tid 832898] [client 14.225.17.146:60249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DocwAAAGI"], referer: http://webgardensbypaula.com/WORDPRESS
[Mon Jul 20 06:09:50.552721 2026] [security2:error] [pid 832668:tid 832925] [client 45.116.69.230:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DolwAAAH0"]
[Mon Jul 20 06:09:50.552851 2026] [security2:error] [pid 832668:tid 832925] [client 45.116.69.230:49173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DolwAAAH0"]
[Mon Jul 20 06:09:50.733175 2026] [security2:error] [pid 832668:tid 832707] [remote 162.19.86.63:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QDmci6KgEEltqA3DopgAAVCQ"]
[Mon Jul 20 06:09:50.775217 2026] [security2:error] [pid 832668:tid 832804] [client 14.225.17.146:58393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DonQAAAAQ"], referer: http://nextlvlmarketingco.com/WORDPRESS
[Mon Jul 20 06:09:50.923821 2026] [proxy:error] [pid 832668:tid 832846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:50.923862 2026] [proxy_http:error] [pid 832668:tid 832846] [client 8.229.28.226:47808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:50.924553 2026] [proxy:error] [pid 832668:tid 832846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:50.924582 2026] [proxy_http:error] [pid 832668:tid 832846] [client 8.229.28.226:47808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:50.941973 2026] [security2:error] [pid 832668:tid 832781] [remote 162.19.86.63:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QDmci6KgEEltqA3DowQAAF24"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:09:51.056341 2026] [security2:error] [pid 832668:tid 832819] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DotwAAABM"]
[Mon Jul 20 06:09:51.167854 2026] [security2:error] [pid 832668:tid 832710] [remote 110.249.201.119:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2021/11/final-letter-congressional-districts-plan-submission.pdf"] [unique_id "al4QD2ci6KgEEltqA3Do1AAAZyc"]
[Mon Jul 20 06:09:51.190426 2026] [security2:error] [pid 832668:tid 832920] [client 41.173.37.102:11968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do2QAAAHg"]
[Mon Jul 20 06:09:51.190528 2026] [security2:error] [pid 832668:tid 832920] [client 41.173.37.102:11968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do2QAAAHg"]
[Mon Jul 20 06:09:51.223384 2026] [security2:error] [pid 832668:tid 832917] [client 104.234.53.66:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QD2ci6KgEEltqA3Do1gAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:51.357827 2026] [security2:error] [pid 832668:tid 832808] [client 14.225.17.146:59439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4QD2ci6KgEEltqA3Do4gAAAAg"], referer: https://friendlyspreadsheet.com/WORDPRESS
[Mon Jul 20 06:09:51.646958 2026] [security2:error] [pid 832668:tid 832894] [client 185.132.186.64:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/modules/file.php"] [unique_id "al4QD2ci6KgEEltqA3Do-QAAAF4"]
[Mon Jul 20 06:09:51.769041 2026] [security2:error] [pid 832668:tid 832842] [client 106.192.104.4:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do_gAAACo"]
[Mon Jul 20 06:09:51.769187 2026] [security2:error] [pid 832668:tid 832842] [client 106.192.104.4:57060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do_gAAACo"]
[Mon Jul 20 06:09:51.891593 2026] [security2:error] [pid 832668:tid 832678] [remote 124.55.178.99:43064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QD2ci6KgEEltqA3DpEAAARwc"]
[Mon Jul 20 06:09:52.067543 2026] [security2:error] [pid 832668:tid 832754] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpIwAAQVM"]
[Mon Jul 20 06:09:52.067796 2026] [security2:error] [pid 832668:tid 832865] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpIwAAQVM"]
[Mon Jul 20 06:09:52.200664 2026] [security2:error] [pid 832668:tid 832682] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpMgAAOgs"]
[Mon Jul 20 06:09:52.200907 2026] [security2:error] [pid 832668:tid 832858] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpMgAAOgs"]
[Mon Jul 20 06:09:52.203867 2026] [security2:error] [pid 832668:tid 832872] [client 57.141.18.71:54116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QDGci6KgEEltqA3DoAgAASHc"]
[Mon Jul 20 06:09:52.353056 2026] [security2:error] [pid 832668:tid 832676] [remote 124.55.178.99:43064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QEGci6KgEEltqA3DpPgAARwU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:52.545470 2026] [security2:error] [pid 832668:tid 832865] [client 50.116.65.227:52632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QEGci6KgEEltqA3DpTQAAAEE"]
[Mon Jul 20 06:09:52.559001 2026] [security2:error] [pid 832668:tid 832821] [client 50.116.65.227:52646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QEGci6KgEEltqA3DpTgAAABU"]
[Mon Jul 20 06:09:52.585539 2026] [security2:error] [pid 832668:tid 832840] [client 14.225.17.146:53632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4QD2ci6KgEEltqA3Do5wAAACg"]
[Mon Jul 20 06:09:53.476007 2026] [security2:error] [pid 832668:tid 832823] [client 182.189.46.35:33038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QEWci6KgEEltqA3DpigAAABc"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:53.522554 2026] [security2:error] [pid 832668:tid 832903] [client 164.100.212.184:59248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QEWci6KgEEltqA3DplAAAAGc"]
[Mon Jul 20 06:09:53.522688 2026] [security2:error] [pid 832668:tid 832903] [client 164.100.212.184:59248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QEWci6KgEEltqA3DplAAAAGc"]
[Mon Jul 20 06:09:53.596003 2026] [security2:error] [pid 832668:tid 832844] [client 57.141.18.84:53690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DoeQAALGg"]
[Mon Jul 20 06:09:53.614996 2026] [security2:error] [pid 832668:tid 832809] [client 185.132.186.80:32101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/x.php"] [unique_id "al4QEWci6KgEEltqA3DpmQAAAAk"]
[Mon Jul 20 06:09:53.652709 2026] [security2:error] [pid 832668:tid 832860] [client 47.128.56.199:15304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theshakespeareconspiracy.com"] [uri "/robots.txt"] [unique_id "al4QEWci6KgEEltqA3DpnAAAADw"]
[Mon Jul 20 06:09:53.862001 2026] [security2:error] [pid 832668:tid 832745] [remote 57.141.18.25:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4QEWci6KgEEltqA3DpqAAAWko"]
[Mon Jul 20 06:09:54.038182 2026] [security2:error] [pid 832668:tid 832761] [remote 8.217.108.67:55958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4QEmci6KgEEltqA3DptAAAaVo"]
[Mon Jul 20 06:09:54.189388 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:51829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpUAAAABw"], referer: http://vinovinhowine.com/WORDPRESS
[Mon Jul 20 06:09:54.367604 2026] [security2:error] [pid 832668:tid 832921] [client 57.141.18.24:51296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DowwAAeUw"]
[Mon Jul 20 06:09:54.417337 2026] [security2:error] [pid 832668:tid 832836] [client 14.225.17.146:54810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpZgAAACQ"], referer: http://blaizeaccountingservices.com/WORDPRESS
[Mon Jul 20 06:09:54.559148 2026] [http2:info] [pid 843279:tid 843279] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:09:55.084789 2026] [security2:error] [pid 843279:tid 843298] [remote 192.241.143.148:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CNpwAAqhE"]
[Mon Jul 20 06:09:55.152436 2026] [security2:error] [pid 843279:tid 843301] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QE_qvKNcW5yy5T2CNrQAAsRQ"]
[Mon Jul 20 06:09:55.152636 2026] [security2:error] [pid 843279:tid 843454] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QE_qvKNcW5yy5T2CNrQAAsRQ"]
[Mon Jul 20 06:09:55.198518 2026] [security2:error] [pid 832668:tid 832736] [remote 57.141.18.60:43486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpNQAAEUE"]
[Mon Jul 20 06:09:55.286795 2026] [security2:error] [pid 832668:tid 832689] [remote 57.141.18.54:54976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpRwAAaxI"]
[Mon Jul 20 06:09:55.286813 2026] [security2:error] [pid 843279:tid 843308] [remote 192.241.143.148:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CNuwAA3Bs"], referer: https://soloceos.com/wp-login.php
[Mon Jul 20 06:09:55.566266 2026] [security2:error] [pid 843279:tid 843534] [client 185.132.186.81:47219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/wp.php"] [unique_id "al4QE_qvKNcW5yy5T2CNywAAAQA"]
[Mon Jul 20 06:09:55.584344 2026] [security2:error] [pid 843279:tid 843317] [remote 192.241.143.148:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CN0AAA6CQ"]
[Mon Jul 20 06:09:55.773292 2026] [security2:error] [pid 843279:tid 843324] [remote 192.241.143.148:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CN4gAAoys"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:09:55.876073 2026] [security2:error] [pid 832668:tid 832842] [client 104.234.53.47:35253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QE2ci6KgEEltqA3Dp1wAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:55.912261 2026] [security2:error] [pid 843279:tid 843438] [client 14.225.17.146:53260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QE_qvKNcW5yy5T2CN2gAAAKE"]
[Mon Jul 20 06:09:55.936153 2026] [security2:error] [pid 843279:tid 843478] [client 50.116.65.227:48248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QE_qvKNcW5yy5T2CN7QAAAMk"]
[Mon Jul 20 06:09:55.949669 2026] [security2:error] [pid 843279:tid 843483] [client 50.116.65.227:52686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QE_qvKNcW5yy5T2CN7gAAAM4"]
[Mon Jul 20 06:09:56.072574 2026] [security2:error] [pid 843279:tid 843495] [client 182.189.46.35:33039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QFPqvKNcW5yy5T2CN8QAAANo"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:56.166161 2026] [security2:error] [pid 843279:tid 843498] [client 94.154.43.178:36164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rrf.lcd.mybluehost.me"] [uri "/.env"] [unique_id "al4QFPqvKNcW5yy5T2COBgAAAN0"]
[Mon Jul 20 06:09:56.323597 2026] [security2:error] [pid 832668:tid 832760] [remote 57.141.18.89:38636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QEWci6KgEEltqA3DpkQAAfFk"]
[Mon Jul 20 06:09:56.328925 2026] [security2:error] [pid 843279:tid 843493] [client 14.225.17.146:59432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4QFPqvKNcW5yy5T2COFQAAANg"], referer: http://momheadquarters.com/WORDPRESS
[Mon Jul 20 06:09:57.053350 2026] [security2:error] [pid 843279:tid 843418] [client 192.236.168.43:33156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.absolutehomeinspections-net.nextlvlmarketingco.com"] [uri "/wp-json/batch/v1"] [unique_id "al4QFfqvKNcW5yy5T2CORAAAAI0"]
[Mon Jul 20 06:09:57.130998 2026] [security2:error] [pid 843279:tid 843454] [client 66.249.93.99:54324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4QFPqvKNcW5yy5T2COOQAAALE"]
[Mon Jul 20 06:09:57.401412 2026] [fcgid:warn] [pid 843279:tid 843443] (70014)End of file found: [client 80.87.206.20:55576] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.401897 2026] [fcgid:warn] [pid 843279:tid 843432] (70014)End of file found: [client 80.87.206.20:55572] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.402464 2026] [fcgid:warn] [pid 843279:tid 843449] (70014)End of file found: [client 80.87.206.20:55574] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.403805 2026] [fcgid:warn] [pid 843279:tid 843424] (70014)End of file found: [client 80.87.206.20:55570] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.516012 2026] [security2:error] [pid 843279:tid 843514] [client 185.132.186.97:54103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/options-writing.php"] [unique_id "al4QFfqvKNcW5yy5T2COaAAAAOw"]
[Mon Jul 20 06:09:57.954724 2026] [security2:error] [pid 843279:tid 843452] [client 103.77.203.233:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QFfqvKNcW5yy5T2COmgAAAK8"]
[Mon Jul 20 06:09:57.954861 2026] [security2:error] [pid 843279:tid 843452] [client 103.77.203.233:60436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QFfqvKNcW5yy5T2COmgAAAK8"]
[Mon Jul 20 06:09:58.082511 2026] [security2:error] [pid 843279:tid 843512] [client 57.141.18.38:64352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QE_qvKNcW5yy5T2CNwAAA6h0"]
[Mon Jul 20 06:09:58.277165 2026] [security2:error] [pid 843279:tid 843290] [remote 157.66.26.183:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QFvqvKNcW5yy5T2COrAAAoQk"]
[Mon Jul 20 06:09:58.284464 2026] [security2:error] [pid 843279:tid 843432] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2COogAAAJs"]
[Mon Jul 20 06:09:58.550284 2026] [security2:error] [pid 843279:tid 843447] [client 57.141.18.50:58336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QE_qvKNcW5yy5T2CN6AAAqi8"]
[Mon Jul 20 06:09:58.760355 2026] [security2:error] [pid 843279:tid 843304] [remote 157.66.26.183:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QFvqvKNcW5yy5T2COzQABARc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:58.816645 2026] [security2:error] [pid 843279:tid 843464] [client 103.95.123.246:21297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QFvqvKNcW5yy5T2CO3AAAALs"]
[Mon Jul 20 06:09:58.817468 2026] [security2:error] [pid 843279:tid 843464] [client 103.95.123.246:21297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QFvqvKNcW5yy5T2CO3AAAALs"]
[Mon Jul 20 06:09:59.423555 2026] [proxy:error] [pid 843279:tid 843489] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:59.423612 2026] [proxy_http:error] [pid 843279:tid 843489] [client 8.229.28.226:60868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:59.425141 2026] [proxy:error] [pid 843279:tid 843489] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:59.425184 2026] [proxy_http:error] [pid 843279:tid 843489] [client 8.229.28.226:60868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:59.451692 2026] [security2:error] [pid 843279:tid 843490] [client 185.132.186.85:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/options-reading.php"] [unique_id "al4QF_qvKNcW5yy5T2CPDwAAANU"]
[Mon Jul 20 06:09:59.578412 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPEgAAAPI"]
[Mon Jul 20 06:09:59.578576 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:53511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPEgAAAPI"]
[Mon Jul 20 06:09:59.607118 2026] [security2:error] [pid 843279:tid 843415] [client 57.141.18.97:27348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFPqvKNcW5yy5T2COPgAAil8"]
[Mon Jul 20 06:09:59.642657 2026] [security2:error] [pid 843279:tid 843463] [client 14.225.17.146:58140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2COxAAAALo"], referer: http://travelbyfire.com/WORDPRESS
[Mon Jul 20 06:09:59.781701 2026] [security2:error] [pid 843279:tid 843473] [client 57.141.18.26:60832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFfqvKNcW5yy5T2CORgAAxGM"]
[Mon Jul 20 06:09:59.939710 2026] [security2:error] [pid 843279:tid 843483] [client 115.246.21.170:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPMQAAAM4"]
[Mon Jul 20 06:09:59.939905 2026] [security2:error] [pid 843279:tid 843483] [client 115.246.21.170:61328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPMQAAAM4"]
[Mon Jul 20 06:09:59.947345 2026] [security2:error] [pid 843279:tid 843518] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "joulecommunications.com"] [uri "/index.php"] [unique_id "al4QFfqvKNcW5yy5T2COmwAAAPA"]
[Mon Jul 20 06:10:00.303543 2026] [security2:error] [pid 843279:tid 843513] [client 98.159.234.160:28643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QGPqvKNcW5yy5T2CPRwAAAOs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:00.333577 2026] [security2:error] [pid 843279:tid 843430] [client 57.141.18.116:31674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFfqvKNcW5yy5T2COcQAAmXM"]
[Mon Jul 20 06:10:00.408151 2026] [security2:error] [pid 843279:tid 843372] [remote 160.187.68.132:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QGPqvKNcW5yy5T2CPVAAA9Vs"]
[Mon Jul 20 06:10:00.444072 2026] [security2:error] [pid 843279:tid 843516] [client 104.234.53.81:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QGPqvKNcW5yy5T2CPSgAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:00.485527 2026] [security2:error] [pid 843279:tid 843382] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPZgAAoGU"]
[Mon Jul 20 06:10:00.485689 2026] [security2:error] [pid 843279:tid 843437] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPZgAAoGU"]
[Mon Jul 20 06:10:00.584225 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:12480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPcAAAAQA"]
[Mon Jul 20 06:10:00.584493 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:12480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPcAAAAQA"]
[Mon Jul 20 06:10:00.586386 2026] [security2:error] [pid 843279:tid 843495] [client 14.225.17.146:61384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2CO1QAAANo"], referer: http://mobilesurvsolutions.com/WORDPRESS
[Mon Jul 20 06:10:00.743406 2026] [security2:error] [pid 843279:tid 843477] [client 14.225.17.146:52859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4QGPqvKNcW5yy5T2CPeAAAAMg"], referer: https://travelbyfire.com/WORDPRESS
[Mon Jul 20 06:10:00.830616 2026] [security2:error] [pid 843279:tid 843456] [client 112.213.160.112:30724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPhQAAALM"]
[Mon Jul 20 06:10:00.830706 2026] [security2:error] [pid 843279:tid 843456] [client 112.213.160.112:30724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPhQAAALM"]
[Mon Jul 20 06:10:00.890121 2026] [security2:error] [pid 843279:tid 843392] [remote 160.187.68.132:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QGPqvKNcW5yy5T2CPiQAA9W8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:00.953353 2026] [security2:error] [pid 843279:tid 843432] [client 181.224.94.124:44564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPkQAAAJs"]
[Mon Jul 20 06:10:00.953513 2026] [security2:error] [pid 843279:tid 843432] [client 181.224.94.124:44564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPkQAAAJs"]
[Mon Jul 20 06:10:01.090538 2026] [security2:error] [pid 843279:tid 843482] [client 57.141.18.92:27744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2COvgAAzRg"]
[Mon Jul 20 06:10:01.222194 2026] [security2:error] [pid 843279:tid 843498] [client 104.234.53.81:24583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QGfqvKNcW5yy5T2CPqwAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:01.391591 2026] [security2:error] [pid 843279:tid 843438] [client 45.116.69.230:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CPwgAAAKE"]
[Mon Jul 20 06:10:01.391719 2026] [security2:error] [pid 843279:tid 843438] [client 45.116.69.230:49676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CPwgAAAKE"]
[Mon Jul 20 06:10:01.398951 2026] [security2:error] [pid 843279:tid 843451] [client 185.132.186.83:37797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wsad.php"] [unique_id "al4QGfqvKNcW5yy5T2CPwwAAAK4"]
[Mon Jul 20 06:10:01.862799 2026] [core:error] [pid 843279:tid 843477] [client 14.225.17.146:52045] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:01.862831 2026] [core:error] [pid 843279:tid 843477] [client 14.225.17.146:52045] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:01.957698 2026] [security2:error] [pid 843279:tid 843501] [client 41.173.37.102:12418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CP6wAAAOA"]
[Mon Jul 20 06:10:01.957814 2026] [security2:error] [pid 843279:tid 843501] [client 41.173.37.102:12418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CP6wAAAOA"]
[Mon Jul 20 06:10:01.981970 2026] [security2:error] [pid 843279:tid 843459] [client 57.141.18.31:49372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QF_qvKNcW5yy5T2CO6gAAtiw"]
[Mon Jul 20 06:10:02.112491 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:57564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CP8wAAALA"]
[Mon Jul 20 06:10:02.112653 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:57564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CP8wAAALA"]
[Mon Jul 20 06:10:02.683049 2026] [security2:error] [pid 843279:tid 843419] [client 14.225.17.146:64392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4QGfqvKNcW5yy5T2CPsgAAAI4"], referer: http://windowtx.com/WORDPRESS
[Mon Jul 20 06:10:02.729037 2026] [security2:error] [pid 843279:tid 843326] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQIAAArS0"]
[Mon Jul 20 06:10:02.729222 2026] [security2:error] [pid 843279:tid 843450] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQIAAArS0"]
[Mon Jul 20 06:10:02.843009 2026] [security2:error] [pid 843279:tid 843366] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQJwAAr1U"]
[Mon Jul 20 06:10:02.843210 2026] [security2:error] [pid 843279:tid 843452] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQJwAAr1U"]
[Mon Jul 20 06:10:02.878229 2026] [access_compat:error] [pid 843279:tid 843475] [client 183.47.122.163:54687] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:10:03.385866 2026] [security2:error] [pid 843279:tid 843380] [remote 57.141.18.79:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5490371"] [unique_id "al4QG_qvKNcW5yy5T2CQVwAAsmM"]
[Mon Jul 20 06:10:03.390116 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.83:54775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QG_qvKNcW5yy5T2CQVQAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:03.414136 2026] [security2:error] [pid 843279:tid 843474] [client 185.132.186.101:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/nation.php"] [unique_id "al4QG_qvKNcW5yy5T2CQXQAAAMU"]
[Mon Jul 20 06:10:03.435443 2026] [security2:error] [pid 843279:tid 843456] [client 50.116.65.227:50118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QG_qvKNcW5yy5T2CQXwAAALM"]
[Mon Jul 20 06:10:03.445474 2026] [security2:error] [pid 843279:tid 843431] [client 50.116.65.227:50126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QG_qvKNcW5yy5T2CQYgAAAJo"]
[Mon Jul 20 06:10:03.580662 2026] [security2:error] [pid 843279:tid 843417] [client 14.225.17.146:60528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4QG_qvKNcW5yy5T2CQWAAAAIw"], referer: http://elitetax-mi.com/WORDPRESS
[Mon Jul 20 06:10:03.992931 2026] [security2:error] [pid 843279:tid 843361] [remote 124.55.178.99:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QG_qvKNcW5yy5T2CQjgAA8FA"]
[Mon Jul 20 06:10:04.164412 2026] [security2:error] [pid 843279:tid 843512] [client 164.100.212.184:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QHPqvKNcW5yy5T2CQoQAAAOo"]
[Mon Jul 20 06:10:04.164510 2026] [security2:error] [pid 843279:tid 843512] [client 164.100.212.184:64961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QHPqvKNcW5yy5T2CQoQAAAOo"]
[Mon Jul 20 06:10:04.253674 2026] [security2:error] [pid 843279:tid 843516] [client 57.141.18.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QHPqvKNcW5yy5T2CQnAAAAO4"]
[Mon Jul 20 06:10:04.435622 2026] [security2:error] [pid 843279:tid 843449] [client 14.225.17.146:60882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4QG_qvKNcW5yy5T2CQSgAAAKw"], referer: http://betterbonddogtraining.com/WORDPRESS
[Mon Jul 20 06:10:04.547200 2026] [security2:error] [pid 843279:tid 843423] [client 57.141.18.119:37574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QGfqvKNcW5yy5T2CPxAAAkh0"]
[Mon Jul 20 06:10:04.566738 2026] [security2:error] [pid 843279:tid 843348] [remote 124.55.178.99:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QHPqvKNcW5yy5T2CQxwAA8UM"], referer: https://sarakety.com/wp-login.php
[Mon Jul 20 06:10:05.197261 2026] [security2:error] [pid 843279:tid 843474] [client 213.230.116.128:58991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marscafe.com"] [uri "/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRBgAAAMU"]
[Mon Jul 20 06:10:05.375150 2026] [security2:error] [pid 843279:tid 843493] [client 185.132.186.91:37681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/codemirror/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CREgAAANg"]
[Mon Jul 20 06:10:05.702866 2026] [security2:error] [pid 843279:tid 843325] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRMgAAuCw"]
[Mon Jul 20 06:10:05.703116 2026] [security2:error] [pid 843279:tid 843461] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRMgAAuCw"]
[Mon Jul 20 06:10:05.776678 2026] [security2:error] [pid 843279:tid 843473] [client 195.2.79.165:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.79.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QHfqvKNcW5yy5T2CROQAAAMQ"], referer: https://thslogistics.net/
[Mon Jul 20 06:10:05.831647 2026] [security2:error] [pid 843279:tid 843410] [client 104.234.53.61:32085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRNgAAAIU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:05.927056 2026] [security2:error] [pid 843279:tid 843467] [client 14.225.17.146:51978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRFQAAAL4"], referer: http://uritems.net/WORDPRESS
[Mon Jul 20 06:10:05.999969 2026] [security2:error] [pid 843279:tid 843534] [client 27.96.94.195:36852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRSwAAAQA"]
[Mon Jul 20 06:10:06.000167 2026] [security2:error] [pid 843279:tid 843534] [client 27.96.94.195:36852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRSwAAAQA"]
[Mon Jul 20 06:10:06.030841 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.61:32085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QHvqvKNcW5yy5T2CRTgAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:06.244797 2026] [core:error] [pid 843279:tid 843483] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:06.244826 2026] [core:error] [pid 843279:tid 843483] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:06.293216 2026] [security2:error] [pid 843279:tid 843416] [client 158.173.166.181:64251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QHvqvKNcW5yy5T2CRagAAAIs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:06.475893 2026] [security2:error] [pid 843279:tid 843437] [client 66.249.88.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nandansonscharitablefoundation.com"] [uri "/index.php"] [unique_id "al4QHPqvKNcW5yy5T2CQwAAAAKA"]
[Mon Jul 20 06:10:06.728226 2026] [security2:error] [pid 843279:tid 843534] [client 14.225.17.146:60454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CReQAAAQA"]
[Mon Jul 20 06:10:07.104907 2026] [security2:error] [pid 843279:tid 843380] [remote 8.217.108.67:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CRtAAA8WM"], referer: https://giftofgiving-usa.org/wp-login.php
[Mon Jul 20 06:10:07.131367 2026] [security2:error] [pid 843279:tid 843376] [remote 124.55.178.99:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CRtgAAil8"]
[Mon Jul 20 06:10:07.223769 2026] [security2:error] [pid 843279:tid 843355] [remote 130.185.118.215:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CRvgAAlUo"]
[Mon Jul 20 06:10:07.317424 2026] [security2:error] [pid 843279:tid 843451] [client 185.132.186.104:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp_class_datlib.php"] [unique_id "al4QH_qvKNcW5yy5T2CRygAAAK4"]
[Mon Jul 20 06:10:07.592995 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:61538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRdwAAANs"], referer: http://ravmike.com/WORDPRESS
[Mon Jul 20 06:10:07.594693 2026] [security2:error] [pid 843279:tid 843357] [remote 124.55.178.99:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CR2QAAmUw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:07.604718 2026] [security2:error] [pid 843279:tid 843360] [remote 130.185.118.215:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CR2wAA8E8"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:07.710343 2026] [security2:error] [pid 843279:tid 843507] [client 66.249.79.166:48429] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.heroesoftomorrow.us"] [uri "/robots.txt"] [unique_id "al4QH_qvKNcW5yy5T2CR7AAAAOU"]
[Mon Jul 20 06:10:08.068894 2026] [security2:error] [pid 843279:tid 843440] [client 57.141.18.66:27636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QHPqvKNcW5yy5T2CQ1wAAo20"]
[Mon Jul 20 06:10:08.194665 2026] [security2:error] [pid 843279:tid 843491] [client 14.225.17.146:61534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRdQAAANY"], referer: http://ksands.co.uk/WORDPRESS
[Mon Jul 20 06:10:08.259883 2026] [security2:error] [pid 843279:tid 843530] [client 14.225.17.146:60535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRjwAAAPw"], referer: http://headachescarpaltunnelfibromyalgia.com/WORDPRESS
[Mon Jul 20 06:10:08.451700 2026] [security2:error] [pid 843279:tid 843471] [client 103.77.203.233:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSHgAAAMI"]
[Mon Jul 20 06:10:08.452114 2026] [security2:error] [pid 843279:tid 843471] [client 103.77.203.233:60964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSHgAAAMI"]
[Mon Jul 20 06:10:08.616953 2026] [security2:error] [pid 843279:tid 843520] [client 14.225.17.146:61272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4QIPqvKNcW5yy5T2CSIQAAAPI"], referer: https://ravmike.com/WORDPRESS
[Mon Jul 20 06:10:08.698647 2026] [security2:error] [pid 843279:tid 843523] [client 57.141.18.84:34440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRFwAA9Xc"]
[Mon Jul 20 06:10:08.767449 2026] [security2:error] [pid 843279:tid 843395] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNAAAjXI"]
[Mon Jul 20 06:10:08.767680 2026] [security2:error] [pid 843279:tid 843418] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNAAAjXI"]
[Mon Jul 20 06:10:08.776189 2026] [security2:error] [pid 843279:tid 843294] [remote 38.242.157.30:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNwABAg0"]
[Mon Jul 20 06:10:08.776394 2026] [security2:error] [pid 843279:tid 843536] [client 38.242.157.30:33342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNwABAg0"]
[Mon Jul 20 06:10:08.957083 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4QIPqvKNcW5yy5T2CSRgAA6n4"]
[Mon Jul 20 06:10:08.957391 2026] [security2:error] [pid 843279:tid 843512] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4QIPqvKNcW5yy5T2CSRgAA6n4"]
[Mon Jul 20 06:10:09.076166 2026] [security2:error] [pid 843279:tid 843461] [client 14.225.17.146:60597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRfwAAALg"], referer: http://onewingpictures.com/WORDPRESS
[Mon Jul 20 06:10:09.260536 2026] [security2:error] [pid 843279:tid 843422] [client 185.132.186.76:47091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/tinymce/langs/about.php"] [unique_id "al4QIfqvKNcW5yy5T2CSYwAAAJE"]
[Mon Jul 20 06:10:09.549494 2026] [security2:error] [pid 843279:tid 843325] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/media.php"] [unique_id "al4QIfqvKNcW5yy5T2CSgwABASw"]
[Mon Jul 20 06:10:09.549719 2026] [security2:error] [pid 843279:tid 843535] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/media.php"] [unique_id "al4QIfqvKNcW5yy5T2CSgwABASw"]
[Mon Jul 20 06:10:09.736838 2026] [security2:error] [pid 843279:tid 843303] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/images.php"] [unique_id "al4QIfqvKNcW5yy5T2CShgAAtxY"]
[Mon Jul 20 06:10:09.737054 2026] [security2:error] [pid 843279:tid 843460] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/images.php"] [unique_id "al4QIfqvKNcW5yy5T2CShgAAtxY"]
[Mon Jul 20 06:10:09.804846 2026] [security2:error] [pid 843279:tid 843418] [client 43.173.181.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CSbwAAAI0"]
[Mon Jul 20 06:10:09.932580 2026] [security2:error] [pid 843279:tid 843416] [client 193.19.109.212:59797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4QIfqvKNcW5yy5T2CSlQAAAIs"]
[Mon Jul 20 06:10:09.965033 2026] [security2:error] [pid 843279:tid 843461] [client 193.19.109.227:47287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4QIfqvKNcW5yy5T2CSlgAAALg"]
[Mon Jul 20 06:10:09.989138 2026] [security2:error] [pid 843279:tid 843288] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/gecko.php"] [unique_id "al4QIfqvKNcW5yy5T2CSoQAArgc"]
[Mon Jul 20 06:10:09.989418 2026] [security2:error] [pid 843279:tid 843451] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/gecko.php"] [unique_id "al4QIfqvKNcW5yy5T2CSoQAArgc"]
[Mon Jul 20 06:10:10.095085 2026] [security2:error] [pid 843279:tid 843425] [client 14.225.17.146:64609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CScQAAAJQ"], referer: http://idigress.studio/WORDPRESS
[Mon Jul 20 06:10:10.114654 2026] [security2:error] [pid 843279:tid 843511] [client 57.141.18.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CSnwAAAOk"]
[Mon Jul 20 06:10:10.178439 2026] [security2:error] [pid 843279:tid 843304] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/82.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqQAAyBc"]
[Mon Jul 20 06:10:10.178639 2026] [security2:error] [pid 843279:tid 843477] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/82.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqQAAyBc"]
[Mon Jul 20 06:10:10.184588 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:17897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqgAAAMo"]
[Mon Jul 20 06:10:10.184704 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:17897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqgAAAMo"]
[Mon Jul 20 06:10:10.273920 2026] [security2:error] [pid 843279:tid 843494] [client 57.141.18.94:59344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QH_qvKNcW5yy5T2CRvwAA2T0"]
[Mon Jul 20 06:10:10.346246 2026] [security2:error] [pid 843279:tid 843517] [client 103.141.108.143:53983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CStgAAAO8"]
[Mon Jul 20 06:10:10.347285 2026] [security2:error] [pid 843279:tid 843517] [client 103.141.108.143:53983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CStgAAAO8"]
[Mon Jul 20 06:10:10.455847 2026] [security2:error] [pid 843279:tid 843327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QIvqvKNcW5yy5T2CSxQAAly4"]
[Mon Jul 20 06:10:10.456033 2026] [security2:error] [pid 843279:tid 843428] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QIvqvKNcW5yy5T2CSxQAAly4"]
[Mon Jul 20 06:10:10.608882 2026] [security2:error] [pid 843279:tid 843530] [client 115.246.21.170:21729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSzQAAAPw"]
[Mon Jul 20 06:10:10.609008 2026] [security2:error] [pid 843279:tid 843530] [client 115.246.21.170:21729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSzQAAAPw"]
[Mon Jul 20 06:10:10.704226 2026] [security2:error] [pid 843279:tid 843468] [client 103.153.183.69:27498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//....//var/www/html/wp-config.php"] [unique_id "al4QIvqvKNcW5yy5T2CS0wAAAL8"], referer: https://twitter.com/
[Mon Jul 20 06:10:10.835421 2026] [security2:error] [pid 843279:tid 843331] [remote 74.235.96.117:36242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CS3gAAzTI"]
[Mon Jul 20 06:10:10.835732 2026] [security2:error] [pid 843279:tid 843482] [client 74.235.96.117:36242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CS3gAAzTI"]
[Mon Jul 20 06:10:11.015088 2026] [security2:error] [pid 843279:tid 843493] [client 50.116.65.227:31532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QI_qvKNcW5yy5T2CS7gAAANg"]
[Mon Jul 20 06:10:11.028810 2026] [security2:error] [pid 843279:tid 843471] [client 50.116.65.227:57428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QI_qvKNcW5yy5T2CS8AAAAMI"]
[Mon Jul 20 06:10:11.121837 2026] [security2:error] [pid 843279:tid 843343] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/adminner.php"] [unique_id "al4QI_qvKNcW5yy5T2CS8gAA5j4"]
[Mon Jul 20 06:10:11.122023 2026] [security2:error] [pid 843279:tid 843508] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/adminner.php"] [unique_id "al4QI_qvKNcW5yy5T2CS8gAA5j4"]
[Mon Jul 20 06:10:11.203553 2026] [security2:error] [pid 843279:tid 843492] [client 185.132.186.95:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/autoload_classmap/wso.php"] [unique_id "al4QI_qvKNcW5yy5T2CS9wAAANc"]
[Mon Jul 20 06:10:11.404595 2026] [security2:error] [pid 843279:tid 843344] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTBwAA6T8"]
[Mon Jul 20 06:10:11.404775 2026] [security2:error] [pid 843279:tid 843511] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTBwAA6T8"]
[Mon Jul 20 06:10:11.496562 2026] [security2:error] [pid 843279:tid 843514] [client 181.224.94.124:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTEwAAAOw"]
[Mon Jul 20 06:10:11.496665 2026] [security2:error] [pid 843279:tid 843514] [client 181.224.94.124:49208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTEwAAAOw"]
[Mon Jul 20 06:10:11.537333 2026] [security2:error] [pid 843279:tid 843414] [client 112.213.160.112:31163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTFgAAAIk"]
[Mon Jul 20 06:10:11.537444 2026] [security2:error] [pid 843279:tid 843414] [client 112.213.160.112:31163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTFgAAAIk"]
[Mon Jul 20 06:10:11.561917 2026] [security2:error] [pid 843279:tid 843450] [client 57.141.18.96:60738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIPqvKNcW5yy5T2CSJgAArWw"]
[Mon Jul 20 06:10:11.599655 2026] [security2:error] [pid 843279:tid 843520] [client 86.98.90.58:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTGQAAAPI"]
[Mon Jul 20 06:10:11.599789 2026] [security2:error] [pid 843279:tid 843520] [client 86.98.90.58:13252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTGQAAAPI"]
[Mon Jul 20 06:10:11.723965 2026] [security2:error] [pid 843279:tid 843515] [client 37.236.31.34:46368] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4QI_qvKNcW5yy5T2CTIwAAAO0"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 06:10:11.858358 2026] [security2:error] [pid 843279:tid 843481] [client 104.234.53.94:44591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QI_qvKNcW5yy5T2CTMwAAAMw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:11.888652 2026] [security2:error] [pid 843279:tid 843354] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QI_qvKNcW5yy5T2CTNQAAvUk"]
[Mon Jul 20 06:10:11.888917 2026] [security2:error] [pid 843279:tid 843466] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QI_qvKNcW5yy5T2CTNQAAvUk"]
[Mon Jul 20 06:10:12.028704 2026] [security2:error] [pid 843279:tid 843508] [client 45.116.69.230:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTQgAAAOY"]
[Mon Jul 20 06:10:12.028806 2026] [security2:error] [pid 843279:tid 843508] [client 45.116.69.230:50173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTQgAAAOY"]
[Mon Jul 20 06:10:12.241521 2026] [security2:error] [pid 843279:tid 843412] [client 87.199.196.160:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4QJPqvKNcW5yy5T2CTTwAAAIc"], referer: https://www.friendlyspreadsheet.com/guide-to-getting-pros/
[Mon Jul 20 06:10:12.241661 2026] [security2:error] [pid 843279:tid 843412] [client 87.199.196.160:64740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4QJPqvKNcW5yy5T2CTTwAAAIc"], referer: https://www.friendlyspreadsheet.com/guide-to-getting-pros/
[Mon Jul 20 06:10:12.259860 2026] [security2:error] [pid 843279:tid 843364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJPqvKNcW5yy5T2CTVAAA91M"]
[Mon Jul 20 06:10:12.260123 2026] [security2:error] [pid 843279:tid 843525] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJPqvKNcW5yy5T2CTVAAA91M"]
[Mon Jul 20 06:10:12.260684 2026] [security2:error] [pid 843279:tid 843433] [client 14.225.17.146:54207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4QJPqvKNcW5yy5T2CTSAAAAJw"], referer: http://lutheranphilosopher.com/WORDPRESS
[Mon Jul 20 06:10:12.457035 2026] [security2:error] [pid 843279:tid 843371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/blurbs.php"] [unique_id "al4QJPqvKNcW5yy5T2CTZwAAjVo"]
[Mon Jul 20 06:10:12.457252 2026] [security2:error] [pid 843279:tid 843418] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/blurbs.php"] [unique_id "al4QJPqvKNcW5yy5T2CTZwAAjVo"]
[Mon Jul 20 06:10:12.531023 2026] [security2:error] [pid 843279:tid 843502] [client 41.173.37.102:12862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTbgAAAOE"]
[Mon Jul 20 06:10:12.531149 2026] [security2:error] [pid 843279:tid 843502] [client 41.173.37.102:12862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTbgAAAOE"]
[Mon Jul 20 06:10:12.671128 2026] [security2:error] [pid 843279:tid 843293] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/bajah.php"] [unique_id "al4QJPqvKNcW5yy5T2CTgAAApQw"]
[Mon Jul 20 06:10:12.671335 2026] [security2:error] [pid 843279:tid 843442] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/bajah.php"] [unique_id "al4QJPqvKNcW5yy5T2CTgAAApQw"]
[Mon Jul 20 06:10:12.827001 2026] [security2:error] [pid 843279:tid 843457] [client 57.141.18.61:21240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CShQAAtBQ"]
[Mon Jul 20 06:10:12.872259 2026] [security2:error] [pid 843279:tid 843529] [client 178.152.178.232:36977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTiwAAAPs"]
[Mon Jul 20 06:10:12.872375 2026] [security2:error] [pid 843279:tid 843529] [client 178.152.178.232:36977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTiwAAAPs"]
[Mon Jul 20 06:10:12.919011 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/a.php"] [unique_id "al4QJPqvKNcW5yy5T2CTlAABBH4"]
[Mon Jul 20 06:10:12.919222 2026] [security2:error] [pid 843279:tid 843538] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/a.php"] [unique_id "al4QJPqvKNcW5yy5T2CTlAABBH4"]
[Mon Jul 20 06:10:13.111594 2026] [security2:error] [pid 843279:tid 843317] [remote 8.217.108.67:26046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QJfqvKNcW5yy5T2CTogAA9CQ"]
[Mon Jul 20 06:10:13.166843 2026] [security2:error] [pid 843279:tid 843422] [client 185.132.186.57:46267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-atomx.php"] [unique_id "al4QJfqvKNcW5yy5T2CTpQAAAJE"]
[Mon Jul 20 06:10:13.213031 2026] [security2:error] [pid 843279:tid 843517] [client 27.85.1.30:20005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTpwAAAO8"]
[Mon Jul 20 06:10:13.362618 2026] [security2:error] [pid 843279:tid 843402] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTtwAAtHk"]
[Mon Jul 20 06:10:13.362784 2026] [security2:error] [pid 843279:tid 843457] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTtwAAtHk"]
[Mon Jul 20 06:10:13.382245 2026] [security2:error] [pid 843279:tid 843444] [client 92.77.225.20:41488] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTtAAAAKc"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 06:10:13.416940 2026] [security2:error] [pid 843279:tid 843535] [client 14.225.17.146:62654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4QJPqvKNcW5yy5T2CTTgAAAQE"], referer: http://northbrookcpa.ca/WORDPRESS
[Mon Jul 20 06:10:13.503761 2026] [security2:error] [pid 843279:tid 843330] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTwAAA0TE"]
[Mon Jul 20 06:10:13.503925 2026] [security2:error] [pid 843279:tid 843486] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTwAAA0TE"]
[Mon Jul 20 06:10:13.508569 2026] [security2:error] [pid 843279:tid 843500] [client 27.85.1.30:19129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTwQAAAN8"]
[Mon Jul 20 06:10:13.797409 2026] [security2:error] [pid 843279:tid 843419] [client 27.85.1.30:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CT0AAAAI4"]
[Mon Jul 20 06:10:14.041443 2026] [security2:error] [pid 843279:tid 843300] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/edit.php"] [unique_id "al4QJvqvKNcW5yy5T2CT5wAA1xM"]
[Mon Jul 20 06:10:14.041601 2026] [security2:error] [pid 843279:tid 843492] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/edit.php"] [unique_id "al4QJvqvKNcW5yy5T2CT5wAA1xM"]
[Mon Jul 20 06:10:14.044048 2026] [security2:error] [pid 843279:tid 843503] [client 57.141.18.80:46818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIvqvKNcW5yy5T2CS1QAA4jU"]
[Mon Jul 20 06:10:14.124070 2026] [security2:error] [pid 843279:tid 843509] [client 27.85.1.30:34312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CT7wAAAOc"]
[Mon Jul 20 06:10:14.140698 2026] [security2:error] [pid 843279:tid 843479] [client 57.141.18.101:59370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIvqvKNcW5yy5T2CS3wAAygY"]
[Mon Jul 20 06:10:14.170954 2026] [security2:error] [pid 843279:tid 843442] [client 193.37.33.232:29055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4QJvqvKNcW5yy5T2CT8gAAAKU"]
[Mon Jul 20 06:10:14.230876 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/hosty.php"] [unique_id "al4QJvqvKNcW5yy5T2CT_AAAzh8"]
[Mon Jul 20 06:10:14.231081 2026] [security2:error] [pid 843279:tid 843483] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/hosty.php"] [unique_id "al4QJvqvKNcW5yy5T2CT_AAAzh8"]
[Mon Jul 20 06:10:14.321813 2026] [security2:error] [pid 843279:tid 843292] [remote 8.217.108.67:26046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QJvqvKNcW5yy5T2CUAAAAmQs"], referer: https://zoa.jji.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:14.418585 2026] [security2:error] [pid 843279:tid 843336] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBgAAvzc"]
[Mon Jul 20 06:10:14.418808 2026] [security2:error] [pid 843279:tid 843468] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBgAAvzc"]
[Mon Jul 20 06:10:14.424556 2026] [security2:error] [pid 843279:tid 843497] [client 27.85.1.30:23940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBwAAANw"]
[Mon Jul 20 06:10:14.554039 2026] [security2:error] [pid 843279:tid 843420] [client 106.192.104.4:58069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUEgAAAI8"]
[Mon Jul 20 06:10:14.554231 2026] [security2:error] [pid 843279:tid 843420] [client 106.192.104.4:58069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUEgAAAI8"]
[Mon Jul 20 06:10:14.606540 2026] [security2:error] [pid 843279:tid 843331] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QJvqvKNcW5yy5T2CUFwAAuTI"]
[Mon Jul 20 06:10:14.606797 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QJvqvKNcW5yy5T2CUFwAAuTI"]
[Mon Jul 20 06:10:14.624741 2026] [security2:error] [pid 843279:tid 843535] [client 14.225.17.146:61767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBAAAAQE"], referer: http://idigress.agency/WORDPRESS
[Mon Jul 20 06:10:14.757160 2026] [security2:error] [pid 843279:tid 843432] [client 27.85.1.30:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUJAAAAJs"]
[Mon Jul 20 06:10:14.801946 2026] [security2:error] [pid 843279:tid 843339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file5.php"] [unique_id "al4QJvqvKNcW5yy5T2CUJwAAiDo"]
[Mon Jul 20 06:10:14.802151 2026] [security2:error] [pid 843279:tid 843413] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file5.php"] [unique_id "al4QJvqvKNcW5yy5T2CUJwAAiDo"]
[Mon Jul 20 06:10:14.802469 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUKAAAALc"]
[Mon Jul 20 06:10:14.802585 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:49165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUKAAAALc"]
[Mon Jul 20 06:10:14.946209 2026] [security2:error] [pid 843279:tid 843502] [client 14.225.17.146:54086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTrgAAAOE"], referer: http://amalia-capital.com/WORDPRESS
[Mon Jul 20 06:10:15.022133 2026] [security2:error] [pid 843279:tid 843358] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/222.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUOwAA7E0"]
[Mon Jul 20 06:10:15.022396 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/222.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUOwAA7E0"]
[Mon Jul 20 06:10:15.098174 2026] [security2:error] [pid 843279:tid 843448] [client 185.132.186.61:28095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin-footer.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUQQAAAKs"]
[Mon Jul 20 06:10:15.107851 2026] [security2:error] [pid 843279:tid 843427] [client 27.85.1.30:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUQwAAAJY"]
[Mon Jul 20 06:10:15.215396 2026] [security2:error] [pid 843279:tid 843357] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/test.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUTgAAkkw"]
[Mon Jul 20 06:10:15.215612 2026] [security2:error] [pid 843279:tid 843423] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/test.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUTgAAkkw"]
[Mon Jul 20 06:10:15.395854 2026] [security2:error] [pid 843279:tid 843461] [client 27.85.1.30:34946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUWgAAALg"]
[Mon Jul 20 06:10:15.414120 2026] [security2:error] [pid 843279:tid 843315] [remote 194.164.192.228:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUXAAA1yI"]
[Mon Jul 20 06:10:15.414331 2026] [security2:error] [pid 843279:tid 843419] [client 104.234.53.53:64587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUVAAAAI4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:15.414337 2026] [security2:error] [pid 843279:tid 843492] [client 194.164.192.228:33700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUXAAA1yI"]
[Mon Jul 20 06:10:15.645049 2026] [security2:error] [pid 843279:tid 843350] [remote 182.77.62.24:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUdwAArkU"]
[Mon Jul 20 06:10:15.652660 2026] [security2:error] [pid 843279:tid 843457] [client 14.225.17.146:63489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUZwAAALQ"], referer: http://olearyplumbingllc.com/WORDPRESS
[Mon Jul 20 06:10:15.680602 2026] [security2:error] [pid 843279:tid 843518] [client 27.85.1.30:40553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUfQAAAPA"]
[Mon Jul 20 06:10:15.742988 2026] [security2:error] [pid 843279:tid 843418] [client 50.116.65.227:31538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_d9d7fe47/wp-cron.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUgwAAAI0"]
[Mon Jul 20 06:10:15.784550 2026] [security2:error] [pid 843279:tid 843390] [remote 110.249.201.89:61808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/"] [unique_id "al4QJ_qvKNcW5yy5T2CUhAAAwG0"]
[Mon Jul 20 06:10:15.812674 2026] [security2:error] [pid 843279:tid 843459] [client 212.47.238.7:34902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail-box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4QJ_qvKNcW5yy5T2CUhgAAALY"]
[Mon Jul 20 06:10:15.991795 2026] [security2:error] [pid 843279:tid 843464] [client 27.85.1.30:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUmgAAALs"]
[Mon Jul 20 06:10:16.001734 2026] [security2:error] [pid 843279:tid 843480] [client 92.209.171.215:8533] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUlwAAAMs"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 06:10:16.180003 2026] [security2:error] [pid 843279:tid 843387] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QKPqvKNcW5yy5T2CUqwABBGo"]
[Mon Jul 20 06:10:16.180183 2026] [security2:error] [pid 843279:tid 843538] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QKPqvKNcW5yy5T2CUqwABBGo"]
[Mon Jul 20 06:10:16.244274 2026] [security2:error] [pid 843279:tid 843491] [client 74.208.214.194:42734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QKPqvKNcW5yy5T2CUswAAANY"]
[Mon Jul 20 06:10:16.262432 2026] [security2:error] [pid 843279:tid 843348] [remote 182.77.62.24:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QKPqvKNcW5yy5T2CUtAAA3UM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:16.313474 2026] [security2:error] [pid 843279:tid 843459] [client 27.85.1.30:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CUugAAALY"]
[Mon Jul 20 06:10:16.452557 2026] [security2:error] [pid 843279:tid 843393] [remote 91.142.222.105:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4QKPqvKNcW5yy5T2CUvwAAvHA"]
[Mon Jul 20 06:10:16.494388 2026] [security2:error] [pid 843279:tid 843414] [client 57.141.18.15:25152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTrwAAiX8"]
[Mon Jul 20 06:10:16.521541 2026] [proxy:error] [pid 843279:tid 843453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:16.521576 2026] [proxy_http:error] [pid 843279:tid 843453] [client 20.74.45.95:59509] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:16.522159 2026] [proxy:error] [pid 843279:tid 843453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:16.522185 2026] [proxy_http:error] [pid 843279:tid 843453] [client 20.74.45.95:59509] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:16.565468 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QKPqvKNcW5yy5T2CUzAAA9n4"]
[Mon Jul 20 06:10:16.565657 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QKPqvKNcW5yy5T2CUzAAA9n4"]
[Mon Jul 20 06:10:16.634190 2026] [security2:error] [pid 843279:tid 843468] [client 27.85.1.30:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CU0AAAAL8"]
[Mon Jul 20 06:10:16.768374 2026] [security2:error] [pid 843279:tid 843283] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QKPqvKNcW5yy5T2CU5AAAowI"]
[Mon Jul 20 06:10:16.768554 2026] [security2:error] [pid 843279:tid 843440] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QKPqvKNcW5yy5T2CU5AAAowI"]
[Mon Jul 20 06:10:16.958034 2026] [security2:error] [pid 843279:tid 843306] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/mac.php"] [unique_id "al4QKPqvKNcW5yy5T2CU7wAAjxk"]
[Mon Jul 20 06:10:16.958235 2026] [security2:error] [pid 843279:tid 843420] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/mac.php"] [unique_id "al4QKPqvKNcW5yy5T2CU7wAAjxk"]
[Mon Jul 20 06:10:16.963976 2026] [security2:error] [pid 843279:tid 843528] [client 27.85.1.30:30209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CU8AAAAPo"]
[Mon Jul 20 06:10:16.973233 2026] [security2:error] [pid 843279:tid 843444] [client 121.188.194.82:59418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sarakety.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al4QKPqvKNcW5yy5T2CU8wAAAKc"]
[Mon Jul 20 06:10:17.053296 2026] [security2:error] [pid 843279:tid 843496] [client 185.132.186.100:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/wp-conflg.php"] [unique_id "al4QKfqvKNcW5yy5T2CU-gAAANs"]
[Mon Jul 20 06:10:17.287845 2026] [security2:error] [pid 843279:tid 843499] [client 27.85.1.30:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKfqvKNcW5yy5T2CVDwAAAN4"]
[Mon Jul 20 06:10:17.314300 2026] [security2:error] [pid 843279:tid 843309] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/chosen.php"] [unique_id "al4QKfqvKNcW5yy5T2CVFQAAvBw"]
[Mon Jul 20 06:10:17.314463 2026] [security2:error] [pid 843279:tid 843465] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/chosen.php"] [unique_id "al4QKfqvKNcW5yy5T2CVFQAAvBw"]
[Mon Jul 20 06:10:17.459414 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QKfqvKNcW5yy5T2CVIQAAAN0"]
[Mon Jul 20 06:10:17.459590 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QKfqvKNcW5yy5T2CVIQAAAN0"]
[Mon Jul 20 06:10:17.571359 2026] [security2:error] [pid 843279:tid 843499] [client 104.234.53.53:64587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVJgAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:17.615898 2026] [security2:error] [pid 843279:tid 843531] [client 14.225.17.146:63427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CUoQAAAP0"], referer: http://alexsandbergmusic.com/WORDPRESS
[Mon Jul 20 06:10:17.740850 2026] [security2:error] [pid 843279:tid 843491] [client 13.215.47.127:35236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVMgAAANY"]
[Mon Jul 20 06:10:17.825689 2026] [security2:error] [pid 843279:tid 843313] [remote 91.142.222.105:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVOwAAiSA"], referer: https://mail.legallyknownaszacharyhoy999.com/wp-login.php
[Mon Jul 20 06:10:18.023704 2026] [security2:error] [pid 843279:tid 843470] [client 57.141.18.89:26452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUCwAAwRs"]
[Mon Jul 20 06:10:18.076627 2026] [security2:error] [pid 843279:tid 843292] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/cream1.php"] [unique_id "al4QKvqvKNcW5yy5T2CVUAAA3As"]
[Mon Jul 20 06:10:18.076777 2026] [security2:error] [pid 843279:tid 843497] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/cream1.php"] [unique_id "al4QKvqvKNcW5yy5T2CVUAAA3As"]
[Mon Jul 20 06:10:18.103847 2026] [security2:error] [pid 843279:tid 843514] [client 14.225.17.146:63473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CU5wAAAOw"], referer: http://wathenbartlett.co.uk/WORDPRESS
[Mon Jul 20 06:10:18.282977 2026] [security2:error] [pid 843279:tid 843530] [client 121.188.194.82:59420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVQQAAAPw"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:18.328205 2026] [security2:error] [pid 843279:tid 843478] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-content/uploads/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVYwAAyTI"]
[Mon Jul 20 06:10:18.597765 2026] [security2:error] [pid 843279:tid 843454] [client 186.216.45.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVZQAAALE"]
[Mon Jul 20 06:10:18.613480 2026] [security2:error] [pid 843279:tid 843351] [remote 81.173.115.7:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "katsklar.com"] [uri "/wp-login.php"] [unique_id "al4QKvqvKNcW5yy5T2CVgQAA9UY"]
[Mon Jul 20 06:10:18.669161 2026] [security2:error] [pid 843279:tid 843469] [client 104.234.53.61:64781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QKvqvKNcW5yy5T2CVfgAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:18.725206 2026] [autoindex:error] [pid 843279:tid 843372] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:18.725792 2026] [security2:error] [pid 843279:tid 843489] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/Text/"] [unique_id "al4QKvqvKNcW5yy5T2CVhwAA1Fs"]
[Mon Jul 20 06:10:18.857784 2026] [security2:error] [pid 843279:tid 843534] [client 104.234.53.61:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QKvqvKNcW5yy5T2CVmwAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:18.884472 2026] [security2:error] [pid 843279:tid 843349] [remote 81.173.115.7:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "katsklar.com"] [uri "/wp-login.php"] [unique_id "al4QKvqvKNcW5yy5T2CVnQAAhUQ"], referer: https://katsklar.com/wp-login.php
[Mon Jul 20 06:10:18.913798 2026] [security2:error] [pid 843279:tid 843384] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/dr.php"] [unique_id "al4QKvqvKNcW5yy5T2CVoQAA9Gc"]
[Mon Jul 20 06:10:18.913971 2026] [security2:error] [pid 843279:tid 843522] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/dr.php"] [unique_id "al4QKvqvKNcW5yy5T2CVoQAA9Gc"]
[Mon Jul 20 06:10:18.920685 2026] [security2:error] [pid 843279:tid 843524] [client 103.77.203.233:61502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QKvqvKNcW5yy5T2CVowAAAPY"]
[Mon Jul 20 06:10:18.920803 2026] [security2:error] [pid 843279:tid 843524] [client 103.77.203.233:61502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QKvqvKNcW5yy5T2CVowAAAPY"]
[Mon Jul 20 06:10:18.981949 2026] [security2:error] [pid 843279:tid 843315] [remote 57.141.18.79:28768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5703786"] [unique_id "al4QKvqvKNcW5yy5T2CVpwAAuiI"]
[Mon Jul 20 06:10:19.004847 2026] [security2:error] [pid 843279:tid 843441] [client 185.132.186.61:49565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/XxX.php"] [unique_id "al4QK_qvKNcW5yy5T2CVqgAAAKQ"]
[Mon Jul 20 06:10:19.090802 2026] [security2:error] [pid 843279:tid 843483] [client 54.204.158.117:26956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.158.204.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QK_qvKNcW5yy5T2CVsAAAAM4"]
[Mon Jul 20 06:10:19.091033 2026] [security2:error] [pid 843279:tid 843483] [client 54.204.158.117:26956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QK_qvKNcW5yy5T2CVsAAAAM4"]
[Mon Jul 20 06:10:19.095157 2026] [security2:error] [pid 843279:tid 843472] [client 14.225.17.146:62510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4QK_qvKNcW5yy5T2CVrAAAAMM"], referer: https://wathenbartlett.co.uk/WORDPRESS
[Mon Jul 20 06:10:19.138194 2026] [security2:error] [pid 843279:tid 843500] [client 47.129.222.11:14946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QK_qvKNcW5yy5T2CVtwAAAN8"]
[Mon Jul 20 06:10:19.149156 2026] [security2:error] [pid 843279:tid 843368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/x.php"] [unique_id "al4QK_qvKNcW5yy5T2CVugAA3Fc"]
[Mon Jul 20 06:10:19.149443 2026] [security2:error] [pid 843279:tid 843497] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/x.php"] [unique_id "al4QK_qvKNcW5yy5T2CVugAA3Fc"]
[Mon Jul 20 06:10:19.349882 2026] [security2:error] [pid 843279:tid 843400] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/155.php"] [unique_id "al4QK_qvKNcW5yy5T2CVyAAA1Hc"]
[Mon Jul 20 06:10:19.350044 2026] [security2:error] [pid 843279:tid 843489] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/155.php"] [unique_id "al4QK_qvKNcW5yy5T2CVyAAA1Hc"]
[Mon Jul 20 06:10:19.548377 2026] [security2:error] [pid 843279:tid 843382] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ops.php"] [unique_id "al4QK_qvKNcW5yy5T2CV1QAAtGU"]
[Mon Jul 20 06:10:19.548572 2026] [security2:error] [pid 843279:tid 843457] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ops.php"] [unique_id "al4QK_qvKNcW5yy5T2CV1QAAtGU"]
[Mon Jul 20 06:10:19.731579 2026] [security2:error] [pid 843279:tid 843528] [client 66.249.73.64:55523] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ericsnotary.com"] [uri "/robots.txt"] [unique_id "al4QK_qvKNcW5yy5T2CV5gAAAPo"]
[Mon Jul 20 06:10:19.736819 2026] [security2:error] [pid 843279:tid 843379] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file31.php"] [unique_id "al4QK_qvKNcW5yy5T2CV5wAAsmI"]
[Mon Jul 20 06:10:19.736941 2026] [security2:error] [pid 843279:tid 843455] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file31.php"] [unique_id "al4QK_qvKNcW5yy5T2CV5wAAsmI"]
[Mon Jul 20 06:10:19.893215 2026] [security2:error] [pid 843279:tid 843430] [client 121.188.194.82:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QK_qvKNcW5yy5T2CV1AAAAJk"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:19.928877 2026] [security2:error] [pid 843279:tid 843395] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file6.php"] [unique_id "al4QK_qvKNcW5yy5T2CV_gAAnHI"]
[Mon Jul 20 06:10:19.929079 2026] [security2:error] [pid 843279:tid 843433] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file6.php"] [unique_id "al4QK_qvKNcW5yy5T2CV_gAAnHI"]
[Mon Jul 20 06:10:20.079401 2026] [security2:error] [pid 843279:tid 843522] [client 13.229.223.11:34240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QLPqvKNcW5yy5T2CWCQAAAPQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:10:20.432854 2026] [autoindex:error] [pid 843279:tid 843301] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:20.433439 2026] [security2:error] [pid 843279:tid 843430] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/assets/"] [unique_id "al4QLPqvKNcW5yy5T2CWJQAAmRQ"]
[Mon Jul 20 06:10:20.453232 2026] [security2:error] [pid 843279:tid 843480] [client 104.234.53.67:41703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QLPqvKNcW5yy5T2CWJgAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:20.536542 2026] [core:error] [pid 843279:tid 843524] [client 185.247.137.2:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:20.536561 2026] [core:error] [pid 843279:tid 843524] [client 185.247.137.2:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:20.621599 2026] [security2:error] [pid 843279:tid 843394] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/adminfuns.php"] [unique_id "al4QLPqvKNcW5yy5T2CWOAAAw3E"]
[Mon Jul 20 06:10:20.621820 2026] [security2:error] [pid 843279:tid 843472] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/adminfuns.php"] [unique_id "al4QLPqvKNcW5yy5T2CWOAAAw3E"]
[Mon Jul 20 06:10:20.746110 2026] [security2:error] [pid 843279:tid 843498] [client 103.153.183.69:4640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/shadow"] [unique_id "al4QLPqvKNcW5yy5T2CWQQAAAN0"], referer: https://www.google.com/search?q=bzqj9a
[Mon Jul 20 06:10:20.756984 2026] [security2:error] [pid 843279:tid 843469] [client 14.225.17.146:62335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4QLPqvKNcW5yy5T2CWPQAAAMA"], referer: http://thefriendlyspreadsheet.com/WORDPRESS
[Mon Jul 20 06:10:20.790529 2026] [security2:error] [pid 843279:tid 843428] [client 14.225.17.146:62334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4QLPqvKNcW5yy5T2CWPAAAAJc"], referer: http://collectingrealestate.com/WORDPRESS
[Mon Jul 20 06:10:20.829927 2026] [security2:error] [pid 843279:tid 843330] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/goods.php"] [unique_id "al4QLPqvKNcW5yy5T2CWTQAAoTE"]
[Mon Jul 20 06:10:20.830123 2026] [security2:error] [pid 843279:tid 843438] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/goods.php"] [unique_id "al4QLPqvKNcW5yy5T2CWTQAAoTE"]
[Mon Jul 20 06:10:20.947211 2026] [security2:error] [pid 843279:tid 843430] [client 185.132.186.85:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ubh/install.php"] [unique_id "al4QLPqvKNcW5yy5T2CWWgAAAJk"]
[Mon Jul 20 06:10:21.018828 2026] [security2:error] [pid 843279:tid 843297] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/100.php"] [unique_id "al4QLfqvKNcW5yy5T2CWYwABAhA"]
[Mon Jul 20 06:10:21.019022 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/100.php"] [unique_id "al4QLfqvKNcW5yy5T2CWYwABAhA"]
[Mon Jul 20 06:10:21.150446 2026] [security2:error] [pid 843279:tid 843431] [client 50.116.65.227:28648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QLfqvKNcW5yy5T2CWaQAAAJo"]
[Mon Jul 20 06:10:21.163487 2026] [security2:error] [pid 843279:tid 843456] [client 50.116.65.227:28662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QLfqvKNcW5yy5T2CWagAAALM"]
[Mon Jul 20 06:10:21.203785 2026] [security2:error] [pid 843279:tid 843508] [client 103.141.108.143:54445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWbgAAAOY"]
[Mon Jul 20 06:10:21.203923 2026] [security2:error] [pid 843279:tid 843508] [client 103.141.108.143:54445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWbgAAAOY"]
[Mon Jul 20 06:10:21.235621 2026] [security2:error] [pid 843279:tid 843479] [client 115.246.21.170:22296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWegAAAMo"]
[Mon Jul 20 06:10:21.235772 2026] [security2:error] [pid 843279:tid 843479] [client 115.246.21.170:22296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWegAAAMo"]
[Mon Jul 20 06:10:21.237898 2026] [security2:error] [pid 843279:tid 843320] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWfAAA6Sc"]
[Mon Jul 20 06:10:21.238162 2026] [security2:error] [pid 843279:tid 843511] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWfAAA6Sc"]
[Mon Jul 20 06:10:21.426432 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWjgAA7B8"]
[Mon Jul 20 06:10:21.426652 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWjgAA7B8"]
[Mon Jul 20 06:10:21.501281 2026] [security2:error] [pid 843279:tid 843513] [client 103.95.123.246:18619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWlAAAAOs"]
[Mon Jul 20 06:10:21.501472 2026] [security2:error] [pid 843279:tid 843513] [client 103.95.123.246:18619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWlAAAAOs"]
[Mon Jul 20 06:10:21.583126 2026] [security2:error] [pid 843279:tid 843439] [client 121.188.194.82:59428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QLfqvKNcW5yy5T2CWcAAAAKI"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:21.593008 2026] [security2:error] [pid 843279:tid 843502] [client 14.225.17.146:63955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4QK_qvKNcW5yy5T2CWAgAAAOE"], referer: https://north-woods-engineering.com/WORDPRESS
[Mon Jul 20 06:10:21.614829 2026] [security2:error] [pid 843279:tid 843292] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWmgAAsws"]
[Mon Jul 20 06:10:21.615044 2026] [security2:error] [pid 843279:tid 843456] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWmgAAsws"]
[Mon Jul 20 06:10:21.816028 2026] [security2:error] [pid 843279:tid 843341] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWsQAAmTw"]
[Mon Jul 20 06:10:21.816221 2026] [security2:error] [pid 843279:tid 843430] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWsQAAmTw"]
[Mon Jul 20 06:10:21.817174 2026] [security2:error] [pid 843279:tid 843299] [remote 78.46.157.202:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4QLfqvKNcW5yy5T2CWrgAAlBI"]
[Mon Jul 20 06:10:21.829551 2026] [security2:error] [pid 843279:tid 843424] [client 57.141.18.86:28722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QKfqvKNcW5yy5T2CVSAAAky4"]
[Mon Jul 20 06:10:22.036937 2026] [security2:error] [pid 843279:tid 843316] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/themes.php"] [unique_id "al4QLvqvKNcW5yy5T2CWwAAApiM"]
[Mon Jul 20 06:10:22.037143 2026] [security2:error] [pid 843279:tid 843443] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/themes.php"] [unique_id "al4QLvqvKNcW5yy5T2CWwAAApiM"]
[Mon Jul 20 06:10:22.131185 2026] [security2:error] [pid 843279:tid 843459] [client 86.98.90.58:14007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWyQAAALY"]
[Mon Jul 20 06:10:22.131582 2026] [security2:error] [pid 843279:tid 843459] [client 86.98.90.58:14007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWyQAAALY"]
[Mon Jul 20 06:10:22.150372 2026] [security2:error] [pid 843279:tid 843321] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWzQAAryg"]
[Mon Jul 20 06:10:22.150511 2026] [security2:error] [pid 843279:tid 843452] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWzQAAryg"]
[Mon Jul 20 06:10:22.232455 2026] [security2:error] [pid 843279:tid 843504] [client 104.234.53.89:60577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW1wAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:22.233347 2026] [security2:error] [pid 843279:tid 843426] [client 112.213.160.112:31065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW2AAAAJU"]
[Mon Jul 20 06:10:22.233436 2026] [security2:error] [pid 843279:tid 843426] [client 112.213.160.112:31065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW2AAAAJU"]
[Mon Jul 20 06:10:22.291392 2026] [security2:error] [pid 843279:tid 843367] [remote 78.46.157.202:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4QLvqvKNcW5yy5T2CW3QAA9VY"], referer: https://mail.innspace.ca/wp-login.php
[Mon Jul 20 06:10:22.308294 2026] [security2:error] [pid 843279:tid 843502] [client 114.119.166.95:45353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ferrellroofing.com"] [uri "/commercial-roofing"] [unique_id "al4QLvqvKNcW5yy5T2CW4QAAAOE"], referer: https://www.ferrellroofing.com/commercial-roofing
[Mon Jul 20 06:10:22.352374 2026] [security2:error] [pid 843279:tid 843496] [client 57.141.18.91:63548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVcQAA2y0"]
[Mon Jul 20 06:10:22.380608 2026] [autoindex:error] [pid 843279:tid 843340] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:22.381275 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/blocks/details/"] [unique_id "al4QLvqvKNcW5yy5T2CW5AAA3Ts"]
[Mon Jul 20 06:10:22.419009 2026] [core:error] [pid 843279:tid 843508] [client 14.225.17.146:50384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WORDPRESS
[Mon Jul 20 06:10:22.419026 2026] [core:error] [pid 843279:tid 843508] [client 14.225.17.146:50384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WORDPRESS
[Mon Jul 20 06:10:22.484989 2026] [security2:error] [pid 843279:tid 843456] [client 181.224.94.124:60538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW6wAAALM"]
[Mon Jul 20 06:10:22.485151 2026] [security2:error] [pid 843279:tid 843456] [client 181.224.94.124:60538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW6wAAALM"]
[Mon Jul 20 06:10:22.701445 2026] [security2:error] [pid 843279:tid 843449] [client 45.116.69.230:50669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW_gAAAKw"]
[Mon Jul 20 06:10:22.701543 2026] [security2:error] [pid 843279:tid 843449] [client 45.116.69.230:50669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW_gAAAKw"]
[Mon Jul 20 06:10:22.847238 2026] [security2:error] [pid 843279:tid 843434] [client 57.141.18.107:45054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVngAAnUA"]
[Mon Jul 20 06:10:22.899408 2026] [security2:error] [pid 843279:tid 843487] [client 185.132.186.55:44733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Registry-private.php"] [unique_id "al4QLvqvKNcW5yy5T2CXFAAAANI"]
[Mon Jul 20 06:10:23.156067 2026] [security2:error] [pid 843279:tid 843483] [client 41.173.37.102:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXLgAAAM4"]
[Mon Jul 20 06:10:23.156224 2026] [security2:error] [pid 843279:tid 843483] [client 41.173.37.102:13312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXLgAAAM4"]
[Mon Jul 20 06:10:23.248775 2026] [security2:error] [pid 843279:tid 843517] [client 20.197.195.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW9QAA70k"]
[Mon Jul 20 06:10:23.248810 2026] [security2:error] [pid 843279:tid 843517] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW9QAA70k"]
[Mon Jul 20 06:10:23.285461 2026] [security2:error] [pid 843279:tid 843436] [client 121.188.194.82:59432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QLvqvKNcW5yy5T2CXGQAAAJ8"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:23.349202 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:62182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CWygAAAK4"], referer: http://sarahholyfield.com/WORDPRESS
[Mon Jul 20 06:10:23.379343 2026] [security2:error] [pid 843279:tid 843293] [remote 52.167.144.168:9890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4QL_qvKNcW5yy5T2CXOwAAmAw"]
[Mon Jul 20 06:10:23.503606 2026] [security2:error] [pid 843279:tid 843281] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/.well-known/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXSwAAjQA"]
[Mon Jul 20 06:10:23.503787 2026] [security2:error] [pid 843279:tid 843418] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/.well-known/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXSwAAjQA"]
[Mon Jul 20 06:10:23.546033 2026] [security2:error] [pid 843279:tid 843538] [client 178.152.178.232:36004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXTgAAAQQ"]
[Mon Jul 20 06:10:23.546162 2026] [security2:error] [pid 843279:tid 843538] [client 178.152.178.232:36004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXTgAAAQQ"]
[Mon Jul 20 06:10:23.714064 2026] [security2:error] [pid 843279:tid 843404] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXYwAAx3s"]
[Mon Jul 20 06:10:23.714236 2026] [security2:error] [pid 843279:tid 843476] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXYwAAx3s"]
[Mon Jul 20 06:10:23.935342 2026] [security2:error] [pid 843279:tid 843282] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wefile.php"] [unique_id "al4QL_qvKNcW5yy5T2CXbwABAAE"]
[Mon Jul 20 06:10:23.935498 2026] [security2:error] [pid 843279:tid 843534] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wefile.php"] [unique_id "al4QL_qvKNcW5yy5T2CXbwABAAE"]
[Mon Jul 20 06:10:23.950816 2026] [security2:error] [pid 843279:tid 843330] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXcQAArjE"]
[Mon Jul 20 06:10:23.950971 2026] [security2:error] [pid 843279:tid 843451] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXcQAArjE"]
[Mon Jul 20 06:10:23.975269 2026] [security2:error] [pid 843279:tid 843436] [client 193.19.109.247:23679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qatestep20-132996.com"] [uri "/wp-login.php"] [unique_id "al4QL_qvKNcW5yy5T2CXcwAAAJ8"]
[Mon Jul 20 06:10:24.154704 2026] [security2:error] [pid 843279:tid 843290] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgAAA7Ak"]
[Mon Jul 20 06:10:24.154906 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgAAA7Ak"]
[Mon Jul 20 06:10:24.174625 2026] [security2:error] [pid 843279:tid 843323] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgQAAkSo"]
[Mon Jul 20 06:10:24.174793 2026] [security2:error] [pid 843279:tid 843422] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgQAAkSo"]
[Mon Jul 20 06:10:24.285697 2026] [security2:error] [pid 843279:tid 843479] [client 13.229.223.11:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXhwAAAMo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:10:24.379181 2026] [autoindex:error] [pid 843279:tid 843296] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:24.379764 2026] [security2:error] [pid 843279:tid 843537] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4QMPqvKNcW5yy5T2CXjQABAw8"]
[Mon Jul 20 06:10:24.629945 2026] [autoindex:error] [pid 843279:tid 843300] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:24.630627 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-admin/js/"] [unique_id "al4QMPqvKNcW5yy5T2CXngABAhM"]
[Mon Jul 20 06:10:24.639047 2026] [security2:error] [pid 843279:tid 843450] [client 106.192.104.4:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXpgAAAK0"]
[Mon Jul 20 06:10:24.639202 2026] [security2:error] [pid 843279:tid 843450] [client 106.192.104.4:58544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXpgAAAK0"]
[Mon Jul 20 06:10:24.749741 2026] [security2:error] [pid 843279:tid 843284] [remote 173.212.252.15:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXsQAA_AM"]
[Mon Jul 20 06:10:24.750056 2026] [security2:error] [pid 843279:tid 843530] [client 173.212.252.15:46484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXsQAA_AM"]
[Mon Jul 20 06:10:24.837992 2026] [security2:error] [pid 843279:tid 843319] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-admin/css/colour.php"] [unique_id "al4QMPqvKNcW5yy5T2CXtAAAmyY"]
[Mon Jul 20 06:10:24.838170 2026] [security2:error] [pid 843279:tid 843432] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-admin/css/colour.php"] [unique_id "al4QMPqvKNcW5yy5T2CXtAAAmyY"]
[Mon Jul 20 06:10:24.850521 2026] [security2:error] [pid 843279:tid 843518] [client 185.132.186.68:39513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-modules-packages.min-meta.php"] [unique_id "al4QMPqvKNcW5yy5T2CXtQAAAPA"]
[Mon Jul 20 06:10:24.903179 2026] [security2:error] [pid 843279:tid 843463] [client 121.188.194.82:59434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXmwAAALo"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:24.926395 2026] [security2:error] [pid 843279:tid 843433] [client 193.19.109.233:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXvgAAAJw"]
[Mon Jul 20 06:10:24.942988 2026] [security2:error] [pid 843279:tid 843501] [client 193.19.109.219:41879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXugAAAOA"]
[Mon Jul 20 06:10:25.025803 2026] [security2:error] [pid 843279:tid 843335] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/8.php"] [unique_id "al4QMfqvKNcW5yy5T2CXxwAA7TY"]
[Mon Jul 20 06:10:25.025993 2026] [security2:error] [pid 843279:tid 843515] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/8.php"] [unique_id "al4QMfqvKNcW5yy5T2CXxwAA7TY"]
[Mon Jul 20 06:10:25.220237 2026] [security2:error] [pid 843279:tid 843339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QMfqvKNcW5yy5T2CX0wABAjo"]
[Mon Jul 20 06:10:25.220418 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QMfqvKNcW5yy5T2CX0wABAjo"]
[Mon Jul 20 06:10:25.227738 2026] [security2:error] [pid 843279:tid 843489] [client 103.153.183.69:4640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/hosts"] [unique_id "al4QMfqvKNcW5yy5T2CX1AAAANQ"], referer: https://t.co/8aijbcelyv
[Mon Jul 20 06:10:25.254889 2026] [security2:error] [pid 843279:tid 843491] [client 57.141.18.49:20254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QLPqvKNcW5yy5T2CWVwAA1hE"]
[Mon Jul 20 06:10:25.362201 2026] [security2:error] [pid 843279:tid 843425] [client 164.100.212.184:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QMfqvKNcW5yy5T2CX5QAAAJQ"]
[Mon Jul 20 06:10:25.362287 2026] [security2:error] [pid 843279:tid 843425] [client 164.100.212.184:64092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QMfqvKNcW5yy5T2CX5QAAAJQ"]
[Mon Jul 20 06:10:25.525470 2026] [security2:error] [pid 843279:tid 843322] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/f6.php"] [unique_id "al4QMfqvKNcW5yy5T2CX9gAAryk"]
[Mon Jul 20 06:10:25.525660 2026] [security2:error] [pid 843279:tid 843452] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/f6.php"] [unique_id "al4QMfqvKNcW5yy5T2CX9gAAryk"]
[Mon Jul 20 06:10:25.658477 2026] [security2:error] [pid 843279:tid 843524] [client 50.116.65.227:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4QMfqvKNcW5yy5T2CYCQAAAPY"]
[Mon Jul 20 06:10:25.673404 2026] [security2:error] [pid 843279:tid 843476] [client 50.116.65.227:28706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4QMfqvKNcW5yy5T2CYCgAAAQI"]
[Mon Jul 20 06:10:26.156108 2026] [security2:error] [pid 843279:tid 843504] [client 87.199.196.181:64249] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.196.181" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4QMvqvKNcW5yy5T2CYLAAAAOM"], referer: https://www.guidehunting.com/guide-school-and-training-in-kentucky/
[Mon Jul 20 06:10:26.156246 2026] [security2:error] [pid 843279:tid 843504] [client 87.199.196.181:64249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4QMvqvKNcW5yy5T2CYLAAAAOM"], referer: https://www.guidehunting.com/guide-school-and-training-in-kentucky/
[Mon Jul 20 06:10:26.423683 2026] [security2:error] [pid 843279:tid 843462] [client 57.141.18.102:57422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW1QAAuVs"]
[Mon Jul 20 06:10:26.547064 2026] [security2:error] [pid 843279:tid 843467] [client 121.188.194.82:59436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QMvqvKNcW5yy5T2CYLQAAAL4"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:26.571438 2026] [security2:error] [pid 843279:tid 843522] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QMvqvKNcW5yy5T2CYQQAAAPQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:26.639199 2026] [security2:error] [pid 843279:tid 843387] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QMvqvKNcW5yy5T2CYUgABBGo"]
[Mon Jul 20 06:10:26.639348 2026] [security2:error] [pid 843279:tid 843538] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QMvqvKNcW5yy5T2CYUgABBGo"]
[Mon Jul 20 06:10:26.709727 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:61947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4QMPqvKNcW5yy5T2CXrgAAAJM"], referer: http://narv.co/WORDPRESS
[Mon Jul 20 06:10:26.787438 2026] [security2:error] [pid 843279:tid 843433] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QMvqvKNcW5yy5T2CYXAAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:26.787508 2026] [security2:error] [pid 843279:tid 843513] [client 185.132.186.53:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/bypass.php"] [unique_id "al4QMvqvKNcW5yy5T2CYXwAAAOs"]
[Mon Jul 20 06:10:26.823608 2026] [security2:error] [pid 843279:tid 843391] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QMvqvKNcW5yy5T2CYYQAA824"]
[Mon Jul 20 06:10:26.823933 2026] [security2:error] [pid 843279:tid 843521] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QMvqvKNcW5yy5T2CYYQAA824"]
[Mon Jul 20 06:10:27.013276 2026] [security2:error] [pid 843279:tid 843383] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QM_qvKNcW5yy5T2CYcAAAomY"]
[Mon Jul 20 06:10:27.013571 2026] [security2:error] [pid 843279:tid 843439] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QM_qvKNcW5yy5T2CYcAAAomY"]
[Mon Jul 20 06:10:27.096540 2026] [security2:error] [pid 843279:tid 843477] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QM_qvKNcW5yy5T2CYcQAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:27.201626 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/classwithtostring.php"] [unique_id "al4QM_qvKNcW5yy5T2CYhAAAjH4"]
[Mon Jul 20 06:10:27.201831 2026] [security2:error] [pid 843279:tid 843417] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/classwithtostring.php"] [unique_id "al4QM_qvKNcW5yy5T2CYhAAAjH4"]
[Mon Jul 20 06:10:27.377348 2026] [security2:error] [pid 843279:tid 843449] [client 27.96.94.195:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QM_qvKNcW5yy5T2CYlgAAAKw"]
[Mon Jul 20 06:10:27.377461 2026] [security2:error] [pid 843279:tid 843449] [client 27.96.94.195:37589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QM_qvKNcW5yy5T2CYlgAAAKw"]
[Mon Jul 20 06:10:27.399178 2026] [security2:error] [pid 843279:tid 843301] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/themes/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYmgAA9RQ"]
[Mon Jul 20 06:10:27.399404 2026] [security2:error] [pid 843279:tid 843523] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/themes/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYmgAA9RQ"]
[Mon Jul 20 06:10:27.582913 2026] [security2:error] [pid 843279:tid 843437] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QM_qvKNcW5yy5T2CYpgAAAKA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:27.664308 2026] [security2:error] [pid 843279:tid 843317] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-blog.php"] [unique_id "al4QM_qvKNcW5yy5T2CYsgAAliQ"]
[Mon Jul 20 06:10:27.664474 2026] [security2:error] [pid 843279:tid 843427] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-blog.php"] [unique_id "al4QM_qvKNcW5yy5T2CYsgAAliQ"]
[Mon Jul 20 06:10:27.846193 2026] [security2:error] [pid 843279:tid 843462] [client 14.225.17.146:57147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYrgAAALk"], referer: https://narv.co/WORDPRESS
[Mon Jul 20 06:10:27.914137 2026] [autoindex:error] [pid 843279:tid 843397] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:27.914772 2026] [security2:error] [pid 843279:tid 843459] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/js/jquery/"] [unique_id "al4QM_qvKNcW5yy5T2CYwQAAtnQ"]
[Mon Jul 20 06:10:28.155294 2026] [security2:error] [pid 843279:tid 843422] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QNPqvKNcW5yy5T2CYywAAAJE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:28.185664 2026] [security2:error] [pid 843279:tid 843450] [client 50.116.65.227:59334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QNPqvKNcW5yy5T2CY2wAAAK0"]
[Mon Jul 20 06:10:28.201047 2026] [security2:error] [pid 843279:tid 843457] [client 50.116.65.227:28722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QNPqvKNcW5yy5T2CY3AAAALQ"]
[Mon Jul 20 06:10:28.214352 2026] [security2:error] [pid 843279:tid 843507] [client 103.153.183.69:4640] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//proc/self/environ"] [unique_id "al4QNPqvKNcW5yy5T2CY3QAAAOU"], referer: https://www.facebook.com/
[Mon Jul 20 06:10:28.220036 2026] [security2:error] [pid 843279:tid 843302] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QNPqvKNcW5yy5T2CY4AAA3RU"]
[Mon Jul 20 06:10:28.220230 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QNPqvKNcW5yy5T2CY4AAA3RU"]
[Mon Jul 20 06:10:28.380230 2026] [security2:error] [pid 843279:tid 843429] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QNPqvKNcW5yy5T2CY8wAAAJg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:28.451508 2026] [security2:error] [pid 843279:tid 843288] [remote 5.161.225.162:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4QNPqvKNcW5yy5T2CY-AAAjAc"]
[Mon Jul 20 06:10:28.472820 2026] [security2:error] [pid 843279:tid 843418] [client 57.141.18.46:51736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QMPqvKNcW5yy5T2CXfQAAjQU"]
[Mon Jul 20 06:10:28.694314 2026] [security2:error] [pid 843279:tid 843513] [client 185.132.186.62:20659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/content-index.php"] [unique_id "al4QNPqvKNcW5yy5T2CZDAAAAOs"]
[Mon Jul 20 06:10:29.192224 2026] [security2:error] [pid 843279:tid 843447] [client 45.157.112.60:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QNfqvKNcW5yy5T2CZKgAAAKo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:29.293667 2026] [security2:error] [pid 843279:tid 843510] [client 14.225.17.146:55387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4QNfqvKNcW5yy5T2CZIwAAAOg"]
[Mon Jul 20 06:10:29.319445 2026] [security2:error] [pid 843279:tid 843507] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QNfqvKNcW5yy5T2CZPAAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:29.319683 2026] [security2:error] [pid 843279:tid 843507] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QNfqvKNcW5yy5T2CZPAAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:29.329663 2026] [proxy:error] [pid 843279:tid 843473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:29.329700 2026] [proxy_http:error] [pid 843279:tid 843473] [client 185.247.137.170:60047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:29.330484 2026] [proxy:error] [pid 843279:tid 843473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:29.330514 2026] [proxy_http:error] [pid 843279:tid 843473] [client 185.247.137.170:60047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:29.333395 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:62850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYoAAAAJM"], referer: http://qualitycoatingsinspection.com/WORDPRESS
[Mon Jul 20 06:10:29.402408 2026] [security2:error] [pid 843279:tid 843418] [client 103.77.203.233:62043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QNfqvKNcW5yy5T2CZSQAAAI0"]
[Mon Jul 20 06:10:29.402636 2026] [security2:error] [pid 843279:tid 843418] [client 103.77.203.233:62043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QNfqvKNcW5yy5T2CZSQAAAI0"]
[Mon Jul 20 06:10:29.915012 2026] [security2:error] [pid 843279:tid 843357] [remote 5.161.225.162:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4QNfqvKNcW5yy5T2CZbwAAtkw"], referer: https://daseighty.net/wp-login.php
[Mon Jul 20 06:10:30.127625 2026] [proxy:error] [pid 843279:tid 843520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:30.127698 2026] [proxy_http:error] [pid 843279:tid 843520] [client 205.210.31.46:62564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:30.128380 2026] [proxy:error] [pid 843279:tid 843520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:30.128422 2026] [proxy_http:error] [pid 843279:tid 843520] [client 205.210.31.46:62564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:30.283713 2026] [security2:error] [pid 843279:tid 843411] [client 57.141.18.25:63492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QMfqvKNcW5yy5T2CYEAAAhj4"]
[Mon Jul 20 06:10:30.355924 2026] [security2:error] [pid 843279:tid 843382] [remote 5.161.225.162:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4QNvqvKNcW5yy5T2CZngAA-2U"]
[Mon Jul 20 06:10:30.362435 2026] [security2:error] [pid 843279:tid 843495] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZlQAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:30.419545 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:61755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZjwAAAKQ"], referer: https://qualitycoatingsinspection.com/WORDPRESS
[Mon Jul 20 06:10:30.490096 2026] [security2:error] [pid 843279:tid 843338] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ms-edit.php"] [unique_id "al4QNvqvKNcW5yy5T2CZpgAA_zk"]
[Mon Jul 20 06:10:30.490243 2026] [security2:error] [pid 843279:tid 843533] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ms-edit.php"] [unique_id "al4QNvqvKNcW5yy5T2CZpgAA_zk"]
[Mon Jul 20 06:10:30.507185 2026] [security2:error] [pid 843279:tid 843501] [client 57.141.18.63:54878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QMfqvKNcW5yy5T2CYHgAA4DA"]
[Mon Jul 20 06:10:30.690153 2026] [security2:error] [pid 843279:tid 843436] [client 50.116.65.227:23822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QNvqvKNcW5yy5T2CZtQAAAJ8"]
[Mon Jul 20 06:10:30.696167 2026] [security2:error] [pid 843279:tid 843396] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/cgi-bin/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZtgAAr3M"]
[Mon Jul 20 06:10:30.696367 2026] [security2:error] [pid 843279:tid 843452] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/cgi-bin/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZtgAAr3M"]
[Mon Jul 20 06:10:30.700011 2026] [security2:error] [pid 843279:tid 843460] [client 50.116.65.227:23830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QNvqvKNcW5yy5T2CZtwAAALc"]
[Mon Jul 20 06:10:30.712802 2026] [security2:error] [pid 843279:tid 843362] [remote 5.161.225.162:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4QNvqvKNcW5yy5T2CZuQAAv1E"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 06:10:30.761798 2026] [core:error] [pid 843279:tid 843484] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:30.761830 2026] [core:error] [pid 843279:tid 843484] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:30.916955 2026] [autoindex:error] [pid 843279:tid 843408] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:30.918088 2026] [security2:error] [pid 843279:tid 843520] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/css/dist/"] [unique_id "al4QNvqvKNcW5yy5T2CZ0AAA8n8"]
[Mon Jul 20 06:10:31.009930 2026] [security2:error] [pid 843279:tid 843507] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ2AAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:31.212107 2026] [security2:error] [pid 843279:tid 843513] [client 185.132.186.65:38023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin/controller/extension/extension/alfa.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ6QAAAOs"]
[Mon Jul 20 06:10:31.255342 2026] [security2:error] [pid 843279:tid 843473] [client 66.249.70.104:56706] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.hardman.international"] [uri "/robots.txt"] [unique_id "al4QN_qvKNcW5yy5T2CZ7AAAAMQ"]
[Mon Jul 20 06:10:31.289525 2026] [security2:error] [pid 843279:tid 843443] [client 50.116.65.227:23858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ3gAAAKY"]
[Mon Jul 20 06:10:31.295632 2026] [security2:error] [pid 843279:tid 843406] [remote 45.90.123.233:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ7wAAzn0"]
[Mon Jul 20 06:10:31.368484 2026] [security2:error] [pid 843279:tid 843431] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ8AAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:31.504883 2026] [security2:error] [pid 843279:tid 843290] [remote 45.90.123.233:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CaCwAApAk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:31.524055 2026] [security2:error] [pid 843279:tid 843526] [client 50.116.65.227:23870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ8gAAAPg"]
[Mon Jul 20 06:10:31.544187 2026] [security2:error] [pid 843279:tid 843497] [client 57.141.18.69:38018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYdgAA3AA"]
[Mon Jul 20 06:10:31.555526 2026] [security2:error] [pid 843279:tid 843412] [client 114.119.146.114:21881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oswegooperatheater.com"] [uri "/tag/alan-martin"] [unique_id "al4QN_qvKNcW5yy5T2CaEAAAAIc"], referer: https://oswegooperatheater.com/tag/theatre
[Mon Jul 20 06:10:31.721965 2026] [security2:error] [pid 843279:tid 843522] [client 66.249.73.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.goyalsatyam.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CaEQAAAPQ"]
[Mon Jul 20 06:10:31.779997 2026] [security2:error] [pid 843279:tid 843297] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/BDKR28WP.php"] [unique_id "al4QN_qvKNcW5yy5T2CaJwAAsxA"]
[Mon Jul 20 06:10:31.780198 2026] [security2:error] [pid 843279:tid 843456] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/BDKR28WP.php"] [unique_id "al4QN_qvKNcW5yy5T2CaJwAAsxA"]
[Mon Jul 20 06:10:31.800648 2026] [security2:error] [pid 843279:tid 843491] [client 115.246.21.170:54000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaLAAAANY"]
[Mon Jul 20 06:10:31.800797 2026] [security2:error] [pid 843279:tid 843491] [client 115.246.21.170:54000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaLAAAANY"]
[Mon Jul 20 06:10:31.802221 2026] [security2:error] [pid 843279:tid 843457] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CaKgAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:31.873810 2026] [security2:error] [pid 843279:tid 843454] [client 103.141.108.143:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaNAAAALE"]
[Mon Jul 20 06:10:31.874148 2026] [security2:error] [pid 843279:tid 843454] [client 103.141.108.143:54897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaNAAAALE"]
[Mon Jul 20 06:10:31.960023 2026] [security2:error] [pid 843279:tid 843450] [client 14.225.17.146:53116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ9AAAAK0"], referer: http://bruceledewitz.com/WORDPRESS
[Mon Jul 20 06:10:32.032484 2026] [autoindex:error] [pid 843279:tid 843288] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:32.033213 2026] [security2:error] [pid 843279:tid 843463] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/l10n/"] [unique_id "al4QOPqvKNcW5yy5T2CaRAAAugc"]
[Mon Jul 20 06:10:32.081545 2026] [security2:error] [pid 843279:tid 843434] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QOPqvKNcW5yy5T2CaQgAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:32.144555 2026] [security2:error] [pid 843279:tid 843307] [remote 192.241.143.148:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CaTgAAnBo"]
[Mon Jul 20 06:10:32.271086 2026] [security2:error] [pid 843279:tid 843484] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-content/uploads/index.php"] [unique_id "al4QOPqvKNcW5yy5T2CaVAAAzy8"]
[Mon Jul 20 06:10:32.287679 2026] [security2:error] [pid 843279:tid 843423] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CaWwAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:32.335149 2026] [security2:error] [pid 843279:tid 843363] [remote 192.241.143.148:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CaYgAA-lI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:32.487744 2026] [security2:error] [pid 843279:tid 843366] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/abcd.php"] [unique_id "al4QOPqvKNcW5yy5T2CaeQAAi1U"]
[Mon Jul 20 06:10:32.487926 2026] [security2:error] [pid 843279:tid 843416] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/abcd.php"] [unique_id "al4QOPqvKNcW5yy5T2CaeQAAi1U"]
[Mon Jul 20 06:10:32.541534 2026] [security2:error] [pid 843279:tid 843495] [client 150.228.148.150:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CafwAAANo"]
[Mon Jul 20 06:10:32.546313 2026] [security2:error] [pid 843279:tid 843495] [client 150.228.148.150:6111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CafwAAANo"]
[Mon Jul 20 06:10:32.582520 2026] [security2:error] [pid 843279:tid 843425] [client 181.224.94.124:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CagAAAAJQ"]
[Mon Jul 20 06:10:32.582663 2026] [security2:error] [pid 843279:tid 843425] [client 181.224.94.124:10078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CagAAAAJQ"]
[Mon Jul 20 06:10:32.695422 2026] [security2:error] [pid 843279:tid 843367] [remote 173.249.4.11:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CahgAA_FY"]
[Mon Jul 20 06:10:32.783836 2026] [security2:error] [pid 843279:tid 843451] [client 193.19.109.243:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CajgAAAK4"]
[Mon Jul 20 06:10:32.784082 2026] [security2:error] [pid 843279:tid 843493] [client 193.19.109.246:57247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CajQAAANg"]
[Mon Jul 20 06:10:32.929826 2026] [security2:error] [pid 843279:tid 843429] [client 57.141.18.120:45690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QNPqvKNcW5yy5T2CZFQAAmDw"]
[Mon Jul 20 06:10:32.949362 2026] [security2:error] [pid 843279:tid 843533] [client 103.95.123.246:19164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CangAAAP8"]
[Mon Jul 20 06:10:32.949488 2026] [security2:error] [pid 843279:tid 843533] [client 103.95.123.246:19164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CangAAAP8"]
[Mon Jul 20 06:10:32.953362 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:14830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaogAAAQA"]
[Mon Jul 20 06:10:32.953470 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:14830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaogAAAQA"]
[Mon Jul 20 06:10:32.999172 2026] [security2:error] [pid 843279:tid 843356] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaqwAAh0s"]
[Mon Jul 20 06:10:32.999432 2026] [security2:error] [pid 843279:tid 843412] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaqwAAh0s"]
[Mon Jul 20 06:10:33.012926 2026] [security2:error] [pid 843279:tid 843449] [client 57.141.18.104:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QNPqvKNcW5yy5T2CZGwAArDo"]
[Mon Jul 20 06:10:33.032053 2026] [security2:error] [pid 843279:tid 843477] [client 112.213.160.112:8647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CarQAAAMg"]
[Mon Jul 20 06:10:33.032215 2026] [security2:error] [pid 843279:tid 843477] [client 112.213.160.112:8647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CarQAAAMg"]
[Mon Jul 20 06:10:33.185654 2026] [security2:error] [pid 843279:tid 843520] [client 185.132.186.99:65017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/system_cache.php%20"] [unique_id "al4QOfqvKNcW5yy5T2CatgAAAPI"]
[Mon Jul 20 06:10:33.355189 2026] [security2:error] [pid 843279:tid 843448] [client 45.116.69.230:51167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CavQAAAKs"]
[Mon Jul 20 06:10:33.355439 2026] [security2:error] [pid 843279:tid 843448] [client 45.116.69.230:51167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CavQAAAKs"]
[Mon Jul 20 06:10:33.442151 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QOfqvKNcW5yy5T2CavwAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:33.732397 2026] [security2:error] [pid 843279:tid 843473] [client 41.173.37.102:13750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2Ca3gAAAMQ"]
[Mon Jul 20 06:10:33.733506 2026] [security2:error] [pid 843279:tid 843473] [client 41.173.37.102:13750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2Ca3gAAAMQ"]
[Mon Jul 20 06:10:34.010212 2026] [security2:error] [pid 843279:tid 843450] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca9wAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.138103 2026] [security2:error] [pid 843279:tid 843364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file15.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca-wABAVM"]
[Mon Jul 20 06:10:34.138349 2026] [security2:error] [pid 843279:tid 843535] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file15.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca-wABAVM"]
[Mon Jul 20 06:10:34.208144 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca_gAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.208368 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca_gAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.325925 2026] [security2:error] [pid 843279:tid 843408] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/jp.php"] [unique_id "al4QOvqvKNcW5yy5T2CbDQAAkX8"]
[Mon Jul 20 06:10:34.326139 2026] [security2:error] [pid 843279:tid 843422] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/jp.php"] [unique_id "al4QOvqvKNcW5yy5T2CbDQAAkX8"]
[Mon Jul 20 06:10:34.502989 2026] [security2:error] [pid 843279:tid 843496] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QOvqvKNcW5yy5T2CbGQAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.548049 2026] [security2:error] [pid 843279:tid 843301] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/f35.php"] [unique_id "al4QOvqvKNcW5yy5T2CbIgAA7BQ"]
[Mon Jul 20 06:10:34.548280 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/f35.php"] [unique_id "al4QOvqvKNcW5yy5T2CbIgAA7BQ"]
[Mon Jul 20 06:10:34.578763 2026] [security2:error] [pid 843279:tid 843462] [client 57.141.18.34:37030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZgAAAuUg"]
[Mon Jul 20 06:10:34.608897 2026] [security2:error] [pid 843279:tid 843392] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbJAAAq28"]
[Mon Jul 20 06:10:34.609087 2026] [security2:error] [pid 843279:tid 843448] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbJAAAq28"]
[Mon Jul 20 06:10:34.691347 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2CbLgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.737178 2026] [security2:error] [pid 843279:tid 843282] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-load.php"] [unique_id "al4QOvqvKNcW5yy5T2CbMQAAvQE"]
[Mon Jul 20 06:10:34.737385 2026] [security2:error] [pid 843279:tid 843466] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-load.php"] [unique_id "al4QOvqvKNcW5yy5T2CbMQAAvQE"]
[Mon Jul 20 06:10:34.806293 2026] [security2:error] [pid 843279:tid 843305] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbOQABABg"]
[Mon Jul 20 06:10:34.806566 2026] [security2:error] [pid 843279:tid 843534] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbOQABABg"]
[Mon Jul 20 06:10:34.870110 2026] [security2:error] [pid 843279:tid 843426] [client 14.225.17.146:62296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4QOfqvKNcW5yy5T2CazQAAAJU"], referer: http://iagdevelopments.com/WORDPRESS
[Mon Jul 20 06:10:34.938163 2026] [security2:error] [pid 843279:tid 843318] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/xyn.php"] [unique_id "al4QOvqvKNcW5yy5T2CbQAAAkyU"]
[Mon Jul 20 06:10:34.938373 2026] [security2:error] [pid 843279:tid 843424] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/xyn.php"] [unique_id "al4QOvqvKNcW5yy5T2CbQAAAkyU"]
[Mon Jul 20 06:10:34.986433 2026] [security2:error] [pid 843279:tid 843537] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QOvqvKNcW5yy5T2CbPwAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.132838 2026] [security2:error] [pid 843279:tid 843467] [client 185.132.186.55:57845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/modern/colors.css.php"] [unique_id "al4QO_qvKNcW5yy5T2CbUwAAAL4"]
[Mon Jul 20 06:10:35.142380 2026] [autoindex:error] [pid 843279:tid 843405] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:35.142963 2026] [security2:error] [pid 843279:tid 843432] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/assets/"] [unique_id "al4QO_qvKNcW5yy5T2CbUgAAm3w"]
[Mon Jul 20 06:10:35.193437 2026] [security2:error] [pid 843279:tid 843309] [remote 173.212.252.15:40672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbWwAA7Rw"]
[Mon Jul 20 06:10:35.241550 2026] [security2:error] [pid 843279:tid 843459] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbYQAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.656993 2026] [security2:error] [pid 843279:tid 843308] [remote 173.212.252.15:40672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbgwAAvxs"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:10:35.741448 2026] [security2:error] [pid 843279:tid 843414] [client 106.192.104.4:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QO_qvKNcW5yy5T2CbhwAAAIk"]
[Mon Jul 20 06:10:35.741619 2026] [security2:error] [pid 843279:tid 843414] [client 106.192.104.4:59045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QO_qvKNcW5yy5T2CbhwAAAIk"]
[Mon Jul 20 06:10:35.757691 2026] [security2:error] [pid 843279:tid 843448] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QO_qvKNcW5yy5T2CbhQAAAKs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.762473 2026] [security2:error] [pid 843279:tid 843519] [client 57.141.18.42:20988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ2QAA8Vo"]
[Mon Jul 20 06:10:35.822834 2026] [security2:error] [pid 843279:tid 843452] [client 14.225.17.146:54566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4QO_qvKNcW5yy5T2CbiAAAAK8"], referer: https://iagdevelopments.com/WORDPRESS
[Mon Jul 20 06:10:35.925221 2026] [security2:error] [pid 843279:tid 843426] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbmQAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.994125 2026] [autoindex:error] [pid 843279:tid 843292] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:35.994849 2026] [security2:error] [pid 843279:tid 843447] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al4QO_qvKNcW5yy5T2CbmgAAqgs"]
[Mon Jul 20 06:10:36.000976 2026] [security2:error] [pid 843279:tid 843432] [client 164.100.212.184:54813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbnQAAAJs"]
[Mon Jul 20 06:10:36.001064 2026] [security2:error] [pid 843279:tid 843432] [client 164.100.212.184:54813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbnQAAAJs"]
[Mon Jul 20 06:10:36.177482 2026] [security2:error] [pid 843279:tid 843430] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QPPqvKNcW5yy5T2CbpgAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:36.188121 2026] [security2:error] [pid 843279:tid 843376] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ccc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbsgAAhV8"]
[Mon Jul 20 06:10:36.188361 2026] [security2:error] [pid 843279:tid 843410] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ccc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbsgAAhV8"]
[Mon Jul 20 06:10:36.470700 2026] [security2:error] [pid 843279:tid 843500] [client 57.141.18.84:45536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CaGwAA3yw"]
[Mon Jul 20 06:10:36.490013 2026] [security2:error] [pid 843279:tid 843529] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPPqvKNcW5yy5T2CbwwAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:36.732590 2026] [core:error] [pid 843279:tid 843491] [client 14.225.17.146:63873] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WORDPRESS
[Mon Jul 20 06:10:36.732613 2026] [core:error] [pid 843279:tid 843491] [client 14.225.17.146:63873] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WORDPRESS
[Mon Jul 20 06:10:36.763289 2026] [security2:error] [pid 843279:tid 843365] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/w.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb4QAAklQ"]
[Mon Jul 20 06:10:36.763428 2026] [security2:error] [pid 843279:tid 843423] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/w.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb4QAAklQ"]
[Mon Jul 20 06:10:36.957559 2026] [security2:error] [pid 843279:tid 843326] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb7wAApy0"]
[Mon Jul 20 06:10:36.957809 2026] [security2:error] [pid 843279:tid 843444] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb7wAApy0"]
[Mon Jul 20 06:10:37.081405 2026] [security2:error] [pid 843279:tid 843529] [client 185.132.186.91:61567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/adminfus.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb9AAAAPs"]
[Mon Jul 20 06:10:37.131026 2026] [security2:error] [pid 843279:tid 843454] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb-QAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.131225 2026] [security2:error] [pid 843279:tid 843454] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb-QAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.149147 2026] [security2:error] [pid 843279:tid 843343] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/FWAZ.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb_QAAxz4"]
[Mon Jul 20 06:10:37.149329 2026] [security2:error] [pid 843279:tid 843476] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/FWAZ.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb_QAAxz4"]
[Mon Jul 20 06:10:37.240740 2026] [security2:error] [pid 843279:tid 843359] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QPfqvKNcW5yy5T2CcAQAA5k4"]
[Mon Jul 20 06:10:37.240902 2026] [security2:error] [pid 843279:tid 843508] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QPfqvKNcW5yy5T2CcAQAA5k4"]
[Mon Jul 20 06:10:37.256160 2026] [security2:error] [pid 843279:tid 843315] [remote 173.249.4.11:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2CcAgAAoiI"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:10:37.301250 2026] [security2:error] [pid 843279:tid 843502] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4QPfqvKNcW5yy5T2CcCQAAAOE"]
[Mon Jul 20 06:10:37.304167 2026] [security2:error] [pid 843279:tid 843484] [client 74.7.175.151:52270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4QPfqvKNcW5yy5T2CcAwAAz1s"]
[Mon Jul 20 06:10:37.326436 2026] [security2:error] [pid 843279:tid 843419] [client 57.141.18.83:46554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QOPqvKNcW5yy5T2CaYAAAjjY"]
[Mon Jul 20 06:10:37.367728 2026] [security2:error] [pid 843279:tid 843368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/miru1.php"] [unique_id "al4QPfqvKNcW5yy5T2CcDQAAv1c"]
[Mon Jul 20 06:10:37.368000 2026] [security2:error] [pid 843279:tid 843468] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/miru1.php"] [unique_id "al4QPfqvKNcW5yy5T2CcDQAAv1c"]
[Mon Jul 20 06:10:37.440060 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcDAAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.586997 2026] [security2:error] [pid 843279:tid 843504] [client 14.225.17.146:54368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcCwAAAOM"], referer: http://www.justinagrayman.com/WORDPRESS
[Mon Jul 20 06:10:37.629485 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:63871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcGwAAAIU"], referer: http://adultdaycarereno.com/WORDPRESS
[Mon Jul 20 06:10:37.709900 2026] [security2:error] [pid 843279:tid 843518] [client 14.225.17.146:63862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb2AAAAPA"], referer: http://entuvy.com/WORDPRESS
[Mon Jul 20 06:10:37.780766 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2CcOQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.926301 2026] [security2:error] [pid 843279:tid 843407] [remote 5.161.225.162:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2CcSgAAun4"]
[Mon Jul 20 06:10:38.329577 2026] [security2:error] [pid 843279:tid 843392] [remote 162.19.86.63:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcYAAA3G8"]
[Mon Jul 20 06:10:38.470013 2026] [security2:error] [pid 843279:tid 843515] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QPvqvKNcW5yy5T2CcZgAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:38.472293 2026] [security2:error] [pid 843279:tid 843513] [client 193.19.109.234:38507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcbwAAAOs"]
[Mon Jul 20 06:10:38.508139 2026] [security2:error] [pid 843279:tid 843317] [remote 162.19.86.63:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcegAA2SQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:10:38.516240 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:64974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4QPvqvKNcW5yy5T2CcbgAAAJM"], referer: https://adultdaycarereno.com/WORDPRESS
[Mon Jul 20 06:10:38.640978 2026] [security2:error] [pid 843279:tid 843281] [remote 192.241.143.148:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcgwAA4wA"]
[Mon Jul 20 06:10:38.749600 2026] [security2:error] [pid 843279:tid 843488] [client 14.225.17.146:54329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcFgAAANM"], referer: http://mazzucelli.com/WORDPRESS
[Mon Jul 20 06:10:38.853085 2026] [security2:error] [pid 843279:tid 843291] [remote 192.241.143.148:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcmAAA3Qo"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:10:38.911851 2026] [security2:error] [pid 843279:tid 843405] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/aa.php"] [unique_id "al4QPvqvKNcW5yy5T2CcnwAAnXw"]
[Mon Jul 20 06:10:38.912115 2026] [security2:error] [pid 843279:tid 843434] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/aa.php"] [unique_id "al4QPvqvKNcW5yy5T2CcnwAAnXw"]
[Mon Jul 20 06:10:39.054668 2026] [security2:error] [pid 843279:tid 843449] [client 158.173.89.95:44787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QP_qvKNcW5yy5T2CcqgAAAKw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:39.054959 2026] [security2:error] [pid 843279:tid 843484] [client 185.132.186.53:63869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/media-widget-vide02.php"] [unique_id "al4QP_qvKNcW5yy5T2CcqQAAAM8"]
[Mon Jul 20 06:10:39.100364 2026] [security2:error] [pid 843279:tid 843300] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/122.php"] [unique_id "al4QP_qvKNcW5yy5T2CcrAAA-xM"]
[Mon Jul 20 06:10:39.100564 2026] [security2:error] [pid 843279:tid 843529] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/122.php"] [unique_id "al4QP_qvKNcW5yy5T2CcrAAA-xM"]
[Mon Jul 20 06:10:39.167145 2026] [security2:error] [pid 843279:tid 843453] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2CcsgAAALA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:39.204281 2026] [security2:error] [pid 843279:tid 843312] [remote 124.55.178.99:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2CcuAAA8h8"]
[Mon Jul 20 06:10:39.268621 2026] [security2:error] [pid 843279:tid 843334] [remote 57.141.18.110:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4QP_qvKNcW5yy5T2CcvgAAsTU"]
[Mon Jul 20 06:10:39.288973 2026] [security2:error] [pid 843279:tid 843371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/get.php"] [unique_id "al4QP_qvKNcW5yy5T2CcwQAA_Fo"]
[Mon Jul 20 06:10:39.289182 2026] [security2:error] [pid 843279:tid 843530] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/get.php"] [unique_id "al4QP_qvKNcW5yy5T2CcwQAA_Fo"]
[Mon Jul 20 06:10:39.300992 2026] [security2:error] [pid 843279:tid 843307] [remote 202.51.202.242:43558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2CcvwAAuRo"]
[Mon Jul 20 06:10:39.478775 2026] [security2:error] [pid 843279:tid 843469] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QP_qvKNcW5yy5T2CczgAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:39.510829 2026] [security2:error] [pid 843279:tid 843531] [client 27.96.94.195:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc2QAAAP0"]
[Mon Jul 20 06:10:39.510977 2026] [security2:error] [pid 843279:tid 843531] [client 27.96.94.195:37230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc2QAAAP0"]
[Mon Jul 20 06:10:39.784738 2026] [security2:error] [pid 843279:tid 843523] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc8AAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:39.890220 2026] [security2:error] [pid 843279:tid 843478] [client 103.77.203.233:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc_QAAAMk"]
[Mon Jul 20 06:10:39.890491 2026] [security2:error] [pid 843279:tid 843478] [client 103.77.203.233:62577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc_QAAAMk"]
[Mon Jul 20 06:10:39.950647 2026] [security2:error] [pid 843279:tid 843443] [client 14.225.17.146:54332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4QPvqvKNcW5yy5T2CcVAAAAKY"]
[Mon Jul 20 06:10:40.182726 2026] [security2:error] [pid 843279:tid 843496] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QQPqvKNcW5yy5T2CdFQAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:40.189073 2026] [security2:error] [pid 843279:tid 843442] [client 185.63.81.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc0AAAAKU"]
[Mon Jul 20 06:10:40.201582 2026] [security2:error] [pid 843279:tid 843351] [remote 124.55.178.99:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdHgAAuUY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:10:40.386930 2026] [security2:error] [pid 843279:tid 843443] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdKgAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:40.437392 2026] [security2:error] [pid 843279:tid 843357] [remote 45.150.79.142:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdLwAAk0w"]
[Mon Jul 20 06:10:40.510350 2026] [security2:error] [pid 843279:tid 843346] [remote 110.249.202.73:55076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2000-commission/2000-commission-maps-and-population-tables/"] [unique_id "al4QQPqvKNcW5yy5T2CdNgAA50E"]
[Mon Jul 20 06:10:40.598941 2026] [security2:error] [pid 843279:tid 843337] [remote 45.150.79.142:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdPwAAiDg"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:40.675082 2026] [security2:error] [pid 843279:tid 843360] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/as.php"] [unique_id "al4QQPqvKNcW5yy5T2CdQgAAuU8"]
[Mon Jul 20 06:10:40.675330 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/as.php"] [unique_id "al4QQPqvKNcW5yy5T2CdQgAAuU8"]
[Mon Jul 20 06:10:40.677931 2026] [security2:error] [pid 843279:tid 843507] [client 57.141.18.67:52888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QO_qvKNcW5yy5T2CbggAA5T0"]
[Mon Jul 20 06:10:40.880379 2026] [security2:error] [pid 843279:tid 843382] [remote 5.161.225.162:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdUwAAz2U"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:41.466528 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQfqvKNcW5yy5T2CdfQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:41.466730 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQfqvKNcW5yy5T2CdfQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:41.679915 2026] [security2:error] [pid 843279:tid 843448] [client 50.116.65.227:23862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4QQfqvKNcW5yy5T2CdjQAAAKs"]
[Mon Jul 20 06:10:41.684480 2026] [security2:error] [pid 843279:tid 843434] [client 14.225.17.146:57137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4QQPqvKNcW5yy5T2CdHQAAAJ0"]
[Mon Jul 20 06:10:41.880283 2026] [security2:error] [pid 843279:tid 843521] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdlAAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:41.938015 2026] [security2:error] [pid 843279:tid 843421] [client 50.116.65.227:23874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4QQfqvKNcW5yy5T2CdoQAAAJA"]
[Mon Jul 20 06:10:41.949079 2026] [security2:error] [pid 843279:tid 843535] [client 50.116.65.227:55694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4QQfqvKNcW5yy5T2CdowAAAQE"]
[Mon Jul 20 06:10:41.980918 2026] [security2:error] [pid 843279:tid 843479] [client 57.141.18.119:39138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb7gAAyk0"]
[Mon Jul 20 06:10:42.043578 2026] [security2:error] [pid 843279:tid 843513] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQvqvKNcW5yy5T2CdpwAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:42.180706 2026] [security2:error] [pid 843279:tid 843388] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ccou.php"] [unique_id "al4QQvqvKNcW5yy5T2CdtAAA02s"]
[Mon Jul 20 06:10:42.180900 2026] [security2:error] [pid 843279:tid 843488] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ccou.php"] [unique_id "al4QQvqvKNcW5yy5T2CdtAAA02s"]
[Mon Jul 20 06:10:42.276832 2026] [security2:error] [pid 843279:tid 843473] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QQvqvKNcW5yy5T2CdtQAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:42.319726 2026] [security2:error] [pid 843279:tid 843493] [client 193.19.109.227:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/wp-login.php"] [unique_id "al4QQvqvKNcW5yy5T2CduQAAANg"]
[Mon Jul 20 06:10:42.355730 2026] [security2:error] [pid 843279:tid 843411] [client 13.201.64.214:25262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2CdvwAAAIY"]
[Mon Jul 20 06:10:42.355878 2026] [security2:error] [pid 843279:tid 843411] [client 13.201.64.214:25262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2CdvwAAAIY"]
[Mon Jul 20 06:10:42.394499 2026] [security2:error] [pid 843279:tid 843402] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/w3lls.php"] [unique_id "al4QQvqvKNcW5yy5T2CdwwAA43k"]
[Mon Jul 20 06:10:42.394680 2026] [security2:error] [pid 843279:tid 843504] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/w3lls.php"] [unique_id "al4QQvqvKNcW5yy5T2CdwwAA43k"]
[Mon Jul 20 06:10:42.584360 2026] [security2:error] [pid 843279:tid 843296] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/test1.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd0QAA-g8"]
[Mon Jul 20 06:10:42.584705 2026] [security2:error] [pid 843279:tid 843528] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/test1.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd0QAA-g8"]
[Mon Jul 20 06:10:42.619715 2026] [security2:error] [pid 843279:tid 843479] [client 185.132.186.83:46767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/blocks/group/wp-style.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd1AAAAMo"]
[Mon Jul 20 06:10:42.645334 2026] [security2:error] [pid 843279:tid 843443] [client 103.141.108.143:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd2gAAAKY"]
[Mon Jul 20 06:10:42.645722 2026] [security2:error] [pid 843279:tid 843443] [client 103.141.108.143:55353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd2gAAAKY"]
[Mon Jul 20 06:10:42.803191 2026] [security2:error] [pid 843279:tid 843394] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/database.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd4QAA5XE"]
[Mon Jul 20 06:10:42.803425 2026] [security2:error] [pid 843279:tid 843507] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/database.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd4QAA5XE"]
[Mon Jul 20 06:10:42.925202 2026] [security2:error] [pid 843279:tid 843334] [remote 147.50.252.213:40080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd7wABBDU"]
[Mon Jul 20 06:10:43.009061 2026] [security2:error] [pid 843279:tid 843462] [client 14.225.17.146:50339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd6AAAALk"], referer: http://chestermonty.com/WORDPRESS
[Mon Jul 20 06:10:43.026948 2026] [security2:error] [pid 843279:tid 843519] [client 14.225.17.146:57131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdgQAAAPE"]
[Mon Jul 20 06:10:43.030418 2026] [security2:error] [pid 843279:tid 843421] [client 14.225.17.146:65130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd4wAAAJA"], referer: http://mezzacraft.com/WORDPRESS
[Mon Jul 20 06:10:43.050118 2026] [security2:error] [pid 843279:tid 843320] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd9gAA4Cc"]
[Mon Jul 20 06:10:43.050349 2026] [security2:error] [pid 843279:tid 843501] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd9gAA4Cc"]
[Mon Jul 20 06:10:43.108206 2026] [security2:error] [pid 843279:tid 843530] [client 181.224.94.124:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd_AAAAPw"]
[Mon Jul 20 06:10:43.108333 2026] [security2:error] [pid 843279:tid 843530] [client 181.224.94.124:4289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd_AAAAPw"]
[Mon Jul 20 06:10:43.218356 2026] [security2:error] [pid 843279:tid 843431] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeAgAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.250797 2026] [security2:error] [pid 843279:tid 843461] [client 57.141.18.79:58802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QPvqvKNcW5yy5T2CccQAAuGA"]
[Mon Jul 20 06:10:43.314485 2026] [security2:error] [pid 843279:tid 843426] [client 50.116.65.227:55708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd_gAAAJU"]
[Mon Jul 20 06:10:43.337622 2026] [security2:error] [pid 843279:tid 843418] [client 150.228.148.150:30228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeBwAAAI0"]
[Mon Jul 20 06:10:43.344044 2026] [security2:error] [pid 843279:tid 843418] [client 150.228.148.150:30228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeBwAAAI0"]
[Mon Jul 20 06:10:43.365125 2026] [security2:error] [pid 843279:tid 843460] [client 74.7.227.179:34510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeAwAAt1I"], referer: https://tejasenvironmental.com/p=437209
[Mon Jul 20 06:10:43.418507 2026] [security2:error] [pid 843279:tid 843327] [remote 147.50.252.213:40080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeEAAA7i4"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:10:43.453233 2026] [security2:error] [pid 843279:tid 843457] [client 50.116.65.227:55724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeBgAAALQ"]
[Mon Jul 20 06:10:43.467348 2026] [security2:error] [pid 843279:tid 843454] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeDQAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.638930 2026] [security2:error] [pid 843279:tid 843470] [client 86.98.90.58:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeIgAAAME"]
[Mon Jul 20 06:10:43.639123 2026] [security2:error] [pid 843279:tid 843470] [client 86.98.90.58:15603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeIgAAAME"]
[Mon Jul 20 06:10:43.679664 2026] [security2:error] [pid 843279:tid 843447] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeJAAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.766766 2026] [security2:error] [pid 843279:tid 843340] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLQAAqzs"]
[Mon Jul 20 06:10:43.767067 2026] [security2:error] [pid 843279:tid 843448] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLQAAqzs"]
[Mon Jul 20 06:10:43.774999 2026] [security2:error] [pid 843279:tid 843386] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLgAAiWk"]
[Mon Jul 20 06:10:43.775176 2026] [security2:error] [pid 843279:tid 843414] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLgAAiWk"]
[Mon Jul 20 06:10:43.787130 2026] [security2:error] [pid 843279:tid 843507] [client 112.213.160.112:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeMQAAAOU"]
[Mon Jul 20 06:10:43.787237 2026] [security2:error] [pid 843279:tid 843507] [client 112.213.160.112:8272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeMQAAAOU"]
[Mon Jul 20 06:10:43.987021 2026] [security2:error] [pid 843279:tid 843349] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/777.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeQwAA7kQ"]
[Mon Jul 20 06:10:43.987314 2026] [security2:error] [pid 843279:tid 843516] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/777.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeQwAA7kQ"]
[Mon Jul 20 06:10:43.988384 2026] [security2:error] [pid 843279:tid 843497] [client 14.225.17.146:57155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeNQAAANw"], referer: https://chestermonty.com/WORDPRESS
[Mon Jul 20 06:10:43.996618 2026] [security2:error] [pid 843279:tid 843426] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QQ_qvKNcW5yy5T2CePAAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.998567 2026] [security2:error] [pid 843279:tid 843393] [remote 194.164.192.228:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeRQAAuHA"]
[Mon Jul 20 06:10:44.014999 2026] [security2:error] [pid 843279:tid 843454] [client 50.116.65.227:23888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4QRPqvKNcW5yy5T2CeSQAAALE"]
[Mon Jul 20 06:10:44.026685 2026] [security2:error] [pid 843279:tid 843491] [client 50.116.65.227:55750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4QRPqvKNcW5yy5T2CeSwAAANY"]
[Mon Jul 20 06:10:44.050644 2026] [security2:error] [pid 843279:tid 843476] [client 57.141.18.108:40122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QP_qvKNcW5yy5T2CcrwAAxyo"]
[Mon Jul 20 06:10:44.055479 2026] [security2:error] [pid 843279:tid 843479] [client 193.19.109.247:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetalkswithkay.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeTAAAAMo"]
[Mon Jul 20 06:10:44.104948 2026] [security2:error] [pid 843279:tid 843431] [client 45.116.69.230:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeUAAAAJo"]
[Mon Jul 20 06:10:44.105121 2026] [security2:error] [pid 843279:tid 843431] [client 45.116.69.230:51650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeUAAAAJo"]
[Mon Jul 20 06:10:44.186317 2026] [security2:error] [pid 843279:tid 843337] [remote 194.164.192.228:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeWgAAwzg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:44.202354 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeXAAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:44.223668 2026] [security2:error] [pid 843279:tid 843319] [remote 91.142.222.105:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeYQAAsCY"]
[Mon Jul 20 06:10:44.230636 2026] [security2:error] [pid 843279:tid 843342] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ssixta.php"] [unique_id "al4QRPqvKNcW5yy5T2CeYgAAlz0"]
[Mon Jul 20 06:10:44.230845 2026] [security2:error] [pid 843279:tid 843428] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ssixta.php"] [unique_id "al4QRPqvKNcW5yy5T2CeYgAAlz0"]
[Mon Jul 20 06:10:44.267212 2026] [security2:error] [pid 843279:tid 843515] [client 103.95.123.246:19629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZQAAAO0"]
[Mon Jul 20 06:10:44.267356 2026] [security2:error] [pid 843279:tid 843515] [client 103.95.123.246:19629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZQAAAO0"]
[Mon Jul 20 06:10:44.313623 2026] [security2:error] [pid 843279:tid 843422] [client 41.173.37.102:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZwAAAJE"]
[Mon Jul 20 06:10:44.313760 2026] [security2:error] [pid 843279:tid 843422] [client 41.173.37.102:14204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZwAAAJE"]
[Mon Jul 20 06:10:44.419580 2026] [security2:error] [pid 843279:tid 843369] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/1c.php"] [unique_id "al4QRPqvKNcW5yy5T2CebAAAuVg"]
[Mon Jul 20 06:10:44.419854 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/1c.php"] [unique_id "al4QRPqvKNcW5yy5T2CebAAAuVg"]
[Mon Jul 20 06:10:44.565489 2026] [security2:error] [pid 843279:tid 843481] [client 14.225.17.146:49302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeIwAAAMw"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WORDPRESS
[Mon Jul 20 06:10:44.602099 2026] [security2:error] [pid 843279:tid 843505] [client 185.132.186.53:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/buy.php"] [unique_id "al4QRPqvKNcW5yy5T2CegAAAAOQ"]
[Mon Jul 20 06:10:44.650845 2026] [security2:error] [pid 843279:tid 843359] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/test2.php"] [unique_id "al4QRPqvKNcW5yy5T2CeggAAqk4"]
[Mon Jul 20 06:10:44.651086 2026] [security2:error] [pid 843279:tid 843447] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/test2.php"] [unique_id "al4QRPqvKNcW5yy5T2CeggAAqk4"]
[Mon Jul 20 06:10:44.747973 2026] [security2:error] [pid 843279:tid 843465] [client 178.152.178.232:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CehAAAALw"]
[Mon Jul 20 06:10:44.748089 2026] [security2:error] [pid 843279:tid 843465] [client 178.152.178.232:36710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CehAAAALw"]
[Mon Jul 20 06:10:44.809951 2026] [security2:error] [pid 843279:tid 843451] [client 74.208.214.194:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QRPqvKNcW5yy5T2CeiwAAAK4"]
[Mon Jul 20 06:10:44.898838 2026] [security2:error] [pid 843279:tid 843350] [remote 91.142.222.105:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CejAAAm0U"], referer: https://travelbyfire.com/wp-login.php
[Mon Jul 20 06:10:44.960133 2026] [security2:error] [pid 843279:tid 843390] [remote 57.141.18.92:64462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4QRPqvKNcW5yy5T2CekQAAjW0"]
[Mon Jul 20 06:10:45.137504 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRfqvKNcW5yy5T2CengAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.137626 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRfqvKNcW5yy5T2CengAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.160938 2026] [security2:error] [pid 843279:tid 843293] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CeoAAAtAw"]
[Mon Jul 20 06:10:45.161128 2026] [security2:error] [pid 843279:tid 843457] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CeoAAAtAw"]
[Mon Jul 20 06:10:45.401812 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QRfqvKNcW5yy5T2CesAAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.565333 2026] [security2:error] [pid 843279:tid 843353] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CewgAAsEg"]
[Mon Jul 20 06:10:45.565546 2026] [security2:error] [pid 843279:tid 843453] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CewgAAsEg"]
[Mon Jul 20 06:10:45.703662 2026] [security2:error] [pid 843279:tid 843481] [client 43.205.139.3:21238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CevgAAAMw"]
[Mon Jul 20 06:10:45.744145 2026] [security2:error] [pid 843279:tid 843492] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRfqvKNcW5yy5T2CezwAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.814575 2026] [security2:error] [pid 843279:tid 843290] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/buy.php"] [unique_id "al4QRfqvKNcW5yy5T2Ce1wAA-gk"]
[Mon Jul 20 06:10:45.814778 2026] [security2:error] [pid 843279:tid 843528] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/buy.php"] [unique_id "al4QRfqvKNcW5yy5T2Ce1wAA-gk"]
[Mon Jul 20 06:10:46.001872 2026] [security2:error] [pid 843279:tid 843285] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ssend.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce5AAArQQ"]
[Mon Jul 20 06:10:46.002081 2026] [security2:error] [pid 843279:tid 843450] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ssend.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce5AAArQQ"]
[Mon Jul 20 06:10:46.017634 2026] [security2:error] [pid 843279:tid 843441] [client 57.141.18.73:30776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQPqvKNcW5yy5T2CdVAAApA4"]
[Mon Jul 20 06:10:46.179502 2026] [security2:error] [pid 843279:tid 843529] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce6gAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:46.179573 2026] [security2:error] [pid 843279:tid 843462] [client 106.192.104.4:59515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce8wAAALk"]
[Mon Jul 20 06:10:46.194522 2026] [security2:error] [pid 843279:tid 843462] [client 106.192.104.4:59515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce8wAAALk"]
[Mon Jul 20 06:10:46.202867 2026] [security2:error] [pid 843279:tid 843465] [client 193.19.109.248:54193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce9QAAALw"]
[Mon Jul 20 06:10:46.512334 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfGAAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:46.515518 2026] [security2:error] [pid 843279:tid 843320] [remote 91.142.222.105:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfFgAA0Cc"]
[Mon Jul 20 06:10:46.544621 2026] [security2:error] [pid 843279:tid 843449] [client 57.141.18.60:39946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdcwAArGQ"]
[Mon Jul 20 06:10:46.561929 2026] [security2:error] [pid 843279:tid 843528] [client 164.100.212.184:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfHgAAAPo"]
[Mon Jul 20 06:10:46.562087 2026] [security2:error] [pid 843279:tid 843528] [client 164.100.212.184:55393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfHgAAAPo"]
[Mon Jul 20 06:10:46.747439 2026] [security2:error] [pid 843279:tid 843497] [client 3.109.4.218:26150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfLQAAANw"]
[Mon Jul 20 06:10:46.747552 2026] [security2:error] [pid 843279:tid 843497] [client 3.109.4.218:26150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfLQAAANw"]
[Mon Jul 20 06:10:46.749880 2026] [security2:error] [pid 843279:tid 843513] [client 103.153.183.69:13850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/.env"] [unique_id "al4QRvqvKNcW5yy5T2CfMAAAAOs"], referer: https://www.reddit.com/
[Mon Jul 20 06:10:46.754425 2026] [security2:error] [pid 843279:tid 843363] [remote 216.73.216.55:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4QRvqvKNcW5yy5T2CfMQAA3lI"]
[Mon Jul 20 06:10:46.789344 2026] [security2:error] [pid 843279:tid 843308] [remote 5.252.52.249:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfNAAAwRs"]
[Mon Jul 20 06:10:46.944375 2026] [security2:error] [pid 843279:tid 843475] [client 57.141.18.12:20248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdjAAAxnM"]
[Mon Jul 20 06:10:46.970425 2026] [security2:error] [pid 843279:tid 843299] [remote 5.252.52.249:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfPQAAiBI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:47.177783 2026] [security2:error] [pid 843279:tid 843478] [client 185.132.186.87:24395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/templates/beez3/av.php"] [unique_id "al4QR_qvKNcW5yy5T2CfSgAAAMk"]
[Mon Jul 20 06:10:47.245423 2026] [security2:error] [pid 843279:tid 843473] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QR_qvKNcW5yy5T2CfSAAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:47.342587 2026] [security2:error] [pid 843279:tid 843341] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/item.php"] [unique_id "al4QR_qvKNcW5yy5T2CfXwAA-zw"]
[Mon Jul 20 06:10:47.342811 2026] [security2:error] [pid 843279:tid 843529] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/item.php"] [unique_id "al4QR_qvKNcW5yy5T2CfXwAA-zw"]
[Mon Jul 20 06:10:47.451684 2026] [core:error] [pid 843279:tid 843437] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:47.451704 2026] [core:error] [pid 843279:tid 843437] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:47.536402 2026] [security2:error] [pid 843279:tid 843515] [client 14.225.17.146:52981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4QR_qvKNcW5yy5T2CfUgAAAO0"], referer: http://aljosour-alarabia.com/WORDPRESS
[Mon Jul 20 06:10:47.580218 2026] [security2:error] [pid 843279:tid 843440] [client 190.173.33.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4QR_qvKNcW5yy5T2CfVgAAozs"]
[Mon Jul 20 06:10:47.637143 2026] [security2:error] [pid 843279:tid 843447] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QR_qvKNcW5yy5T2CfdwAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:47.736372 2026] [security2:error] [pid 843279:tid 843337] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QR_qvKNcW5yy5T2CfgwAA7zg"]
[Mon Jul 20 06:10:47.736662 2026] [security2:error] [pid 843279:tid 843517] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QR_qvKNcW5yy5T2CfgwAA7zg"]
[Mon Jul 20 06:10:47.745876 2026] [security2:error] [pid 843279:tid 843527] [client 114.119.153.97:36075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4QR_qvKNcW5yy5T2CfhAAAAPk"], referer: http://www.thecreole.com?p=50750
[Mon Jul 20 06:10:47.869152 2026] [security2:error] [pid 843279:tid 843439] [client 57.141.18.97:24192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQvqvKNcW5yy5T2CdzAAAonw"]
[Mon Jul 20 06:10:48.080235 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QSPqvKNcW5yy5T2CfnwAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.149639 2026] [security2:error] [pid 843279:tid 843382] [remote 91.142.222.105:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2CfrwAAk2U"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 06:10:48.190660 2026] [security2:error] [pid 843279:tid 843335] [remote 157.66.26.183:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2CfswAAvzY"]
[Mon Jul 20 06:10:48.401232 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2CfyQAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.663081 2026] [security2:error] [pid 843279:tid 843364] [remote 157.66.26.183:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf0wAAjVM"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:10:48.732350 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf3QAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.732456 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf3QAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.854364 2026] [security2:error] [pid 843279:tid 843355] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ss.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf5gAAp0o"]
[Mon Jul 20 06:10:48.854495 2026] [security2:error] [pid 843279:tid 843444] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ss.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf5gAAp0o"]
[Mon Jul 20 06:10:48.953970 2026] [security2:error] [pid 843279:tid 843424] [client 193.19.109.236:20831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf8wAAAJM"]
[Mon Jul 20 06:10:49.103375 2026] [security2:error] [pid 843279:tid 843400] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/hypo.php"] [unique_id "al4QSfqvKNcW5yy5T2Cf-AAAxnc"]
[Mon Jul 20 06:10:49.103595 2026] [security2:error] [pid 843279:tid 843475] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/hypo.php"] [unique_id "al4QSfqvKNcW5yy5T2Cf-AAAxnc"]
[Mon Jul 20 06:10:49.128635 2026] [security2:error] [pid 843279:tid 843503] [client 185.132.186.62:48571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-wolf-widget.php"] [unique_id "al4QSfqvKNcW5yy5T2Cf-wAAAOI"]
[Mon Jul 20 06:10:49.234076 2026] [security2:error] [pid 843279:tid 843535] [client 27.96.94.195:37285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QSfqvKNcW5yy5T2CgAwAAAQE"]
[Mon Jul 20 06:10:49.234231 2026] [security2:error] [pid 843279:tid 843535] [client 27.96.94.195:37285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QSfqvKNcW5yy5T2CgAwAAAQE"]
[Mon Jul 20 06:10:49.326743 2026] [security2:error] [pid 843279:tid 843282] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/users.php"] [unique_id "al4QSfqvKNcW5yy5T2CgDQAA9gE"]
[Mon Jul 20 06:10:49.326919 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/users.php"] [unique_id "al4QSfqvKNcW5yy5T2CgDQAA9gE"]
[Mon Jul 20 06:10:49.464401 2026] [security2:error] [pid 843279:tid 843413] [client 98.159.234.160:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QSfqvKNcW5yy5T2CgGQAAAIg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:49.535880 2026] [security2:error] [pid 843279:tid 843527] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QSfqvKNcW5yy5T2CgGgAAAPk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:49.555029 2026] [security2:error] [pid 843279:tid 843380] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/177.php"] [unique_id "al4QSfqvKNcW5yy5T2CgHQAAsGM"]
[Mon Jul 20 06:10:49.555257 2026] [security2:error] [pid 843279:tid 843453] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/177.php"] [unique_id "al4QSfqvKNcW5yy5T2CgHQAAsGM"]
[Mon Jul 20 06:10:49.713674 2026] [security2:error] [pid 843279:tid 843478] [client 50.116.65.227:37536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QSfqvKNcW5yy5T2CgKgAAAMk"]
[Mon Jul 20 06:10:49.724422 2026] [security2:error] [pid 843279:tid 843502] [client 50.116.65.227:37538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QSfqvKNcW5yy5T2CgKwAAAOE"]
[Mon Jul 20 06:10:49.744380 2026] [security2:error] [pid 843279:tid 843397] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/config.php"] [unique_id "al4QSfqvKNcW5yy5T2CgLwAA23Q"]
[Mon Jul 20 06:10:49.744589 2026] [security2:error] [pid 843279:tid 843496] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/config.php"] [unique_id "al4QSfqvKNcW5yy5T2CgLwAA23Q"]
[Mon Jul 20 06:10:49.888668 2026] [security2:error] [pid 843279:tid 843443] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSfqvKNcW5yy5T2CgPAAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:49.911971 2026] [security2:error] [pid 843279:tid 843526] [client 44.245.170.32:15526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QSfqvKNcW5yy5T2CgPwAAAPg"]
[Mon Jul 20 06:10:49.972757 2026] [security2:error] [pid 843279:tid 843307] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/gettest.php"] [unique_id "al4QSfqvKNcW5yy5T2CgSQAAkxo"]
[Mon Jul 20 06:10:49.972994 2026] [security2:error] [pid 843279:tid 843424] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/gettest.php"] [unique_id "al4QSfqvKNcW5yy5T2CgSQAAkxo"]
[Mon Jul 20 06:10:50.161644 2026] [security2:error] [pid 843279:tid 843303] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/min.php"] [unique_id "al4QSvqvKNcW5yy5T2CgUgAAlBY"]
[Mon Jul 20 06:10:50.161867 2026] [security2:error] [pid 843279:tid 843425] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/min.php"] [unique_id "al4QSvqvKNcW5yy5T2CgUgAAlBY"]
[Mon Jul 20 06:10:50.195646 2026] [security2:error] [pid 843279:tid 843502] [client 50.116.65.227:37562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QSvqvKNcW5yy5T2CgXAAAAOE"]
[Mon Jul 20 06:10:50.205484 2026] [security2:error] [pid 843279:tid 843377] [remote 144.79.133.30:33396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgYAAA1mA"]
[Mon Jul 20 06:10:50.205690 2026] [security2:error] [pid 843279:tid 843491] [client 144.79.133.30:33396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgYAAA1mA"]
[Mon Jul 20 06:10:50.209427 2026] [security2:error] [pid 843279:tid 843428] [client 50.116.65.227:37564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QSvqvKNcW5yy5T2CgYQAAAJc"]
[Mon Jul 20 06:10:50.238941 2026] [security2:error] [pid 843279:tid 843469] [client 57.141.18.83:23694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QRPqvKNcW5yy5T2CefwAAwAU"]
[Mon Jul 20 06:10:50.286525 2026] [security2:error] [pid 843279:tid 843501] [client 35.90.38.209:29954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QSvqvKNcW5yy5T2CgcQAAAOA"]
[Mon Jul 20 06:10:50.350072 2026] [security2:error] [pid 843279:tid 843396] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/3PJcpMFsD8B.php"] [unique_id "al4QSvqvKNcW5yy5T2CgdwAAt3M"]
[Mon Jul 20 06:10:50.350284 2026] [security2:error] [pid 843279:tid 843460] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/3PJcpMFsD8B.php"] [unique_id "al4QSvqvKNcW5yy5T2CgdwAAt3M"]
[Mon Jul 20 06:10:50.426923 2026] [security2:error] [pid 843279:tid 843430] [client 14.225.17.146:56443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf1wAAAJk"], referer: http://superiorcopywriting.com/WORDPRESS
[Mon Jul 20 06:10:50.428723 2026] [security2:error] [pid 843279:tid 843422] [client 103.77.203.233:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgfwAAAJE"]
[Mon Jul 20 06:10:50.428887 2026] [security2:error] [pid 843279:tid 843422] [client 103.77.203.233:63110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgfwAAAJE"]
[Mon Jul 20 06:10:50.537511 2026] [security2:error] [pid 843279:tid 843367] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/dvjul.php"] [unique_id "al4QSvqvKNcW5yy5T2CgigAA4FY"]
[Mon Jul 20 06:10:50.537731 2026] [security2:error] [pid 843279:tid 843501] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/dvjul.php"] [unique_id "al4QSvqvKNcW5yy5T2CgigAA4FY"]
[Mon Jul 20 06:10:50.565163 2026] [security2:error] [pid 843279:tid 843477] [client 34.230.176.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4QSvqvKNcW5yy5T2CggAAAAMg"]
[Mon Jul 20 06:10:50.615592 2026] [security2:error] [pid 843279:tid 843414] [client 57.141.18.73:63374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QRPqvKNcW5yy5T2CeiAAAiTc"]
[Mon Jul 20 06:10:50.710578 2026] [security2:error] [pid 843279:tid 843452] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QSvqvKNcW5yy5T2CgkgAAAK8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:50.730220 2026] [security2:error] [pid 843279:tid 843313] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/biufile.php"] [unique_id "al4QSvqvKNcW5yy5T2CgowAAxiA"]
[Mon Jul 20 06:10:50.730469 2026] [security2:error] [pid 843279:tid 843475] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/biufile.php"] [unique_id "al4QSvqvKNcW5yy5T2CgowAAxiA"]
[Mon Jul 20 06:10:50.795373 2026] [security2:error] [pid 843279:tid 843498] [client 3.253.146.161:60926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4QSvqvKNcW5yy5T2CgiQAAAN0"]
[Mon Jul 20 06:10:50.931223 2026] [security2:error] [pid 843279:tid 843412] [client 44.245.170.32:15530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QSvqvKNcW5yy5T2CgvQAAAIc"]
[Mon Jul 20 06:10:50.951693 2026] [security2:error] [pid 843279:tid 843370] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/av.php"] [unique_id "al4QSvqvKNcW5yy5T2CgwQAAm1k"]
[Mon Jul 20 06:10:50.951853 2026] [security2:error] [pid 843279:tid 843432] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/av.php"] [unique_id "al4QSvqvKNcW5yy5T2CgwQAAm1k"]
[Mon Jul 20 06:10:51.022035 2026] [security2:error] [pid 843279:tid 843481] [client 35.90.38.209:24266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QS_qvKNcW5yy5T2CgxAAAAMw"]
[Mon Jul 20 06:10:51.102982 2026] [security2:error] [pid 843279:tid 843477] [client 185.132.186.80:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/install.php"] [unique_id "al4QS_qvKNcW5yy5T2CgxgAAAMg"]
[Mon Jul 20 06:10:51.170726 2026] [security2:error] [pid 843279:tid 843405] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/coffexium.php"] [unique_id "al4QS_qvKNcW5yy5T2CgygAA9nw"]
[Mon Jul 20 06:10:51.170932 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/coffexium.php"] [unique_id "al4QS_qvKNcW5yy5T2CgygAA9nw"]
[Mon Jul 20 06:10:51.351188 2026] [security2:error] [pid 843279:tid 843369] [remote 91.142.222.105:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg3QAArFg"]
[Mon Jul 20 06:10:51.359783 2026] [security2:error] [pid 843279:tid 843389] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/app.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg3wAAkWw"]
[Mon Jul 20 06:10:51.359948 2026] [security2:error] [pid 843279:tid 843422] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/app.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg3wAAkWw"]
[Mon Jul 20 06:10:51.408009 2026] [security2:error] [pid 843279:tid 843497] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg4QAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:51.576989 2026] [security2:error] [pid 843279:tid 843360] [remote 160.187.68.132:36526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg6wAApk8"]
[Mon Jul 20 06:10:51.681126 2026] [security2:error] [pid 843279:tid 843474] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg7gAAAMU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:51.721832 2026] [security2:error] [pid 843279:tid 843478] [client 3.109.4.218:37562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg-QAAAMk"]
[Mon Jul 20 06:10:51.721944 2026] [security2:error] [pid 843279:tid 843478] [client 3.109.4.218:37562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg-QAAAMk"]
[Mon Jul 20 06:10:51.982505 2026] [security2:error] [pid 843279:tid 843467] [client 158.173.166.181:27731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QS_qvKNcW5yy5T2ChFgAAAL4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:52.062206 2026] [security2:error] [pid 843279:tid 843407] [remote 160.187.68.132:36526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QTPqvKNcW5yy5T2ChHQAA7n4"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:10:52.309520 2026] [security2:error] [pid 843279:tid 843495] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTPqvKNcW5yy5T2ChMAAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:52.506495 2026] [security2:error] [pid 843279:tid 843510] [client 57.141.18.113:35864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QRvqvKNcW5yy5T2CfDQAA6DU"]
[Mon Jul 20 06:10:52.581224 2026] [security2:error] [pid 843279:tid 843465] [client 52.91.65.34:58742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gertoger.org"] [uri "/wp-content/uploads/2018/01/GERtoGER-Geotourism-Mongolia-_-Mongolian-Nomadic-Homestays-1.jpg"] [unique_id "al4QTPqvKNcW5yy5T2ChQAAAALw"]
[Mon Jul 20 06:10:52.770373 2026] [security2:error] [pid 843279:tid 843474] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QTPqvKNcW5yy5T2ChUgAAAMU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:52.957130 2026] [security2:error] [pid 843279:tid 843295] [remote 91.142.222.105:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QTPqvKNcW5yy5T2ChawAA5A4"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:53.324045 2026] [security2:error] [pid 843279:tid 843537] [client 57.141.18.91:51152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QR_qvKNcW5yy5T2CfRwABAyk"]
[Mon Jul 20 06:10:53.327730 2026] [security2:error] [pid 843279:tid 843307] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/core.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhgAA3Ro"]
[Mon Jul 20 06:10:53.327991 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/core.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhgAA3Ro"]
[Mon Jul 20 06:10:53.329767 2026] [security2:error] [pid 843279:tid 843477] [client 103.141.108.143:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhwAAAMg"]
[Mon Jul 20 06:10:53.330999 2026] [security2:error] [pid 843279:tid 843477] [client 103.141.108.143:55812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhwAAAMg"]
[Mon Jul 20 06:10:53.621325 2026] [security2:error] [pid 843279:tid 843503] [client 181.224.94.124:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChmQAAAOI"]
[Mon Jul 20 06:10:53.621484 2026] [security2:error] [pid 843279:tid 843503] [client 181.224.94.124:4300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChmQAAAOI"]
[Mon Jul 20 06:10:53.668884 2026] [security2:error] [pid 843279:tid 843492] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTfqvKNcW5yy5T2ChoAAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:53.702009 2026] [security2:error] [pid 843279:tid 843507] [client 45.141.148.148:54866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zarbeautyworld.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg8QAAAOU"]
[Mon Jul 20 06:10:53.753599 2026] [security2:error] [pid 843279:tid 843289] [remote 5.161.225.162:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e36532c6.faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4QTfqvKNcW5yy5T2ChpwAA5gg"]
[Mon Jul 20 06:10:53.756619 2026] [security2:error] [pid 843279:tid 843308] [remote 124.55.178.99:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChqAAApRs"]
[Mon Jul 20 06:10:53.756715 2026] [security2:error] [pid 843279:tid 843442] [client 124.55.178.99:55784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChqAAApRs"]
[Mon Jul 20 06:10:53.828370 2026] [security2:error] [pid 843279:tid 843447] [client 114.119.144.7:60679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiandcitystreets.com"] [uri "/robots.txt"] [unique_id "al4QTfqvKNcW5yy5T2ChsAAAAKo"], referer: http://acaiandcitystreets.com/robots.txt
[Mon Jul 20 06:10:54.366693 2026] [security2:error] [pid 843279:tid 843465] [client 86.98.90.58:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch6wAAALw"]
[Mon Jul 20 06:10:54.370851 2026] [security2:error] [pid 843279:tid 843465] [client 86.98.90.58:16380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch6wAAALw"]
[Mon Jul 20 06:10:54.447224 2026] [security2:error] [pid 843279:tid 843513] [client 150.228.148.150:10370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch8gAAAOs"]
[Mon Jul 20 06:10:54.478998 2026] [security2:error] [pid 843279:tid 843513] [client 150.228.148.150:10370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch8gAAAOs"]
[Mon Jul 20 06:10:54.501204 2026] [security2:error] [pid 843279:tid 843356] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch-QAA8Us"]
[Mon Jul 20 06:10:54.501443 2026] [security2:error] [pid 843279:tid 843519] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch-QAA8Us"]
[Mon Jul 20 06:10:54.526656 2026] [security2:error] [pid 843279:tid 843450] [client 112.213.160.112:31186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch_gAAAK0"]
[Mon Jul 20 06:10:54.526900 2026] [security2:error] [pid 843279:tid 843450] [client 112.213.160.112:31186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch_gAAAK0"]
[Mon Jul 20 06:10:54.602016 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTvqvKNcW5yy5T2CiAQAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:54.602197 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTvqvKNcW5yy5T2CiAQAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:54.718110 2026] [security2:error] [pid 843279:tid 843442] [client 185.132.186.66:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugins/function.php"] [unique_id "al4QTvqvKNcW5yy5T2CiDAAAAKU"]
[Mon Jul 20 06:10:54.843398 2026] [security2:error] [pid 843279:tid 843415] [client 45.116.69.230:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiFgAAAIo"]
[Mon Jul 20 06:10:54.843516 2026] [security2:error] [pid 843279:tid 843415] [client 45.116.69.230:52141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiFgAAAIo"]
[Mon Jul 20 06:10:54.885306 2026] [security2:error] [pid 843279:tid 843469] [client 41.173.37.102:14657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiGAAAAMA"]
[Mon Jul 20 06:10:54.885447 2026] [security2:error] [pid 843279:tid 843469] [client 41.173.37.102:14657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiGAAAAMA"]
[Mon Jul 20 06:10:55.010912 2026] [security2:error] [pid 843279:tid 843439] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QTvqvKNcW5yy5T2CiHgAAAKI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:55.099346 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:19885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiJwAAAMo"]
[Mon Jul 20 06:10:55.099974 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:19885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiJwAAAMo"]
[Mon Jul 20 06:10:55.414578 2026] [security2:error] [pid 843279:tid 843385] [remote 8.217.108.67:57214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiPgAAx2g"]
[Mon Jul 20 06:10:55.414793 2026] [security2:error] [pid 843279:tid 843476] [client 8.217.108.67:57214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiPgAAx2g"]
[Mon Jul 20 06:10:55.555070 2026] [security2:error] [pid 843279:tid 843436] [client 57.141.18.87:32894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QSfqvKNcW5yy5T2CgDgAAn30"]
[Mon Jul 20 06:10:55.710860 2026] [security2:error] [pid 843279:tid 843407] [remote 100.42.191.181:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.191.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiVgAAwH4"]
[Mon Jul 20 06:10:55.711153 2026] [security2:error] [pid 843279:tid 843469] [client 100.42.191.181:35560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiVgAAwH4"]
[Mon Jul 20 06:10:55.748087 2026] [security2:error] [pid 843279:tid 843390] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiWQAA0W0"]
[Mon Jul 20 06:10:55.748264 2026] [security2:error] [pid 843279:tid 843486] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiWQAA0W0"]
[Mon Jul 20 06:10:55.843127 2026] [security2:error] [pid 843279:tid 843310] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/header.php"] [unique_id "al4QT_qvKNcW5yy5T2CiZgAA3R0"]
[Mon Jul 20 06:10:55.843331 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/header.php"] [unique_id "al4QT_qvKNcW5yy5T2CiZgAA3R0"]
[Mon Jul 20 06:10:56.032512 2026] [security2:error] [pid 843279:tid 843374] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/als.php"] [unique_id "al4QUPqvKNcW5yy5T2CieQAA5F0"]
[Mon Jul 20 06:10:56.032821 2026] [security2:error] [pid 843279:tid 843505] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/als.php"] [unique_id "al4QUPqvKNcW5yy5T2CieQAA5F0"]
[Mon Jul 20 06:10:56.222972 2026] [security2:error] [pid 843279:tid 843290] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CijQABAQk"]
[Mon Jul 20 06:10:56.223175 2026] [security2:error] [pid 843279:tid 843535] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CijQABAQk"]
[Mon Jul 20 06:10:56.454072 2026] [security2:error] [pid 843279:tid 843431] [client 14.225.17.146:53874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4QT_qvKNcW5yy5T2CiJAAAAJo"], referer: http://phillipbloch.com/WORDPRESS
[Mon Jul 20 06:10:56.625503 2026] [security2:error] [pid 843279:tid 843516] [client 14.225.17.146:56301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4QUPqvKNcW5yy5T2CipwAAAO4"], referer: http://nextlevelpressurewashing.com/WORDPRESS
[Mon Jul 20 06:10:56.653123 2026] [security2:error] [pid 843279:tid 843522] [client 185.132.186.53:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/header.php"] [unique_id "al4QUPqvKNcW5yy5T2CitAAAAPQ"]
[Mon Jul 20 06:10:56.775705 2026] [security2:error] [pid 843279:tid 843460] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QUPqvKNcW5yy5T2CiugAAALc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:56.787096 2026] [security2:error] [pid 843279:tid 843464] [client 57.141.18.61:21832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QSvqvKNcW5yy5T2CgoQAAu3A"]
[Mon Jul 20 06:10:56.826619 2026] [security2:error] [pid 843279:tid 843451] [client 106.192.104.4:60001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CiwQAAAK4"]
[Mon Jul 20 06:10:56.826800 2026] [security2:error] [pid 843279:tid 843451] [client 106.192.104.4:60001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CiwQAAAK4"]
[Mon Jul 20 06:10:56.955209 2026] [security2:error] [pid 843279:tid 843339] [remote 5.161.225.162:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e36532c6.faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4QUPqvKNcW5yy5T2CizQAAzjo"], referer: https://website-e36532c6.faadenergy.com/wp-login.php
[Mon Jul 20 06:10:57.081073 2026] [security2:error] [pid 843279:tid 843537] [client 14.225.17.146:53877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch_wAAAQM"], referer: http://overloadcomedy.com/WORDPRESS
[Mon Jul 20 06:10:57.093674 2026] [security2:error] [pid 843279:tid 843403] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/simple.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci2QAAqno"]
[Mon Jul 20 06:10:57.093950 2026] [security2:error] [pid 843279:tid 843447] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/simple.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci2QAAqno"]
[Mon Jul 20 06:10:57.116409 2026] [security2:error] [pid 843279:tid 843286] [remote 95.217.78.234:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci2wAA2wU"]
[Mon Jul 20 06:10:57.173887 2026] [security2:error] [pid 843279:tid 843497] [client 164.100.212.184:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci4AAAANw"]
[Mon Jul 20 06:10:57.173996 2026] [security2:error] [pid 843279:tid 843497] [client 164.100.212.184:57417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci4AAAANw"]
[Mon Jul 20 06:10:57.352453 2026] [security2:error] [pid 843279:tid 843396] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/init.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci7wAAinM"]
[Mon Jul 20 06:10:57.352715 2026] [security2:error] [pid 843279:tid 843415] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/init.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci7wAAinM"]
[Mon Jul 20 06:10:57.362376 2026] [security2:error] [pid 843279:tid 843499] [client 14.225.17.146:63131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci3gAAAN4"], referer: http://soloceos.com/WORDPRESS
[Mon Jul 20 06:10:57.385802 2026] [security2:error] [pid 843279:tid 843528] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci6AAAAPo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:57.386124 2026] [security2:error] [pid 843279:tid 843316] [remote 95.217.78.234:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci9QAAziM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:57.491103 2026] [security2:error] [pid 843279:tid 843521] [client 57.141.18.46:39908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg6QAA81s"]
[Mon Jul 20 06:10:57.539475 2026] [security2:error] [pid 843279:tid 843371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/fpwch.php"] [unique_id "al4QUfqvKNcW5yy5T2CjAAAAiFo"]
[Mon Jul 20 06:10:57.539640 2026] [security2:error] [pid 843279:tid 843413] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/fpwch.php"] [unique_id "al4QUfqvKNcW5yy5T2CjAAAAiFo"]
[Mon Jul 20 06:10:57.697667 2026] [security2:error] [pid 843279:tid 843440] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QUfqvKNcW5yy5T2CjEAAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:57.727683 2026] [security2:error] [pid 843279:tid 843349] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/domvf.php"] [unique_id "al4QUfqvKNcW5yy5T2CjEwAAz0Q"]
[Mon Jul 20 06:10:57.727897 2026] [security2:error] [pid 843279:tid 843484] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/domvf.php"] [unique_id "al4QUfqvKNcW5yy5T2CjEwAAz0Q"]
[Mon Jul 20 06:10:57.855214 2026] [security2:error] [pid 843279:tid 843446] [client 45.141.148.148:54874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "zarbeautyworld.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4QUPqvKNcW5yy5T2CiiwAAAKk"], referer: https://zarbeautyworld.twz.oin.mybluehost.me/contact
[Mon Jul 20 06:10:57.954950 2026] [security2:error] [pid 843279:tid 843327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp.php"] [unique_id "al4QUfqvKNcW5yy5T2CjIwABAi4"]
[Mon Jul 20 06:10:57.955112 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp.php"] [unique_id "al4QUfqvKNcW5yy5T2CjIwABAi4"]
[Mon Jul 20 06:10:58.041342 2026] [security2:error] [pid 843279:tid 843478] [client 196.251.121.187:64441] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "aviationsynergy.aero"] [uri "/wp-json/batch/v1"] [unique_id "al4QUvqvKNcW5yy5T2CjKQAAAMk"]
[Mon Jul 20 06:10:58.237681 2026] [security2:error] [pid 843279:tid 843287] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjOgAAsgY"]
[Mon Jul 20 06:10:58.237921 2026] [security2:error] [pid 843279:tid 843455] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjOgAAsgY"]
[Mon Jul 20 06:10:58.273297 2026] [security2:error] [pid 843279:tid 843366] [remote 51.222.168.118:37988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "taskidsvirginia.com"] [uri "/casino-711-nl-volledige-handleiding-aanmelden-bonussen-berekenen-veilig-spelen/"] [unique_id "al4QUvqvKNcW5yy5T2CjPQAAt1U"]
[Mon Jul 20 06:10:58.273495 2026] [security2:error] [pid 843279:tid 843460] [client 51.222.168.118:37988] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "taskidsvirginia.com"] [uri "/casino-711-nl-volledige-handleiding-aanmelden-bonussen-berekenen-veilig-spelen/"] [unique_id "al4QUvqvKNcW5yy5T2CjPQAAt1U"]
[Mon Jul 20 06:10:58.411617 2026] [security2:error] [pid 843279:tid 843418] [client 57.141.18.22:22960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QTPqvKNcW5yy5T2ChZgAAjQ0"]
[Mon Jul 20 06:10:58.619916 2026] [security2:error] [pid 843279:tid 843343] [remote 162.19.86.63:43764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QUvqvKNcW5yy5T2CjWAAA2D4"]
[Mon Jul 20 06:10:58.693857 2026] [security2:error] [pid 843279:tid 843459] [client 14.225.17.146:63155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci3wAAALY"], referer: http://reosportsboats.com/WORDPRESS
[Mon Jul 20 06:10:58.715417 2026] [security2:error] [pid 843279:tid 843514] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QUvqvKNcW5yy5T2CjVgAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:58.770063 2026] [autoindex:error] [pid 843279:tid 843453] [client 65.49.1.46:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:58.826565 2026] [security2:error] [pid 843279:tid 843360] [remote 162.19.86.63:43764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QUvqvKNcW5yy5T2CjcAAAuU8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:10:58.927067 2026] [security2:error] [pid 843279:tid 843354] [remote 182.77.62.24:35248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjdgAA50k"]
[Mon Jul 20 06:10:58.927283 2026] [security2:error] [pid 843279:tid 843509] [client 182.77.62.24:35248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjdgAA50k"]
[Mon Jul 20 06:10:58.948625 2026] [security2:error] [pid 843279:tid 843364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/class.php"] [unique_id "al4QUvqvKNcW5yy5T2CjfQABAVM"]
[Mon Jul 20 06:10:58.948883 2026] [security2:error] [pid 843279:tid 843535] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/class.php"] [unique_id "al4QUvqvKNcW5yy5T2CjfQABAVM"]
[Mon Jul 20 06:10:59.083744 2026] [security2:error] [pid 843279:tid 843414] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QU_qvKNcW5yy5T2CjiQAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:59.173120 2026] [security2:error] [pid 843279:tid 843288] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/echkm.php"] [unique_id "al4QU_qvKNcW5yy5T2CjlwAAuQc"]
[Mon Jul 20 06:10:59.173336 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/echkm.php"] [unique_id "al4QU_qvKNcW5yy5T2CjlwAAuQc"]
[Mon Jul 20 06:10:59.425101 2026] [security2:error] [pid 843279:tid 843400] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/lib.php"] [unique_id "al4QU_qvKNcW5yy5T2CjogAA0nc"]
[Mon Jul 20 06:10:59.425274 2026] [security2:error] [pid 843279:tid 843487] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/lib.php"] [unique_id "al4QU_qvKNcW5yy5T2CjogAA0nc"]
[Mon Jul 20 06:10:59.611705 2026] [security2:error] [pid 843279:tid 843428] [client 14.225.17.146:56156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjqQAAAJc"], referer: https://reosportsboats.com/WORDPRESS
[Mon Jul 20 06:10:59.617661 2026] [security2:error] [pid 843279:tid 843355] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/login.php"] [unique_id "al4QU_qvKNcW5yy5T2CjsAAA7Eo"]
[Mon Jul 20 06:10:59.617845 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/login.php"] [unique_id "al4QU_qvKNcW5yy5T2CjsAAA7Eo"]
[Mon Jul 20 06:10:59.658410 2026] [security2:error] [pid 843279:tid 843453] [client 185.132.186.71:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wordpress/wp-content/uploads/install.php"] [unique_id "al4QU_qvKNcW5yy5T2CjsgAAALA"]
[Mon Jul 20 06:10:59.688703 2026] [security2:error] [pid 843279:tid 843521] [client 54.158.124.211:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjmAAAAPM"]
[Mon Jul 20 06:10:59.691673 2026] [security2:error] [pid 843279:tid 843499] [client 54.158.124.211:21442] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/robots.txt"] [unique_id "al4QU_qvKNcW5yy5T2CjkwAAAN4"]
[Mon Jul 20 06:10:59.856912 2026] [security2:error] [pid 843279:tid 843402] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/sites.php"] [unique_id "al4QU_qvKNcW5yy5T2CjxgAA8nk"]
[Mon Jul 20 06:10:59.857228 2026] [security2:error] [pid 843279:tid 843520] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/sites.php"] [unique_id "al4QU_qvKNcW5yy5T2CjxgAA8nk"]
[Mon Jul 20 06:11:00.052800 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:57061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjzAAAAKQ"], referer: http://39ishlife.com/WORDPRESS
[Mon Jul 20 06:11:00.069663 2026] [security2:error] [pid 843279:tid 843425] [client 14.225.17.146:56158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4QUvqvKNcW5yy5T2CjVAAAAJQ"], referer: http://dadanetnet.net/WORDPRESS
[Mon Jul 20 06:11:00.112833 2026] [security2:error] [pid 843279:tid 843393] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/a2.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj3wAAlXA"]
[Mon Jul 20 06:11:00.113097 2026] [security2:error] [pid 843279:tid 843426] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/a2.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj3wAAlXA"]
[Mon Jul 20 06:11:00.250701 2026] [security2:error] [pid 843279:tid 843464] [client 14.225.17.146:56011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjpAAAALs"], referer: http://waterproofgoods.com/WORDPRESS
[Mon Jul 20 06:11:00.275722 2026] [security2:error] [pid 843279:tid 843532] [client 14.225.17.146:56054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4QUfqvKNcW5yy5T2CjDAAAAP4"], referer: http://gearwaterproof.com/WORDPRESS
[Mon Jul 20 06:11:00.301326 2026] [security2:error] [pid 843279:tid 843381] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/d61.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj9gAA8mQ"]
[Mon Jul 20 06:11:00.301581 2026] [security2:error] [pid 843279:tid 843520] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/d61.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj9gAA8mQ"]
[Mon Jul 20 06:11:00.346333 2026] [security2:error] [pid 843279:tid 843526] [client 57.141.18.41:50330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QTvqvKNcW5yy5T2CiFAAA-Hw"]
[Mon Jul 20 06:11:00.617865 2026] [security2:error] [pid 843279:tid 843492] [client 50.116.65.227:20762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QVPqvKNcW5yy5T2CkCwAAANc"]
[Mon Jul 20 06:11:00.628496 2026] [security2:error] [pid 843279:tid 843462] [client 50.116.65.227:19838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QVPqvKNcW5yy5T2CkDQAAALk"]
[Mon Jul 20 06:11:00.716271 2026] [security2:error] [pid 843279:tid 843378] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/info.php"] [unique_id "al4QVPqvKNcW5yy5T2CkFQAA4mE"]
[Mon Jul 20 06:11:00.716536 2026] [security2:error] [pid 843279:tid 843503] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/info.php"] [unique_id "al4QVPqvKNcW5yy5T2CkFQAA4mE"]
[Mon Jul 20 06:11:00.766174 2026] [security2:error] [pid 843279:tid 843514] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QVPqvKNcW5yy5T2CkEwAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:00.879857 2026] [security2:error] [pid 843279:tid 843488] [client 3.87.117.29:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj3gAAANM"]
[Mon Jul 20 06:11:00.903769 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QVPqvKNcW5yy5T2CkLgAAAJA"]
[Mon Jul 20 06:11:00.903926 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:63646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QVPqvKNcW5yy5T2CkLgAAAJA"]
[Mon Jul 20 06:11:00.914973 2026] [security2:error] [pid 843279:tid 843413] [client 3.87.117.29:13186] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4QVPqvKNcW5yy5T2Cj2QAAAIg"]
[Mon Jul 20 06:11:00.919915 2026] [security2:error] [pid 843279:tid 843309] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QVPqvKNcW5yy5T2CkMAAApBw"]
[Mon Jul 20 06:11:00.920111 2026] [security2:error] [pid 843279:tid 843441] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QVPqvKNcW5yy5T2CkMAAApBw"]
[Mon Jul 20 06:11:00.972728 2026] [security2:error] [pid 843279:tid 843464] [client 14.225.17.146:55269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2CkKgAAALs"], referer: https://39ishlife.com/WORDPRESS
[Mon Jul 20 06:11:01.047529 2026] [security2:error] [pid 843279:tid 843474] [client 57.141.18.107:53256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QT_qvKNcW5yy5T2CiPQAAxVQ"]
[Mon Jul 20 06:11:01.098655 2026] [security2:error] [pid 843279:tid 843404] [remote 57.141.18.32:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3096972"] [unique_id "al4QVfqvKNcW5yy5T2CkPAAA-Hs"]
[Mon Jul 20 06:11:01.107947 2026] [security2:error] [pid 843279:tid 843359] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/v2.php"] [unique_id "al4QVfqvKNcW5yy5T2CkPwAA504"]
[Mon Jul 20 06:11:01.109087 2026] [security2:error] [pid 843279:tid 843509] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/v2.php"] [unique_id "al4QVfqvKNcW5yy5T2CkPwAA504"]
[Mon Jul 20 06:11:01.178193 2026] [security2:error] [pid 843279:tid 843527] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkRQAAAPk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.256717 2026] [security2:error] [pid 843279:tid 843313] [remote 217.61.143.92:39040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkTgAA_iA"]
[Mon Jul 20 06:11:01.354078 2026] [security2:error] [pid 843279:tid 843337] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/panel.php"] [unique_id "al4QVfqvKNcW5yy5T2CkXQAAujg"]
[Mon Jul 20 06:11:01.354352 2026] [security2:error] [pid 843279:tid 843463] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/panel.php"] [unique_id "al4QVfqvKNcW5yy5T2CkXQAAujg"]
[Mon Jul 20 06:11:01.393397 2026] [security2:error] [pid 843279:tid 843294] [remote 8.217.108.67:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkYAAA1Q0"]
[Mon Jul 20 06:11:01.494117 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QVfqvKNcW5yy5T2CkaQAAAN0"]
[Mon Jul 20 06:11:01.494260 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QVfqvKNcW5yy5T2CkaQAAAN0"]
[Mon Jul 20 06:11:01.501483 2026] [security2:error] [pid 843279:tid 843342] [remote 217.61.143.92:39040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkagAAyD0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:11:01.542558 2026] [security2:error] [pid 843279:tid 843346] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/dex.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbAAA50E"]
[Mon Jul 20 06:11:01.542852 2026] [security2:error] [pid 843279:tid 843509] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/dex.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbAAA50E"]
[Mon Jul 20 06:11:01.553452 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.553628 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.682305 2026] [security2:error] [pid 843279:tid 843343] [remote 72.167.132.114:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkdQAAij4"]
[Mon Jul 20 06:11:01.730514 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "origine.nz"] [uri "/1.php"] [unique_id "al4QVfqvKNcW5yy5T2CkegAAuh8"]
[Mon Jul 20 06:11:01.730603 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/1.php"] [unique_id "al4QVfqvKNcW5yy5T2CkegAAuh8"]
[Mon Jul 20 06:11:01.730795 2026] [security2:error] [pid 843279:tid 843463] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/1.php"] [unique_id "al4QVfqvKNcW5yy5T2CkegAAuh8"]
[Mon Jul 20 06:11:01.929610 2026] [security2:error] [pid 843279:tid 843369] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ms.php"] [unique_id "al4QVfqvKNcW5yy5T2CkiwAA9lg"]
[Mon Jul 20 06:11:01.929892 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ms.php"] [unique_id "al4QVfqvKNcW5yy5T2CkiwAA9lg"]
[Mon Jul 20 06:11:01.964866 2026] [security2:error] [pid 843279:tid 843420] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QVfqvKNcW5yy5T2CkiQAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.992170 2026] [security2:error] [pid 843279:tid 843490] [client 82.135.202.97:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.202.135.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/books/books_3.php"] [unique_id "al4QVfqvKNcW5yy5T2CkjwAAANU"]
[Mon Jul 20 06:11:02.090095 2026] [security2:error] [pid 843279:tid 843391] [remote 72.167.132.114:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CklgAA_24"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:11:02.167623 2026] [security2:error] [pid 843279:tid 843512] [client 57.141.18.23:64728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QUPqvKNcW5yy5T2CingAA6jE"]
[Mon Jul 20 06:11:02.232988 2026] [autoindex:error] [pid 843279:tid 843379] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:11:02.233608 2026] [security2:error] [pid 843279:tid 843450] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4QVvqvKNcW5yy5T2CknAAArWI"]
[Mon Jul 20 06:11:02.248179 2026] [security2:error] [pid 843279:tid 843345] [remote 188.40.28.4:44854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CkoQAAkkA"]
[Mon Jul 20 06:11:02.404821 2026] [security2:error] [pid 843279:tid 843412] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CkswAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:02.451144 2026] [security2:error] [pid 843279:tid 843361] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/memberfuns.php"] [unique_id "al4QVvqvKNcW5yy5T2CktwAA01A"]
[Mon Jul 20 06:11:02.451275 2026] [security2:error] [pid 843279:tid 843488] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/memberfuns.php"] [unique_id "al4QVvqvKNcW5yy5T2CktwAA01A"]
[Mon Jul 20 06:11:02.460305 2026] [security2:error] [pid 843279:tid 843401] [remote 188.40.28.4:44854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CkuAAAsXg"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:11:02.516356 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:56146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2CkFgAAAK4"], referer: http://koaconsultants.com/WORDPRESS
[Mon Jul 20 06:11:02.670101 2026] [security2:error] [pid 843279:tid 843353] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/0.php"] [unique_id "al4QVvqvKNcW5yy5T2CkxQAAq0g"]
[Mon Jul 20 06:11:02.670323 2026] [security2:error] [pid 843279:tid 843448] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/0.php"] [unique_id "al4QVvqvKNcW5yy5T2CkxQAAq0g"]
[Mon Jul 20 06:11:02.857761 2026] [security2:error] [pid 843279:tid 843380] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/BDKR28.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck4AAAymM"]
[Mon Jul 20 06:11:02.857977 2026] [security2:error] [pid 843279:tid 843479] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/BDKR28.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck4AAAymM"]
[Mon Jul 20 06:11:02.959029 2026] [security2:error] [pid 843279:tid 843447] [client 144.217.244.188:52442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck1AAAAKo"]
[Mon Jul 20 06:11:02.982154 2026] [security2:error] [pid 843279:tid 843314] [remote 103.187.169.251:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck7AAAzyE"]
[Mon Jul 20 06:11:03.023137 2026] [security2:error] [pid 843279:tid 843440] [client 14.225.17.146:57715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck4wAAAKM"]
[Mon Jul 20 06:11:03.080772 2026] [security2:error] [pid 843279:tid 843285] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/green1.php"] [unique_id "al4QV_qvKNcW5yy5T2Ck-QAA7AQ"]
[Mon Jul 20 06:11:03.081004 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/green1.php"] [unique_id "al4QV_qvKNcW5yy5T2Ck-QAA7AQ"]
[Mon Jul 20 06:11:03.272421 2026] [security2:error] [pid 843279:tid 843381] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/nc4.php"] [unique_id "al4QV_qvKNcW5yy5T2ClBAAA7mQ"]
[Mon Jul 20 06:11:03.272615 2026] [security2:error] [pid 843279:tid 843516] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/nc4.php"] [unique_id "al4QV_qvKNcW5yy5T2ClBAAA7mQ"]
[Mon Jul 20 06:11:03.510260 2026] [security2:error] [pid 843279:tid 843281] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/a1.php"] [unique_id "al4QV_qvKNcW5yy5T2ClGwAAhQA"]
[Mon Jul 20 06:11:03.510486 2026] [security2:error] [pid 843279:tid 843410] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/a1.php"] [unique_id "al4QV_qvKNcW5yy5T2ClGwAAhQA"]
[Mon Jul 20 06:11:03.577779 2026] [security2:error] [pid 843279:tid 843519] [client 14.225.17.146:57483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CklwAAAPE"], referer: http://samdothan.org/WORDPRESS
[Mon Jul 20 06:11:03.646738 2026] [security2:error] [pid 843279:tid 843320] [remote 103.187.169.251:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4QV_qvKNcW5yy5T2ClJwAAsSc"], referer: https://adambergeron.com/wp-login.php
[Mon Jul 20 06:11:03.698673 2026] [security2:error] [pid 843279:tid 843316] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/eee.php"] [unique_id "al4QV_qvKNcW5yy5T2ClLAAAkCM"]
[Mon Jul 20 06:11:03.698870 2026] [security2:error] [pid 843279:tid 843421] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/eee.php"] [unique_id "al4QV_qvKNcW5yy5T2ClLAAAkCM"]
[Mon Jul 20 06:11:03.795405 2026] [security2:error] [pid 843279:tid 843447] [client 14.225.17.146:54962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4QV_qvKNcW5yy5T2ClKAAAAKo"], referer: http://christiancountytrumpet.com/WORDPRESS
[Mon Jul 20 06:11:03.812084 2026] [security2:error] [pid 843279:tid 843309] [remote 216.73.216.55:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4QV_qvKNcW5yy5T2ClOwAAwBw"]
[Mon Jul 20 06:11:03.828725 2026] [security2:error] [pid 843279:tid 843444] [client 14.225.17.146:57463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CkywAAAKc"], referer: http://daseighty.net/WORDPRESS
[Mon Jul 20 06:11:03.927208 2026] [security2:error] [pid 843279:tid 843368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-aothait.php"] [unique_id "al4QV_qvKNcW5yy5T2ClRAAAtlc"]
[Mon Jul 20 06:11:03.927386 2026] [security2:error] [pid 843279:tid 843459] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-aothait.php"] [unique_id "al4QV_qvKNcW5yy5T2ClRAAAtlc"]
[Mon Jul 20 06:11:03.968895 2026] [security2:error] [pid 843279:tid 843537] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QV_qvKNcW5yy5T2ClQAAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.147051 2026] [security2:error] [pid 843279:tid 843327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/config.json.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVgAA1C4"]
[Mon Jul 20 06:11:04.147275 2026] [security2:error] [pid 843279:tid 843489] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/config.json.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVgAA1C4"]
[Mon Jul 20 06:11:04.179021 2026] [security2:error] [pid 843279:tid 843428] [client 103.141.108.143:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVwAAAJc"]
[Mon Jul 20 06:11:04.179154 2026] [security2:error] [pid 843279:tid 843428] [client 103.141.108.143:56280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVwAAAJc"]
[Mon Jul 20 06:11:04.179341 2026] [security2:error] [pid 843279:tid 843411] [client 181.224.94.124:6819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClWAAAAIY"]
[Mon Jul 20 06:11:04.179468 2026] [security2:error] [pid 843279:tid 843411] [client 181.224.94.124:6819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClWAAAAIY"]
[Mon Jul 20 06:11:04.209681 2026] [security2:error] [pid 843279:tid 843526] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QWPqvKNcW5yy5T2ClWgAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.307266 2026] [security2:error] [pid 843279:tid 843470] [client 66.249.73.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CkygAAAME"]
[Mon Jul 20 06:11:04.349703 2026] [security2:error] [pid 843279:tid 843375] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/2PJcpMFsD8B.php"] [unique_id "al4QWPqvKNcW5yy5T2ClagAAr14"]
[Mon Jul 20 06:11:04.349921 2026] [security2:error] [pid 843279:tid 843452] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/2PJcpMFsD8B.php"] [unique_id "al4QWPqvKNcW5yy5T2ClagAAr14"]
[Mon Jul 20 06:11:04.423081 2026] [security2:error] [pid 843279:tid 843323] [remote 202.51.202.242:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QWPqvKNcW5yy5T2ClcAAAoCo"]
[Mon Jul 20 06:11:04.524766 2026] [security2:error] [pid 843279:tid 843464] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QWPqvKNcW5yy5T2CldAAAALs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.563833 2026] [security2:error] [pid 843279:tid 843342] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/k2.php"] [unique_id "al4QWPqvKNcW5yy5T2ClfAAAlD0"]
[Mon Jul 20 06:11:04.564001 2026] [security2:error] [pid 843279:tid 843425] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/k2.php"] [unique_id "al4QWPqvKNcW5yy5T2ClfAAAlD0"]
[Mon Jul 20 06:11:04.712801 2026] [security2:error] [pid 843279:tid 843469] [client 185.132.186.82:40213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/server.php"] [unique_id "al4QWPqvKNcW5yy5T2ClhQAAAMA"]
[Mon Jul 20 06:11:04.774220 2026] [security2:error] [pid 843279:tid 843343] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/uiuvs58l.php"] [unique_id "al4QWPqvKNcW5yy5T2CljQAAmT4"]
[Mon Jul 20 06:11:04.774412 2026] [security2:error] [pid 843279:tid 843430] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/uiuvs58l.php"] [unique_id "al4QWPqvKNcW5yy5T2CljQAAmT4"]
[Mon Jul 20 06:11:04.826554 2026] [security2:error] [pid 843279:tid 843414] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QWPqvKNcW5yy5T2CllAAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.975440 2026] [security2:error] [pid 843279:tid 843385] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/40p9ixjd.php"] [unique_id "al4QWPqvKNcW5yy5T2ClpAAA7Wg"]
[Mon Jul 20 06:11:04.975570 2026] [security2:error] [pid 843279:tid 843515] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/40p9ixjd.php"] [unique_id "al4QWPqvKNcW5yy5T2ClpAAA7Wg"]
[Mon Jul 20 06:11:05.056166 2026] [security2:error] [pid 843279:tid 843443] [client 86.98.90.58:17138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClqgAAAKY"]
[Mon Jul 20 06:11:05.056530 2026] [security2:error] [pid 843279:tid 843443] [client 86.98.90.58:17138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClqgAAAKY"]
[Mon Jul 20 06:11:05.154418 2026] [security2:error] [pid 843279:tid 843330] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClrwAAijE"]
[Mon Jul 20 06:11:05.154546 2026] [security2:error] [pid 843279:tid 843415] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClrwAAijE"]
[Mon Jul 20 06:11:05.221520 2026] [security2:error] [pid 843279:tid 843457] [client 150.228.148.150:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2CltQAAALQ"]
[Mon Jul 20 06:11:05.221710 2026] [security2:error] [pid 843279:tid 843457] [client 150.228.148.150:61606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2CltQAAALQ"]
[Mon Jul 20 06:11:05.313832 2026] [security2:error] [pid 843279:tid 843528] [client 112.213.160.112:8633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClwQAAAPo"]
[Mon Jul 20 06:11:05.314061 2026] [security2:error] [pid 843279:tid 843528] [client 112.213.160.112:8633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClwQAAAPo"]
[Mon Jul 20 06:11:05.450409 2026] [security2:error] [pid 843279:tid 843461] [client 45.116.69.230:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1gAAALg"]
[Mon Jul 20 06:11:05.450564 2026] [security2:error] [pid 843279:tid 843461] [client 45.116.69.230:52645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1gAAALg"]
[Mon Jul 20 06:11:05.475897 2026] [security2:error] [pid 843279:tid 843329] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/uiuvs58l.update.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1wAA6zA"]
[Mon Jul 20 06:11:05.476175 2026] [security2:error] [pid 843279:tid 843513] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/uiuvs58l.update.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1wAA6zA"]
[Mon Jul 20 06:11:05.516273 2026] [security2:error] [pid 843279:tid 843418] [client 41.173.37.102:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl3AAAAI0"]
[Mon Jul 20 06:11:05.516383 2026] [security2:error] [pid 843279:tid 843418] [client 41.173.37.102:1153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl3AAAAI0"]
[Mon Jul 20 06:11:05.647190 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4QWfqvKNcW5yy5T2ClrAAAAK4"]
[Mon Jul 20 06:11:05.803187 2026] [security2:error] [pid 843279:tid 843510] [client 57.141.18.9:51176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj2wAA6CI"]
[Mon Jul 20 06:11:05.858496 2026] [security2:error] [pid 843279:tid 843290] [remote 111.225.148.180:28712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/08/combined-august-30-2022-predeadline-comment.pdf"] [unique_id "al4QWfqvKNcW5yy5T2Cl8AAA4Qk"]
[Mon Jul 20 06:11:05.984839 2026] [security2:error] [pid 843279:tid 843291] [remote 202.51.202.242:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl9gAAqgo"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:11:06.333026 2026] [security2:error] [pid 843279:tid 843402] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmGAAA_3k"]
[Mon Jul 20 06:11:06.333191 2026] [security2:error] [pid 843279:tid 843533] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmGAAA_3k"]
[Mon Jul 20 06:11:06.466207 2026] [proxy:error] [pid 843279:tid 843495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:06.466247 2026] [proxy_http:error] [pid 843279:tid 843495] [client 198.235.24.57:61392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:06.467551 2026] [proxy:error] [pid 843279:tid 843495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:06.467581 2026] [proxy_http:error] [pid 843279:tid 843495] [client 198.235.24.57:61392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:06.932328 2026] [security2:error] [pid 843279:tid 843468] [client 14.225.17.146:52788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4QWvqvKNcW5yy5T2CmOQAAAL8"], referer: http://swafforddetailing.com/WORDPRESS
[Mon Jul 20 06:11:06.933709 2026] [security2:error] [pid 843279:tid 843304] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmSQAAhhc"]
[Mon Jul 20 06:11:06.933928 2026] [security2:error] [pid 843279:tid 843411] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmSQAAhhc"]
[Mon Jul 20 06:11:07.062036 2026] [security2:error] [pid 843279:tid 843423] [client 178.152.178.232:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmUQAAAJI"]
[Mon Jul 20 06:11:07.062181 2026] [security2:error] [pid 843279:tid 843423] [client 178.152.178.232:36428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmUQAAAJI"]
[Mon Jul 20 06:11:07.570130 2026] [security2:error] [pid 843279:tid 843292] [remote 160.187.68.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4QW_qvKNcW5yy5T2CmdQAA2Qs"]
[Mon Jul 20 06:11:07.742439 2026] [security2:error] [pid 843279:tid 843519] [client 185.132.186.69:37677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/autoload_classmap/install.php"] [unique_id "al4QW_qvKNcW5yy5T2CmhgAAAPE"]
[Mon Jul 20 06:11:07.777702 2026] [security2:error] [pid 843279:tid 843414] [client 164.100.212.184:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmigAAAIk"]
[Mon Jul 20 06:11:07.777810 2026] [security2:error] [pid 843279:tid 843414] [client 164.100.212.184:50711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmigAAAIk"]
[Mon Jul 20 06:11:07.911822 2026] [security2:error] [pid 843279:tid 843537] [client 103.153.183.69:61444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../var/www/html/.env"] [unique_id "al4QW_qvKNcW5yy5T2CmmAAAAQM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:07.921656 2026] [security2:error] [pid 843279:tid 843509] [client 57.141.18.59:58922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CklQAA51M"]
[Mon Jul 20 06:11:08.097526 2026] [security2:error] [pid 843279:tid 843484] [client 50.116.65.227:20812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4QXPqvKNcW5yy5T2CmpgAAAM8"]
[Mon Jul 20 06:11:08.098504 2026] [security2:error] [pid 843279:tid 843487] [client 50.116.65.227:19950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QXPqvKNcW5yy5T2CmpwAAANI"]
[Mon Jul 20 06:11:08.109193 2026] [security2:error] [pid 843279:tid 843466] [client 50.116.65.227:19974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QXPqvKNcW5yy5T2CmqgAAAL0"]
[Mon Jul 20 06:11:08.109204 2026] [security2:error] [pid 843279:tid 843490] [client 50.116.65.227:19962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4QXPqvKNcW5yy5T2CmqQAAAQQ"]
[Mon Jul 20 06:11:08.223787 2026] [security2:error] [pid 843279:tid 843419] [client 52.167.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QW_qvKNcW5yy5T2CmngAAAI4"]
[Mon Jul 20 06:11:08.444016 2026] [security2:error] [pid 843279:tid 843485] [client 106.192.104.4:60484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2CmygAAANA"]
[Mon Jul 20 06:11:08.445366 2026] [security2:error] [pid 843279:tid 843485] [client 106.192.104.4:60484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2CmygAAANA"]
[Mon Jul 20 06:11:08.465346 2026] [security2:error] [pid 843279:tid 843343] [remote 160.187.68.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4QXPqvKNcW5yy5T2CmzgAAsT4"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:11:08.759084 2026] [security2:error] [pid 843279:tid 843384] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2Cm4wABBGc"]
[Mon Jul 20 06:11:08.759276 2026] [security2:error] [pid 843279:tid 843538] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2Cm4wABBGc"]
[Mon Jul 20 06:11:08.992518 2026] [security2:error] [pid 843279:tid 843432] [client 104.234.53.70:33089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QXPqvKNcW5yy5T2Cm9wAAAJs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:09.104663 2026] [security2:error] [pid 843279:tid 843455] [client 57.141.18.81:47018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QV_qvKNcW5yy5T2Ck-gAAshM"]
[Mon Jul 20 06:11:09.307281 2026] [security2:error] [pid 843279:tid 843533] [client 14.225.17.146:54600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4QW_qvKNcW5yy5T2CmdgAAAP8"], referer: http://maplerespiteservices.com/WORDPRESS
[Mon Jul 20 06:11:09.403723 2026] [security2:error] [pid 843279:tid 843465] [client 57.141.18.14:22664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QV_qvKNcW5yy5T2ClHgAAvAg"]
[Mon Jul 20 06:11:09.718232 2026] [security2:error] [pid 843279:tid 843516] [client 104.234.53.73:39011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QXfqvKNcW5yy5T2CnHQAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:09.916616 2026] [security2:error] [pid 843279:tid 843475] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QXfqvKNcW5yy5T2CnLwAAAMY"]
[Mon Jul 20 06:11:10.101377 2026] [security2:error] [pid 843279:tid 843400] [remote 152.228.213.32:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnTgAAy3c"]
[Mon Jul 20 06:11:10.101605 2026] [security2:error] [pid 843279:tid 843480] [client 152.228.213.32:39906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnTgAAy3c"]
[Mon Jul 20 06:11:10.227483 2026] [security2:error] [pid 843279:tid 843411] [client 103.153.183.69:19140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8froot/.ssh/id_rsa"] [unique_id "al4QXvqvKNcW5yy5T2CnVgAAAIY"], referer: https://twitter.com/
[Mon Jul 20 06:11:10.357215 2026] [security2:error] [pid 843279:tid 843408] [remote 38.242.157.30:49180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnYQAA3H8"]
[Mon Jul 20 06:11:10.357419 2026] [security2:error] [pid 843279:tid 843497] [client 38.242.157.30:49180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnYQAA3H8"]
[Mon Jul 20 06:11:11.020812 2026] [security2:error] [pid 843279:tid 843478] [client 57.141.18.102:35518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QWPqvKNcW5yy5T2ClowAAyVg"]
[Mon Jul 20 06:11:11.147010 2026] [security2:error] [pid 843279:tid 843340] [remote 72.167.132.114:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnoQAAuDs"]
[Mon Jul 20 06:11:11.147229 2026] [security2:error] [pid 843279:tid 843461] [client 72.167.132.114:33568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnoQAAuDs"]
[Mon Jul 20 06:11:11.481127 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnsgAAAJk"]
[Mon Jul 20 06:11:11.481329 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnsgAAAJk"]
[Mon Jul 20 06:11:11.540492 2026] [security2:error] [pid 843279:tid 843433] [client 103.153.183.69:61444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../var/www/.env"] [unique_id "al4QX_qvKNcW5yy5T2CntgAAAJw"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:11.699040 2026] [security2:error] [pid 843279:tid 843527] [client 2.50.103.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QXfqvKNcW5yy5T2CnLgAAAPk"]
[Mon Jul 20 06:11:11.795960 2026] [security2:error] [pid 843279:tid 843528] [client 185.132.186.75:39759] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "al4QX_qvKNcW5yy5T2CnyAAAAPo"]
[Mon Jul 20 06:11:11.796088 2026] [security2:error] [pid 843279:tid 843528] [client 185.132.186.75:39759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "al4QX_qvKNcW5yy5T2CnyAAAAPo"]
[Mon Jul 20 06:11:12.033126 2026] [security2:error] [pid 843279:tid 843366] [remote 81.173.115.7:41692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QYPqvKNcW5yy5T2Cn2gAAy1U"]
[Mon Jul 20 06:11:12.033286 2026] [security2:error] [pid 843279:tid 843480] [client 81.173.115.7:41692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QYPqvKNcW5yy5T2Cn2gAAy1U"]
[Mon Jul 20 06:11:12.054150 2026] [security2:error] [pid 843279:tid 843459] [client 57.141.18.42:54358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QWvqvKNcW5yy5T2CmCgAAtiE"]
[Mon Jul 20 06:11:12.360333 2026] [security2:error] [pid 843279:tid 843419] [client 40.77.179.244:39490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "juniper3medical.com"] [uri "/index.php"] [unique_id "al4QYPqvKNcW5yy5T2Cn8QAAjlY"]
[Mon Jul 20 06:11:12.733914 2026] [security2:error] [pid 843279:tid 843520] [client 104.234.53.60:33315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QYPqvKNcW5yy5T2CoGQAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:14.126544 2026] [security2:error] [pid 843279:tid 843408] [remote 81.173.115.7:39962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4QYvqvKNcW5yy5T2CojQAA_X8"]
[Mon Jul 20 06:11:14.257248 2026] [security2:error] [pid 843279:tid 843479] [client 66.249.65.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4QYPqvKNcW5yy5T2CoIwAAAMo"]
[Mon Jul 20 06:11:14.398897 2026] [security2:error] [pid 843279:tid 843393] [remote 216.73.216.55:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4QYvqvKNcW5yy5T2CoqAAA33A"]
[Mon Jul 20 06:11:14.501991 2026] [security2:error] [pid 843279:tid 843296] [remote 81.173.115.7:39962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4QYvqvKNcW5yy5T2CosQAA4w8"], referer: https://north-woods-engineering.com/wp-login.php
[Mon Jul 20 06:11:14.533253 2026] [security2:error] [pid 843279:tid 843430] [client 14.225.17.146:49245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CokQAAAJk"], referer: http://carolinapressurewashers.com/WORDPRESS
[Mon Jul 20 06:11:14.737639 2026] [security2:error] [pid 843279:tid 843473] [client 181.224.94.124:38435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2CowwAAAMQ"]
[Mon Jul 20 06:11:14.737812 2026] [security2:error] [pid 843279:tid 843473] [client 181.224.94.124:38435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2CowwAAAMQ"]
[Mon Jul 20 06:11:14.891879 2026] [security2:error] [pid 843279:tid 843479] [client 103.141.108.143:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2Co0wAAAMo"]
[Mon Jul 20 06:11:14.892006 2026] [security2:error] [pid 843279:tid 843479] [client 103.141.108.143:56754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2Co0wAAAMo"]
[Mon Jul 20 06:11:14.984528 2026] [security2:error] [pid 843279:tid 843486] [client 47.128.55.158:53068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mollycahill.com"] [uri "/robots.txt"] [unique_id "al4QYvqvKNcW5yy5T2Co3AAAANE"]
[Mon Jul 20 06:11:15.012841 2026] [security2:error] [pid 843279:tid 843351] [remote 81.173.115.7:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co3gAAyUY"]
[Mon Jul 20 06:11:15.153878 2026] [security2:error] [pid 843279:tid 843317] [remote 84.247.172.23:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co6QAAzyQ"]
[Mon Jul 20 06:11:15.224314 2026] [security2:error] [pid 843279:tid 843320] [remote 81.173.115.7:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co7AAAzic"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 06:11:15.245645 2026] [security2:error] [pid 843279:tid 843454] [client 63.179.149.246:28378] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/bistec-encebollado-puerto-rican-steak-and-onions"] [unique_id "al4QY_qvKNcW5yy5T2Co7gAAALE"]
[Mon Jul 20 06:11:15.356212 2026] [security2:error] [pid 843279:tid 843486] [client 185.132.186.93:55753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ubh/av.php"] [unique_id "al4QY_qvKNcW5yy5T2Co9gAAANE"]
[Mon Jul 20 06:11:15.383032 2026] [security2:error] [pid 843279:tid 843359] [remote 84.247.172.23:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co-QAAxU4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:11:15.520882 2026] [security2:error] [pid 843279:tid 843498] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QY_qvKNcW5yy5T2Co_AAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:15.675822 2026] [security2:error] [pid 843279:tid 843455] [client 14.225.17.146:55979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CovgAAALI"], referer: http://retzkolonglogistics.com/WORDPRESS
[Mon Jul 20 06:11:15.706571 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2CpEAAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:15.709523 2026] [security2:error] [pid 843279:tid 843425] [client 150.228.148.150:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpEQAAAJQ"]
[Mon Jul 20 06:11:15.710164 2026] [security2:error] [pid 843279:tid 843425] [client 150.228.148.150:16900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpEQAAAJQ"]
[Mon Jul 20 06:11:15.822988 2026] [security2:error] [pid 843279:tid 843314] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpGgABASE"]
[Mon Jul 20 06:11:15.823140 2026] [security2:error] [pid 843279:tid 843535] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpGgABASE"]
[Mon Jul 20 06:11:15.945173 2026] [security2:error] [pid 843279:tid 843538] [client 112.213.160.112:30747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpLwAAAQQ"]
[Mon Jul 20 06:11:15.945293 2026] [security2:error] [pid 843279:tid 843538] [client 112.213.160.112:30747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpLwAAAQQ"]
[Mon Jul 20 06:11:16.113543 2026] [security2:error] [pid 843279:tid 843513] [client 86.98.90.58:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpPwAAAOs"]
[Mon Jul 20 06:11:16.113797 2026] [security2:error] [pid 843279:tid 843513] [client 86.98.90.58:17935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpPwAAAOs"]
[Mon Jul 20 06:11:16.147784 2026] [security2:error] [pid 843279:tid 843531] [client 50.116.65.227:60478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QZPqvKNcW5yy5T2CpQQAAAP0"]
[Mon Jul 20 06:11:16.160179 2026] [security2:error] [pid 843279:tid 843410] [client 41.173.37.102:1619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpQwAAAIU"]
[Mon Jul 20 06:11:16.160303 2026] [security2:error] [pid 843279:tid 843410] [client 41.173.37.102:1619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpQwAAAIU"]
[Mon Jul 20 06:11:16.161401 2026] [security2:error] [pid 843279:tid 843426] [client 50.116.65.227:15680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QZPqvKNcW5yy5T2CpQgAAAJU"]
[Mon Jul 20 06:11:16.168725 2026] [security2:error] [pid 843279:tid 843423] [client 45.116.69.230:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpRAAAAJI"]
[Mon Jul 20 06:11:16.168891 2026] [security2:error] [pid 843279:tid 843423] [client 45.116.69.230:53136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpRAAAAJI"]
[Mon Jul 20 06:11:16.266623 2026] [security2:error] [pid 843279:tid 843508] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpPgAAAOY"]
[Mon Jul 20 06:11:16.362099 2026] [security2:error] [pid 843279:tid 843486] [client 63.177.52.239:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QY_qvKNcW5yy5T2CpIAAAANE"]
[Mon Jul 20 06:11:16.369219 2026] [security2:error] [pid 843279:tid 843529] [client 63.177.52.239:62090] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/bistec-encebollado-puerto-rican-steak-and-onions"] [unique_id "al4QY_qvKNcW5yy5T2CpHAAAAPs"]
[Mon Jul 20 06:11:16.630795 2026] [security2:error] [pid 843279:tid 843532] [client 178.152.178.232:35842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpagAAAP4"]
[Mon Jul 20 06:11:16.630974 2026] [security2:error] [pid 843279:tid 843532] [client 178.152.178.232:35842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpagAAAP4"]
[Mon Jul 20 06:11:16.738193 2026] [security2:error] [pid 843279:tid 843476] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QZPqvKNcW5yy5T2CpbAAAAMc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:16.837338 2026] [security2:error] [pid 843279:tid 843433] [client 151.244.158.67:63536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpbQAAAJw"]
[Mon Jul 20 06:11:16.977103 2026] [security2:error] [pid 843279:tid 843309] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpggAA2xw"]
[Mon Jul 20 06:11:16.977293 2026] [security2:error] [pid 843279:tid 843496] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpggAA2xw"]
[Mon Jul 20 06:11:16.998761 2026] [security2:error] [pid 843279:tid 843412] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZPqvKNcW5yy5T2CphgAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:17.072167 2026] [security2:error] [pid 843279:tid 843461] [client 14.225.17.146:64175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4QY_qvKNcW5yy5T2Co7wAAALg"], referer: http://tacticaltreeoperations.com/WORDPRESS
[Mon Jul 20 06:11:17.355881 2026] [security2:error] [pid 843279:tid 843416] [client 185.132.186.68:27351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/anas.php"] [unique_id "al4QZfqvKNcW5yy5T2CpogAAAIs"]
[Mon Jul 20 06:11:17.379211 2026] [security2:error] [pid 843279:tid 843353] [remote 182.77.62.24:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QZfqvKNcW5yy5T2CppQAA5Ug"]
[Mon Jul 20 06:11:17.444031 2026] [security2:error] [pid 843279:tid 843473] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QZfqvKNcW5yy5T2CppwAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:17.591584 2026] [security2:error] [pid 843279:tid 843503] [client 114.119.136.8:38509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "momheadquarters.com"] [uri "/robots.txt"] [unique_id "al4QZfqvKNcW5yy5T2CpwAAAAOI"], referer: http://momheadquarters.com/robots.txt
[Mon Jul 20 06:11:17.604780 2026] [security2:error] [pid 843279:tid 843302] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QZfqvKNcW5yy5T2CpwgAAsRU"]
[Mon Jul 20 06:11:17.604985 2026] [security2:error] [pid 843279:tid 843454] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QZfqvKNcW5yy5T2CpwgAAsRU"]
[Mon Jul 20 06:11:17.730632 2026] [security2:error] [pid 843279:tid 843518] [client 52.59.238.198:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpfQAAAPA"]
[Mon Jul 20 06:11:17.783883 2026] [security2:error] [pid 843279:tid 843489] [client 52.59.238.198:55048] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/bistec-encebollado-puerto-rican-steak-and-onions/"] [unique_id "al4QZPqvKNcW5yy5T2CpdwAAANQ"]
[Mon Jul 20 06:11:17.808330 2026] [security2:error] [pid 843279:tid 843433] [client 50.116.65.227:15724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QZfqvKNcW5yy5T2CpzwAAAJw"]
[Mon Jul 20 06:11:17.821267 2026] [security2:error] [pid 843279:tid 843524] [client 50.116.65.227:15738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QZfqvKNcW5yy5T2Cp0gAAAPY"]
[Mon Jul 20 06:11:18.408917 2026] [security2:error] [pid 843279:tid 843460] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAQAAALc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:18.413863 2026] [security2:error] [pid 843279:tid 843476] [client 164.100.212.184:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAgAAAMc"]
[Mon Jul 20 06:11:18.413958 2026] [security2:error] [pid 843279:tid 843476] [client 164.100.212.184:51298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAgAAAMc"]
[Mon Jul 20 06:11:18.454270 2026] [security2:error] [pid 843279:tid 843439] [client 23.251.146.115:1264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAAAAonI"]
[Mon Jul 20 06:11:18.457182 2026] [security2:error] [pid 843279:tid 843531] [client 23.251.146.115:1904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2Cp_gAA_XQ"]
[Mon Jul 20 06:11:18.503220 2026] [security2:error] [pid 843279:tid 843495] [client 57.141.18.75:63364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QYPqvKNcW5yy5T2CoFAAA2i8"]
[Mon Jul 20 06:11:18.557018 2026] [security2:error] [pid 843279:tid 843488] [client 14.225.17.146:55728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpdQAAANM"], referer: http://nurturemarple.co.uk/WORDPRESS
[Mon Jul 20 06:11:18.576257 2026] [security2:error] [pid 843279:tid 843415] [client 23.251.146.115:1264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqDwAAijo"]
[Mon Jul 20 06:11:18.599106 2026] [security2:error] [pid 843279:tid 843437] [client 23.251.146.115:1904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqEQAAoAA"]
[Mon Jul 20 06:11:18.612819 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZvqvKNcW5yy5T2CqGwAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:18.630840 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZvqvKNcW5yy5T2CqGwAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:18.841707 2026] [security2:error] [pid 843279:tid 843536] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqKwAAAQI"]
[Mon Jul 20 06:11:18.877700 2026] [security2:error] [pid 843279:tid 843535] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqLQAAAQE"]
[Mon Jul 20 06:11:18.948841 2026] [security2:error] [pid 843279:tid 843534] [client 198.44.157.34:40310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqPgAAAQA"]
[Mon Jul 20 06:11:18.948975 2026] [security2:error] [pid 843279:tid 843534] [client 198.44.157.34:40310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqPgAAAQA"]
[Mon Jul 20 06:11:18.959883 2026] [security2:error] [pid 843279:tid 843531] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqOQAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:19.050007 2026] [security2:error] [pid 843279:tid 843413] [client 50.116.65.227:15774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqIQAAAIg"]
[Mon Jul 20 06:11:19.134170 2026] [security2:error] [pid 843279:tid 843519] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqWAAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:19.242527 2026] [security2:error] [pid 843279:tid 843352] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqXwAA7kc"]
[Mon Jul 20 06:11:19.242810 2026] [security2:error] [pid 843279:tid 843516] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqXwAA7kc"]
[Mon Jul 20 06:11:19.310905 2026] [security2:error] [pid 843279:tid 843520] [client 50.116.65.227:52180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqUwAAAPI"]
[Mon Jul 20 06:11:19.434887 2026] [security2:error] [pid 843279:tid 843524] [client 45.157.112.60:36893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqcQAAAPY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:19.471540 2026] [security2:error] [pid 843279:tid 843476] [client 106.192.104.4:60992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqfQAAAMc"]
[Mon Jul 20 06:11:19.471659 2026] [security2:error] [pid 843279:tid 843476] [client 106.192.104.4:60992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqfQAAAMc"]
[Mon Jul 20 06:11:19.499611 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:64243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqbwAAAJM"], referer: https://nurturemarple.co.uk/WORDPRESS
[Mon Jul 20 06:11:19.529109 2026] [security2:error] [pid 843279:tid 843489] [client 23.251.146.115:12320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqcgAA1CE"]
[Mon Jul 20 06:11:19.652600 2026] [security2:error] [pid 843279:tid 843501] [client 23.251.146.115:12320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqhwAA4Es"]
[Mon Jul 20 06:11:19.951451 2026] [security2:error] [pid 843279:tid 843521] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqmgAAAPM"]
[Mon Jul 20 06:11:19.975861 2026] [security2:error] [pid 843279:tid 843425] [client 107.175.132.21:50150] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "mail.tripppconsulting.com"] [uri "/"] [unique_id "al4QZ_qvKNcW5yy5T2CqpwAAAJQ"]
[Mon Jul 20 06:11:20.190316 2026] [security2:error] [pid 843279:tid 843300] [remote 182.77.62.24:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QaPqvKNcW5yy5T2CqwAAAixM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:11:20.210435 2026] [security2:error] [pid 843279:tid 843493] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QaPqvKNcW5yy5T2CqtgAAANg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:20.272722 2026] [security2:error] [pid 843279:tid 843432] [client 57.141.18.90:44582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CotgAAmyk"]
[Mon Jul 20 06:11:20.367567 2026] [security2:error] [pid 843279:tid 843443] [client 185.132.186.74:30899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/shell.php"] [unique_id "al4QaPqvKNcW5yy5T2Cq0QAAAKY"]
[Mon Jul 20 06:11:20.400153 2026] [security2:error] [pid 843279:tid 843428] [client 57.141.18.0:24482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CovAAAl3Y"]
[Mon Jul 20 06:11:20.495161 2026] [security2:error] [pid 843279:tid 843459] [client 14.225.17.146:64255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqTwAAALY"], referer: http://scott-assist.com/WORDPRESS
[Mon Jul 20 06:11:20.745186 2026] [security2:error] [pid 843279:tid 843472] [client 14.225.17.146:64276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqVwAAAMM"], referer: http://cephasnext.com/WORDPRESS
[Mon Jul 20 06:11:20.854645 2026] [security2:error] [pid 843279:tid 843413] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QaPqvKNcW5yy5T2Cq_QAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:20.925124 2026] [security2:error] [pid 843279:tid 843473] [client 74.7.230.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/robots.txt"] [unique_id "al4QaPqvKNcW5yy5T2CrAwAAAMQ"]
[Mon Jul 20 06:11:20.941250 2026] [security2:error] [pid 843279:tid 843477] [client 74.7.230.6:55774] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.maxenengineering.com"] [uri "/robots.txt"] [unique_id "al4QaPqvKNcW5yy5T2Cq_gAAyDM"]
[Mon Jul 20 06:11:21.138522 2026] [security2:error] [pid 843279:tid 843431] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QafqvKNcW5yy5T2CrDgAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:21.314941 2026] [security2:error] [pid 843279:tid 843402] [remote 130.51.180.8:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QafqvKNcW5yy5T2CrHwAA53k"]
[Mon Jul 20 06:11:21.464580 2026] [security2:error] [pid 843279:tid 843522] [client 14.225.17.146:64207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqZQAAAPQ"], referer: http://expertcultures.com/WORDPRESS
[Mon Jul 20 06:11:21.488680 2026] [security2:error] [pid 843279:tid 843295] [remote 130.51.180.8:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QafqvKNcW5yy5T2CrNAAAhQ4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:11:21.726097 2026] [security2:error] [pid 843279:tid 843328] [remote 92.222.104.201:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "puppoopatrol.com"] [uri "/wp-sitemap.xml"] [unique_id "al4QafqvKNcW5yy5T2CrTQAA8y8"]
[Mon Jul 20 06:11:21.726295 2026] [security2:error] [pid 843279:tid 843521] [client 92.222.104.201:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "puppoopatrol.com"] [uri "/wp-sitemap.xml"] [unique_id "al4QafqvKNcW5yy5T2CrTQAA8y8"]
[Mon Jul 20 06:11:21.892241 2026] [security2:error] [pid 843279:tid 843454] [client 27.96.94.195:37702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QafqvKNcW5yy5T2CrYgAAALE"]
[Mon Jul 20 06:11:21.892373 2026] [security2:error] [pid 843279:tid 843454] [client 27.96.94.195:37702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QafqvKNcW5yy5T2CrYgAAALE"]
[Mon Jul 20 06:11:21.978856 2026] [security2:error] [pid 843279:tid 843508] [client 14.225.17.146:55110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4QafqvKNcW5yy5T2CrMwAAAOY"]
[Mon Jul 20 06:11:22.021078 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2CqwgAApGw"], referer: http://aleishapenny.ca/WORDPRESS
[Mon Jul 20 06:11:22.114363 2026] [security2:error] [pid 843279:tid 843416] [client 103.77.203.233:64726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QavqvKNcW5yy5T2CreAAAAIs"]
[Mon Jul 20 06:11:22.114720 2026] [security2:error] [pid 843279:tid 843416] [client 103.77.203.233:64726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QavqvKNcW5yy5T2CreAAAAIs"]
[Mon Jul 20 06:11:22.416719 2026] [security2:error] [pid 843279:tid 843419] [client 57.141.18.120:38604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpcgAAjk8"]
[Mon Jul 20 06:11:22.446069 2026] [security2:error] [pid 843279:tid 843530] [client 14.225.17.146:65499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2CqrQAAAPw"], referer: http://balticsteelmgmt.com/WORDPRESS
[Mon Jul 20 06:11:22.550137 2026] [security2:error] [pid 843279:tid 843470] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QavqvKNcW5yy5T2CrkgAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:22.623057 2026] [security2:error] [pid 843279:tid 843457] [client 57.141.18.99:38360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZfqvKNcW5yy5T2CpigAAtCY"]
[Mon Jul 20 06:11:22.799776 2026] [security2:error] [pid 843279:tid 843511] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4QavqvKNcW5yy5T2CrmwAA6Sw"], referer: https://aleishapenny.ca/WORDPRESS
[Mon Jul 20 06:11:22.799776 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QavqvKNcW5yy5T2CrpAAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:22.818081 2026] [security2:error] [pid 843279:tid 843502] [client 57.141.18.63:30510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZfqvKNcW5yy5T2CplAAA4TU"]
[Mon Jul 20 06:11:23.314843 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qa_qvKNcW5yy5T2CrzwAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:23.383682 2026] [security2:error] [pid 843279:tid 843503] [client 185.132.186.82:35067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/erinyani/default.php"] [unique_id "al4Qa_qvKNcW5yy5T2Cr2wAAAOI"]
[Mon Jul 20 06:11:23.457242 2026] [security2:error] [pid 843279:tid 843533] [client 3.109.4.218:14676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Qa_qvKNcW5yy5T2Cr3wAAAP8"]
[Mon Jul 20 06:11:23.497724 2026] [core:error] [pid 843279:tid 843504] [client 14.225.17.146:59992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:23.497744 2026] [core:error] [pid 843279:tid 843504] [client 14.225.17.146:59992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:24.026707 2026] [security2:error] [pid 843279:tid 843484] [client 57.141.18.37:65102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqFwAAzys"]
[Mon Jul 20 06:11:24.189453 2026] [security2:error] [pid 843279:tid 843456] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsHQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.189624 2026] [security2:error] [pid 843279:tid 843456] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsHQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.219835 2026] [security2:error] [pid 843279:tid 843443] [client 74.7.228.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsFAAAAKY"], referer: https://www.maxenengineering.com/use-of-concrete-cutting-equipment/
[Mon Jul 20 06:11:24.473426 2026] [security2:error] [pid 843279:tid 843504] [client 14.225.17.146:60264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsLAAAAOM"], referer: http://fkconstructionfunding.com/WORDPRESS
[Mon Jul 20 06:11:24.504223 2026] [security2:error] [pid 843279:tid 843521] [client 65.1.132.125:12478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsOgAAAPM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:11:24.572176 2026] [security2:error] [pid 843279:tid 843537] [client 14.225.17.146:55233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsMwAAAQM"]
[Mon Jul 20 06:11:24.626116 2026] [security2:error] [pid 843279:tid 843513] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsPgAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.966488 2026] [security2:error] [pid 843279:tid 843485] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsaAAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.971375 2026] [security2:error] [pid 843279:tid 843495] [client 50.116.65.227:29158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QbPqvKNcW5yy5T2CsagAAANo"]
[Mon Jul 20 06:11:24.987016 2026] [security2:error] [pid 843279:tid 843427] [client 50.116.65.227:52230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QbPqvKNcW5yy5T2CsbAAAAJY"]
[Mon Jul 20 06:11:25.348515 2026] [security2:error] [pid 843279:tid 843511] [client 181.224.94.124:10329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CsiQAAAOk"]
[Mon Jul 20 06:11:25.348634 2026] [security2:error] [pid 843279:tid 843511] [client 181.224.94.124:10329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CsiQAAAOk"]
[Mon Jul 20 06:11:25.466278 2026] [security2:error] [pid 843279:tid 843455] [client 103.141.108.143:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CskgAAALI"]
[Mon Jul 20 06:11:25.466454 2026] [security2:error] [pid 843279:tid 843455] [client 103.141.108.143:57218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CskgAAALI"]
[Mon Jul 20 06:11:25.544624 2026] [security2:error] [pid 843279:tid 843418] [client 14.225.17.146:55453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QbfqvKNcW5yy5T2CsiwAAAI0"], referer: https://fkconstructionfunding.com/WORDPRESS
[Mon Jul 20 06:11:25.676167 2026] [security2:error] [pid 843279:tid 843486] [client 57.141.18.111:30134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2CqyAAA0Rw"]
[Mon Jul 20 06:11:25.754702 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:60239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsKgAAAJM"], referer: http://omrobuildingcenter.com/WORDPRESS
[Mon Jul 20 06:11:25.942047 2026] [security2:error] [pid 843279:tid 843389] [remote 212.95.34.85:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QbfqvKNcW5yy5T2CssgAAj2w"]
[Mon Jul 20 06:11:26.078843 2026] [security2:error] [pid 843279:tid 843317] [remote 20.87.239.85:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2CswAAA_yQ"]
[Mon Jul 20 06:11:26.151251 2026] [security2:error] [pid 843279:tid 843308] [remote 212.95.34.85:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2CsxwAA7xs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:11:26.172800 2026] [security2:error] [pid 843279:tid 843299] [remote 5.161.225.162:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2CsyQAA5hI"]
[Mon Jul 20 06:11:26.299632 2026] [security2:error] [pid 843279:tid 843448] [client 57.141.18.122:59510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2Cq9wAAqzA"]
[Mon Jul 20 06:11:26.414157 2026] [security2:error] [pid 843279:tid 843526] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs1AAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:26.596063 2026] [security2:error] [pid 843279:tid 843334] [remote 20.87.239.85:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs6wAAzzU"], referer: https://website-e4de5cd0.epu.kzx.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:11:26.609222 2026] [security2:error] [pid 843279:tid 843313] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs7QAA0yA"]
[Mon Jul 20 06:11:26.609381 2026] [security2:error] [pid 843279:tid 843488] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs7QAA0yA"]
[Mon Jul 20 06:11:26.691049 2026] [security2:error] [pid 843279:tid 843431] [client 112.213.160.112:30876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs-wAAAJo"]
[Mon Jul 20 06:11:26.691186 2026] [security2:error] [pid 843279:tid 843431] [client 112.213.160.112:30876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs-wAAAJo"]
[Mon Jul 20 06:11:26.719389 2026] [security2:error] [pid 843279:tid 843475] [client 14.225.17.146:49331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4QbvqvKNcW5yy5T2CsxAAAAMY"], referer: http://idigress.group/WORDPRESS
[Mon Jul 20 06:11:26.853127 2026] [security2:error] [pid 843279:tid 843434] [client 41.173.37.102:2095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtAgAAAJ0"]
[Mon Jul 20 06:11:26.853249 2026] [security2:error] [pid 843279:tid 843434] [client 41.173.37.102:2095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtAgAAAJ0"]
[Mon Jul 20 06:11:26.874887 2026] [security2:error] [pid 843279:tid 843478] [client 150.228.148.150:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtBQAAAMk"]
[Mon Jul 20 06:11:26.875001 2026] [security2:error] [pid 843279:tid 843478] [client 150.228.148.150:57920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtBQAAAMk"]
[Mon Jul 20 06:11:26.877694 2026] [security2:error] [pid 843279:tid 843489] [client 45.116.69.230:53638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtCAAAANQ"]
[Mon Jul 20 06:11:26.877793 2026] [security2:error] [pid 843279:tid 843489] [client 45.116.69.230:53638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtCAAAANQ"]
[Mon Jul 20 06:11:26.900809 2026] [security2:error] [pid 843279:tid 843416] [client 66.249.70.32:56580] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "gitec.org"] [uri "/robots.txt"] [unique_id "al4QbvqvKNcW5yy5T2CtDAAAAIs"]
[Mon Jul 20 06:11:26.915829 2026] [security2:error] [pid 843279:tid 843500] [client 185.132.186.75:48387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/index.php"] [unique_id "al4QbvqvKNcW5yy5T2CtEQAAAN8"]
[Mon Jul 20 06:11:27.133500 2026] [security2:error] [pid 843279:tid 843367] [remote 5.161.225.162:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtKAAAjFY"], referer: https://michiganhomecaregroup.com/wp-login.php
[Mon Jul 20 06:11:27.588866 2026] [security2:error] [pid 843279:tid 843371] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRgAA6lo"]
[Mon Jul 20 06:11:27.589021 2026] [security2:error] [pid 843279:tid 843512] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRgAA6lo"]
[Mon Jul 20 06:11:27.592277 2026] [security2:error] [pid 843279:tid 843486] [client 86.98.90.58:18668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRQAAANE"]
[Mon Jul 20 06:11:27.592374 2026] [security2:error] [pid 843279:tid 843486] [client 86.98.90.58:18668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRQAAANE"]
[Mon Jul 20 06:11:27.645077 2026] [security2:error] [pid 843279:tid 843410] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtSAAAAIU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:27.652205 2026] [security2:error] [pid 843279:tid 843505] [client 57.141.18.31:47876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QavqvKNcW5yy5T2CrfAAA5Ho"]
[Mon Jul 20 06:11:27.904425 2026] [security2:error] [pid 843279:tid 843472] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtVAAAAMM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:28.098598 2026] [security2:error] [pid 843279:tid 843390] [remote 152.228.213.32:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4QcPqvKNcW5yy5T2CtcwAA-20"]
[Mon Jul 20 06:11:28.203471 2026] [security2:error] [pid 843279:tid 843522] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtbwAAAPQ"]
[Mon Jul 20 06:11:28.244663 2026] [security2:error] [pid 843279:tid 843387] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CtewAA72o"]
[Mon Jul 20 06:11:28.244931 2026] [security2:error] [pid 843279:tid 843517] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CtewAA72o"]
[Mon Jul 20 06:11:28.304885 2026] [security2:error] [pid 843279:tid 843315] [remote 152.228.213.32:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4QcPqvKNcW5yy5T2CtfQAA7iI"], referer: https://musichaven.info/wp-login.php
[Mon Jul 20 06:11:28.358275 2026] [security2:error] [pid 843279:tid 843413] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QcPqvKNcW5yy5T2CtfwAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:28.433033 2026] [security2:error] [pid 843279:tid 843504] [client 158.173.89.95:40299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QcPqvKNcW5yy5T2CtigAAAOM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:28.903296 2026] [security2:error] [pid 843279:tid 843499] [client 185.132.186.79:37127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/xex.php"] [unique_id "al4QcPqvKNcW5yy5T2CttQAAAN4"]
[Mon Jul 20 06:11:28.913937 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CttwAAALc"]
[Mon Jul 20 06:11:28.914061 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:56189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CttwAAALc"]
[Mon Jul 20 06:11:29.363563 2026] [security2:error] [pid 843279:tid 843504] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QcfqvKNcW5yy5T2Ct1wAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:29.397947 2026] [core:error] [pid 843279:tid 843434] [client 14.225.17.146:59940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:29.397969 2026] [core:error] [pid 843279:tid 843434] [client 14.225.17.146:59940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:29.567067 2026] [security2:error] [pid 843279:tid 843475] [client 74.208.214.194:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QcfqvKNcW5yy5T2Ct8wAAAMY"]
[Mon Jul 20 06:11:29.763830 2026] [security2:error] [pid 843279:tid 843308] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QcfqvKNcW5yy5T2CuBQABAhs"]
[Mon Jul 20 06:11:29.764027 2026] [security2:error] [pid 843279:tid 843536] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QcfqvKNcW5yy5T2CuBQABAhs"]
[Mon Jul 20 06:11:29.918603 2026] [security2:error] [pid 843279:tid 843535] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2CuBAAAAQE"]
[Mon Jul 20 06:11:29.966824 2026] [security2:error] [pid 843279:tid 843398] [remote 110.249.202.189:14778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/lsd-legal-memo-prisoner-reallocation-final-august-2021.pdf"] [unique_id "al4QcfqvKNcW5yy5T2CuFQAAtHU"]
[Mon Jul 20 06:11:30.383246 2026] [security2:error] [pid 843279:tid 843509] [client 106.192.104.4:61519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOAAAAOc"]
[Mon Jul 20 06:11:30.383357 2026] [security2:error] [pid 843279:tid 843509] [client 106.192.104.4:61519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOAAAAOc"]
[Mon Jul 20 06:11:30.561110 2026] [security2:error] [pid 843279:tid 843418] [client 14.225.17.146:53393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2CtwwAAAI0"], referer: http://sarahsnyder.net/WORDPRESS
[Mon Jul 20 06:11:30.572462 2026] [security2:error] [pid 843279:tid 843470] [client 57.141.18.34:49660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsSwAAwTQ"]
[Mon Jul 20 06:11:30.642161 2026] [security2:error] [pid 843279:tid 843492] [client 14.225.17.146:60313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOwAAANc"], referer: http://longevityperformanceclinic.com/WORDPRESS
[Mon Jul 20 06:11:30.654905 2026] [security2:error] [pid 843279:tid 843463] [client 82.215.102.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtowAAALo"]
[Mon Jul 20 06:11:30.665338 2026] [security2:error] [pid 843279:tid 843448] [client 14.225.17.146:53311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtsgAAAKs"], referer: http://bigwormfishing.com/WORDPRESS
[Mon Jul 20 06:11:30.818380 2026] [security2:error] [pid 843279:tid 843537] [client 14.225.17.146:60311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOgAAAQM"], referer: http://hilltopnurseryinc.com/WORDPRESS
[Mon Jul 20 06:11:30.843267 2026] [security2:error] [pid 843279:tid 843530] [client 185.132.186.56:43117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/about.php"] [unique_id "al4QcvqvKNcW5yy5T2CuZwAAAPw"]
[Mon Jul 20 06:11:31.399607 2026] [security2:error] [pid 843279:tid 843440] [client 14.225.17.146:63051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CukAAAAKM"], referer: http://grndl.com/WORDPRESS
[Mon Jul 20 06:11:31.501509 2026] [security2:error] [pid 843279:tid 843499] [client 74.208.214.194:48910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Qc_qvKNcW5yy5T2CulwAAAN4"]
[Mon Jul 20 06:11:31.624500 2026] [security2:error] [pid 843279:tid 843463] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qc_qvKNcW5yy5T2CumgAAALo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:31.672302 2026] [security2:error] [pid 843279:tid 843442] [client 14.225.17.146:63043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CulgAAAKU"], referer: https://bigwormfishing.com/WORDPRESS
[Mon Jul 20 06:11:31.697211 2026] [security2:error] [pid 843279:tid 843513] [client 14.225.17.146:63111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CunAAAAOs"], referer: https://sarahsnyder.net/WORDPRESS
[Mon Jul 20 06:11:31.799010 2026] [security2:error] [pid 843279:tid 843468] [client 14.225.17.146:60116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2CuEgAAAL8"], referer: http://fluidtemple.org/WORDPRESS
[Mon Jul 20 06:11:32.179781 2026] [security2:error] [pid 843279:tid 843495] [client 57.141.18.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QdPqvKNcW5yy5T2CuwwAAANo"]
[Mon Jul 20 06:11:32.356037 2026] [security2:error] [pid 843279:tid 843493] [client 14.225.17.146:55187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CucAAAANg"], referer: http://cloudspacesgroup.com/WORDPRESS
[Mon Jul 20 06:11:32.383335 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu5AAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:32.383497 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu5AAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:32.524872 2026] [security2:error] [pid 843279:tid 843290] [remote 209.97.182.179:60542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu6wAAjwk"]
[Mon Jul 20 06:11:32.525118 2026] [security2:error] [pid 843279:tid 843420] [client 209.97.182.179:60542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu6wAAjwk"]
[Mon Jul 20 06:11:32.539356 2026] [security2:error] [pid 843279:tid 843513] [client 50.116.65.227:15434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4QdPqvKNcW5yy5T2Cu9AAAAOs"]
[Mon Jul 20 06:11:32.547468 2026] [security2:error] [pid 843279:tid 843456] [client 14.225.17.146:60268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOQAAALM"], referer: http://oldracelimited.com/WORDPRESS
[Mon Jul 20 06:11:32.553291 2026] [security2:error] [pid 843279:tid 843443] [client 50.116.65.227:31678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4QdPqvKNcW5yy5T2Cu9wAAAKY"]
[Mon Jul 20 06:11:32.794097 2026] [security2:error] [pid 843279:tid 843446] [client 185.132.186.70:44365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/install.php"] [unique_id "al4QdPqvKNcW5yy5T2CvBgAAAKk"]
[Mon Jul 20 06:11:32.814428 2026] [security2:error] [pid 843279:tid 843462] [client 103.77.203.233:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2CvCAAAALk"]
[Mon Jul 20 06:11:32.815689 2026] [security2:error] [pid 843279:tid 843462] [client 103.77.203.233:65265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2CvCAAAALk"]
[Mon Jul 20 06:11:32.946849 2026] [security2:error] [pid 843279:tid 843532] [client 50.116.65.227:31694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4QdPqvKNcW5yy5T2CvAwAAAP4"]
[Mon Jul 20 06:11:33.156660 2026] [security2:error] [pid 843279:tid 843420] [client 50.116.65.227:31708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4QdPqvKNcW5yy5T2CvFAAAAI8"]
[Mon Jul 20 06:11:33.234371 2026] [security2:error] [pid 843279:tid 843417] [client 57.141.18.22:62068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtTgAAjC0"]
[Mon Jul 20 06:11:33.339764 2026] [security2:error] [pid 843279:tid 843446] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvLwAAAKk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:33.344317 2026] [security2:error] [pid 843279:tid 843479] [client 27.96.94.195:37743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QdfqvKNcW5yy5T2CvOAAAAMo"]
[Mon Jul 20 06:11:33.344457 2026] [security2:error] [pid 843279:tid 843479] [client 27.96.94.195:37743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QdfqvKNcW5yy5T2CvOAAAAMo"]
[Mon Jul 20 06:11:33.475609 2026] [security2:error] [pid 843279:tid 843510] [client 170.106.142.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvNAAA6Hw"]
[Mon Jul 20 06:11:33.482380 2026] [security2:error] [pid 843279:tid 843423] [client 14.225.17.146:55191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CucQAAAJI"], referer: http://adastra.love/WORDPRESS
[Mon Jul 20 06:11:33.561111 2026] [security2:error] [pid 843279:tid 843434] [client 52.167.144.168:9411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvPQAAnRg"]
[Mon Jul 20 06:11:33.784546 2026] [security2:error] [pid 843279:tid 843292] [remote 84.247.172.23:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QdfqvKNcW5yy5T2CvYgAAmws"]
[Mon Jul 20 06:11:33.792827 2026] [security2:error] [pid 843279:tid 843452] [client 57.141.18.51:42976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtgAAArwU"]
[Mon Jul 20 06:11:33.939816 2026] [security2:error] [pid 843279:tid 843535] [client 142.93.64.197:40864] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4QdfqvKNcW5yy5T2CveAAAAQE"]
[Mon Jul 20 06:11:33.986005 2026] [security2:error] [pid 843279:tid 843327] [remote 84.247.172.23:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QdfqvKNcW5yy5T2CvfwAAoy4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:11:34.027465 2026] [security2:error] [pid 843279:tid 843514] [client 142.93.64.197:45784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4QdvqvKNcW5yy5T2CvgQAAAOw"]
[Mon Jul 20 06:11:34.052522 2026] [security2:error] [pid 843279:tid 843463] [client 103.153.183.69:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//var/www/html/config.php"] [unique_id "al4QdvqvKNcW5yy5T2CvhwAAALo"], referer: https://www.facebook.com/
[Mon Jul 20 06:11:34.295589 2026] [security2:error] [pid 843279:tid 843355] [remote 154.66.198.148:19178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdvqvKNcW5yy5T2CvnQAA2Uo"]
[Mon Jul 20 06:11:34.295855 2026] [security2:error] [pid 843279:tid 843494] [client 154.66.198.148:19178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdvqvKNcW5yy5T2CvnQAA2Uo"]
[Mon Jul 20 06:11:34.322913 2026] [security2:error] [pid 843279:tid 843537] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QdvqvKNcW5yy5T2CvowAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:34.376729 2026] [security2:error] [pid 843279:tid 843513] [client 103.153.183.69:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//var/www/html/configuration.php"] [unique_id "al4QdvqvKNcW5yy5T2CvqQAAAOs"], referer: https://www.bing.com/search?q=q7awxx
[Mon Jul 20 06:11:34.424573 2026] [security2:error] [pid 843279:tid 843536] [client 174.138.89.209:44958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4QdvqvKNcW5yy5T2CvrAAAAQI"]
[Mon Jul 20 06:11:34.460663 2026] [security2:error] [pid 843279:tid 843524] [client 57.141.18.31:47882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2Ct0AAA9mY"]
[Mon Jul 20 06:11:34.719612 2026] [security2:error] [pid 843279:tid 843428] [client 185.132.186.70:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/upload/install.php"] [unique_id "al4QdvqvKNcW5yy5T2CvwQAAAJc"]
[Mon Jul 20 06:11:34.761020 2026] [security2:error] [pid 843279:tid 843486] [client 103.153.183.69:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../app/.env"] [unique_id "al4QdvqvKNcW5yy5T2CvwgAAANE"], referer: https://t.co/huedcyk2vi
[Mon Jul 20 06:11:34.820860 2026] [security2:error] [pid 843279:tid 843442] [client 103.153.183.69:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../srv/.env"] [unique_id "al4QdvqvKNcW5yy5T2CvxwAAAKU"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:34.893673 2026] [security2:error] [pid 843279:tid 843538] [client 103.153.183.69:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/.env"] [unique_id "al4QdvqvKNcW5yy5T2CvzwAAAQQ"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:35.291570 2026] [security2:error] [pid 843279:tid 843414] [client 74.7.228.25:53202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "intelligentengineeringsolutions.com"] [uri "/robots.txt"] [unique_id "al4Qd_qvKNcW5yy5T2Cv-QAAAIk"]
[Mon Jul 20 06:11:35.372415 2026] [security2:error] [pid 843279:tid 843467] [client 57.141.18.61:36796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuIAAAvlc"]
[Mon Jul 20 06:11:35.552242 2026] [security2:error] [pid 843279:tid 843421] [client 14.225.17.146:64437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvOwAAAJA"], referer: http://dollpassionista.com/WORDPRESS
[Mon Jul 20 06:11:35.585286 2026] [security2:error] [pid 843279:tid 843514] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwGQAAAOw"], referer: http://intelligentengineeringsolutions.com/robots.txt
[Mon Jul 20 06:11:35.602476 2026] [security2:error] [pid 843279:tid 843524] [client 74.7.228.25:41184] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/robots.txt"] [unique_id "al4Qd_qvKNcW5yy5T2CwEAAA9l4"], referer: http://intelligentengineeringsolutions.com/robots.txt
[Mon Jul 20 06:11:35.610391 2026] [security2:error] [pid 843279:tid 843517] [client 180.191.126.129:25657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.126.191.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apolloinfrastructureholdings.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwIQAAAO8"]
[Mon Jul 20 06:11:35.610553 2026] [security2:error] [pid 843279:tid 843517] [client 180.191.126.129:25657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apolloinfrastructureholdings.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwIQAAAO8"]
[Mon Jul 20 06:11:35.901356 2026] [security2:error] [pid 843279:tid 843502] [client 181.224.94.124:24069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwQwAAAOE"]
[Mon Jul 20 06:11:35.901521 2026] [security2:error] [pid 843279:tid 843502] [client 181.224.94.124:24069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwQwAAAOE"]
[Mon Jul 20 06:11:35.913641 2026] [security2:error] [pid 843279:tid 843474] [client 50.116.65.227:31790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Qd_qvKNcW5yy5T2CwRQAAAMU"]
[Mon Jul 20 06:11:35.927400 2026] [security2:error] [pid 843279:tid 843421] [client 50.116.65.227:31796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Qd_qvKNcW5yy5T2CwSAAAAJA"]
[Mon Jul 20 06:11:36.090282 2026] [security2:error] [pid 843279:tid 843407] [remote 119.94.178.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.178.94.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apolloinfrastructureholdings.online"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwUAAAhX4"]
[Mon Jul 20 06:11:36.090652 2026] [security2:error] [pid 843279:tid 843410] [client 119.94.178.137:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apolloinfrastructureholdings.online"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwUAAAhX4"]
[Mon Jul 20 06:11:36.220160 2026] [security2:error] [pid 843279:tid 843493] [client 103.141.108.143:57687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwXQAAANg"]
[Mon Jul 20 06:11:36.220328 2026] [security2:error] [pid 843279:tid 843493] [client 103.141.108.143:57687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwXQAAANg"]
[Mon Jul 20 06:11:36.437320 2026] [security2:error] [pid 843279:tid 843431] [client 14.225.17.146:64003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwXwAAAJo"], referer: http://adirondackengineering.com/WORDPRESS
[Mon Jul 20 06:11:36.593687 2026] [security2:error] [pid 843279:tid 843412] [client 14.225.17.146:53600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwZAAAAIc"], referer: https://dollpassionista.com/WORDPRESS
[Mon Jul 20 06:11:36.616584 2026] [security2:error] [pid 843279:tid 843461] [client 170.62.100.241:50402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "adirondackengineering.com"] [uri "/wp-content/plugins/miniorange-login-openid/readme.txt"] [unique_id "al4QePqvKNcW5yy5T2CwigAAALg"]
[Mon Jul 20 06:11:36.810766 2026] [security2:error] [pid 843279:tid 843511] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QePqvKNcW5yy5T2CwjQAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:36.877420 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:49787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4Qd_qvKNcW5yy5T2Cv_QAAANs"], referer: http://thechancersband.com/WORDPRESS
[Mon Jul 20 06:11:37.080392 2026] [security2:error] [pid 843279:tid 843501] [client 57.141.18.107:46184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CujgAA4Bc"]
[Mon Jul 20 06:11:37.181966 2026] [security2:error] [pid 843279:tid 843329] [remote 57.141.18.72:35938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6001418"] [unique_id "al4QefqvKNcW5yy5T2CwvgAAsDA"]
[Mon Jul 20 06:11:37.242631 2026] [security2:error] [pid 843279:tid 843470] [client 150.228.148.150:31375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwxQAAAME"]
[Mon Jul 20 06:11:37.242770 2026] [security2:error] [pid 843279:tid 843470] [client 150.228.148.150:31375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwxQAAAME"]
[Mon Jul 20 06:11:37.330016 2026] [security2:error] [pid 843279:tid 843327] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyAAAny4"]
[Mon Jul 20 06:11:37.330218 2026] [security2:error] [pid 843279:tid 843436] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyAAAny4"]
[Mon Jul 20 06:11:37.351337 2026] [security2:error] [pid 843279:tid 843412] [client 112.213.160.112:31216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyQAAAIc"]
[Mon Jul 20 06:11:37.351429 2026] [security2:error] [pid 843279:tid 843412] [client 112.213.160.112:31216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyQAAAIc"]
[Mon Jul 20 06:11:37.406087 2026] [security2:error] [pid 843279:tid 843420] [client 45.116.69.230:54143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwzAAAAI8"]
[Mon Jul 20 06:11:37.406209 2026] [security2:error] [pid 843279:tid 843420] [client 45.116.69.230:54143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwzAAAAI8"]
[Mon Jul 20 06:11:37.414525 2026] [security2:error] [pid 843279:tid 843426] [client 41.173.37.102:2557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwywAAAJU"]
[Mon Jul 20 06:11:37.414695 2026] [security2:error] [pid 843279:tid 843426] [client 41.173.37.102:2557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwywAAAJU"]
[Mon Jul 20 06:11:37.671004 2026] [http2:info] [pid 858085:tid 858085] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:11:37.876807 2026] [security2:error] [pid 843279:tid 843421] [client 86.98.90.58:19396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2Cw9wAAAJA"]
[Mon Jul 20 06:11:37.877035 2026] [security2:error] [pid 843279:tid 843421] [client 86.98.90.58:19396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2Cw9wAAAJA"]
[Mon Jul 20 06:11:37.958736 2026] [security2:error] [pid 843279:tid 843418] [client 111.225.149.104:33212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "timespans.org"] [uri "/robots.txt"] [unique_id "al4QefqvKNcW5yy5T2Cw_AAAAI0"]
[Mon Jul 20 06:11:37.991673 2026] [security2:error] [pid 858085:tid 858224] [client 185.132.186.88:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-head.php"] [unique_id "al4QeTAtbv2vrjByhUphNAAAAAg"]
[Mon Jul 20 06:11:38.152461 2026] [security2:error] [pid 843279:tid 843513] [client 52.167.144.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Qd_qvKNcW5yy5T2Cv_gAAAOs"]
[Mon Jul 20 06:11:38.210733 2026] [security2:error] [pid 843279:tid 843301] [remote 173.212.252.15:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4QevqvKNcW5yy5T2CxCQAAxxQ"]
[Mon Jul 20 06:11:38.232098 2026] [security2:error] [pid 843279:tid 843456] [client 37.139.53.5:59269] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxDAAAALM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.232191 2026] [security2:error] [pid 843279:tid 843456] [client 37.139.53.5:59269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxDAAAALM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.232284 2026] [security2:error] [pid 843279:tid 843475] [client 37.139.53.5:59268] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxCwAAAMY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.232399 2026] [security2:error] [pid 843279:tid 843475] [client 37.139.53.5:59268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxCwAAAMY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.263894 2026] [security2:error] [pid 843279:tid 843345] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QevqvKNcW5yy5T2CxDgAAvEA"]
[Mon Jul 20 06:11:38.264147 2026] [security2:error] [pid 843279:tid 843465] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QevqvKNcW5yy5T2CxDgAAvEA"]
[Mon Jul 20 06:11:38.407737 2026] [security2:error] [pid 843279:tid 843343] [remote 173.212.252.15:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4QevqvKNcW5yy5T2CxGQAA3D4"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:11:38.533185 2026] [security2:error] [pid 858085:tid 858226] [client 178.152.178.232:37420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphQwAAAAo"]
[Mon Jul 20 06:11:38.533371 2026] [security2:error] [pid 858085:tid 858226] [client 178.152.178.232:37420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphQwAAAAo"]
[Mon Jul 20 06:11:38.816718 2026] [security2:error] [pid 858085:tid 858089] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphUAAALAI"]
[Mon Jul 20 06:11:38.816906 2026] [security2:error] [pid 858085:tid 858260] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphUAAALAI"]
[Mon Jul 20 06:11:38.958796 2026] [security2:error] [pid 843279:tid 843348] [remote 192.241.143.148:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4QevqvKNcW5yy5T2CxPQAA8UM"]
[Mon Jul 20 06:11:38.990229 2026] [security2:error] [pid 858085:tid 858264] [client 170.62.100.241:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.100.62.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-content/plugins/miniorange-login-openid/mo-openid-social-login-functions.php"] [unique_id "al4QejAtbv2vrjByhUphVAAAADA"]
[Mon Jul 20 06:11:39.059441 2026] [security2:error] [pid 858085:tid 858281] [client 74.7.227.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QejAtbv2vrjByhUphUwAAAEE"], referer: https://www.maxenengineering.com/importance-of-soil-compaction-in-construction-and-how-it-is-done/
[Mon Jul 20 06:11:39.152430 2026] [security2:error] [pid 843279:tid 843289] [remote 192.241.143.148:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxTQAAvwg"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:11:39.181039 2026] [security2:error] [pid 858085:tid 858277] [client 158.173.166.181:44833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QezAtbv2vrjByhUphYAAAAD0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:39.225833 2026] [security2:error] [pid 843279:tid 843428] [client 142.147.108.203:23377] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSwAAAJc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:39.232390 2026] [security2:error] [pid 843279:tid 843426] [client 74.7.228.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSQAAAJU"], referer: https://www.maxenengineering.com/use-of-concrete-cutting-equipment/
[Mon Jul 20 06:11:39.426840 2026] [security2:error] [pid 843279:tid 843472] [client 130.44.202.223:64317] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxUgAAAMM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:39.485254 2026] [security2:error] [pid 843279:tid 843402] [remote 103.57.220.209:38084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxVAAA0Xk"]
[Mon Jul 20 06:11:39.485477 2026] [security2:error] [pid 843279:tid 843486] [client 103.57.220.209:38084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxVAAA0Xk"]
[Mon Jul 20 06:11:39.537205 2026] [security2:error] [pid 858085:tid 858307] [client 164.100.212.184:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QezAtbv2vrjByhUphbQAAAFs"]
[Mon Jul 20 06:11:39.537340 2026] [security2:error] [pid 858085:tid 858307] [client 164.100.212.184:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QezAtbv2vrjByhUphbQAAAFs"]
[Mon Jul 20 06:11:39.754736 2026] [security2:error] [pid 843279:tid 843449] [client 34.221.76.50:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxbwAAAKw"]
[Mon Jul 20 06:11:39.791880 2026] [security2:error] [pid 843279:tid 843484] [client 50.116.65.227:55462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Qe_qvKNcW5yy5T2CxdAAAAM8"]
[Mon Jul 20 06:11:39.799894 2026] [security2:error] [pid 858085:tid 858241] [client 43.205.139.3:48860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphRAAAABk"]
[Mon Jul 20 06:11:39.808018 2026] [security2:error] [pid 858085:tid 858217] [client 50.116.65.227:44646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4QezAtbv2vrjByhUphfQAAAAE"]
[Mon Jul 20 06:11:39.809551 2026] [security2:error] [pid 843279:tid 843346] [remote 20.173.88.122:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxcwAApEE"]
[Mon Jul 20 06:11:39.842581 2026] [security2:error] [pid 843279:tid 843532] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxdQAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:39.935926 2026] [security2:error] [pid 843279:tid 843463] [client 185.132.186.72:36863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/admin-footer.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxegAAALo"]
[Mon Jul 20 06:11:40.120364 2026] [security2:error] [pid 843279:tid 843451] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QfPqvKNcW5yy5T2CxgQAAAK4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:40.142742 2026] [security2:error] [pid 843279:tid 843380] [remote 20.173.88.122:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QfPqvKNcW5yy5T2CxhwAAt2M"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:11:40.264205 2026] [security2:error] [pid 858085:tid 858104] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QfDAtbv2vrjByhUphkgAAVRE"]
[Mon Jul 20 06:11:40.264437 2026] [security2:error] [pid 858085:tid 858301] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QfDAtbv2vrjByhUphkgAAVRE"]
[Mon Jul 20 06:11:40.370230 2026] [security2:error] [pid 843279:tid 843469] [client 57.141.18.22:62110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QdvqvKNcW5yy5T2CvpgAAwEs"]
[Mon Jul 20 06:11:40.501222 2026] [security2:error] [pid 858085:tid 858283] [client 14.225.17.146:64746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4QfDAtbv2vrjByhUphlgAAAEM"], referer: http://margaretspeckogawa.com/WORDPRESS
[Mon Jul 20 06:11:40.637551 2026] [security2:error] [pid 843279:tid 843444] [client 103.153.183.69:63998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8fhome/deploy/.ssh/id_rsa"] [unique_id "al4QfPqvKNcW5yy5T2CxpAAAAKc"], referer: https://www.reddit.com/
[Mon Jul 20 06:11:40.639486 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QfPqvKNcW5yy5T2CxpQAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:41.293533 2026] [security2:error] [pid 843279:tid 843472] [client 130.44.202.223:64317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxUgAAAMM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:41.293588 2026] [security2:error] [pid 843279:tid 843472] [client 130.44.202.223:64317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxUgAAAMM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:41.464972 2026] [security2:error] [pid 843279:tid 843461] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QffqvKNcW5yy5T2CxzgAAALg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:41.506981 2026] [security2:error] [pid 843279:tid 843498] [client 103.153.183.69:63998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8fhome/ec2-user/.ssh/id_rsa"] [unique_id "al4QffqvKNcW5yy5T2Cx0AAAAN0"], referer: https://twitter.com/
[Mon Jul 20 06:11:41.561162 2026] [security2:error] [pid 858085:tid 858258] [client 136.67.14.254:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.14.67.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUphzQAAACo"]
[Mon Jul 20 06:11:41.561276 2026] [security2:error] [pid 858085:tid 858258] [client 136.67.14.254:53539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "according2plant.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUphzQAAACo"]
[Mon Jul 20 06:11:41.669569 2026] [core:error] [pid 858085:tid 858239] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:41.669590 2026] [core:error] [pid 858085:tid 858239] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:41.719517 2026] [security2:error] [pid 858085:tid 858259] [client 98.159.234.160:36751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QfTAtbv2vrjByhUph3QAAACs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:41.815995 2026] [security2:error] [pid 858085:tid 858291] [client 106.192.104.4:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUph4AAAAEs"]
[Mon Jul 20 06:11:41.822620 2026] [security2:error] [pid 858085:tid 858291] [client 106.192.104.4:62024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUph4AAAAEs"]
[Mon Jul 20 06:11:41.885864 2026] [security2:error] [pid 843279:tid 843445] [client 185.132.186.76:37013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/wp-conflg.php"] [unique_id "al4QffqvKNcW5yy5T2Cx5wAAAKg"]
[Mon Jul 20 06:11:41.910363 2026] [security2:error] [pid 843279:tid 843297] [remote 5.161.225.162:39740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4QffqvKNcW5yy5T2Cx6AAAyBA"]
[Mon Jul 20 06:11:42.032871 2026] [security2:error] [pid 843279:tid 843534] [client 57.141.18.55:65070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwTwABAGA"]
[Mon Jul 20 06:11:42.141769 2026] [security2:error] [pid 843279:tid 843442] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QfvqvKNcW5yy5T2Cx8wAAAKU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:42.229208 2026] [security2:error] [pid 843279:tid 843428] [client 142.147.108.203:23377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSwAAAJc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:42.229283 2026] [security2:error] [pid 843279:tid 843428] [client 142.147.108.203:23377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSwAAAJc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:42.240679 2026] [security2:error] [pid 858085:tid 858235] [client 216.73.217.138:41384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QfjAtbv2vrjByhUph7AAAEx0"]
[Mon Jul 20 06:11:42.793249 2026] [security2:error] [pid 843279:tid 843481] [client 57.141.18.47:52592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwlAAAzGs"]
[Mon Jul 20 06:11:42.862275 2026] [security2:error] [pid 843279:tid 843293] [remote 5.161.225.162:39740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4QfvqvKNcW5yy5T2CyIAAA_gw"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:11:43.098253 2026] [security2:error] [pid 843279:tid 843446] [client 47.128.61.169:12114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.polishedpicture.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4Qf_qvKNcW5yy5T2CyLAAAAKk"]
[Mon Jul 20 06:11:43.286763 2026] [security2:error] [pid 843279:tid 843410] [client 65.1.132.125:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyOQAAAIU"]
[Mon Jul 20 06:11:43.429775 2026] [security2:error] [pid 858085:tid 858319] [client 103.77.203.233:49421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QfzAtbv2vrjByhUpiLgAAAGc"]
[Mon Jul 20 06:11:43.429898 2026] [security2:error] [pid 858085:tid 858319] [client 103.77.203.233:49421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QfzAtbv2vrjByhUpiLgAAAGc"]
[Mon Jul 20 06:11:43.442440 2026] [security2:error] [pid 843279:tid 843457] [client 57.141.18.113:23554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QefqvKNcW5yy5T2Cw3gAAtFs"]
[Mon Jul 20 06:11:43.469978 2026] [security2:error] [pid 843279:tid 843470] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyQwAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:43.470123 2026] [security2:error] [pid 843279:tid 843470] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyQwAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:43.831162 2026] [security2:error] [pid 843279:tid 843514] [client 185.132.186.64:20051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/makeasmtp.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyWAAAAOw"]
[Mon Jul 20 06:11:44.024766 2026] [security2:error] [pid 843279:tid 843434] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyYQAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:44.322272 2026] [security2:error] [pid 858085:tid 858327] [client 13.201.64.214:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QgDAtbv2vrjByhUpiUwAAAG8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:11:44.464280 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QgPqvKNcW5yy5T2CyggAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:44.683000 2026] [security2:error] [pid 858085:tid 858343] [client 50.116.65.227:44696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QgDAtbv2vrjByhUpiXwAAAH8"]
[Mon Jul 20 06:11:44.693874 2026] [security2:error] [pid 843279:tid 843494] [client 50.116.65.227:44702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QgPqvKNcW5yy5T2CyjAAAANk"]
[Mon Jul 20 06:11:45.319589 2026] [security2:error] [pid 843279:tid 843461] [client 27.96.94.195:38196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QgfqvKNcW5yy5T2CytgAAALg"]
[Mon Jul 20 06:11:45.319934 2026] [security2:error] [pid 843279:tid 843461] [client 27.96.94.195:38196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QgfqvKNcW5yy5T2CytgAAALg"]
[Mon Jul 20 06:11:45.371709 2026] [security2:error] [pid 843279:tid 843477] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QgfqvKNcW5yy5T2CysgAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:45.465469 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:58445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4QgPqvKNcW5yy5T2CyeAAAAIU"], referer: http://getgarrison.com/WORDPRESS
[Mon Jul 20 06:11:45.614936 2026] [security2:error] [pid 843279:tid 843511] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QgfqvKNcW5yy5T2CyxgAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:45.785265 2026] [security2:error] [pid 843279:tid 843447] [client 185.132.186.87:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp-sup.php"] [unique_id "al4QgfqvKNcW5yy5T2Cy1AAAAKo"]
[Mon Jul 20 06:11:45.856839 2026] [security2:error] [pid 858085:tid 858342] [client 57.141.18.27:46696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QezAtbv2vrjByhUphewAAfgs"]
[Mon Jul 20 06:11:46.057078 2026] [security2:error] [pid 843279:tid 843319] [remote 88.99.30.91:38436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.30.99.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QgvqvKNcW5yy5T2Cy5wAA-yY"]
[Mon Jul 20 06:11:46.248369 2026] [security2:error] [pid 843279:tid 843313] [remote 88.99.30.91:38436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.30.99.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QgvqvKNcW5yy5T2Cy7wAA1CA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:11:46.306907 2026] [security2:error] [pid 843279:tid 843509] [client 14.225.17.146:54100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4QgPqvKNcW5yy5T2CygwAAAOc"], referer: http://outlookturf.com/WORDPRESS
[Mon Jul 20 06:11:46.360302 2026] [security2:error] [pid 843279:tid 843475] [client 139.28.219.68:39194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "skiboutiques.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4QgvqvKNcW5yy5T2Cy8wAAAMY"]
[Mon Jul 20 06:11:46.402076 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiqQAAAEo"]
[Mon Jul 20 06:11:46.402171 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:47166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiqQAAAEo"]
[Mon Jul 20 06:11:46.557392 2026] [security2:error] [pid 843279:tid 843419] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QgvqvKNcW5yy5T2Cy_QAAAI4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:46.862659 2026] [proxy:error] [pid 858085:tid 858272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:46.862699 2026] [proxy_http:error] [pid 858085:tid 858272] [client 198.235.24.45:64180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:46.863133 2026] [proxy:error] [pid 858085:tid 858272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:46.863156 2026] [proxy_http:error] [pid 858085:tid 858272] [client 198.235.24.45:64180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:46.937222 2026] [security2:error] [pid 858085:tid 858226] [client 87.236.176.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4QgjAtbv2vrjByhUpivgAAAAo"]
[Mon Jul 20 06:11:46.953511 2026] [security2:error] [pid 843279:tid 843488] [client 195.96.139.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4QgvqvKNcW5yy5T2CzDwAAANM"]
[Mon Jul 20 06:11:46.961610 2026] [security2:error] [pid 858085:tid 858230] [client 103.141.108.143:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiwwAAAA4"]
[Mon Jul 20 06:11:46.962238 2026] [security2:error] [pid 858085:tid 858230] [client 103.141.108.143:58408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiwwAAAA4"]
[Mon Jul 20 06:11:46.965322 2026] [security2:error] [pid 843279:tid 843434] [client 139.28.219.68:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/xmlrpc.php"] [unique_id "al4QgvqvKNcW5yy5T2CzGQAAAJ0"]
[Mon Jul 20 06:11:47.371282 2026] [security2:error] [pid 858085:tid 858159] [remote 192.241.143.148:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QgzAtbv2vrjByhUpi1AAAGkg"]
[Mon Jul 20 06:11:47.371475 2026] [security2:error] [pid 858085:tid 858242] [client 192.241.143.148:40928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QgzAtbv2vrjByhUpi1AAAGkg"]
[Mon Jul 20 06:11:47.426009 2026] [security2:error] [pid 858085:tid 858271] [client 46.110.96.34:41170] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4QgzAtbv2vrjByhUpi1wAAADc"]
[Mon Jul 20 06:11:47.457054 2026] [security2:error] [pid 858085:tid 858225] [client 14.224.227.113:58334] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4QgzAtbv2vrjByhUpi2gAAAAk"]
[Mon Jul 20 06:11:47.598652 2026] [security2:error] [pid 858085:tid 858260] [client 50.116.65.227:55482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QgzAtbv2vrjByhUpi4gAAACw"]
[Mon Jul 20 06:11:47.608023 2026] [security2:error] [pid 843279:tid 843441] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzPwAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:47.609156 2026] [security2:error] [pid 858085:tid 858272] [client 50.116.65.227:44760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QgzAtbv2vrjByhUpi5AAAADg"]
[Mon Jul 20 06:11:47.728588 2026] [security2:error] [pid 858085:tid 858276] [client 185.132.186.85:57583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wordpress/wp-includes/class-wp-http-ixr-client-view.php"] [unique_id "al4QgzAtbv2vrjByhUpi7QAAADw"]
[Mon Jul 20 06:11:47.851676 2026] [security2:error] [pid 858085:tid 858255] [client 57.141.18.50:23568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QfjAtbv2vrjByhUph-gAAJyA"]
[Mon Jul 20 06:11:47.975138 2026] [security2:error] [pid 843279:tid 843447] [client 41.173.37.102:3009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzUwAAAKo"]
[Mon Jul 20 06:11:47.975303 2026] [security2:error] [pid 843279:tid 843447] [client 41.173.37.102:3009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzUwAAAKo"]
[Mon Jul 20 06:11:48.009510 2026] [security2:error] [pid 858085:tid 858165] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9wAAek4"]
[Mon Jul 20 06:11:48.009678 2026] [security2:error] [pid 858085:tid 858338] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9wAAek4"]
[Mon Jul 20 06:11:48.020651 2026] [security2:error] [pid 858085:tid 858249] [client 150.228.148.150:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9gAAACE"]
[Mon Jul 20 06:11:48.020815 2026] [security2:error] [pid 858085:tid 858249] [client 150.228.148.150:6554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9gAAACE"]
[Mon Jul 20 06:11:48.072325 2026] [security2:error] [pid 858085:tid 858230] [client 112.213.160.112:30954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi-wAAAA4"]
[Mon Jul 20 06:11:48.072537 2026] [security2:error] [pid 858085:tid 858230] [client 112.213.160.112:30954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi-wAAAA4"]
[Mon Jul 20 06:11:48.107441 2026] [security2:error] [pid 858085:tid 858342] [client 86.98.90.58:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_gAAAH4"]
[Mon Jul 20 06:11:48.107635 2026] [security2:error] [pid 858085:tid 858342] [client 86.98.90.58:20182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_gAAAH4"]
[Mon Jul 20 06:11:48.116011 2026] [security2:error] [pid 858085:tid 858269] [client 45.116.69.230:54646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_QAAADU"]
[Mon Jul 20 06:11:48.116193 2026] [security2:error] [pid 858085:tid 858269] [client 45.116.69.230:54646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_QAAADU"]
[Mon Jul 20 06:11:48.380977 2026] [security2:error] [pid 843279:tid 843435] [client 74.7.241.147:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzSAAAAJ4"]
[Mon Jul 20 06:11:48.382980 2026] [security2:error] [pid 843279:tid 843450] [client 74.7.241.147:36056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "overloadcomedy.com"] [uri "/robots.txt"] [unique_id "al4Qg_qvKNcW5yy5T2CzRAAArXM"]
[Mon Jul 20 06:11:48.600341 2026] [security2:error] [pid 858085:tid 858239] [client 74.7.227.179:43060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QhDAtbv2vrjByhUpjEAAAF1Y"], referer: https://tejasenvironmental.com/p=3235839
[Mon Jul 20 06:11:48.839344 2026] [lsapi:warn] [pid 843279:tid 843494] [client 14.225.17.146:50088] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:48.839379 2026] [lsapi:warn] [pid 843279:tid 843494] [client 14.225.17.146:50088] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:48.873645 2026] [security2:error] [pid 858085:tid 858181] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpjKAAAVl4"]
[Mon Jul 20 06:11:48.873867 2026] [security2:error] [pid 858085:tid 858302] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpjKAAAVl4"]
[Mon Jul 20 06:11:49.008540 2026] [security2:error] [pid 858085:tid 858328] [client 14.225.17.146:49980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4QgzAtbv2vrjByhUpi0gAAAHA"], referer: http://bnb-engineering.com/WORDPRESS
[Mon Jul 20 06:11:49.020342 2026] [security2:error] [pid 843279:tid 843412] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QhPqvKNcW5yy5T2CzggAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:49.269906 2026] [security2:error] [pid 843279:tid 843434] [client 43.205.139.3:47564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzlAAAAJ0"]
[Mon Jul 20 06:11:49.270112 2026] [security2:error] [pid 843279:tid 843434] [client 43.205.139.3:47564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzlAAAAJ0"]
[Mon Jul 20 06:11:49.271075 2026] [security2:error] [pid 843279:tid 843501] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QhfqvKNcW5yy5T2CzlQAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:49.369762 2026] [lsapi:warn] [pid 858085:tid 858339] [client 50.116.65.227:41438] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:49.369787 2026] [lsapi:warn] [pid 858085:tid 858339] [client 50.116.65.227:41438] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:49.384024 2026] [security2:error] [pid 843279:tid 843494] [client 14.225.17.146:50088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4QhPqvKNcW5yy5T2CzXgAAANk"], referer: http://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:49.512520 2026] [security2:error] [pid 843279:tid 843356] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzpgAAlUs"]
[Mon Jul 20 06:11:49.512739 2026] [security2:error] [pid 843279:tid 843426] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzpgAAlUs"]
[Mon Jul 20 06:11:49.523127 2026] [security2:error] [pid 858085:tid 858185] [remote 5.161.225.162:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QhTAtbv2vrjByhUpjTgAATWI"]
[Mon Jul 20 06:11:49.692764 2026] [security2:error] [pid 858085:tid 858275] [client 185.132.186.56:63187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/bypass.php"] [unique_id "al4QhTAtbv2vrjByhUpjWQAAADs"]
[Mon Jul 20 06:11:49.759494 2026] [security2:error] [pid 858085:tid 858281] [client 139.28.219.68:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/xmlrpc.php"] [unique_id "al4QhTAtbv2vrjByhUpjXgAAAEE"]
[Mon Jul 20 06:11:49.759593 2026] [security2:error] [pid 858085:tid 858281] [client 139.28.219.68:43316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skiboutiques.com"] [uri "/xmlrpc.php"] [unique_id "al4QhTAtbv2vrjByhUpjXgAAAEE"]
[Mon Jul 20 06:11:50.126477 2026] [security2:error] [pid 858085:tid 858232] [client 164.100.212.184:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjawAAABA"]
[Mon Jul 20 06:11:50.126613 2026] [security2:error] [pid 858085:tid 858232] [client 164.100.212.184:54561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjawAAABA"]
[Mon Jul 20 06:11:50.287768 2026] [security2:error] [pid 858085:tid 858295] [client 57.141.18.13:60328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgDAtbv2vrjByhUpiXQAATzM"]
[Mon Jul 20 06:11:50.388701 2026] [lsapi:warn] [pid 843279:tid 843526] [client 14.225.17.146:59362] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:50.388726 2026] [lsapi:warn] [pid 843279:tid 843526] [client 14.225.17.146:59362] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:50.436428 2026] [security2:error] [pid 843279:tid 843526] [client 14.225.17.146:59362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4QhvqvKNcW5yy5T2CzxwAAAPg"], referer: https://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:50.669201 2026] [security2:error] [pid 843279:tid 843423] [client 142.250.32.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4QhfqvKNcW5yy5T2CzkwAAAJI"]
[Mon Jul 20 06:11:50.699125 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:54049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4QhTAtbv2vrjByhUpjVQAAABM"], referer: http://musichaven.info/WORDPRESS
[Mon Jul 20 06:11:50.747372 2026] [security2:error] [pid 858085:tid 858266] [client 57.141.18.87:42206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgTAtbv2vrjByhUpiawAAMjU"]
[Mon Jul 20 06:11:50.770464 2026] [security2:error] [pid 858085:tid 858192] [remote 5.161.225.162:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QhjAtbv2vrjByhUpjggAAZWk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:11:50.841478 2026] [security2:error] [pid 858085:tid 858194] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjhgAAcGs"]
[Mon Jul 20 06:11:50.841667 2026] [security2:error] [pid 858085:tid 858328] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjhgAAcGs"]
[Mon Jul 20 06:11:50.850086 2026] [security2:error] [pid 843279:tid 843420] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QhvqvKNcW5yy5T2Cz3AAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:50.850246 2026] [security2:error] [pid 843279:tid 843420] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QhvqvKNcW5yy5T2Cz3AAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.011655 2026] [security2:error] [pid 843279:tid 843472] [client 57.141.18.10:65132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgfqvKNcW5yy5T2CywQAAw04"]
[Mon Jul 20 06:11:51.133232 2026] [security2:error] [pid 843279:tid 843452] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz5wAAAK8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.352380 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz9wAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.608709 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:59227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz_gAAAKQ"], referer: https://musichaven.info/WORDPRESS
[Mon Jul 20 06:11:51.629338 2026] [security2:error] [pid 858085:tid 858238] [client 185.132.186.57:31289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-t.api.php"] [unique_id "al4QhzAtbv2vrjByhUpjpQAAABY"]
[Mon Jul 20 06:11:51.644992 2026] [security2:error] [pid 843279:tid 843471] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz_wAAAMI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.908717 2026] [security2:error] [pid 843279:tid 843529] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qh_qvKNcW5yy5T2C0DQAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:52.077351 2026] [security2:error] [pid 843279:tid 843488] [client 106.192.104.4:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QiPqvKNcW5yy5T2C0FwAAANM"]
[Mon Jul 20 06:11:52.077517 2026] [security2:error] [pid 843279:tid 843488] [client 106.192.104.4:62493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QiPqvKNcW5yy5T2C0FwAAANM"]
[Mon Jul 20 06:11:52.149117 2026] [security2:error] [pid 843279:tid 843493] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QiPqvKNcW5yy5T2C0GAAAANg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:52.166310 2026] [security2:error] [pid 843279:tid 843467] [client 57.141.18.4:40070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgvqvKNcW5yy5T2CzAgAAvko"]
[Mon Jul 20 06:11:52.441846 2026] [security2:error] [pid 843279:tid 843411] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QiPqvKNcW5yy5T2C0JgAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.155421 2026] [security2:error] [pid 843279:tid 843441] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QifqvKNcW5yy5T2C0SQAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.378200 2026] [security2:error] [pid 843279:tid 843467] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QifqvKNcW5yy5T2C0WQAAAL4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.570107 2026] [security2:error] [pid 858085:tid 858328] [client 185.132.186.55:34705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/edit.php"] [unique_id "al4QiTAtbv2vrjByhUpj8gAAAHA"]
[Mon Jul 20 06:11:53.653301 2026] [security2:error] [pid 843279:tid 843515] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QifqvKNcW5yy5T2C0aAAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.653456 2026] [security2:error] [pid 843279:tid 843515] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QifqvKNcW5yy5T2C0aAAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.896283 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QifqvKNcW5yy5T2C0cwAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:54.007085 2026] [security2:error] [pid 858085:tid 858223] [client 57.141.18.99:56484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhDAtbv2vrjByhUpjIAAAB1o"]
[Mon Jul 20 06:11:54.101483 2026] [security2:error] [pid 843279:tid 843521] [client 103.77.203.233:49973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QivqvKNcW5yy5T2C0fAAAAPM"]
[Mon Jul 20 06:11:54.101616 2026] [security2:error] [pid 843279:tid 843521] [client 103.77.203.233:49973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QivqvKNcW5yy5T2C0fAAAAPM"]
[Mon Jul 20 06:11:54.387967 2026] [security2:error] [pid 858085:tid 858096] [remote 110.249.201.49:43416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2023/01/HDP7_CommissionCompetitivenessMetric.pdf"] [unique_id "al4QijAtbv2vrjByhUpkEwAAXAk"]
[Mon Jul 20 06:11:54.520210 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QivqvKNcW5yy5T2C0mAAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:54.611344 2026] [security2:error] [pid 843279:tid 843472] [client 50.116.65.227:59948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QivqvKNcW5yy5T2C0nQAAAMM"]
[Mon Jul 20 06:11:54.623279 2026] [security2:error] [pid 843279:tid 843449] [client 50.116.65.227:41480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QivqvKNcW5yy5T2C0nwAAAMA"]
[Mon Jul 20 06:11:54.689285 2026] [security2:error] [pid 843279:tid 843492] [client 57.141.18.60:49692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhfqvKNcW5yy5T2CznAAA1w0"]
[Mon Jul 20 06:11:55.035538 2026] [security2:error] [pid 843279:tid 843422] [client 57.141.18.23:35100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhfqvKNcW5yy5T2CzrwAAkVI"]
[Mon Jul 20 06:11:55.175968 2026] [security2:error] [pid 843279:tid 843459] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0sQAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:55.345464 2026] [security2:error] [pid 843279:tid 843522] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0uwAAAPQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:55.431280 2026] [security2:error] [pid 843279:tid 843431] [client 57.141.18.67:53128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhvqvKNcW5yy5T2CzxAAAmhc"]
[Mon Jul 20 06:11:55.449032 2026] [security2:error] [pid 858085:tid 858275] [client 50.116.65.227:41496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QizAtbv2vrjByhUpkPAAAADs"]
[Mon Jul 20 06:11:55.460719 2026] [security2:error] [pid 858085:tid 858227] [client 50.116.65.227:41502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QizAtbv2vrjByhUpkPQAAAAs"]
[Mon Jul 20 06:11:55.512400 2026] [security2:error] [pid 858085:tid 858302] [client 185.132.186.96:50693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/info.php"] [unique_id "al4QizAtbv2vrjByhUpkQgAAAFY"]
[Mon Jul 20 06:11:55.744577 2026] [security2:error] [pid 858085:tid 858218] [client 14.225.17.146:59124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4QizAtbv2vrjByhUpkRAAAAAI"], referer: http://ccsdifference.com/WORDPRESS
[Mon Jul 20 06:11:55.779154 2026] [security2:error] [pid 843279:tid 843288] [remote 144.79.133.30:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0zwAApAc"]
[Mon Jul 20 06:11:55.779352 2026] [security2:error] [pid 843279:tid 843441] [client 144.79.133.30:53996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0zwAApAc"]
[Mon Jul 20 06:11:55.915245 2026] [security2:error] [pid 843279:tid 843470] [client 57.141.18.116:44520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhvqvKNcW5yy5T2Cz2wAAwSY"]
[Mon Jul 20 06:11:56.078887 2026] [security2:error] [pid 843279:tid 843481] [client 50.116.65.227:41520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Qi_qvKNcW5yy5T2C02AAAAMw"]
[Mon Jul 20 06:11:56.118346 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:59695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4QijAtbv2vrjByhUpkHwAAAEk"]
[Mon Jul 20 06:11:56.235628 2026] [security2:error] [pid 843279:tid 843477] [client 14.225.17.146:59561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4QjPqvKNcW5yy5T2C04gAAAMg"], referer: http://taskidsvirginia.com/WORDPRESS
[Mon Jul 20 06:11:56.291742 2026] [security2:error] [pid 843279:tid 843456] [client 50.116.65.227:41530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QjPqvKNcW5yy5T2C05gAAALM"]
[Mon Jul 20 06:11:56.564765 2026] [lsapi:warn] [pid 843279:tid 843534] [client 116.76.196.216:17177] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:56.564785 2026] [lsapi:warn] [pid 843279:tid 843534] [client 116.76.196.216:17177] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:56.739568 2026] [security2:error] [pid 843279:tid 843323] [remote 5.161.225.162:34366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QjPqvKNcW5yy5T2C1AAAA9io"]
[Mon Jul 20 06:11:56.791896 2026] [security2:error] [pid 858085:tid 858265] [client 14.225.17.146:52336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4QjDAtbv2vrjByhUpkVwAAADE"], referer: https://ccsdifference.com/WORDPRESS
[Mon Jul 20 06:11:56.977802 2026] [security2:error] [pid 858085:tid 858292] [client 181.224.94.124:47490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QjDAtbv2vrjByhUpkYQAAAEw"]
[Mon Jul 20 06:11:56.977947 2026] [security2:error] [pid 858085:tid 858292] [client 181.224.94.124:47490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QjDAtbv2vrjByhUpkYQAAAEw"]
[Mon Jul 20 06:11:57.065157 2026] [security2:error] [pid 843279:tid 843423] [client 14.225.17.146:53670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4QivqvKNcW5yy5T2C0ngAAAJI"], referer: http://mrbambooplus.com/WORDPRESS
[Mon Jul 20 06:11:57.073824 2026] [security2:error] [pid 843279:tid 843457] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QjPqvKNcW5yy5T2C1CQAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:57.425072 2026] [security2:error] [pid 843279:tid 843469] [client 185.132.186.65:37507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/autoload_classmap.php"] [unique_id "al4QjfqvKNcW5yy5T2C1GQAAAMA"]
[Mon Jul 20 06:11:57.437795 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QjfqvKNcW5yy5T2C1GgAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:57.592819 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QjfqvKNcW5yy5T2C1HAAAAJQ"]
[Mon Jul 20 06:11:57.649928 2026] [security2:error] [pid 858085:tid 858251] [client 103.141.108.143:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjTAtbv2vrjByhUpkdAAAACM"]
[Mon Jul 20 06:11:57.650071 2026] [security2:error] [pid 858085:tid 858251] [client 103.141.108.143:59079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjTAtbv2vrjByhUpkdAAAACM"]
[Mon Jul 20 06:11:57.815633 2026] [security2:error] [pid 843279:tid 843414] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QjfqvKNcW5yy5T2C1JwAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:57.821173 2026] [security2:error] [pid 858085:tid 858277] [client 14.225.17.146:52163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4QjDAtbv2vrjByhUpkUwAAAD0"], referer: http://whiteoutcb.com/WORDPRESS
[Mon Jul 20 06:11:58.161769 2026] [security2:error] [pid 843279:tid 843531] [client 57.141.18.92:65164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QiPqvKNcW5yy5T2C0OAAA_Ss"]
[Mon Jul 20 06:11:58.180191 2026] [security2:error] [pid 843279:tid 843347] [remote 5.161.225.162:34366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QjvqvKNcW5yy5T2C1PQAAr0I"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:11:58.470854 2026] [security2:error] [pid 858085:tid 858121] [remote 100.42.189.89:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpkigAAQyI"]
[Mon Jul 20 06:11:58.528086 2026] [security2:error] [pid 858085:tid 858303] [client 41.173.37.102:3467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkjQAAAFc"]
[Mon Jul 20 06:11:58.528209 2026] [security2:error] [pid 858085:tid 858303] [client 41.173.37.102:3467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkjQAAAFc"]
[Mon Jul 20 06:11:58.529414 2026] [security2:error] [pid 858085:tid 858122] [remote 192.241.143.148:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpkjwAAVCM"]
[Mon Jul 20 06:11:58.591927 2026] [security2:error] [pid 858085:tid 858124] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkkQAANCU"]
[Mon Jul 20 06:11:58.592130 2026] [security2:error] [pid 858085:tid 858268] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkkQAANCU"]
[Mon Jul 20 06:11:58.657372 2026] [security2:error] [pid 843279:tid 843440] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QjvqvKNcW5yy5T2C1TgAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:58.664367 2026] [security2:error] [pid 858085:tid 858127] [remote 100.42.189.89:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpklwAACyg"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:11:58.717335 2026] [security2:error] [pid 858085:tid 858326] [client 45.116.69.230:55145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkmgAAAG4"]
[Mon Jul 20 06:11:58.717334 2026] [security2:error] [pid 858085:tid 858128] [remote 192.241.143.148:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpkmwAAaCk"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:11:58.717477 2026] [security2:error] [pid 858085:tid 858326] [client 45.116.69.230:55145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkmgAAAG4"]
[Mon Jul 20 06:11:58.753355 2026] [security2:error] [pid 843279:tid 843399] [remote 45.90.123.233:39374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-login.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UQAAn3Y"]
[Mon Jul 20 06:11:58.783082 2026] [security2:error] [pid 843279:tid 843454] [client 86.98.90.58:20891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UgAAALE"]
[Mon Jul 20 06:11:58.783214 2026] [security2:error] [pid 843279:tid 843454] [client 86.98.90.58:20891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UgAAALE"]
[Mon Jul 20 06:11:58.798951 2026] [security2:error] [pid 843279:tid 843475] [client 150.228.148.150:47707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UwAAAMY"]
[Mon Jul 20 06:11:58.802179 2026] [security2:error] [pid 843279:tid 843475] [client 150.228.148.150:47707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UwAAAMY"]
[Mon Jul 20 06:11:58.805396 2026] [security2:error] [pid 858085:tid 858130] [remote 20.153.140.50:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpknQAAdCs"]
[Mon Jul 20 06:11:58.805674 2026] [security2:error] [pid 858085:tid 858332] [client 20.153.140.50:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpknQAAdCs"]
[Mon Jul 20 06:11:58.820191 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkoAAAABE"]
[Mon Jul 20 06:11:58.820354 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkoAAAABE"]
[Mon Jul 20 06:11:58.947626 2026] [security2:error] [pid 858085:tid 858261] [client 57.141.18.0:32582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QiTAtbv2vrjByhUpj_AAALQE"]
[Mon Jul 20 06:11:58.995761 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.52:23978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QiTAtbv2vrjByhUpj_gAAHAM"]
[Mon Jul 20 06:11:59.087421 2026] [security2:error] [pid 843279:tid 843283] [remote 45.90.123.233:39374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-login.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1YAAA2QI"], referer: https://ferrellroofing.com/wp-login.php
[Mon Jul 20 06:11:59.329355 2026] [security2:error] [pid 858085:tid 858291] [client 144.76.19.75:50176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QjzAtbv2vrjByhUpkugAAAEs"]
[Mon Jul 20 06:11:59.379356 2026] [security2:error] [pid 843279:tid 843511] [client 185.132.186.78:26741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/navi.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1ZgAAAOk"]
[Mon Jul 20 06:11:59.459307 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1aQAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:59.465193 2026] [security2:error] [pid 843279:tid 843476] [client 178.152.178.232:37821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1awAAAMc"]
[Mon Jul 20 06:11:59.465287 2026] [security2:error] [pid 843279:tid 843476] [client 178.152.178.232:37821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1awAAAMc"]
[Mon Jul 20 06:11:59.480471 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1aQAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:59.511925 2026] [security2:error] [pid 843279:tid 843346] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1bgABBEE"]
[Mon Jul 20 06:11:59.512154 2026] [security2:error] [pid 843279:tid 843538] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1bgABBEE"]
[Mon Jul 20 06:11:59.747410 2026] [security2:error] [pid 843279:tid 843523] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1dgAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:59.791482 2026] [security2:error] [pid 858085:tid 858231] [client 57.141.18.73:63860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QijAtbv2vrjByhUpkIAAADwc"]
[Mon Jul 20 06:12:00.064975 2026] [security2:error] [pid 843279:tid 843362] [remote 187.127.191.163:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.191.127.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1fwAA1VE"]
[Mon Jul 20 06:12:00.066315 2026] [security2:error] [pid 858085:tid 858148] [remote 20.153.140.50:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk3gAAaD0"]
[Mon Jul 20 06:12:00.155832 2026] [security2:error] [pid 843279:tid 843531] [client 3.109.4.218:19198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1hwAAAP0"]
[Mon Jul 20 06:12:00.155994 2026] [security2:error] [pid 843279:tid 843531] [client 3.109.4.218:19198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1hwAAAP0"]
[Mon Jul 20 06:12:00.206183 2026] [security2:error] [pid 858085:tid 858147] [remote 109.123.245.117:45202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.245.123.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk4wAAEDw"]
[Mon Jul 20 06:12:00.216659 2026] [security2:error] [pid 843279:tid 843326] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1jAABAS0"]
[Mon Jul 20 06:12:00.216923 2026] [security2:error] [pid 843279:tid 843535] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1jAABAS0"]
[Mon Jul 20 06:12:00.300429 2026] [security2:error] [pid 858085:tid 858272] [client 57.141.18.79:42608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QizAtbv2vrjByhUpkMgAAOBE"]
[Mon Jul 20 06:12:00.384153 2026] [security2:error] [pid 858085:tid 858153] [remote 109.123.245.117:45202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.245.123.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk7QAAT0I"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:12:00.440500 2026] [security2:error] [pid 843279:tid 843516] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1lQAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:00.453221 2026] [security2:error] [pid 843279:tid 843309] [remote 187.127.191.163:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.191.127.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1lwAAwBw"], referer: https://maa.hws.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:00.467133 2026] [security2:error] [pid 858085:tid 858155] [remote 20.153.140.50:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk7gAALEQ"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:12:00.719765 2026] [security2:error] [pid 843279:tid 843488] [client 164.100.212.184:64915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1pAAAANM"]
[Mon Jul 20 06:12:00.719918 2026] [security2:error] [pid 843279:tid 843488] [client 164.100.212.184:64915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1pAAAANM"]
[Mon Jul 20 06:12:00.800042 2026] [security2:error] [pid 858085:tid 858159] [remote 8.217.108.67:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk-gAAaUg"]
[Mon Jul 20 06:12:00.925925 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QkPqvKNcW5yy5T2C1rQAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:01.013957 2026] [security2:error] [pid 843279:tid 843298] [remote 47.86.33.52:59520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1sgAArxE"]
[Mon Jul 20 06:12:01.053048 2026] [security2:error] [pid 843279:tid 843508] [client 57.141.18.56:24532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjPqvKNcW5yy5T2C06QAA5l8"]
[Mon Jul 20 06:12:01.117593 2026] [security2:error] [pid 858085:tid 858308] [client 114.119.146.230:48409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mollycahill.com"] [uri "/molly-cahill-blog/instagram-mindset"] [unique_id "al4QkTAtbv2vrjByhUplCAAAAFw"], referer: https://www.mollycahill.com/molly-cahill-blog/tag/instagram%2Bcoaching
[Mon Jul 20 06:12:01.325698 2026] [security2:error] [pid 858085:tid 858290] [client 57.141.18.55:20188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjDAtbv2vrjByhUpkUgAAShM"]
[Mon Jul 20 06:12:01.329569 2026] [security2:error] [pid 843279:tid 843493] [client 185.132.186.78:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/require-dynamic-blocks.php"] [unique_id "al4QkfqvKNcW5yy5T2C1uQAAANg"]
[Mon Jul 20 06:12:01.371702 2026] [security2:error] [pid 858085:tid 858164] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QkTAtbv2vrjByhUplIgAAe00"]
[Mon Jul 20 06:12:01.371896 2026] [security2:error] [pid 858085:tid 858339] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QkTAtbv2vrjByhUplIgAAe00"]
[Mon Jul 20 06:12:01.392573 2026] [security2:error] [pid 858085:tid 858154] [remote 5.161.225.162:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QkTAtbv2vrjByhUplIwAAf0M"]
[Mon Jul 20 06:12:01.481686 2026] [security2:error] [pid 858085:tid 858171] [remote 8.217.108.67:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QkTAtbv2vrjByhUplKAAARlQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:01.600883 2026] [security2:error] [pid 843279:tid 843514] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QkfqvKNcW5yy5T2C1vgAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:02.023518 2026] [security2:error] [pid 858085:tid 858229] [client 216.73.216.78:65222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/index.php"] [unique_id "al4QkDAtbv2vrjByhUpk8gAADRQ"]
[Mon Jul 20 06:12:02.384528 2026] [security2:error] [pid 858085:tid 858181] [remote 5.161.225.162:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QkjAtbv2vrjByhUplTAAAEF4"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:12:02.397290 2026] [security2:error] [pid 858085:tid 858238] [client 50.116.65.227:45058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QkjAtbv2vrjByhUplTgAAABY"]
[Mon Jul 20 06:12:02.409272 2026] [security2:error] [pid 843279:tid 843460] [client 50.116.65.227:25210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QkvqvKNcW5yy5T2C16QAAALc"]
[Mon Jul 20 06:12:02.463054 2026] [security2:error] [pid 858085:tid 858218] [client 57.141.18.61:58214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjTAtbv2vrjByhUpkawAAAhc"]
[Mon Jul 20 06:12:02.829169 2026] [security2:error] [pid 843279:tid 843457] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QkvqvKNcW5yy5T2C19gAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:03.202146 2026] [security2:error] [pid 858085:tid 858296] [client 106.192.104.4:63000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QkzAtbv2vrjByhUplgAAAAFA"]
[Mon Jul 20 06:12:03.202270 2026] [security2:error] [pid 858085:tid 858296] [client 106.192.104.4:63000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QkzAtbv2vrjByhUplgAAAAFA"]
[Mon Jul 20 06:12:03.277492 2026] [security2:error] [pid 843279:tid 843449] [client 185.132.186.56:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/xp.php%20"] [unique_id "al4Qk_qvKNcW5yy5T2C2AwAAAKw"]
[Mon Jul 20 06:12:03.508397 2026] [security2:error] [pid 858085:tid 858328] [client 103.153.183.69:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../root/.bash_history"] [unique_id "al4QkzAtbv2vrjByhUpliQAAAHA"], referer: https://www.google.com/search?q=m6jj3c
[Mon Jul 20 06:12:03.540677 2026] [security2:error] [pid 843279:tid 843454] [client 14.225.17.146:52063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Qk_qvKNcW5yy5T2C2BQAAALE"], referer: http://lifeisbetterlakeside.com/WORDPRESS
[Mon Jul 20 06:12:03.615209 2026] [security2:error] [pid 858085:tid 858329] [client 18.142.226.106:25930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cryptomeaning.com"] [uri "/ethereum-vs-bitcoin-an-in-depth-comparison-of-two-crypto-giants/"] [unique_id "al4QkzAtbv2vrjByhUplkQAAAHE"], referer: https://cryptomeaning.com/unraveling-the-feline-frenzy-a-deep-dive-into-ethereum-crypto-kitties/
[Mon Jul 20 06:12:03.629071 2026] [security2:error] [pid 858085:tid 858301] [client 57.141.18.122:47774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjjAtbv2vrjByhUpknwAAVSw"]
[Mon Jul 20 06:12:03.833084 2026] [security2:error] [pid 858085:tid 858325] [client 57.141.18.54:29200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjzAtbv2vrjByhUpksgAAbTE"]
[Mon Jul 20 06:12:04.048072 2026] [security2:error] [pid 858085:tid 858298] [client 57.141.18.71:50012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjzAtbv2vrjByhUpkwgAAUjY"]
[Mon Jul 20 06:12:04.147453 2026] [security2:error] [pid 858085:tid 858192] [remote 95.217.78.234:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplsQAAd2k"]
[Mon Jul 20 06:12:04.147628 2026] [security2:error] [pid 858085:tid 858335] [client 95.217.78.234:46296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplsQAAd2k"]
[Mon Jul 20 06:12:04.376144 2026] [security2:error] [pid 858085:tid 858200] [remote 20.153.140.50:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QlDAtbv2vrjByhUplwQAAfHE"]
[Mon Jul 20 06:12:04.441010 2026] [autoindex:error] [pid 858085:tid 858341] [client 205.210.31.46:60970] AH01276: Cannot serve directory /home2/yapvjbmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.yap.vjb.mybluehost.me/
[Mon Jul 20 06:12:04.456505 2026] [security2:error] [pid 843279:tid 843508] [client 50.116.65.227:25248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QlPqvKNcW5yy5T2C2KAAAAOY"]
[Mon Jul 20 06:12:04.466354 2026] [security2:error] [pid 843279:tid 843431] [client 50.116.65.227:25250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QlPqvKNcW5yy5T2C2KQAAAJo"]
[Mon Jul 20 06:12:04.590956 2026] [security2:error] [pid 858085:tid 858277] [client 103.77.203.233:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplzAAAAD0"]
[Mon Jul 20 06:12:04.591140 2026] [security2:error] [pid 858085:tid 858277] [client 103.77.203.233:50508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplzAAAAD0"]
[Mon Jul 20 06:12:04.614273 2026] [security2:error] [pid 858085:tid 858203] [remote 216.73.217.138:19219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4QlDAtbv2vrjByhUplzQAAbXQ"]
[Mon Jul 20 06:12:04.849211 2026] [autoindex:error] [pid 858085:tid 858331] [client 43.164.190.124:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:12:04.995334 2026] [security2:error] [pid 858085:tid 858166] [remote 20.153.140.50:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QlDAtbv2vrjByhUpl6AAADk8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:05.152794 2026] [security2:error] [pid 858085:tid 858309] [client 57.141.18.98:39246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QkDAtbv2vrjByhUpk9QAAXUU"]
[Mon Jul 20 06:12:05.237140 2026] [security2:error] [pid 858085:tid 858233] [client 185.132.186.61:20713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/bypass.php"] [unique_id "al4QlTAtbv2vrjByhUpl8QAAABE"]
[Mon Jul 20 06:12:05.455131 2026] [security2:error] [pid 858085:tid 858292] [client 14.225.17.146:61226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4QlTAtbv2vrjByhUpl9AAAAEw"], referer: http://xp-design.co/WORDPRESS
[Mon Jul 20 06:12:05.631704 2026] [security2:error] [pid 858085:tid 858258] [client 57.141.18.96:21170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QkTAtbv2vrjByhUplFAAAKk4"]
[Mon Jul 20 06:12:06.202993 2026] [security2:error] [pid 858085:tid 858252] [client 14.225.17.146:61317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4QlDAtbv2vrjByhUplwwAAACQ"], referer: http://grecruit.online/WORDPRESS
[Mon Jul 20 06:12:06.243739 2026] [security2:error] [pid 843279:tid 843317] [remote 5.161.225.162:34350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2agAAhSQ"]
[Mon Jul 20 06:12:06.243954 2026] [security2:error] [pid 843279:tid 843410] [client 5.161.225.162:34350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2agAAhSQ"]
[Mon Jul 20 06:12:06.275660 2026] [security2:error] [pid 843279:tid 843415] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QlvqvKNcW5yy5T2C2bAAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:06.464838 2026] [security2:error] [pid 843279:tid 843389] [remote 47.86.33.52:6186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2dQAAzmw"]
[Mon Jul 20 06:12:06.465043 2026] [security2:error] [pid 843279:tid 843483] [client 47.86.33.52:6186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2dQAAzmw"]
[Mon Jul 20 06:12:06.499875 2026] [security2:error] [pid 843279:tid 843534] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QlvqvKNcW5yy5T2C2cwAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:06.543053 2026] [core:error] [pid 858085:tid 858305] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:06.543081 2026] [core:error] [pid 858085:tid 858305] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:06.682955 2026] [security2:error] [pid 858085:tid 858271] [client 57.141.18.94:52884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QkjAtbv2vrjByhUplOwAAN1A"]
[Mon Jul 20 06:12:06.715049 2026] [security2:error] [pid 843279:tid 843455] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QlvqvKNcW5yy5T2C2fAAAALI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:06.755285 2026] [security2:error] [pid 858085:tid 858201] [remote 130.51.180.8:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4QljAtbv2vrjByhUpmJQAALnI"]
[Mon Jul 20 06:12:07.043417 2026] [security2:error] [pid 843279:tid 843425] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2iwAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:07.142213 2026] [security2:error] [pid 843279:tid 843425] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2iwAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:07.150739 2026] [security2:error] [pid 843279:tid 843454] [client 185.132.186.81:55573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/bypass_1.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2jgAAALE"]
[Mon Jul 20 06:12:07.309623 2026] [security2:error] [pid 858085:tid 858240] [client 14.225.17.146:58093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4QljAtbv2vrjByhUpmFAAAABg"], referer: http://dnsplumbing.com/WORDPRESS
[Mon Jul 20 06:12:07.467838 2026] [security2:error] [pid 858085:tid 858116] [remote 130.51.180.8:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4QlzAtbv2vrjByhUpmQgAAPR0"], referer: https://adultdaycarereno.com/wp-login.php
[Mon Jul 20 06:12:07.525211 2026] [security2:error] [pid 843279:tid 843524] [client 181.224.94.124:24483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2nAAAAPY"]
[Mon Jul 20 06:12:07.525356 2026] [security2:error] [pid 843279:tid 843524] [client 181.224.94.124:24483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2nAAAAPY"]
[Mon Jul 20 06:12:07.712976 2026] [security2:error] [pid 843279:tid 843477] [client 103.153.183.69:13644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8fhome/admin/.ssh/id_rsa"] [unique_id "al4Ql_qvKNcW5yy5T2C2ogAAAMg"], referer: https://t.co/y0btos585h
[Mon Jul 20 06:12:07.924055 2026] [security2:error] [pid 858085:tid 858122] [remote 160.187.68.132:35862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QlzAtbv2vrjByhUpmUAAARiM"]
[Mon Jul 20 06:12:08.411959 2026] [security2:error] [pid 858085:tid 858295] [client 52.59.238.198:15912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmXwAAAE8"]
[Mon Jul 20 06:12:08.412060 2026] [security2:error] [pid 858085:tid 858295] [client 52.59.238.198:15912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmXwAAAE8"]
[Mon Jul 20 06:12:08.434410 2026] [security2:error] [pid 858085:tid 858120] [remote 160.187.68.132:35862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QmDAtbv2vrjByhUpmYAAAIiE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:12:08.461656 2026] [security2:error] [pid 858085:tid 858293] [client 103.141.108.143:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmZQAAAE0"]
[Mon Jul 20 06:12:08.462086 2026] [security2:error] [pid 858085:tid 858293] [client 103.141.108.143:59562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmZQAAAE0"]
[Mon Jul 20 06:12:08.520619 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.50:41004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QlDAtbv2vrjByhUplqwAADTg"]
[Mon Jul 20 06:12:08.802608 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QmPqvKNcW5yy5T2C2xQAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:08.898436 2026] [security2:error] [pid 858085:tid 858253] [client 45.157.112.60:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QmDAtbv2vrjByhUpmewAAACU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:09.017964 2026] [security2:error] [pid 843279:tid 843530] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QmfqvKNcW5yy5T2C2zgAAAPw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:09.158927 2026] [security2:error] [pid 843279:tid 843497] [client 41.173.37.102:3930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QmfqvKNcW5yy5T2C20wAAANw"]
[Mon Jul 20 06:12:09.159025 2026] [security2:error] [pid 843279:tid 843497] [client 41.173.37.102:3930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QmfqvKNcW5yy5T2C20wAAANw"]
[Mon Jul 20 06:12:09.270250 2026] [security2:error] [pid 858085:tid 858135] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmkAAABDA"]
[Mon Jul 20 06:12:09.270380 2026] [security2:error] [pid 858085:tid 858220] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmkAAABDA"]
[Mon Jul 20 06:12:09.344270 2026] [security2:error] [pid 843279:tid 843503] [client 57.141.18.2:42668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QlPqvKNcW5yy5T2C2PAAA4m0"]
[Mon Jul 20 06:12:09.530150 2026] [security2:error] [pid 858085:tid 858294] [client 112.213.160.112:30966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmoQAAAE4"]
[Mon Jul 20 06:12:09.530283 2026] [security2:error] [pid 858085:tid 858294] [client 112.213.160.112:30966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmoQAAAE4"]
[Mon Jul 20 06:12:09.548496 2026] [core:error] [pid 858085:tid 858230] [client 87.236.176.216:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:09.548524 2026] [core:error] [pid 858085:tid 858230] [client 87.236.176.216:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:09.581766 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:62651] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WORDPRESS
[Mon Jul 20 06:12:09.581801 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:62651] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WORDPRESS
[Mon Jul 20 06:12:09.592907 2026] [security2:error] [pid 858085:tid 858255] [client 50.116.65.227:38626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QmTAtbv2vrjByhUpmqAAAACc"]
[Mon Jul 20 06:12:09.608461 2026] [security2:error] [pid 858085:tid 858257] [client 50.116.65.227:19092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QmTAtbv2vrjByhUpmrgAAADU"]
[Mon Jul 20 06:12:09.808111 2026] [security2:error] [pid 858085:tid 858271] [client 103.153.183.69:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4QmTAtbv2vrjByhUpmsgAAADc"], referer: https://www.google.com/search?q=hrt92o
[Mon Jul 20 06:12:09.834710 2026] [security2:error] [pid 843279:tid 843521] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QmfqvKNcW5yy5T2C26gAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:10.093839 2026] [security2:error] [pid 858085:tid 858261] [client 185.132.186.69:41777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/elementskit.php"] [unique_id "al4QmjAtbv2vrjByhUpmtwAAAC0"]
[Mon Jul 20 06:12:10.121989 2026] [security2:error] [pid 858085:tid 858098] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmuAAAUAs"]
[Mon Jul 20 06:12:10.122181 2026] [security2:error] [pid 858085:tid 858296] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmuAAAUAs"]
[Mon Jul 20 06:12:10.323288 2026] [security2:error] [pid 858085:tid 858248] [client 14.225.17.146:61322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4QmDAtbv2vrjByhUpmdAAAACA"], referer: http://eduardsales.com/WORDPRESS
[Mon Jul 20 06:12:10.491987 2026] [security2:error] [pid 858085:tid 858222] [client 45.116.69.230:55658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmzQAAAAY"]
[Mon Jul 20 06:12:10.492098 2026] [security2:error] [pid 858085:tid 858222] [client 45.116.69.230:55658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmzQAAAAY"]
[Mon Jul 20 06:12:10.606289 2026] [security2:error] [pid 843279:tid 843437] [client 57.141.18.94:52900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QlvqvKNcW5yy5T2C2ZAAAoC8"]
[Mon Jul 20 06:12:10.745812 2026] [security2:error] [pid 843279:tid 843532] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QmvqvKNcW5yy5T2C3IQAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:10.861017 2026] [security2:error] [pid 843279:tid 843446] [client 192.161.164.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2rgAAqVQ"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91-the-summer-plans-studio-escala-1-6-ayanami-rei/
[Mon Jul 20 06:12:10.988374 2026] [security2:error] [pid 843279:tid 843450] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QmvqvKNcW5yy5T2C3JQAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:11.007279 2026] [security2:error] [pid 858085:tid 858110] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm9wAARRc"]
[Mon Jul 20 06:12:11.007447 2026] [security2:error] [pid 858085:tid 858285] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm9wAARRc"]
[Mon Jul 20 06:12:11.042146 2026] [security2:error] [pid 858085:tid 858332] [client 65.1.132.125:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm-QAAAHQ"]
[Mon Jul 20 06:12:11.042261 2026] [security2:error] [pid 858085:tid 858332] [client 65.1.132.125:26570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm-QAAAHQ"]
[Mon Jul 20 06:12:11.056395 2026] [security2:error] [pid 858085:tid 858315] [client 57.141.18.43:20504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QljAtbv2vrjByhUpmHwAAYw4"]
[Mon Jul 20 06:12:11.059319 2026] [security2:error] [pid 858085:tid 858179] [remote 72.167.132.114:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpm-wAAPVw"]
[Mon Jul 20 06:12:11.156930 2026] [fcgid:warn] [pid 858085:tid 858264] (70014)End of file found: [client 66.132.172.219:18734] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:11.259189 2026] [security2:error] [pid 858085:tid 858219] [client 164.100.212.184:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnDAAAAAM"]
[Mon Jul 20 06:12:11.259301 2026] [security2:error] [pid 858085:tid 858219] [client 164.100.212.184:52512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnDAAAAAM"]
[Mon Jul 20 06:12:11.398886 2026] [security2:error] [pid 858085:tid 858185] [remote 72.167.132.114:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpnEQAAFGI"], referer: https://alaraycreative.com/wp-login.php
[Mon Jul 20 06:12:11.540262 2026] [security2:error] [pid 843279:tid 843401] [remote 47.86.33.52:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3PAAAong"]
[Mon Jul 20 06:12:11.540501 2026] [security2:error] [pid 843279:tid 843439] [client 47.86.33.52:59506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3PAAAong"]
[Mon Jul 20 06:12:11.676312 2026] [security2:error] [pid 858085:tid 858134] [remote 57.141.18.88:33968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2896560"] [unique_id "al4QmzAtbv2vrjByhUpnIQAAGS8"]
[Mon Jul 20 06:12:11.720421 2026] [security2:error] [pid 858085:tid 858189] [remote 173.212.252.15:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpnIgAAV2Y"]
[Mon Jul 20 06:12:11.756714 2026] [security2:error] [pid 843279:tid 843485] [client 57.141.18.25:52330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2jQAA0E8"]
[Mon Jul 20 06:12:11.860791 2026] [security2:error] [pid 858085:tid 858145] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnJwAAEjo"]
[Mon Jul 20 06:12:11.861034 2026] [security2:error] [pid 858085:tid 858234] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnJwAAEjo"]
[Mon Jul 20 06:12:11.902649 2026] [security2:error] [pid 858085:tid 858138] [remote 173.212.252.15:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpnKwAAADM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:12:12.002461 2026] [security2:error] [pid 843279:tid 843430] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3SgAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:12.050128 2026] [security2:error] [pid 858085:tid 858258] [client 185.132.186.94:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-rss-database.php"] [unique_id "al4QnDAtbv2vrjByhUpnMAAAACo"]
[Mon Jul 20 06:12:12.125207 2026] [security2:error] [pid 858085:tid 858320] [client 103.153.183.69:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4QnDAtbv2vrjByhUpnMQAAAGg"], referer: https://t.co/9g09peono2
[Mon Jul 20 06:12:12.601620 2026] [security2:error] [pid 843279:tid 843471] [client 57.141.18.13:44296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2rAAAwno"]
[Mon Jul 20 06:12:12.718083 2026] [security2:error] [pid 858085:tid 858200] [remote 160.187.68.132:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4QnDAtbv2vrjByhUpnTwAAa3E"]
[Mon Jul 20 06:12:13.460180 2026] [security2:error] [pid 858085:tid 858284] [client 57.141.18.61:63198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QmDAtbv2vrjByhUpmbwAARCc"]
[Mon Jul 20 06:12:13.787105 2026] [security2:error] [pid 843279:tid 843473] [client 106.192.104.4:63487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QnfqvKNcW5yy5T2C3ggAAAMQ"]
[Mon Jul 20 06:12:13.787213 2026] [security2:error] [pid 843279:tid 843473] [client 106.192.104.4:63487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QnfqvKNcW5yy5T2C3ggAAAMQ"]
[Mon Jul 20 06:12:13.803645 2026] [security2:error] [pid 858085:tid 858214] [remote 160.187.68.132:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4QnTAtbv2vrjByhUpnhQAANn8"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:12:13.999327 2026] [security2:error] [pid 858085:tid 858265] [client 185.132.186.69:28599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/kur.php"] [unique_id "al4QnTAtbv2vrjByhUpnjQAAADE"]
[Mon Jul 20 06:12:14.142225 2026] [security2:error] [pid 858085:tid 858287] [client 57.141.18.42:32106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QmTAtbv2vrjByhUpmkgAARwQ"]
[Mon Jul 20 06:12:14.222954 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:52094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4QnvqvKNcW5yy5T2C3jAAAANs"], referer: http://jvcmotorsports.com/WORDPRESS
[Mon Jul 20 06:12:14.241377 2026] [security2:error] [pid 843279:tid 843536] [client 57.141.18.114:27868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QmfqvKNcW5yy5T2C22AABAko"]
[Mon Jul 20 06:12:14.342329 2026] [security2:error] [pid 843279:tid 843414] [client 82.102.18.116:57524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QnvqvKNcW5yy5T2C3kwAAAIk"]
[Mon Jul 20 06:12:14.988324 2026] [security2:error] [pid 858085:tid 858254] [client 82.102.18.116:57534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QnjAtbv2vrjByhUpnzQAAACY"]
[Mon Jul 20 06:12:15.051697 2026] [security2:error] [pid 858085:tid 858229] [client 65.1.132.125:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QnzAtbv2vrjByhUpn0AAAAA0"]
[Mon Jul 20 06:12:15.254959 2026] [security2:error] [pid 858085:tid 858307] [client 103.77.203.233:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QnzAtbv2vrjByhUpn2QAAAFs"]
[Mon Jul 20 06:12:15.255245 2026] [security2:error] [pid 858085:tid 858307] [client 103.77.203.233:51049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QnzAtbv2vrjByhUpn2QAAAFs"]
[Mon Jul 20 06:12:15.563411 2026] [security2:error] [pid 858085:tid 858234] [client 74.125.213.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnmAAAABI"]
[Mon Jul 20 06:12:15.875053 2026] [security2:error] [pid 858085:tid 858137] [remote 217.61.143.92:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4QnzAtbv2vrjByhUpoBwAAcDI"]
[Mon Jul 20 06:12:15.938221 2026] [security2:error] [pid 843279:tid 843535] [client 185.132.186.82:58779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/click.php"] [unique_id "al4Qn_qvKNcW5yy5T2C3wAAAAQE"]
[Mon Jul 20 06:12:15.946702 2026] [security2:error] [pid 858085:tid 858332] [client 14.225.17.146:62686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnywAAAHQ"], referer: http://ancestralidadytrance.space/WORDPRESS
[Mon Jul 20 06:12:16.146995 2026] [security2:error] [pid 858085:tid 858094] [remote 217.61.143.92:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4QoDAtbv2vrjByhUpoEgAAIQc"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 06:12:16.361173 2026] [security2:error] [pid 858085:tid 858232] [client 13.229.223.11:40452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QoDAtbv2vrjByhUpoHwAAABA"]
[Mon Jul 20 06:12:16.361297 2026] [security2:error] [pid 858085:tid 858232] [client 13.229.223.11:40452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QoDAtbv2vrjByhUpoHwAAABA"]
[Mon Jul 20 06:12:16.468554 2026] [security2:error] [pid 858085:tid 858304] [client 65.1.132.125:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QoDAtbv2vrjByhUpoKwAAAFg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:12:16.728955 2026] [security2:error] [pid 843279:tid 843436] [client 57.141.18.22:58300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3QgAAn0c"]
[Mon Jul 20 06:12:17.264426 2026] [security2:error] [pid 858085:tid 858257] [client 104.234.53.56:35109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QoTAtbv2vrjByhUpoWwAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:17.746987 2026] [security2:error] [pid 858085:tid 858325] [client 50.116.65.227:38664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QoTAtbv2vrjByhUpohAAAAG0"]
[Mon Jul 20 06:12:17.760847 2026] [security2:error] [pid 858085:tid 858271] [client 50.116.65.227:19156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QoTAtbv2vrjByhUpohQAAADc"]
[Mon Jul 20 06:12:17.859576 2026] [security2:error] [pid 858085:tid 858314] [client 82.102.18.116:57536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QoTAtbv2vrjByhUpoiQAAAGI"]
[Mon Jul 20 06:12:17.859718 2026] [security2:error] [pid 858085:tid 858314] [client 82.102.18.116:57536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QoTAtbv2vrjByhUpoiQAAAGI"]
[Mon Jul 20 06:12:17.863418 2026] [security2:error] [pid 858085:tid 858319] [client 185.132.186.64:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-customize-manager-client.php"] [unique_id "al4QoTAtbv2vrjByhUpoigAAAGc"]
[Mon Jul 20 06:12:18.097975 2026] [security2:error] [pid 858085:tid 858251] [client 181.224.94.124:2180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpolQAAACM"]
[Mon Jul 20 06:12:18.098119 2026] [security2:error] [pid 858085:tid 858251] [client 181.224.94.124:2180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpolQAAACM"]
[Mon Jul 20 06:12:18.134403 2026] [security2:error] [pid 858085:tid 858304] [client 104.234.53.56:35109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QojAtbv2vrjByhUpolgAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:18.378775 2026] [security2:error] [pid 843279:tid 843511] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ferrellroofing.com"] [uri "/index.php"] [unique_id "al4QofqvKNcW5yy5T2C33AAAAOk"]
[Mon Jul 20 06:12:18.445836 2026] [security2:error] [pid 858085:tid 858331] [client 57.141.18.35:29604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QnTAtbv2vrjByhUpnegAAc0U"]
[Mon Jul 20 06:12:18.566592 2026] [security2:error] [pid 858085:tid 858279] [client 158.173.89.95:40017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QojAtbv2vrjByhUposwAAAD8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:18.850183 2026] [security2:error] [pid 858085:tid 858237] [client 27.96.94.195:37556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpowAAAABU"]
[Mon Jul 20 06:12:18.873247 2026] [security2:error] [pid 858085:tid 858237] [client 27.96.94.195:37556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpowAAAABU"]
[Mon Jul 20 06:12:18.880212 2026] [security2:error] [pid 858085:tid 858305] [client 57.141.18.7:59042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnjgAAWQU"]
[Mon Jul 20 06:12:18.882271 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:54207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4QoPqvKNcW5yy5T2C3ygAAAK4"], referer: http://drewsasburyparkbeachhouse.com/WORDPRESS
[Mon Jul 20 06:12:19.163799 2026] [security2:error] [pid 858085:tid 858270] [client 103.141.108.143:60023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo0AAAADY"]
[Mon Jul 20 06:12:19.163909 2026] [security2:error] [pid 858085:tid 858270] [client 103.141.108.143:60023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo0AAAADY"]
[Mon Jul 20 06:12:19.181866 2026] [security2:error] [pid 843279:tid 843450] [client 216.244.66.243:55096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4Qo_qvKNcW5yy5T2C4EAAAAK0"]
[Mon Jul 20 06:12:19.181981 2026] [security2:error] [pid 843279:tid 843450] [client 216.244.66.243:55096] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4Qo_qvKNcW5yy5T2C4EAAAAK0"]
[Mon Jul 20 06:12:19.298206 2026] [security2:error] [pid 858085:tid 858211] [remote 110.249.201.94:19254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2010-commission/"] [unique_id "al4QozAtbv2vrjByhUpo2QAAYHw"]
[Mon Jul 20 06:12:19.530829 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.116:37802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnuAAAFBU"]
[Mon Jul 20 06:12:19.808193 2026] [security2:error] [pid 858085:tid 858266] [client 41.173.37.102:4380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo9AAAADI"]
[Mon Jul 20 06:12:19.808315 2026] [security2:error] [pid 858085:tid 858266] [client 41.173.37.102:4380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo9AAAADI"]
[Mon Jul 20 06:12:19.820244 2026] [security2:error] [pid 858085:tid 858253] [client 185.132.186.70:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-modules-packages.min-boolean.php"] [unique_id "al4QozAtbv2vrjByhUpo9wAAACU"]
[Mon Jul 20 06:12:19.834072 2026] [security2:error] [pid 843279:tid 843289] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qo_qvKNcW5yy5T2C4IwAA3gg"]
[Mon Jul 20 06:12:19.834219 2026] [security2:error] [pid 843279:tid 843499] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qo_qvKNcW5yy5T2C4IwAA3gg"]
[Mon Jul 20 06:12:20.016848 2026] [security2:error] [pid 858085:tid 858315] [client 14.225.17.146:51991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4QozAtbv2vrjByhUpo8AAAAGM"], referer: http://floorsourcestock.com/WORDPRESS
[Mon Jul 20 06:12:20.138623 2026] [security2:error] [pid 858085:tid 858221] [client 45.116.69.230:56167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppBgAAAAU"]
[Mon Jul 20 06:12:20.138761 2026] [security2:error] [pid 858085:tid 858221] [client 45.116.69.230:56167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppBgAAAAU"]
[Mon Jul 20 06:12:20.248686 2026] [security2:error] [pid 858085:tid 858303] [client 112.213.160.112:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppEAAAAFc"]
[Mon Jul 20 06:12:20.248832 2026] [security2:error] [pid 858085:tid 858303] [client 112.213.160.112:31231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppEAAAAFc"]
[Mon Jul 20 06:12:20.618237 2026] [security2:error] [pid 858085:tid 858111] [remote 47.86.33.52:15538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4QpDAtbv2vrjByhUppJAAAARg"], referer: https://mail.indiraskitchenllc.com/wp-login.php
[Mon Jul 20 06:12:20.788301 2026] [security2:error] [pid 843279:tid 843282] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QpPqvKNcW5yy5T2C4QAAA-gE"]
[Mon Jul 20 06:12:20.788614 2026] [security2:error] [pid 843279:tid 843528] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QpPqvKNcW5yy5T2C4QAAA-gE"]
[Mon Jul 20 06:12:20.858758 2026] [fcgid:warn] [pid 843279:tid 843493] (70014)End of file found: [client 93.174.93.12:60000] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:21.035289 2026] [security2:error] [pid 858085:tid 858125] [remote 81.173.115.7:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppNwAAMSY"]
[Mon Jul 20 06:12:21.136505 2026] [security2:error] [pid 858085:tid 858238] [client 57.141.18.123:32312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QoDAtbv2vrjByhUpoMAAAFko"]
[Mon Jul 20 06:12:21.214477 2026] [security2:error] [pid 858085:tid 858128] [remote 103.255.134.61:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "test.koaconsultants.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppRQAAWyk"]
[Mon Jul 20 06:12:21.227963 2026] [security2:error] [pid 858085:tid 858135] [remote 81.173.115.7:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppSQAARjA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:12:21.272499 2026] [autoindex:error] [pid 843279:tid 843510] [client 43.153.48.240:0] AH01276: Cannot serve directory /home1/itdynami/public_html/misralrakamia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:12:21.342859 2026] [security2:error] [pid 858085:tid 858315] [client 178.152.178.232:36663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppUAAAAGM"]
[Mon Jul 20 06:12:21.349289 2026] [security2:error] [pid 858085:tid 858315] [client 178.152.178.232:36663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppUAAAAGM"]
[Mon Jul 20 06:12:21.764772 2026] [security2:error] [pid 858085:tid 858094] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppZwAAfAc"]
[Mon Jul 20 06:12:21.764975 2026] [security2:error] [pid 858085:tid 858340] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppZwAAfAc"]
[Mon Jul 20 06:12:21.765945 2026] [security2:error] [pid 858085:tid 858318] [client 185.132.186.102:26099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/error.php"] [unique_id "al4QpTAtbv2vrjByhUppaAAAAGY"]
[Mon Jul 20 06:12:21.799580 2026] [security2:error] [pid 858085:tid 858342] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QpTAtbv2vrjByhUppPwAAAH4"]
[Mon Jul 20 06:12:21.814998 2026] [security2:error] [pid 858085:tid 858103] [remote 103.255.134.61:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "test.koaconsultants.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppawAAERA"], referer: https://test.koaconsultants.com/wp-login.php
[Mon Jul 20 06:12:21.816906 2026] [security2:error] [pid 843279:tid 843462] [client 3.85.28.216:63106] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/avocado-crema-crema-de-aguacate"] [unique_id "al4QpfqvKNcW5yy5T2C4TAAAALk"]
[Mon Jul 20 06:12:21.846475 2026] [security2:error] [pid 843279:tid 843485] [client 3.109.4.218:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QpfqvKNcW5yy5T2C4XwAAANA"]
[Mon Jul 20 06:12:21.846706 2026] [security2:error] [pid 843279:tid 843485] [client 3.109.4.218:52670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QpfqvKNcW5yy5T2C4XwAAANA"]
[Mon Jul 20 06:12:21.911586 2026] [security2:error] [pid 858085:tid 858239] [client 192.149.70.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4QpDAtbv2vrjByhUppCwAAABc"]
[Mon Jul 20 06:12:21.932100 2026] [security2:error] [pid 858085:tid 858323] [client 57.141.18.6:27758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QoTAtbv2vrjByhUpoXgAAaxQ"]
[Mon Jul 20 06:12:22.116117 2026] [security2:error] [pid 843279:tid 843425] [client 46.110.96.34:55004] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4QpvqvKNcW5yy5T2C4awAAAJQ"]
[Mon Jul 20 06:12:22.116202 2026] [security2:error] [pid 843279:tid 843425] [client 46.110.96.34:55004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4QpvqvKNcW5yy5T2C4awAAAJQ"]
[Mon Jul 20 06:12:22.377351 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.51:57150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QoTAtbv2vrjByhUpogAAAd2I"]
[Mon Jul 20 06:12:22.409929 2026] [security2:error] [pid 843279:tid 843463] [client 45.61.188.240:63716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mcg.homes"] [uri "/"] [unique_id "al4QpvqvKNcW5yy5T2C4bwAAALo"]
[Mon Jul 20 06:12:22.419126 2026] [security2:error] [pid 858085:tid 858303] [client 14.225.17.146:61766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUppfwAAAFc"], referer: http://omenana.com/WORDPRESS
[Mon Jul 20 06:12:22.421842 2026] [security2:error] [pid 858085:tid 858149] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QpjAtbv2vrjByhUppigAAbT4"]
[Mon Jul 20 06:12:22.422030 2026] [security2:error] [pid 858085:tid 858325] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QpjAtbv2vrjByhUppigAAbT4"]
[Mon Jul 20 06:12:22.470077 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4QpDAtbv2vrjByhUppMAAAABk"], referer: http://bbwipartnerconference.com/WORDPRESS
[Mon Jul 20 06:12:22.543934 2026] [security2:error] [pid 858085:tid 858292] [client 14.225.17.146:63470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4QpDAtbv2vrjByhUppHgAAAEw"], referer: http://areitoproducciones.com/WORDPRESS
[Mon Jul 20 06:12:22.708104 2026] [security2:error] [pid 843279:tid 843521] [client 45.61.188.240:63774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mcg.homes"] [uri "/"] [unique_id "al4QpvqvKNcW5yy5T2C4dwAAAPM"]
[Mon Jul 20 06:12:22.735189 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.32:53448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QojAtbv2vrjByhUpokQAAKWY"]
[Mon Jul 20 06:12:23.019907 2026] [security2:error] [pid 843279:tid 843424] [client 57.141.18.0:24146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QovqvKNcW5yy5T2C38QAAkyg"]
[Mon Jul 20 06:12:23.240516 2026] [core:error] [pid 858085:tid 858292] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:23.240538 2026] [core:error] [pid 858085:tid 858292] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:23.455441 2026] [security2:error] [pid 858085:tid 858332] [client 104.234.53.78:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QpzAtbv2vrjByhUpp1wAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:23.582680 2026] [security2:error] [pid 843279:tid 843448] [client 14.225.17.146:51216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4QpvqvKNcW5yy5T2C4aAAAAKs"], referer: http://detroitcsc.com/WORDPRESS
[Mon Jul 20 06:12:23.612702 2026] [security2:error] [pid 858085:tid 858290] [client 54.198.0.135:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUpppAAAAEo"]
[Mon Jul 20 06:12:23.617508 2026] [security2:error] [pid 858085:tid 858229] [client 54.198.0.135:28172] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/avocado-crema-crema-de-aguacate/"] [unique_id "al4QpjAtbv2vrjByhUppoAAAAA0"]
[Mon Jul 20 06:12:23.729842 2026] [security2:error] [pid 858085:tid 858296] [client 185.132.186.90:36077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ALFA_DATA/alfacgiapi/all.php"] [unique_id "al4QpzAtbv2vrjByhUpp5wAAAFA"]
[Mon Jul 20 06:12:24.310994 2026] [security2:error] [pid 843279:tid 843473] [client 57.141.18.11:54672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qo_qvKNcW5yy5T2C4HgAAxHM"]
[Mon Jul 20 06:12:24.375529 2026] [security2:error] [pid 843279:tid 843446] [client 50.116.65.227:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QqPqvKNcW5yy5T2C4nAAAAKk"]
[Mon Jul 20 06:12:24.386434 2026] [security2:error] [pid 843279:tid 843414] [client 50.116.65.227:36286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QqPqvKNcW5yy5T2C4nQAAAIk"]
[Mon Jul 20 06:12:24.470075 2026] [security2:error] [pid 858085:tid 858279] [client 14.225.17.146:62103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUppmwAAAD8"], referer: http://partnerselectricalllc.com/WORDPRESS
[Mon Jul 20 06:12:24.629348 2026] [security2:error] [pid 858085:tid 858222] [client 57.141.18.23:59260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QozAtbv2vrjByhUpo-QAABns"]
[Mon Jul 20 06:12:24.662359 2026] [security2:error] [pid 843279:tid 843492] [client 14.225.17.146:62467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4QqPqvKNcW5yy5T2C4nwAAANc"], referer: http://according2plant.com/WORDPRESS
[Mon Jul 20 06:12:24.686258 2026] [security2:error] [pid 843279:tid 843538] [client 158.173.166.181:52757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QqPqvKNcW5yy5T2C4qAAAAQQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:24.762394 2026] [security2:error] [pid 858085:tid 858256] [client 106.192.104.4:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QqDAtbv2vrjByhUpqIgAAACg"]
[Mon Jul 20 06:12:24.771818 2026] [security2:error] [pid 858085:tid 858256] [client 106.192.104.4:63972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QqDAtbv2vrjByhUpqIgAAACg"]
[Mon Jul 20 06:12:24.996076 2026] [security2:error] [pid 858085:tid 858212] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QqDAtbv2vrjByhUpqLAAAD30"]
[Mon Jul 20 06:12:25.132282 2026] [security2:error] [pid 843279:tid 843498] [client 57.141.18.22:57142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpPqvKNcW5yy5T2C4MAAA3Uk"]
[Mon Jul 20 06:12:25.267461 2026] [security2:error] [pid 843279:tid 843460] [client 57.141.18.108:46522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpPqvKNcW5yy5T2C4NgAAt1I"]
[Mon Jul 20 06:12:25.463018 2026] [security2:error] [pid 858085:tid 858100] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QqTAtbv2vrjByhUpqPwAAMg0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:12:25.487739 2026] [security2:error] [pid 858085:tid 858167] [remote 18.61.192.253:36944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QqTAtbv2vrjByhUpqQgAASFA"]
[Mon Jul 20 06:12:25.546239 2026] [security2:error] [pid 858085:tid 858262] [client 14.225.17.146:61906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4QpzAtbv2vrjByhUpp7gAAAC4"], referer: http://nwcarvingacademy.com/WORDPRESS
[Mon Jul 20 06:12:25.676394 2026] [security2:error] [pid 843279:tid 843444] [client 185.132.186.88:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/autoload_classmap.php"] [unique_id "al4QqfqvKNcW5yy5T2C4xAAAAKc"]
[Mon Jul 20 06:12:25.881660 2026] [security2:error] [pid 858085:tid 858251] [client 103.77.203.233:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QqTAtbv2vrjByhUpqYQAAACM"]
[Mon Jul 20 06:12:25.882426 2026] [security2:error] [pid 858085:tid 858251] [client 103.77.203.233:51584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QqTAtbv2vrjByhUpqYQAAACM"]
[Mon Jul 20 06:12:25.901741 2026] [security2:error] [pid 858085:tid 858252] [client 57.141.18.18:57940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpTAtbv2vrjByhUppTgAAJC4"]
[Mon Jul 20 06:12:25.914952 2026] [security2:error] [pid 843279:tid 843430] [client 50.116.65.227:15206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4QqfqvKNcW5yy5T2C4zgAAAJk"]
[Mon Jul 20 06:12:25.929559 2026] [security2:error] [pid 843279:tid 843465] [client 50.116.65.227:36322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4QqfqvKNcW5yy5T2C4zwAAAOY"]
[Mon Jul 20 06:12:26.004114 2026] [security2:error] [pid 858085:tid 858121] [remote 57.141.18.47:39630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3874665"] [unique_id "al4QqTAtbv2vrjByhUpqaQAADSI"]
[Mon Jul 20 06:12:26.339802 2026] [security2:error] [pid 858085:tid 858128] [remote 18.61.192.253:36944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QqjAtbv2vrjByhUpqegAAXik"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:12:26.394716 2026] [security2:error] [pid 843279:tid 843299] [remote 192.241.143.148:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QqvqvKNcW5yy5T2C43AAA5BI"]
[Mon Jul 20 06:12:26.421572 2026] [security2:error] [pid 858085:tid 858143] [remote 209.133.215.178:59240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.215.133.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QqjAtbv2vrjByhUpqfwAANzg"]
[Mon Jul 20 06:12:26.608526 2026] [security2:error] [pid 858085:tid 858139] [remote 209.133.215.178:59240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.215.133.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QqjAtbv2vrjByhUpqhAAASjQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:12:26.615313 2026] [security2:error] [pid 843279:tid 843288] [remote 192.241.143.148:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QqvqvKNcW5yy5T2C43wAAuAc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:26.773550 2026] [security2:error] [pid 858085:tid 858243] [client 14.225.17.146:58156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4QqTAtbv2vrjByhUpqMAAAABs"], referer: http://laceycaraccident.com/WORDPRESS
[Mon Jul 20 06:12:26.800961 2026] [security2:error] [pid 843279:tid 843434] [client 14.225.17.146:60734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4QqvqvKNcW5yy5T2C43gAAAJ0"], referer: https://nwcarvingacademy.com/WORDPRESS
[Mon Jul 20 06:12:27.051616 2026] [security2:error] [pid 843279:tid 843489] [client 57.141.18.74:56066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpvqvKNcW5yy5T2C4bgAA1A8"]
[Mon Jul 20 06:12:27.470262 2026] [security2:error] [pid 858085:tid 858315] [client 57.141.18.121:22068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUppqwAAY1k"]
[Mon Jul 20 06:12:27.528801 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:61966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4QqfqvKNcW5yy5T2C4zQAAANs"], referer: http://aberballet.co.uk/WORDPRESS
[Mon Jul 20 06:12:27.620400 2026] [security2:error] [pid 858085:tid 858296] [client 185.132.186.104:27293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "al4QqzAtbv2vrjByhUpquAAAAFA"]
[Mon Jul 20 06:12:27.839541 2026] [security2:error] [pid 858085:tid 858294] [client 98.159.234.160:42429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QqzAtbv2vrjByhUpqxAAAAE4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:28.139137 2026] [security2:error] [pid 858085:tid 858267] [client 216.73.217.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpqygAAADM"]
[Mon Jul 20 06:12:28.309342 2026] [security2:error] [pid 843279:tid 843419] [client 27.96.94.195:38243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QrPqvKNcW5yy5T2C5DQAAAI4"]
[Mon Jul 20 06:12:28.309475 2026] [security2:error] [pid 843279:tid 843419] [client 27.96.94.195:38243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QrPqvKNcW5yy5T2C5DQAAAI4"]
[Mon Jul 20 06:12:28.579201 2026] [autoindex:error] [pid 858085:tid 858243] [client 205.210.31.50:65466] AH01276: Cannot serve directory /home2/zajlqimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.zaj.lqi.mybluehost.me/
[Mon Jul 20 06:12:28.649290 2026] [security2:error] [pid 858085:tid 858216] [client 181.224.94.124:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QrDAtbv2vrjByhUpq-AAAAAA"]
[Mon Jul 20 06:12:28.649444 2026] [security2:error] [pid 858085:tid 858216] [client 181.224.94.124:63717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QrDAtbv2vrjByhUpq-AAAAAA"]
[Mon Jul 20 06:12:29.580897 2026] [security2:error] [pid 858085:tid 858246] [client 185.132.186.88:49667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/repairs.php"] [unique_id "al4QrTAtbv2vrjByhUprFQAAAB4"]
[Mon Jul 20 06:12:29.638693 2026] [security2:error] [pid 843279:tid 843342] [remote 160.187.68.132:44330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4QrfqvKNcW5yy5T2C5MwAA7T0"]
[Mon Jul 20 06:12:29.871728 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QrfqvKNcW5yy5T2C5PgAAAPI"]
[Mon Jul 20 06:12:29.872119 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:60492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QrfqvKNcW5yy5T2C5PgAAAPI"]
[Mon Jul 20 06:12:29.929409 2026] [security2:error] [pid 858085:tid 858220] [client 57.141.18.111:56362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqTAtbv2vrjByhUpqRQAABBI"]
[Mon Jul 20 06:12:30.144843 2026] [security2:error] [pid 858085:tid 858323] [client 14.225.17.146:49955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpq-gAAAGs"], referer: http://eframiproperties.com/WORDPRESS
[Mon Jul 20 06:12:30.263245 2026] [security2:error] [pid 843279:tid 843510] [client 216.73.217.138:12796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QrvqvKNcW5yy5T2C5SAAA6Fg"]
[Mon Jul 20 06:12:30.332851 2026] [security2:error] [pid 858085:tid 858301] [client 65.21.32.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4QrjAtbv2vrjByhUprLwAAAFU"]
[Mon Jul 20 06:12:30.361856 2026] [security2:error] [pid 858085:tid 858260] [client 57.141.18.74:55950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqTAtbv2vrjByhUpqYAAALB4"]
[Mon Jul 20 06:12:30.392125 2026] [security2:error] [pid 843279:tid 843471] [client 41.173.37.102:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5TQAAAMI"]
[Mon Jul 20 06:12:30.392269 2026] [security2:error] [pid 843279:tid 843471] [client 41.173.37.102:4853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5TQAAAMI"]
[Mon Jul 20 06:12:30.410665 2026] [security2:error] [pid 858085:tid 858196] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrjAtbv2vrjByhUprOQAAL20"]
[Mon Jul 20 06:12:30.410833 2026] [security2:error] [pid 858085:tid 858263] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrjAtbv2vrjByhUprOQAAL20"]
[Mon Jul 20 06:12:30.480811 2026] [security2:error] [pid 858085:tid 858208] [remote 154.0.166.254:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QrjAtbv2vrjByhUprPQAAd3k"]
[Mon Jul 20 06:12:30.504689 2026] [security2:error] [pid 858085:tid 858241] [client 57.141.18.12:22196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqjAtbv2vrjByhUpqcAAAGSE"]
[Mon Jul 20 06:12:30.851548 2026] [security2:error] [pid 858085:tid 858288] [client 57.141.18.64:44364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqjAtbv2vrjByhUpqeQAASCg"]
[Mon Jul 20 06:12:30.862325 2026] [security2:error] [pid 843279:tid 843451] [client 45.116.69.230:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5WwAAAK4"]
[Mon Jul 20 06:12:30.862457 2026] [security2:error] [pid 843279:tid 843451] [client 45.116.69.230:56684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5WwAAAK4"]
[Mon Jul 20 06:12:30.929320 2026] [security2:error] [pid 843279:tid 843466] [client 112.213.160.112:31012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5XAAAAL0"]
[Mon Jul 20 06:12:30.929451 2026] [security2:error] [pid 843279:tid 843466] [client 112.213.160.112:31012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5XAAAAL0"]
[Mon Jul 20 06:12:30.967739 2026] [security2:error] [pid 858085:tid 858163] [remote 154.0.166.254:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QrjAtbv2vrjByhUprVwAAbEw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:12:31.076415 2026] [security2:error] [pid 843279:tid 843406] [remote 47.86.33.52:15096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5YQAAvn0"]
[Mon Jul 20 06:12:31.187590 2026] [security2:error] [pid 858085:tid 858275] [client 104.234.53.89:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QrzAtbv2vrjByhUprYwAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:31.213298 2026] [proxy:error] [pid 858085:tid 858296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:31.213347 2026] [proxy_http:error] [pid 858085:tid 858296] [client 8.229.28.226:54204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:31.214186 2026] [proxy:error] [pid 858085:tid 858296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:31.214219 2026] [proxy_http:error] [pid 858085:tid 858296] [client 8.229.28.226:54204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:31.215585 2026] [security2:error] [pid 858085:tid 858333] [client 47.128.117.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QrjAtbv2vrjByhUprUQAAAHU"]
[Mon Jul 20 06:12:31.325576 2026] [security2:error] [pid 858085:tid 858100] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUprcwAAGQ0"]
[Mon Jul 20 06:12:31.325745 2026] [security2:error] [pid 858085:tid 858241] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUprcwAAGQ0"]
[Mon Jul 20 06:12:31.361598 2026] [security2:error] [pid 843279:tid 843372] [remote 160.187.68.132:44330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5ZgAA_ls"], referer: https://solkeetw.com/wp-login.php
[Mon Jul 20 06:12:31.476491 2026] [security2:error] [pid 858085:tid 858277] [client 178.152.178.232:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUpreAAAAD0"]
[Mon Jul 20 06:12:31.476638 2026] [security2:error] [pid 858085:tid 858277] [client 178.152.178.232:37154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUpreAAAAD0"]
[Mon Jul 20 06:12:31.515446 2026] [security2:error] [pid 843279:tid 843455] [client 74.208.214.194:42486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5bAAAALI"]
[Mon Jul 20 06:12:31.517280 2026] [security2:error] [pid 858085:tid 858280] [client 185.132.186.59:57729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/smilies/simi.php"] [unique_id "al4QrzAtbv2vrjByhUprewAAAEA"]
[Mon Jul 20 06:12:31.753430 2026] [security2:error] [pid 858085:tid 858340] [client 57.141.18.75:23422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqzAtbv2vrjByhUpqogAAfBQ"]
[Mon Jul 20 06:12:32.437110 2026] [security2:error] [pid 843279:tid 843328] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5fAAA_y8"]
[Mon Jul 20 06:12:32.437275 2026] [security2:error] [pid 843279:tid 843533] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5fAAA_y8"]
[Mon Jul 20 06:12:32.456966 2026] [security2:error] [pid 858085:tid 858321] [client 14.225.17.146:51037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4QsDAtbv2vrjByhUprogAAAGk"], referer: http://alrowad-hub.net/WORDPRESS
[Mon Jul 20 06:12:32.671389 2026] [security2:error] [pid 843279:tid 843425] [client 3.109.4.218:53762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5iwAAAJQ"]
[Mon Jul 20 06:12:32.671548 2026] [security2:error] [pid 843279:tid 843425] [client 3.109.4.218:53762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5iwAAAJQ"]
[Mon Jul 20 06:12:32.955737 2026] [security2:error] [pid 843279:tid 843462] [client 14.225.17.146:50621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5bwAAALk"], referer: http://alaraycreative.com/WORDPRESS
[Mon Jul 20 06:12:32.993843 2026] [security2:error] [pid 858085:tid 858098] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QsDAtbv2vrjByhUprxwAAMAs"]
[Mon Jul 20 06:12:32.994142 2026] [security2:error] [pid 858085:tid 858264] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QsDAtbv2vrjByhUprxwAAMAs"]
[Mon Jul 20 06:12:33.029332 2026] [security2:error] [pid 843279:tid 843424] [client 94.154.43.178:32340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.muamoicosmetics.com"] [uri "/.env"] [unique_id "al4QsfqvKNcW5yy5T2C5lAAAAJM"]
[Mon Jul 20 06:12:33.182509 2026] [security2:error] [pid 858085:tid 858146] [remote 3.7.185.37:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4QsTAtbv2vrjByhUprzwAAbjs"]
[Mon Jul 20 06:12:33.185865 2026] [security2:error] [pid 858085:tid 858304] [client 57.141.18.48:23858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpq4AAAWEs"]
[Mon Jul 20 06:12:33.292201 2026] [security2:error] [pid 858085:tid 858262] [client 57.141.18.121:22080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpq7wAALkQ"]
[Mon Jul 20 06:12:33.462947 2026] [security2:error] [pid 858085:tid 858257] [client 185.132.186.65:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin.php"] [unique_id "al4QsTAtbv2vrjByhUpr4gAAACk"]
[Mon Jul 20 06:12:33.467554 2026] [security2:error] [pid 858085:tid 858340] [client 50.116.65.227:11482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QsTAtbv2vrjByhUpr4wAAAHw"]
[Mon Jul 20 06:12:33.481831 2026] [security2:error] [pid 858085:tid 858299] [client 50.116.65.227:11498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QsTAtbv2vrjByhUpr5AAAAFM"]
[Mon Jul 20 06:12:33.492111 2026] [ssl:error] [pid 858085:tid 858254] [client 98.88.137.2:5576] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname autodiscover.ugx.lqn.mybluehost.me provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:12:33.611729 2026] [security2:error] [pid 858085:tid 858159] [remote 3.7.185.37:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4QsTAtbv2vrjByhUpr7gAAGEg"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:12:33.790610 2026] [security2:error] [pid 858085:tid 858227] [client 50.116.65.227:57086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QsTAtbv2vrjByhUpr_AAAAAs"]
[Mon Jul 20 06:12:33.804713 2026] [security2:error] [pid 843279:tid 843515] [client 50.116.65.227:11510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QsfqvKNcW5yy5T2C5pgAAAO0"]
[Mon Jul 20 06:12:34.120005 2026] [security2:error] [pid 858085:tid 858220] [client 66.249.64.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.indiraskitchenllc.com"] [uri "/index.php"] [unique_id "al4QsDAtbv2vrjByhUprtAAABDQ"]
[Mon Jul 20 06:12:34.149413 2026] [security2:error] [pid 843279:tid 843400] [remote 47.86.33.52:15096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QsvqvKNcW5yy5T2C5sgAA4nc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:34.177534 2026] [security2:error] [pid 858085:tid 858276] [client 13.201.64.214:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QsjAtbv2vrjByhUpsCQAAADw"]
[Mon Jul 20 06:12:34.177656 2026] [security2:error] [pid 858085:tid 858276] [client 13.201.64.214:46456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QsjAtbv2vrjByhUpsCQAAADw"]
[Mon Jul 20 06:12:34.522542 2026] [proxy:error] [pid 858085:tid 858340] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:34.522591 2026] [proxy_http:error] [pid 858085:tid 858340] [client 23.180.120.147:33334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:34.524196 2026] [proxy:error] [pid 858085:tid 858340] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:34.524261 2026] [proxy_http:error] [pid 858085:tid 858340] [client 23.180.120.147:33334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:34.951928 2026] [security2:error] [pid 858085:tid 858301] [client 13.201.64.214:46468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QsjAtbv2vrjByhUpsPgAAAFU"]
[Mon Jul 20 06:12:35.001872 2026] [security2:error] [pid 843279:tid 843361] [remote 208.109.9.173:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4QsvqvKNcW5yy5T2C5yQAA1VA"]
[Mon Jul 20 06:12:35.093955 2026] [security2:error] [pid 858085:tid 858251] [client 188.253.17.6:39322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QsjAtbv2vrjByhUpsHwAAACM"], referer: https://mezzacraft.com/why-i-dont-sell-my-crochet-creations-for-a-living/
[Mon Jul 20 06:12:35.157211 2026] [security2:error] [pid 843279:tid 843413] [client 114.119.144.29:29523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ksands.co.uk"] [uri "/security-services-in-brazil/"] [unique_id "al4Qs_qvKNcW5yy5T2C5zQAAAIg"], referer: https://ksands.co.uk/safety-security-services/resilience-and-continuity-consultancy/
[Mon Jul 20 06:12:35.162198 2026] [security2:error] [pid 843279:tid 843424] [client 54.169.146.187:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C5zAAAAJM"]
[Mon Jul 20 06:12:35.162288 2026] [security2:error] [pid 843279:tid 843424] [client 54.169.146.187:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C5zAAAAJM"]
[Mon Jul 20 06:12:35.273741 2026] [security2:error] [pid 858085:tid 858281] [client 74.208.214.194:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QszAtbv2vrjByhUpsSgAAAEE"]
[Mon Jul 20 06:12:35.411020 2026] [security2:error] [pid 858085:tid 858279] [client 185.132.186.78:20863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-header.php%20"] [unique_id "al4QszAtbv2vrjByhUpsUwAAAD8"]
[Mon Jul 20 06:12:35.435778 2026] [security2:error] [pid 843279:tid 843294] [remote 208.109.9.173:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4Qs_qvKNcW5yy5T2C51wAApg0"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 06:12:35.741294 2026] [security2:error] [pid 858085:tid 858226] [client 13.217.4.236:48336] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "206"] [hostname "elespecialista.mx"] [uri "/index.html"] [unique_id "al4QszAtbv2vrjByhUpsXwAAAAo"]
[Mon Jul 20 06:12:35.775142 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.62:48036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QrzAtbv2vrjByhUprbAAAd1o"]
[Mon Jul 20 06:12:35.778983 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C54QAAALA"]
[Mon Jul 20 06:12:35.779129 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:64466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C54QAAALA"]
[Mon Jul 20 06:12:35.881057 2026] [security2:error] [pid 843279:tid 843475] [client 14.225.17.146:50984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4Qs_qvKNcW5yy5T2C53AAAAMY"], referer: http://transparentservices.online/WORDPRESS
[Mon Jul 20 06:12:36.032334 2026] [security2:error] [pid 843279:tid 843480] [client 57.141.18.9:30868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5aQAAy24"]
[Mon Jul 20 06:12:36.053556 2026] [security2:error] [pid 858085:tid 858330] [client 18.208.166.180:63294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "elespecialista.mx"] [uri "/favicon.ico"] [unique_id "al4QtDAtbv2vrjByhUpscgAAAHI"]
[Mon Jul 20 06:12:36.294002 2026] [security2:error] [pid 843279:tid 843415] [client 3.109.4.218:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QtPqvKNcW5yy5T2C5-wAAAIo"]
[Mon Jul 20 06:12:36.424148 2026] [security2:error] [pid 858085:tid 858214] [remote 47.128.99.94:17732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/roleta-online-editavel-2024-01-29-id-33127.pdf"] [unique_id "al4QtDAtbv2vrjByhUpshAAAGn8"]
[Mon Jul 20 06:12:36.434747 2026] [security2:error] [pid 858085:tid 858342] [client 14.225.17.146:54771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4QtDAtbv2vrjByhUpseAAAAH4"], referer: http://ivetstrategies.com/WORDPRESS
[Mon Jul 20 06:12:36.482240 2026] [security2:error] [pid 843279:tid 843533] [client 103.77.203.233:52118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QtPqvKNcW5yy5T2C6BgAAAP8"]
[Mon Jul 20 06:12:36.482578 2026] [security2:error] [pid 843279:tid 843533] [client 103.77.203.233:52118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QtPqvKNcW5yy5T2C6BgAAAP8"]
[Mon Jul 20 06:12:37.124396 2026] [security2:error] [pid 858085:tid 858289] [client 57.141.18.59:61644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QsDAtbv2vrjByhUpruwAASTc"]
[Mon Jul 20 06:12:37.193607 2026] [security2:error] [pid 843279:tid 843469] [client 3.109.4.218:53786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QtfqvKNcW5yy5T2C6EQAAAMA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:12:37.372527 2026] [security2:error] [pid 858085:tid 858303] [client 185.132.186.83:33557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/file.php%20"] [unique_id "al4QtTAtbv2vrjByhUpssAAAAFc"]
[Mon Jul 20 06:12:37.534839 2026] [security2:error] [pid 843279:tid 843438] [client 57.141.18.84:29398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QsfqvKNcW5yy5T2C5mAAAoVw"]
[Mon Jul 20 06:12:37.637666 2026] [security2:error] [pid 858085:tid 858233] [client 14.225.17.146:54893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QtTAtbv2vrjByhUpstwAAABE"], referer: http://maxenengineering.com/WORDPRESS
[Mon Jul 20 06:12:37.881821 2026] [security2:error] [pid 843279:tid 843511] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4QtPqvKNcW5yy5T2C59gAA6Q4"], referer: http://assasalnazaha.com/WORDPRESS
[Mon Jul 20 06:12:37.970481 2026] [security2:error] [pid 858085:tid 858301] [client 34.221.76.50:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QtTAtbv2vrjByhUpsogAAAFU"]
[Mon Jul 20 06:12:37.977914 2026] [security2:error] [pid 843279:tid 843459] [client 34.221.76.50:38500] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-meatballs-in-sofrito-sauce-recipe/"] [unique_id "al4QtfqvKNcW5yy5T2C6EAAAALY"]
[Mon Jul 20 06:12:38.329794 2026] [proxy:error] [pid 858085:tid 858286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:38.329840 2026] [proxy_http:error] [pid 858085:tid 858286] [client 8.229.28.226:35608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:38.330422 2026] [proxy:error] [pid 858085:tid 858286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:38.330452 2026] [proxy_http:error] [pid 858085:tid 858286] [client 8.229.28.226:35608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:38.673968 2026] [security2:error] [pid 843279:tid 843531] [client 14.225.17.146:64684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QtvqvKNcW5yy5T2C6PAAAAP0"], referer: https://maxenengineering.com/WORDPRESS
[Mon Jul 20 06:12:38.743953 2026] [security2:error] [pid 858085:tid 858331] [client 57.141.18.20:30432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QsjAtbv2vrjByhUpsDgAAc1Y"]
[Mon Jul 20 06:12:39.017841 2026] [security2:error] [pid 843279:tid 843302] [remote 188.40.28.4:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6SgAAmRU"]
[Mon Jul 20 06:12:39.185291 2026] [security2:error] [pid 843279:tid 843439] [client 181.224.94.124:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6UAAAAKI"]
[Mon Jul 20 06:12:39.185429 2026] [security2:error] [pid 843279:tid 843439] [client 181.224.94.124:35858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6UAAAAKI"]
[Mon Jul 20 06:12:39.194535 2026] [security2:error] [pid 858085:tid 858254] [client 27.96.94.195:37947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QtzAtbv2vrjByhUptHAAAACY"]
[Mon Jul 20 06:12:39.194645 2026] [security2:error] [pid 858085:tid 858254] [client 27.96.94.195:37947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QtzAtbv2vrjByhUptHAAAACY"]
[Mon Jul 20 06:12:39.214396 2026] [security2:error] [pid 843279:tid 843333] [remote 188.40.28.4:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6UgAAyzQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:39.504085 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:63934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4QtjAtbv2vrjByhUps9AAAABM"], referer: http://massagelacey.com/WORDPRESS
[Mon Jul 20 06:12:39.663756 2026] [security2:error] [pid 858085:tid 858332] [client 57.141.18.15:44466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QszAtbv2vrjByhUpsRAAAdFc"]
[Mon Jul 20 06:12:39.764585 2026] [security2:error] [pid 858085:tid 858152] [remote 57.141.18.72:32318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5991539"] [unique_id "al4QtzAtbv2vrjByhUptNAAAD0E"]
[Mon Jul 20 06:12:39.856338 2026] [security2:error] [pid 858085:tid 858284] [client 185.132.186.87:29113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.tmb/doc.php"] [unique_id "al4QtzAtbv2vrjByhUptOwAAAEQ"]
[Mon Jul 20 06:12:40.306634 2026] [security2:error] [pid 858085:tid 858271] [client 14.225.17.146:59060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4QuDAtbv2vrjByhUptUAAAADc"], referer: http://katsklar.com/WORDPRESS
[Mon Jul 20 06:12:40.596909 2026] [security2:error] [pid 843279:tid 843464] [client 103.141.108.143:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QuPqvKNcW5yy5T2C6dQAAALs"]
[Mon Jul 20 06:12:40.597034 2026] [security2:error] [pid 843279:tid 843464] [client 103.141.108.143:60964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QuPqvKNcW5yy5T2C6dQAAALs"]
[Mon Jul 20 06:12:40.602247 2026] [fcgid:warn] [pid 858085:tid 858299] (70014)End of file found: [client 64.225.75.246:55094] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:40.813109 2026] [security2:error] [pid 843279:tid 843507] [client 17.246.19.86:58564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.suretybonds-california.com"] [uri "/index.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6ZwAAAOU"]
[Mon Jul 20 06:12:40.828449 2026] [security2:error] [pid 858085:tid 858328] [client 14.225.17.146:54932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4QtjAtbv2vrjByhUps-wAAAHA"], referer: http://worbals.com/WORDPRESS
[Mon Jul 20 06:12:40.927065 2026] [fcgid:warn] [pid 843279:tid 843467] (70014)End of file found: [client 64.225.75.246:55108] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:40.963889 2026] [security2:error] [pid 843279:tid 843438] [client 14.225.17.146:63866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6YgAAAKE"], referer: http://alchemygroup.ca/WORDPRESS
[Mon Jul 20 06:12:40.995551 2026] [security2:error] [pid 858085:tid 858217] [client 41.173.37.102:5310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QuDAtbv2vrjByhUptfgAAAAE"]
[Mon Jul 20 06:12:40.995686 2026] [security2:error] [pid 858085:tid 858217] [client 41.173.37.102:5310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QuDAtbv2vrjByhUptfgAAAAE"]
[Mon Jul 20 06:12:41.107762 2026] [security2:error] [pid 858085:tid 858247] [client 52.28.162.93:48226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4QuDAtbv2vrjByhUptfAAAAB8"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:12:41.233799 2026] [security2:error] [pid 858085:tid 858089] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptnAAAIwI"]
[Mon Jul 20 06:12:41.233952 2026] [security2:error] [pid 858085:tid 858251] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptnAAAIwI"]
[Mon Jul 20 06:12:41.327833 2026] [security2:error] [pid 858085:tid 858331] [client 14.225.17.146:63895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4QuTAtbv2vrjByhUptmgAAAHM"], referer: http://mcg.homes/WORDPRESS
[Mon Jul 20 06:12:41.467340 2026] [security2:error] [pid 858085:tid 858266] [client 50.116.65.227:49118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QuTAtbv2vrjByhUptqgAAADI"]
[Mon Jul 20 06:12:41.481764 2026] [security2:error] [pid 843279:tid 843451] [client 50.116.65.227:48340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QufqvKNcW5yy5T2C6lAAAAOo"]
[Mon Jul 20 06:12:41.511795 2026] [security2:error] [pid 843279:tid 843481] [client 45.116.69.230:57213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QufqvKNcW5yy5T2C6lQAAAMw"]
[Mon Jul 20 06:12:41.511906 2026] [security2:error] [pid 843279:tid 843481] [client 45.116.69.230:57213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QufqvKNcW5yy5T2C6lQAAAMw"]
[Mon Jul 20 06:12:41.593233 2026] [core:error] [pid 858085:tid 858234] [client 14.225.17.146:54410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:41.593253 2026] [core:error] [pid 858085:tid 858234] [client 14.225.17.146:54410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:41.704627 2026] [security2:error] [pid 843279:tid 843428] [client 104.234.53.59:46653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QufqvKNcW5yy5T2C6mgAAAJc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:41.714698 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptuwAAABE"]
[Mon Jul 20 06:12:41.714815 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptuwAAABE"]
[Mon Jul 20 06:12:41.731103 2026] [security2:error] [pid 858085:tid 858254] [client 103.153.183.69:59794] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..%ef%bc%8f..%ef%bc%8fproc/self/environ"] [unique_id "al4QuTAtbv2vrjByhUptvwAAACY"], referer: https://twitter.com/
[Mon Jul 20 06:12:41.807005 2026] [security2:error] [pid 843279:tid 843447] [client 185.132.186.80:27313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-editor.php"] [unique_id "al4QufqvKNcW5yy5T2C6nAAAAKo"]
[Mon Jul 20 06:12:41.841375 2026] [security2:error] [pid 858085:tid 858250] [client 5.35.93.45:37052] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cja.jby.mybluehost.me"] [uri "/wp-comments-post.php"] [unique_id "al4QuTAtbv2vrjByhUptwQAAACI"]
[Mon Jul 20 06:12:41.884766 2026] [security2:error] [pid 858085:tid 858250] [client 5.35.93.45:37052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "cja.jby.mybluehost.me"] [uri "/wp-comments-post.php"] [unique_id "al4QuTAtbv2vrjByhUptwQAAACI"]
[Mon Jul 20 06:12:41.895331 2026] [security2:error] [pid 858085:tid 858099] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUpt0AAAKww"]
[Mon Jul 20 06:12:41.895552 2026] [security2:error] [pid 858085:tid 858259] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUpt0AAAKww"]
[Mon Jul 20 06:12:42.140385 2026] [security2:error] [pid 858085:tid 858338] [client 57.141.18.8:55428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QtTAtbv2vrjByhUpsrgAAehg"]
[Mon Jul 20 06:12:42.576372 2026] [security2:error] [pid 858085:tid 858324] [client 14.225.17.146:63920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4QuTAtbv2vrjByhUpttwAAAGw"], referer: http://processorstudio.com/WORDPRESS
[Mon Jul 20 06:12:42.720474 2026] [security2:error] [pid 858085:tid 858260] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QujAtbv2vrjByhUpt4wAAACw"]
[Mon Jul 20 06:12:43.056848 2026] [security2:error] [pid 843279:tid 843303] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Qu_qvKNcW5yy5T2C6xQAA_hY"]
[Mon Jul 20 06:12:43.057097 2026] [security2:error] [pid 843279:tid 843532] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Qu_qvKNcW5yy5T2C6xQAA_hY"]
[Mon Jul 20 06:12:43.430787 2026] [security2:error] [pid 858085:tid 858266] [client 14.225.17.146:50766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4QuzAtbv2vrjByhUpuKQAAADI"], referer: https://processorstudio.com/WORDPRESS
[Mon Jul 20 06:12:43.492952 2026] [security2:error] [pid 858085:tid 858104] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuLwAAWRE"]
[Mon Jul 20 06:12:43.493217 2026] [security2:error] [pid 858085:tid 858305] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuLwAAWRE"]
[Mon Jul 20 06:12:43.567325 2026] [security2:error] [pid 858085:tid 858148] [remote 103.255.134.61:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QuzAtbv2vrjByhUpuNAAAXj0"]
[Mon Jul 20 06:12:43.620531 2026] [security2:error] [pid 843279:tid 843436] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Qu_qvKNcW5yy5T2C60QAAAJ8"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:12:43.624173 2026] [security2:error] [pid 858085:tid 858281] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QuzAtbv2vrjByhUpuLAAAAEE"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:12:43.626272 2026] [security2:error] [pid 858085:tid 858262] [client 14.225.17.146:54402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4QuTAtbv2vrjByhUptzQAAAC4"], referer: http://nomorewetsheets.net/WORDPRESS
[Mon Jul 20 06:12:43.657146 2026] [security2:error] [pid 858085:tid 858233] [client 13.201.64.214:65272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuOQAAABE"]
[Mon Jul 20 06:12:43.657233 2026] [security2:error] [pid 858085:tid 858233] [client 13.201.64.214:65272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuOQAAABE"]
[Mon Jul 20 06:12:43.725123 2026] [security2:error] [pid 858085:tid 858274] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QuzAtbv2vrjByhUpuEgAAADo"]
[Mon Jul 20 06:12:43.786046 2026] [security2:error] [pid 843279:tid 843469] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4QuvqvKNcW5yy5T2C6uQAAwAM"], referer: http://ardhalwafaa.com/WORDPRESS
[Mon Jul 20 06:12:43.801593 2026] [security2:error] [pid 858085:tid 858223] [client 185.132.186.85:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine-session.php"] [unique_id "al4QuzAtbv2vrjByhUpuRQAAAAc"]
[Mon Jul 20 06:12:43.962891 2026] [security2:error] [pid 843279:tid 843437] [client 57.141.18.95:36134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6WQAAoGA"]
[Mon Jul 20 06:12:44.242495 2026] [access_compat:error] [pid 843279:tid 843472] [client 64.225.75.246:55146] AH01797: client denied by server configuration: proxy:http://127.0.0.1:8080/server-status
[Mon Jul 20 06:12:44.277287 2026] [security2:error] [pid 843279:tid 843375] [remote 110.249.201.190:18292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/comments-predeadline-5pm-Nov-7-s-z.pdf"] [unique_id "al4QvPqvKNcW5yy5T2C68QAAuF4"]
[Mon Jul 20 06:12:44.455561 2026] [security2:error] [pid 858085:tid 858291] [client 57.141.18.84:29406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QtzAtbv2vrjByhUptNQAASzU"]
[Mon Jul 20 06:12:44.460973 2026] [security2:error] [pid 843279:tid 843495] [client 34.21.84.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4QvPqvKNcW5yy5T2C69gAAANo"]
[Mon Jul 20 06:12:44.567782 2026] [security2:error] [pid 858085:tid 858274] [client 34.21.84.81:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.84.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4QvDAtbv2vrjByhUpubQAAADo"]
[Mon Jul 20 06:12:44.897487 2026] [security2:error] [pid 858085:tid 858294] [client 34.21.84.81:61906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4QvDAtbv2vrjByhUpuegAAAE4"]
[Mon Jul 20 06:12:44.904076 2026] [security2:error] [pid 858085:tid 858157] [remote 103.255.134.61:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QvDAtbv2vrjByhUpuewAAKkY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:44.924858 2026] [security2:error] [pid 843279:tid 843484] [client 14.225.17.146:50376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4Qu_qvKNcW5yy5T2C63wAAAM8"], referer: http://nikkidesigns.net/WORDPRESS
[Mon Jul 20 06:12:44.953706 2026] [security2:error] [pid 858085:tid 858337] [client 57.141.18.10:62026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QuDAtbv2vrjByhUptUgAAeTM"]
[Mon Jul 20 06:12:45.196496 2026] [security2:error] [pid 858085:tid 858238] [client 34.21.84.81:51157] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4QvTAtbv2vrjByhUpuigAAABY"]
[Mon Jul 20 06:12:45.321193 2026] [security2:error] [pid 843279:tid 843497] [client 104.234.53.86:23181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QvfqvKNcW5yy5T2C7EAAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:45.468134 2026] [security2:error] [pid 858085:tid 858289] [client 34.21.84.81:57017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4QvTAtbv2vrjByhUpulQAAAEk"]
[Mon Jul 20 06:12:45.723030 2026] [security2:error] [pid 843279:tid 843471] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QvfqvKNcW5yy5T2C7CQAAAMI"]
[Mon Jul 20 06:12:45.800988 2026] [security2:error] [pid 858085:tid 858229] [client 34.21.84.81:59585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4QvTAtbv2vrjByhUpuqgAAAA0"]
[Mon Jul 20 06:12:45.949108 2026] [security2:error] [pid 843279:tid 843473] [client 13.215.47.127:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QvfqvKNcW5yy5T2C7HQAAAMQ"]
[Mon Jul 20 06:12:46.106895 2026] [security2:error] [pid 858085:tid 858286] [client 34.21.84.81:49403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4QvjAtbv2vrjByhUpuswAAAEY"]
[Mon Jul 20 06:12:46.136431 2026] [security2:error] [pid 843279:tid 843486] [client 13.201.64.214:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QvvqvKNcW5yy5T2C7IgAAANE"]
[Mon Jul 20 06:12:46.136538 2026] [security2:error] [pid 843279:tid 843486] [client 13.201.64.214:65286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QvvqvKNcW5yy5T2C7IgAAANE"]
[Mon Jul 20 06:12:46.359534 2026] [security2:error] [pid 843279:tid 843461] [client 34.21.84.81:59108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4QvvqvKNcW5yy5T2C7KwAAALg"]
[Mon Jul 20 06:12:46.527068 2026] [security2:error] [pid 858085:tid 858225] [client 14.225.17.146:54480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4QvjAtbv2vrjByhUpuzQAAAAk"]
[Mon Jul 20 06:12:46.663262 2026] [security2:error] [pid 858085:tid 858223] [client 34.21.84.81:52825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4QvjAtbv2vrjByhUpu2QAAAAc"]
[Mon Jul 20 06:12:46.679314 2026] [security2:error] [pid 858085:tid 858219] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QvjAtbv2vrjByhUpuuAAAAAM"]
[Mon Jul 20 06:12:46.715436 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:62463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4QvDAtbv2vrjByhUpudQAAADY"], referer: http://fineartsfactory.net/WORDPRESS
[Mon Jul 20 06:12:46.724431 2026] [security2:error] [pid 858085:tid 858325] [client 14.225.17.146:57123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4QvTAtbv2vrjByhUpujwAAAG0"], referer: http://709fx.com/WORDPRESS
[Mon Jul 20 06:12:46.935760 2026] [security2:error] [pid 858085:tid 858240] [client 47.129.222.11:33116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QvjAtbv2vrjByhUpu6gAAABg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:12:47.000886 2026] [security2:error] [pid 858085:tid 858226] [client 34.21.84.81:59116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4QvzAtbv2vrjByhUpu8gAAAAo"]
[Mon Jul 20 06:12:47.019576 2026] [security2:error] [pid 858085:tid 858216] [client 103.153.183.69:64728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../root/.ssh/id_rsa"] [unique_id "al4QvzAtbv2vrjByhUpu9QAAAAA"], referer: https://www.google.com/search?q=9j9c23
[Mon Jul 20 06:12:47.022612 2026] [security2:error] [pid 858085:tid 858319] [client 57.141.18.82:57388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QujAtbv2vrjByhUpt7AAAZ1g"]
[Mon Jul 20 06:12:47.120688 2026] [security2:error] [pid 858085:tid 858304] [client 103.77.203.233:52662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QvzAtbv2vrjByhUpu-QAAAFg"]
[Mon Jul 20 06:12:47.120884 2026] [security2:error] [pid 858085:tid 858304] [client 103.77.203.233:52662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QvzAtbv2vrjByhUpu-QAAAFg"]
[Mon Jul 20 06:12:47.131946 2026] [security2:error] [pid 843279:tid 843449] [client 14.225.17.146:57195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4QvfqvKNcW5yy5T2C7EgAAAKw"], referer: http://ironcitywellness.com/WORDPRESS
[Mon Jul 20 06:12:47.278488 2026] [security2:error] [pid 858085:tid 858229] [client 34.21.84.81:53578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4QvzAtbv2vrjByhUpvAgAAAA0"]
[Mon Jul 20 06:12:47.358212 2026] [cgid:error] [pid 858085:tid 858218] [client 66.132.172.182:19230] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: https://www.website-fa490990.threethirds.co:443/cgi-bin
[Mon Jul 20 06:12:47.532697 2026] [security2:error] [pid 858085:tid 858322] [client 34.21.84.81:51207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4QvzAtbv2vrjByhUpvEwAAAGo"]
[Mon Jul 20 06:12:47.555113 2026] [security2:error] [pid 858085:tid 858307] [client 57.141.18.92:53900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QujAtbv2vrjByhUpuCwAAWys"]
[Mon Jul 20 06:12:47.793942 2026] [security2:error] [pid 843279:tid 843413] [client 34.21.84.81:60912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Qv_qvKNcW5yy5T2C7QAAAAIg"]
[Mon Jul 20 06:12:48.533417 2026] [security2:error] [pid 843279:tid 843464] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7UAAAALs"]
[Mon Jul 20 06:12:48.629205 2026] [security2:error] [pid 858085:tid 858314] [client 106.192.104.4:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QwDAtbv2vrjByhUpvOAAAAGI"]
[Mon Jul 20 06:12:48.629326 2026] [security2:error] [pid 858085:tid 858314] [client 106.192.104.4:64977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QwDAtbv2vrjByhUpvOAAAAGI"]
[Mon Jul 20 06:12:48.695174 2026] [security2:error] [pid 843279:tid 843472] [client 114.119.156.209:38153] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hoomanr.com"] [uri "/robots.txt"] [unique_id "al4QwPqvKNcW5yy5T2C7XAAAAMM"], referer: http://www.hoomanr.com/robots.txt
[Mon Jul 20 06:12:48.792458 2026] [security2:error] [pid 858085:tid 858336] [client 57.141.18.8:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvDAtbv2vrjByhUpuWAAAeFQ"]
[Mon Jul 20 06:12:48.861425 2026] [security2:error] [pid 858085:tid 858155] [remote 20.173.88.122:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4QwDAtbv2vrjByhUpvRwAAbUQ"]
[Mon Jul 20 06:12:49.028791 2026] [security2:error] [pid 843279:tid 843445] [client 74.7.227.179:36704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7ZgAAqE0"], referer: https://tejasenvironmental.com/p=1271672
[Mon Jul 20 06:12:49.282851 2026] [security2:error] [pid 843279:tid 843520] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7YwAAAPI"]
[Mon Jul 20 06:12:49.471836 2026] [security2:error] [pid 843279:tid 843530] [client 57.141.18.60:62894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvPqvKNcW5yy5T2C7AgAA_BM"]
[Mon Jul 20 06:12:49.675353 2026] [security2:error] [pid 858085:tid 858225] [client 171.60.139.123:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvdgAAAAk"]
[Mon Jul 20 06:12:49.675510 2026] [security2:error] [pid 858085:tid 858225] [client 171.60.139.123:51328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvdgAAAAk"]
[Mon Jul 20 06:12:49.734416 2026] [security2:error] [pid 858085:tid 858329] [client 181.224.94.124:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvfQAAAHE"]
[Mon Jul 20 06:12:49.734589 2026] [security2:error] [pid 858085:tid 858329] [client 181.224.94.124:4273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvfQAAAHE"]
[Mon Jul 20 06:12:49.794150 2026] [fcgid:warn] [pid 858085:tid 858254] (70014)End of file found: [client 93.174.93.12:60000] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:49.804070 2026] [security2:error] [pid 858085:tid 858149] [remote 72.167.132.114:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QwTAtbv2vrjByhUpvhAAAQz4"]
[Mon Jul 20 06:12:49.883814 2026] [security2:error] [pid 858085:tid 858233] [client 57.141.18.96:22840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvTAtbv2vrjByhUpumwAAEWk"]
[Mon Jul 20 06:12:49.989671 2026] [security2:error] [pid 858085:tid 858267] [client 50.116.65.227:33236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QwTAtbv2vrjByhUpvlAAAADM"]
[Mon Jul 20 06:12:50.001128 2026] [security2:error] [pid 858085:tid 858288] [client 50.116.65.227:51092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QwTAtbv2vrjByhUpvlgAAAEg"]
[Mon Jul 20 06:12:50.137675 2026] [security2:error] [pid 858085:tid 858280] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwTAtbv2vrjByhUpvcwAAAEA"]
[Mon Jul 20 06:12:50.160545 2026] [security2:error] [pid 858085:tid 858174] [remote 72.167.132.114:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QwjAtbv2vrjByhUpvowAAH1c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:12:50.169672 2026] [security2:error] [pid 858085:tid 858229] [client 27.96.94.195:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QwjAtbv2vrjByhUpvpAAAAA0"]
[Mon Jul 20 06:12:50.169822 2026] [security2:error] [pid 858085:tid 858229] [client 27.96.94.195:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QwjAtbv2vrjByhUpvpAAAAA0"]
[Mon Jul 20 06:12:50.472268 2026] [core:error] [pid 858085:tid 858319] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.472292 2026] [core:error] [pid 858085:tid 858319] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.472945 2026] [core:error] [pid 843279:tid 843434] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.472960 2026] [core:error] [pid 843279:tid 843434] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.616302 2026] [security2:error] [pid 858085:tid 858305] [client 14.225.17.146:56377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvsQAAAFk"], referer: http://savilerowtravel.com/WORDPRESS
[Mon Jul 20 06:12:50.636635 2026] [security2:error] [pid 858085:tid 858323] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvrQAAa10"]
[Mon Jul 20 06:12:50.642161 2026] [security2:error] [pid 858085:tid 858323] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvrgAAa2c"]
[Mon Jul 20 06:12:50.731077 2026] [security2:error] [pid 858085:tid 858105] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.gitconfig"] [unique_id "al4QwjAtbv2vrjByhUpv0AAAOxI"]
[Mon Jul 20 06:12:50.731102 2026] [security2:error] [pid 858085:tid 858177] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/rclone.conf"] [unique_id "al4QwjAtbv2vrjByhUpv0QAAO1o"]
[Mon Jul 20 06:12:50.731273 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.gitconfig"] [unique_id "al4QwjAtbv2vrjByhUpv0AAAOxI"]
[Mon Jul 20 06:12:50.731339 2026] [security2:error] [pid 858085:tid 858191] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/.git/HEAD"] [unique_id "al4QwjAtbv2vrjByhUpv0gAAO2g"]
[Mon Jul 20 06:12:50.731611 2026] [security2:error] [pid 858085:tid 858199] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-json"] [unique_id "al4QwjAtbv2vrjByhUpv0wAAO3A"]
[Mon Jul 20 06:12:50.976603 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzQAAO28"]
[Mon Jul 20 06:12:50.999697 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpv1AAAOx4"]
[Mon Jul 20 06:12:51.000429 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzAAAOy8"]
[Mon Jul 20 06:12:51.014321 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzwAAOxw"]
[Mon Jul 20 06:12:51.022404 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzgAAOyw"]
[Mon Jul 20 06:12:51.080513 2026] [security2:error] [pid 843279:tid 843518] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwvqvKNcW5yy5T2C7lwAAAPA"]
[Mon Jul 20 06:12:51.129267 2026] [security2:error] [pid 858085:tid 858276] [client 185.132.186.57:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/install.php"] [unique_id "al4QwzAtbv2vrjByhUpv-wAAADw"]
[Mon Jul 20 06:12:51.211416 2026] [security2:error] [pid 858085:tid 858328] [client 57.141.18.80:43988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvzAtbv2vrjByhUpu8wAAcAg"]
[Mon Jul 20 06:12:51.369736 2026] [security2:error] [pid 858085:tid 858126] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.bak"] [unique_id "al4QwzAtbv2vrjByhUpwCgAAYic"]
[Mon Jul 20 06:12:51.369945 2026] [security2:error] [pid 858085:tid 858089] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.backup"] [unique_id "al4QwzAtbv2vrjByhUpwCQAAYgI"]
[Mon Jul 20 06:12:51.379803 2026] [security2:error] [pid 858085:tid 858219] [client 103.141.108.143:61432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwBwAAAAM"]
[Mon Jul 20 06:12:51.379946 2026] [security2:error] [pid 858085:tid 858219] [client 103.141.108.143:61432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwBwAAAAM"]
[Mon Jul 20 06:12:51.407411 2026] [security2:error] [pid 858085:tid 858279] [client 14.225.17.146:57324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwBgAAAD8"], referer: http://dasmarque.com/WORDPRESS
[Mon Jul 20 06:12:51.430245 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:56394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwBQAAAEk"], referer: http://cheesewithjam.com/WORDPRESS
[Mon Jul 20 06:12:51.450381 2026] [security2:error] [pid 843279:tid 843480] [client 57.141.18.22:62058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qv_qvKNcW5yy5T2C7NwAAy3A"]
[Mon Jul 20 06:12:51.452202 2026] [fcgid:warn] [pid 843279:tid 843476] (70014)End of file found: [client 66.132.172.109:38552] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:51.473860 2026] [security2:error] [pid 858085:tid 858163] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env"] [unique_id "al4QwzAtbv2vrjByhUpwEwAAYkw"]
[Mon Jul 20 06:12:51.549589 2026] [security2:error] [pid 858085:tid 858143] [remote 81.173.115.7:52748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QwzAtbv2vrjByhUpwGAAAVTg"]
[Mon Jul 20 06:12:51.577135 2026] [security2:error] [pid 858085:tid 858283] [client 64.225.75.246:55070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.uwannaempanada.com"] [uri "/.env"] [unique_id "al4QwzAtbv2vrjByhUpwGwAAAEM"]
[Mon Jul 20 06:12:51.621394 2026] [security2:error] [pid 858085:tid 858334] [client 14.225.17.146:65310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwFwAAAHY"], referer: http://intelligentengineeringsolutions.com/WORDPRESS
[Mon Jul 20 06:12:51.627631 2026] [security2:error] [pid 843279:tid 843534] [client 41.173.37.102:5761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qw_qvKNcW5yy5T2C7qQAAAQA"]
[Mon Jul 20 06:12:51.627813 2026] [security2:error] [pid 843279:tid 843534] [client 41.173.37.102:5761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qw_qvKNcW5yy5T2C7qQAAAQA"]
[Mon Jul 20 06:12:51.643219 2026] [security2:error] [pid 858085:tid 858231] [client 57.141.18.78:39996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvzAtbv2vrjByhUpvCAAADyM"]
[Mon Jul 20 06:12:51.662108 2026] [security2:error] [pid 858085:tid 858314] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwCAAAYnY"]
[Mon Jul 20 06:12:51.678746 2026] [security2:error] [pid 858085:tid 858292] [client 14.225.17.146:56452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwDwAAAEw"], referer: https://savilerowtravel.com/WORDPRESS
[Mon Jul 20 06:12:51.714155 2026] [security2:error] [pid 843279:tid 843512] [client 50.116.65.227:51124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Qw_qvKNcW5yy5T2C7qgAAAOo"]
[Mon Jul 20 06:12:51.725492 2026] [security2:error] [pid 843279:tid 843497] [client 50.116.65.227:51136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Qw_qvKNcW5yy5T2C7qwAAANw"]
[Mon Jul 20 06:12:51.742683 2026] [security2:error] [pid 858085:tid 858314] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwFgAAYng"]
[Mon Jul 20 06:12:51.755733 2026] [security2:error] [pid 858085:tid 858212] [remote 81.173.115.7:52748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QwzAtbv2vrjByhUpwJQAANn0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:51.774847 2026] [security2:error] [pid 858085:tid 858314] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwFAAAYig"]
[Mon Jul 20 06:12:51.817920 2026] [security2:error] [pid 858085:tid 858142] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/backend/.env"] [unique_id "al4QwzAtbv2vrjByhUpwLAAAcTc"]
[Mon Jul 20 06:12:51.819251 2026] [security2:error] [pid 858085:tid 858099] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/api/.env"] [unique_id "al4QwzAtbv2vrjByhUpwLQAAcQw"]
[Mon Jul 20 06:12:51.822361 2026] [security2:error] [pid 858085:tid 858107] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwLgAAIxQ"]
[Mon Jul 20 06:12:51.822527 2026] [security2:error] [pid 858085:tid 858251] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwLgAAIxQ"]
[Mon Jul 20 06:12:51.832243 2026] [security2:error] [pid 858085:tid 858111] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/config/.env"] [unique_id "al4QwzAtbv2vrjByhUpwMAAAcRg"]
[Mon Jul 20 06:12:51.844384 2026] [autoindex:error] [pid 843279:tid 843436] [client 151.243.11.245:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:12:52.038240 2026] [security2:error] [pid 858085:tid 858116] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.old"] [unique_id "al4QxDAtbv2vrjByhUpwPQAAcR0"]
[Mon Jul 20 06:12:52.080326 2026] [security2:error] [pid 858085:tid 858329] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwKwAAcRY"]
[Mon Jul 20 06:12:52.168411 2026] [security2:error] [pid 858085:tid 858343] [client 14.225.17.146:65375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpv3AAAAH8"], referer: http://effingweirdmuseums.com/WORDPRESS
[Mon Jul 20 06:12:52.250300 2026] [security2:error] [pid 858085:tid 858224] [client 50.116.65.227:51174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QxDAtbv2vrjByhUpwVAAAAAg"]
[Mon Jul 20 06:12:52.252494 2026] [security2:error] [pid 858085:tid 858118] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/graphql"] [unique_id "al4QxDAtbv2vrjByhUpwVQAAER8"]
[Mon Jul 20 06:12:52.261573 2026] [security2:error] [pid 858085:tid 858341] [client 50.116.65.227:51178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QxDAtbv2vrjByhUpwVgAAAH0"]
[Mon Jul 20 06:12:52.305929 2026] [security2:error] [pid 843279:tid 843471] [client 45.116.69.230:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QxPqvKNcW5yy5T2C7uQAAAMI"]
[Mon Jul 20 06:12:52.306112 2026] [security2:error] [pid 843279:tid 843471] [client 45.116.69.230:58008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QxPqvKNcW5yy5T2C7uQAAAMI"]
[Mon Jul 20 06:12:52.315551 2026] [security2:error] [pid 843279:tid 843440] [client 57.141.18.52:62650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7UQAAo0k"]
[Mon Jul 20 06:12:52.366833 2026] [security2:error] [pid 858085:tid 858275] [client 57.141.18.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwTAAAADs"]
[Mon Jul 20 06:12:52.384700 2026] [security2:error] [pid 858085:tid 858246] [client 112.213.160.112:8461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwXgAAAB4"]
[Mon Jul 20 06:12:52.384836 2026] [security2:error] [pid 858085:tid 858246] [client 112.213.160.112:8461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwXgAAAB4"]
[Mon Jul 20 06:12:52.456893 2026] [security2:error] [pid 858085:tid 858233] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwTgAAES4"]
[Mon Jul 20 06:12:52.509655 2026] [security2:error] [pid 858085:tid 858098] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwZgAAZgs"]
[Mon Jul 20 06:12:52.509897 2026] [security2:error] [pid 858085:tid 858318] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwZgAAZgs"]
[Mon Jul 20 06:12:52.534211 2026] [security2:error] [pid 858085:tid 858280] [client 14.225.17.146:65518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpv8wAAAEA"], referer: http://slutilities.com/WORDPRESS
[Mon Jul 20 06:12:52.662166 2026] [security2:error] [pid 843279:tid 843485] [client 14.225.17.146:50771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4QxPqvKNcW5yy5T2C7ugAAANA"]
[Mon Jul 20 06:12:52.851594 2026] [security2:error] [pid 858085:tid 858184] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/api/graphql"] [unique_id "al4QxDAtbv2vrjByhUpwfQAAe2E"]
[Mon Jul 20 06:12:52.874221 2026] [security2:error] [pid 858085:tid 858273] [client 178.152.178.232:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwhAAAADk"]
[Mon Jul 20 06:12:52.874346 2026] [security2:error] [pid 858085:tid 858273] [client 178.152.178.232:37707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwhAAAADk"]
[Mon Jul 20 06:12:52.948422 2026] [security2:error] [pid 843279:tid 843323] [remote 72.167.132.114:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4QxPqvKNcW5yy5T2C7zgAA2Co"]
[Mon Jul 20 06:12:53.089398 2026] [security2:error] [pid 843279:tid 843473] [client 14.225.17.146:57381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C70gAAAMQ"], referer: http://claysharecon.com/WORDPRESS
[Mon Jul 20 06:12:53.095224 2026] [security2:error] [pid 843279:tid 843459] [client 14.225.17.146:57377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4QxPqvKNcW5yy5T2C70QAAALY"], referer: https://effingweirdmuseums.com/WORDPRESS
[Mon Jul 20 06:12:53.100819 2026] [security2:error] [pid 858085:tid 858154] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.htpasswd"] [unique_id "al4QxTAtbv2vrjByhUpwkwAAe0M"]
[Mon Jul 20 06:12:53.100826 2026] [security2:error] [pid 858085:tid 858173] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.npmrc"] [unique_id "al4QxTAtbv2vrjByhUpwlQAAe1Y"]
[Mon Jul 20 06:12:53.101079 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.htpasswd"] [unique_id "al4QxTAtbv2vrjByhUpwkwAAe0M"]
[Mon Jul 20 06:12:53.101108 2026] [security2:error] [pid 858085:tid 858154] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_ed25519"] [unique_id "al4QxTAtbv2vrjByhUpwmgAAe0M"]
[Mon Jul 20 06:12:53.101178 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.npmrc"] [unique_id "al4QxTAtbv2vrjByhUpwlQAAe1Y"]
[Mon Jul 20 06:12:53.103249 2026] [security2:error] [pid 858085:tid 858145] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_rsa"] [unique_id "al4QxTAtbv2vrjByhUpwmQAAezo"]
[Mon Jul 20 06:12:53.103468 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_ed25519"] [unique_id "al4QxTAtbv2vrjByhUpwmgAAe0M"]
[Mon Jul 20 06:12:53.112868 2026] [security2:error] [pid 843279:tid 843455] [client 185.132.186.71:40319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/adminfusm.php"] [unique_id "al4QxfqvKNcW5yy5T2C71gAAALI"]
[Mon Jul 20 06:12:53.120880 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwfAAAe0Q"]
[Mon Jul 20 06:12:53.123806 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwfgAAew4"]
[Mon Jul 20 06:12:53.130977 2026] [security2:error] [pid 858085:tid 858162] [remote 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwgAAAe0s"]
[Mon Jul 20 06:12:53.279829 2026] [security2:error] [pid 843279:tid 843341] [remote 72.167.132.114:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4QxfqvKNcW5yy5T2C73gAA_jw"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:12:53.381512 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwlgAAexM"]
[Mon Jul 20 06:12:53.391343 2026] [security2:error] [pid 858085:tid 858139] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/v1/graphql"] [unique_id "al4QxTAtbv2vrjByhUpwrwAAezQ"]
[Mon Jul 20 06:12:53.401663 2026] [security2:error] [pid 858085:tid 858164] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_dsa"] [unique_id "al4QxTAtbv2vrjByhUpwswAAe00"]
[Mon Jul 20 06:12:53.414284 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwmAAAe2Y"]
[Mon Jul 20 06:12:53.491301 2026] [security2:error] [pid 858085:tid 858254] [client 14.225.17.146:63658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwAQAAACY"], referer: http://itdynamix.com/WORDPRESS
[Mon Jul 20 06:12:53.493606 2026] [security2:error] [pid 858085:tid 858179] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/id_dsa"] [unique_id "al4QxTAtbv2vrjByhUpwtwAAe1w"]
[Mon Jul 20 06:12:53.494353 2026] [security2:error] [pid 858085:tid 858138] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/id_rsa"] [unique_id "al4QxTAtbv2vrjByhUpwvAAAezM"]
[Mon Jul 20 06:12:53.521302 2026] [security2:error] [pid 858085:tid 858340] [client 14.225.17.146:65265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwMwAAAHw"], referer: http://tntcatholic.com/WORDPRESS
[Mon Jul 20 06:12:53.689058 2026] [security2:error] [pid 858085:tid 858268] [client 57.141.18.28:32002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwTAtbv2vrjByhUpvaQAANDk"]
[Mon Jul 20 06:12:53.773626 2026] [security2:error] [pid 843279:tid 843450] [client 14.225.17.146:56448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C75gAAAK0"], referer: http://falconarrowshop.com/WORDPRESS
[Mon Jul 20 06:12:53.786902 2026] [security2:error] [pid 843279:tid 843444] [client 35.90.38.209:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxfqvKNcW5yy5T2C78gAAAKc"]
[Mon Jul 20 06:12:53.884870 2026] [security2:error] [pid 843279:tid 843364] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QxfqvKNcW5yy5T2C79AAAklM"]
[Mon Jul 20 06:12:53.885042 2026] [security2:error] [pid 843279:tid 843423] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QxfqvKNcW5yy5T2C79AAAklM"]
[Mon Jul 20 06:12:54.099605 2026] [security2:error] [pid 858085:tid 858308] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwwwAAAFw"]
[Mon Jul 20 06:12:54.131023 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwsgAAe0I"]
[Mon Jul 20 06:12:54.139590 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwsAAAeyA"]
[Mon Jul 20 06:12:54.139898 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwsQAAe1E"]
[Mon Jul 20 06:12:54.192323 2026] [security2:error] [pid 843279:tid 843410] [client 103.145.233.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C7-QAAAIU"]
[Mon Jul 20 06:12:54.240557 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwuwAAe2o"]
[Mon Jul 20 06:12:54.248079 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwugAAe0E"]
[Mon Jul 20 06:12:54.262851 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwuAAAe14"]
[Mon Jul 20 06:12:54.275352 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwuQAAe2Q"]
[Mon Jul 20 06:12:54.299622 2026] [security2:error] [pid 858085:tid 858247] [client 35.90.38.209:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxjAtbv2vrjByhUpw4QAAAB8"]
[Mon Jul 20 06:12:54.334898 2026] [security2:error] [pid 858085:tid 858330] [client 57.141.18.21:31750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvogAAclU"]
[Mon Jul 20 06:12:54.350857 2026] [security2:error] [pid 858085:tid 858208] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/privatekey.key"] [unique_id "al4QxjAtbv2vrjByhUpw5gAAWXk"]
[Mon Jul 20 06:12:54.410871 2026] [security2:error] [pid 843279:tid 843427] [client 104.234.53.88:22385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QxvqvKNcW5yy5T2C8AwAAAJY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:54.443604 2026] [security2:error] [pid 858085:tid 858117] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/key.pem"] [unique_id "al4QxjAtbv2vrjByhUpw6wAAWR4"]
[Mon Jul 20 06:12:54.494421 2026] [security2:error] [pid 843279:tid 843440] [client 14.225.17.146:53861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4QxvqvKNcW5yy5T2C8AAAAAKM"], referer: https://itdynamix.com/WORDPRESS
[Mon Jul 20 06:12:54.549667 2026] [security2:error] [pid 858085:tid 858314] [client 14.225.17.146:58693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw2QAAAGI"], referer: http://mollycahill.com/WORDPRESS
[Mon Jul 20 06:12:54.603176 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw4wAAWSE"]
[Mon Jul 20 06:12:54.607637 2026] [security2:error] [pid 858085:tid 858232] [client 13.201.64.214:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QxjAtbv2vrjByhUpw9gAAABA"]
[Mon Jul 20 06:12:54.607826 2026] [security2:error] [pid 858085:tid 858232] [client 13.201.64.214:55280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QxjAtbv2vrjByhUpw9gAAABA"]
[Mon Jul 20 06:12:54.699659 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw7AAAWW8"]
[Mon Jul 20 06:12:54.719703 2026] [security2:error] [pid 858085:tid 858095] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.openclaw/.env"] [unique_id "al4QxjAtbv2vrjByhUpxAAAAWQg"]
[Mon Jul 20 06:12:54.727539 2026] [security2:error] [pid 843279:tid 843455] [client 35.90.38.209:42084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxvqvKNcW5yy5T2C8DwAAALI"]
[Mon Jul 20 06:12:54.836799 2026] [security2:error] [pid 858085:tid 858264] [client 103.153.183.69:38758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4QxjAtbv2vrjByhUpxDAAAADA"], referer: https://www.bing.com/search?q=2wt9n6
[Mon Jul 20 06:12:54.859157 2026] [security2:error] [pid 858085:tid 858325] [client 54.244.177.189:20814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxjAtbv2vrjByhUpxDQAAAG0"]
[Mon Jul 20 06:12:54.908563 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw-QAAWXs"]
[Mon Jul 20 06:12:54.921051 2026] [security2:error] [pid 858085:tid 858166] [remote 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw-wAAWU8"]
[Mon Jul 20 06:12:54.948992 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw_wAAWXw"]
[Mon Jul 20 06:12:54.960246 2026] [security2:error] [pid 858085:tid 858206] [remote 57.141.18.45:47902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4031319"] [unique_id "al4QxjAtbv2vrjByhUpxEQAAGXc"]
[Mon Jul 20 06:12:55.127073 2026] [security2:error] [pid 843279:tid 843480] [client 185.132.186.56:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/adminfusm.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8GQAAAMs"]
[Mon Jul 20 06:12:55.171953 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.94:30266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpv5QAACX8"]
[Mon Jul 20 06:12:55.530406 2026] [security2:error] [pid 858085:tid 858269] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxKwAANTc"]
[Mon Jul 20 06:12:55.651960 2026] [security2:error] [pid 858085:tid 858116] [remote 20.173.88.122:35896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4QxzAtbv2vrjByhUpxPgAALR0"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:12:55.710170 2026] [security2:error] [pid 843279:tid 843336] [remote 45.90.123.233:52382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8IgAAvzc"]
[Mon Jul 20 06:12:55.776759 2026] [security2:error] [pid 858085:tid 858109] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.hermes/.env"] [unique_id "al4QxzAtbv2vrjByhUpxRQAAThY"]
[Mon Jul 20 06:12:55.833079 2026] [security2:error] [pid 843279:tid 843521] [client 14.225.17.146:53891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8IQAAAPM"], referer: http://secretkeynumerology.com/WORDPRESS
[Mon Jul 20 06:12:55.887005 2026] [security2:error] [pid 858085:tid 858294] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxPQAATnI"]
[Mon Jul 20 06:12:55.902841 2026] [security2:error] [pid 843279:tid 843372] [remote 45.90.123.233:52382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8KQAAwls"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:56.048625 2026] [security2:error] [pid 858085:tid 858294] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxRAAATmw"]
[Mon Jul 20 06:12:56.071953 2026] [security2:error] [pid 843279:tid 843492] [client 14.225.17.146:65260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4QxvqvKNcW5yy5T2C7_gAAANc"], referer: http://aandarealtygroup.com/WORDPRESS
[Mon Jul 20 06:12:56.160987 2026] [security2:error] [pid 858085:tid 858325] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxPwAAAG0"]
[Mon Jul 20 06:12:56.278978 2026] [security2:error] [pid 858085:tid 858297] [client 57.141.18.81:47110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwLwAAUVA"]
[Mon Jul 20 06:12:56.410048 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.56:60848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qw_qvKNcW5yy5T2C7sAAAlG8"]
[Mon Jul 20 06:12:56.556603 2026] [security2:error] [pid 858085:tid 858184] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.bash_profile"] [unique_id "al4QyDAtbv2vrjByhUpxeAAAHmE"]
[Mon Jul 20 06:12:56.556818 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.bash_profile"] [unique_id "al4QyDAtbv2vrjByhUpxeAAAHmE"]
[Mon Jul 20 06:12:56.557975 2026] [security2:error] [pid 858085:tid 858150] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.mcp.json"] [unique_id "al4QyDAtbv2vrjByhUpxfAAAHj8"]
[Mon Jul 20 06:12:56.558137 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.mcp.json"] [unique_id "al4QyDAtbv2vrjByhUpxfAAAHj8"]
[Mon Jul 20 06:12:56.611862 2026] [core:error] [pid 858085:tid 858223] [client 151.243.11.245:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:56.611894 2026] [core:error] [pid 858085:tid 858223] [client 151.243.11.245:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:56.639591 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxbgAAHgc"]
[Mon Jul 20 06:12:56.736686 2026] [security2:error] [pid 858085:tid 858248] [client 57.141.18.56:60858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwWAAAIAk"]
[Mon Jul 20 06:12:56.751880 2026] [security2:error] [pid 858085:tid 858209] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mtredistricting.gov"] [uri "/wp-config.php.old"] [unique_id "al4QyDAtbv2vrjByhUpxiQAAHno"]
[Mon Jul 20 06:12:56.826812 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxewAAHkg"]
[Mon Jul 20 06:12:56.862898 2026] [security2:error] [pid 858085:tid 858247] [client 14.225.17.146:54893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxhgAAAB8"], referer: https://secretkeynumerology.com/WORDPRESS
[Mon Jul 20 06:12:56.934372 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxhQAAHhE"]
[Mon Jul 20 06:12:57.084610 2026] [security2:error] [pid 843279:tid 843399] [remote 162.19.86.63:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4QyfqvKNcW5yy5T2C8VAAArHY"]
[Mon Jul 20 06:12:57.138329 2026] [security2:error] [pid 858085:tid 858269] [client 185.132.186.60:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/js1.php"] [unique_id "al4QyTAtbv2vrjByhUpxlgAAADU"]
[Mon Jul 20 06:12:57.159657 2026] [security2:error] [pid 858085:tid 858162] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.env.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxlwAAR0s"]
[Mon Jul 20 06:12:57.166760 2026] [security2:error] [pid 858085:tid 858123] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/core/.env"] [unique_id "al4QyTAtbv2vrjByhUpxmQAAJCQ"]
[Mon Jul 20 06:12:57.179978 2026] [security2:error] [pid 858085:tid 858147] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/config.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxmAAAJDw"]
[Mon Jul 20 06:12:57.276289 2026] [security2:error] [pid 858085:tid 858139] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/config/.env.php"] [unique_id "al4QyTAtbv2vrjByhUpxnwAATDQ"]
[Mon Jul 20 06:12:57.276343 2026] [security2:error] [pid 858085:tid 858164] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/configuration.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxoAAATE0"]
[Mon Jul 20 06:12:57.277465 2026] [security2:error] [pid 858085:tid 858189] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/laravel/.env"] [unique_id "al4QyTAtbv2vrjByhUpxowAATGY"]
[Mon Jul 20 06:12:57.293985 2026] [security2:error] [pid 843279:tid 843375] [remote 162.19.86.63:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4QyfqvKNcW5yy5T2C8WQAAv14"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:12:57.501583 2026] [security2:error] [pid 858085:tid 858144] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mtredistricting.gov"] [uri "/wp-config.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxtgAATDk"]
[Mon Jul 20 06:12:57.524391 2026] [security2:error] [pid 858085:tid 858292] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxogAATBM"]
[Mon Jul 20 06:12:57.640351 2026] [security2:error] [pid 858085:tid 858190] [remote 72.167.132.114:35802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QyTAtbv2vrjByhUpxvgAAemc"]
[Mon Jul 20 06:12:57.661764 2026] [proxy:error] [pid 858085:tid 858273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:57.661862 2026] [proxy_http:error] [pid 858085:tid 858273] [client 205.210.31.154:63998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:57.662882 2026] [proxy:error] [pid 858085:tid 858273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:57.662926 2026] [proxy_http:error] [pid 858085:tid 858273] [client 205.210.31.154:63998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:57.693270 2026] [security2:error] [pid 858085:tid 858288] [client 103.77.203.233:53200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QyTAtbv2vrjByhUpxwwAAAEg"]
[Mon Jul 20 06:12:57.693469 2026] [security2:error] [pid 858085:tid 858288] [client 103.77.203.233:53200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QyTAtbv2vrjByhUpxwwAAAEg"]
[Mon Jul 20 06:12:57.751031 2026] [security2:error] [pid 858085:tid 858292] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxtQAATF8"]
[Mon Jul 20 06:12:57.864147 2026] [security2:error] [pid 858085:tid 858319] [client 104.155.181.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxvwAAAGc"]
[Mon Jul 20 06:12:57.961571 2026] [security2:error] [pid 858085:tid 858168] [remote 72.167.132.114:35802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QyTAtbv2vrjByhUpxzgAAdFE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:12:57.970774 2026] [security2:error] [pid 858085:tid 858152] [remote 114.119.145.212:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "flowmetersupply.com"] [uri "/robots.txt"] [unique_id "al4QyTAtbv2vrjByhUpx0gAAXkE"], referer: https://flowmetersupply.com/robots.txt
[Mon Jul 20 06:12:57.998830 2026] [security2:error] [pid 843279:tid 843513] [client 57.141.18.26:29636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C76AAA6yA"]
[Mon Jul 20 06:12:58.178964 2026] [security2:error] [pid 858085:tid 858108] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/web/.env"] [unique_id "al4QyjAtbv2vrjByhUpx5AAAfRU"]
[Mon Jul 20 06:12:58.179210 2026] [security2:error] [pid 858085:tid 858341] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/web/.env"] [unique_id "al4QyjAtbv2vrjByhUpx5AAAfRU"]
[Mon Jul 20 06:12:58.203632 2026] [security2:error] [pid 858085:tid 858203] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.swp"] [unique_id "al4QyjAtbv2vrjByhUpx5QAALHQ"]
[Mon Jul 20 06:12:58.204212 2026] [security2:error] [pid 858085:tid 858131] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/public/.env"] [unique_id "al4QyjAtbv2vrjByhUpx6AAALCw"]
[Mon Jul 20 06:12:58.219152 2026] [security2:error] [pid 858085:tid 858303] [client 50.116.65.227:33248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4QyjAtbv2vrjByhUpx6gAAAFc"]
[Mon Jul 20 06:12:58.230143 2026] [security2:error] [pid 843279:tid 843514] [client 50.116.65.227:51232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4QyvqvKNcW5yy5T2C8cQAAAJQ"]
[Mon Jul 20 06:12:58.308505 2026] [security2:error] [pid 858085:tid 858120] [remote 20.153.140.50:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4QyjAtbv2vrjByhUpx6wAAASE"]
[Mon Jul 20 06:12:58.384173 2026] [security2:error] [pid 843279:tid 843530] [client 57.141.18.60:22996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C79QAA_AU"]
[Mon Jul 20 06:12:58.554612 2026] [security2:error] [pid 858085:tid 858299] [client 64.225.75.246:53020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxygAAAFM"]
[Mon Jul 20 06:12:58.668028 2026] [security2:error] [pid 858085:tid 858319] [client 103.153.183.69:38758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4QyjAtbv2vrjByhUpyBAAAAGc"], referer: https://t.co/ng3pmp36x4
[Mon Jul 20 06:12:58.734587 2026] [security2:error] [pid 858085:tid 858089] [remote 20.153.140.50:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4QyjAtbv2vrjByhUpyBwAAUAI"], referer: https://pscmedicalbilling.com/wp-login.php
[Mon Jul 20 06:12:58.861979 2026] [security2:error] [pid 858085:tid 858266] [client 57.141.18.30:55530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw5wAAMmA"]
[Mon Jul 20 06:12:58.865586 2026] [security2:error] [pid 843279:tid 843501] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4QyvqvKNcW5yy5T2C8gQAAAOA"]
[Mon Jul 20 06:12:58.876359 2026] [security2:error] [pid 858085:tid 858295] [client 74.7.228.25:52850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/robots.txt"] [unique_id "al4QyjAtbv2vrjByhUpyCwAAT08"]
[Mon Jul 20 06:12:59.080079 2026] [security2:error] [pid 858085:tid 858218] [client 106.192.104.4:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QyzAtbv2vrjByhUpyLAAAAAI"]
[Mon Jul 20 06:12:59.080234 2026] [security2:error] [pid 858085:tid 858218] [client 106.192.104.4:65461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QyzAtbv2vrjByhUpyLAAAAAI"]
[Mon Jul 20 06:12:59.111918 2026] [security2:error] [pid 843279:tid 843476] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QyvqvKNcW5yy5T2C8igAAAMc"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:12:59.113508 2026] [security2:error] [pid 858085:tid 858255] [client 185.132.186.99:20761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/wp-includes/assets/script-loader-packages.min.php"] [unique_id "al4QyzAtbv2vrjByhUpyLgAAACc"]
[Mon Jul 20 06:12:59.124487 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyFwAAHEw"]
[Mon Jul 20 06:12:59.175495 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyGgAAHAo"]
[Mon Jul 20 06:12:59.230987 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyIAAAHCg"]
[Mon Jul 20 06:12:59.249109 2026] [security2:error] [pid 843279:tid 843511] [client 45.157.112.60:41909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Qy_qvKNcW5yy5T2C8kwAAAOk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:59.296895 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyKQAAHBQ"]
[Mon Jul 20 06:12:59.300743 2026] [security2:error] [pid 858085:tid 858121] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/env.js"] [unique_id "al4QyzAtbv2vrjByhUpyNQAAHCI"]
[Mon Jul 20 06:12:59.394150 2026] [security2:error] [pid 858085:tid 858259] [client 64.225.75.246:53030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyEgAAACs"]
[Mon Jul 20 06:12:59.446765 2026] [security2:error] [pid 858085:tid 858246] [client 14.225.17.146:65318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxzwAAAB4"], referer: http://dereckcastellon.com/WORDPRESS
[Mon Jul 20 06:12:59.451998 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyMAAAHA0"]
[Mon Jul 20 06:12:59.577988 2026] [security2:error] [pid 858085:tid 858128] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/api/v2/settings"] [unique_id "al4QyzAtbv2vrjByhUpyRAAAJCk"]
[Mon Jul 20 06:12:59.578205 2026] [security2:error] [pid 858085:tid 858252] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/api/v2/settings"] [unique_id "al4QyzAtbv2vrjByhUpyRAAAJCk"]
[Mon Jul 20 06:12:59.688556 2026] [security2:error] [pid 858085:tid 858135] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/manifest.webmanifest"] [unique_id "al4QyzAtbv2vrjByhUpyTAAAZDA"]
[Mon Jul 20 06:12:59.688821 2026] [security2:error] [pid 858085:tid 858316] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/manifest.webmanifest"] [unique_id "al4QyzAtbv2vrjByhUpyTAAAZDA"]
[Mon Jul 20 06:12:59.707436 2026] [security2:error] [pid 858085:tid 858197] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/api/v1/config"] [unique_id "al4QyzAtbv2vrjByhUpyUAAAZG4"]
[Mon Jul 20 06:12:59.707688 2026] [security2:error] [pid 858085:tid 858316] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/api/v1/config"] [unique_id "al4QyzAtbv2vrjByhUpyUAAAZG4"]
[Mon Jul 20 06:12:59.756454 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.116:37820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxJQAAFHg"]
[Mon Jul 20 06:12:59.879286 2026] [security2:error] [pid 858085:tid 858184] [remote 89.42.136.2:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QyzAtbv2vrjByhUpyWQAAAGE"]
[Mon Jul 20 06:12:59.919974 2026] [security2:error] [pid 858085:tid 858333] [client 14.225.17.146:56348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyHQAAAHU"], referer: http://walkingandtalking.net/WORDPRESS
[Mon Jul 20 06:12:59.921972 2026] [security2:error] [pid 858085:tid 858316] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyTQAAZCs"]
[Mon Jul 20 06:13:00.077902 2026] [security2:error] [pid 858085:tid 858343] [client 64.225.75.246:53016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxgQAAAH8"]
[Mon Jul 20 06:13:00.141672 2026] [security2:error] [pid 858085:tid 858306] [client 171.60.139.123:51975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpybwAAAFo"]
[Mon Jul 20 06:13:00.141834 2026] [security2:error] [pid 858085:tid 858306] [client 171.60.139.123:51975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpybwAAAFo"]
[Mon Jul 20 06:13:00.219323 2026] [security2:error] [pid 858085:tid 858094] [remote 89.42.136.2:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QzDAtbv2vrjByhUpycQAAOQc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:13:00.237887 2026] [security2:error] [pid 858085:tid 858337] [client 181.224.94.124:3868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpydAAAAHk"]
[Mon Jul 20 06:13:00.238004 2026] [security2:error] [pid 858085:tid 858337] [client 181.224.94.124:3868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpydAAAAHk"]
[Mon Jul 20 06:13:00.320026 2026] [security2:error] [pid 858085:tid 858279] [client 64.225.75.246:53042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpySwAAAD8"]
[Mon Jul 20 06:13:00.577566 2026] [security2:error] [pid 858085:tid 858293] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyegAATUM"]
[Mon Jul 20 06:13:00.578509 2026] [security2:error] [pid 858085:tid 858293] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpydwAATRE"]
[Mon Jul 20 06:13:00.595686 2026] [security2:error] [pid 858085:tid 858139] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/health"] [unique_id "al4QzDAtbv2vrjByhUpyiAAATTQ"]
[Mon Jul 20 06:13:00.742959 2026] [security2:error] [pid 858085:tid 858309] [client 57.141.18.11:31554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxZgAAXS4"]
[Mon Jul 20 06:13:00.793117 2026] [security2:error] [pid 858085:tid 858293] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpygwAATTw"]
[Mon Jul 20 06:13:00.869839 2026] [security2:error] [pid 858085:tid 858238] [client 66.249.64.104:37182] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "jeffjaegerlaw.com"] [uri "/robots.txt"] [unique_id "al4QzDAtbv2vrjByhUpymQAAABY"]
[Mon Jul 20 06:13:00.990858 2026] [security2:error] [pid 843279:tid 843420] [client 14.225.17.146:56186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4QzPqvKNcW5yy5T2C8wQAAAI8"], referer: https://walkingandtalking.net/WORDPRESS
[Mon Jul 20 06:13:01.041502 2026] [security2:error] [pid 858085:tid 858254] [client 185.132.186.66:30815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/blocks/file/wp-style.php"] [unique_id "al4QzTAtbv2vrjByhUpypQAAACY"]
[Mon Jul 20 06:13:01.184428 2026] [security2:error] [pid 858085:tid 858342] [client 64.225.75.246:53054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyiwAAAH4"]
[Mon Jul 20 06:13:01.266013 2026] [security2:error] [pid 858085:tid 858194] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/actuator"] [unique_id "al4QzTAtbv2vrjByhUpyuwAAAWs"]
[Mon Jul 20 06:13:01.334839 2026] [security2:error] [pid 843279:tid 843428] [client 50.116.65.227:11266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QzfqvKNcW5yy5T2C8zQAAAJc"]
[Mon Jul 20 06:13:01.346901 2026] [security2:error] [pid 843279:tid 843484] [client 50.116.65.227:11276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QzfqvKNcW5yy5T2C8zgAAAM8"]
[Mon Jul 20 06:13:01.378642 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyrQAAAVc"]
[Mon Jul 20 06:13:01.388791 2026] [security2:error] [pid 843279:tid 843518] [client 27.96.94.195:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QzfqvKNcW5yy5T2C8zwAAAPA"]
[Mon Jul 20 06:13:01.389415 2026] [security2:error] [pid 843279:tid 843518] [client 27.96.94.195:37058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QzfqvKNcW5yy5T2C8zwAAAPA"]
[Mon Jul 20 06:13:01.398962 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyqwAAARM"]
[Mon Jul 20 06:13:01.483773 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyuAAAAWk"]
[Mon Jul 20 06:13:01.511076 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyugAAAV8"]
[Mon Jul 20 06:13:01.690519 2026] [security2:error] [pid 858085:tid 858235] [client 57.141.18.62:25226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxngAAE1k"]
[Mon Jul 20 06:13:01.764788 2026] [security2:error] [pid 858085:tid 858308] [client 14.225.17.146:58054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyjAAAAFw"], referer: http://ncsynchro.com/WORDPRESS
[Mon Jul 20 06:13:02.012920 2026] [security2:error] [pid 858085:tid 858325] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyxQAAAG0"]
[Mon Jul 20 06:13:02.081828 2026] [security2:error] [pid 858085:tid 858193] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/phpinfo.php"] [unique_id "al4QzjAtbv2vrjByhUpy5QAAK2o"]
[Mon Jul 20 06:13:02.081986 2026] [security2:error] [pid 858085:tid 858259] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/phpinfo.php"] [unique_id "al4QzjAtbv2vrjByhUpy5QAAK2o"]
[Mon Jul 20 06:13:02.113852 2026] [security2:error] [pid 858085:tid 858259] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpy3gAAKx4"]
[Mon Jul 20 06:13:02.114503 2026] [security2:error] [pid 858085:tid 858298] [client 103.141.108.143:61906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy5wAAAFI"]
[Mon Jul 20 06:13:02.115027 2026] [security2:error] [pid 858085:tid 858298] [client 103.141.108.143:61906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy5wAAAFI"]
[Mon Jul 20 06:13:02.161249 2026] [security2:error] [pid 858085:tid 858198] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/actuator/mappings"] [unique_id "al4QzjAtbv2vrjByhUpy7AAABm8"]
[Mon Jul 20 06:13:02.161430 2026] [security2:error] [pid 858085:tid 858120] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/info.php"] [unique_id "al4QzjAtbv2vrjByhUpy6wAABiE"]
[Mon Jul 20 06:13:02.161505 2026] [security2:error] [pid 858085:tid 858136] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/pi.php"] [unique_id "al4QzjAtbv2vrjByhUpy6gAABjE"]
[Mon Jul 20 06:13:02.176106 2026] [security2:error] [pid 858085:tid 858299] [client 41.173.37.102:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy7QAAAFM"]
[Mon Jul 20 06:13:02.176197 2026] [security2:error] [pid 858085:tid 858299] [client 41.173.37.102:6257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy7QAAAFM"]
[Mon Jul 20 06:13:02.216236 2026] [security2:error] [pid 858085:tid 858265] [client 57.141.18.56:56482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxxgAAMU4"]
[Mon Jul 20 06:13:02.351470 2026] [security2:error] [pid 858085:tid 858126] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/test.php"] [unique_id "al4QzjAtbv2vrjByhUpy-QAAdCc"]
[Mon Jul 20 06:13:02.364975 2026] [security2:error] [pid 858085:tid 858134] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/i.php"] [unique_id "al4QzjAtbv2vrjByhUpy_AAAdC8"]
[Mon Jul 20 06:13:02.461517 2026] [security2:error] [pid 858085:tid 858206] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/app_dev.php"] [unique_id "al4QzjAtbv2vrjByhUpzAQAAdHc"]
[Mon Jul 20 06:13:02.461561 2026] [security2:error] [pid 858085:tid 858202] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/app_dev.php/_profiler"] [unique_id "al4QzjAtbv2vrjByhUpzAgAAdHM"]
[Mon Jul 20 06:13:02.579201 2026] [security2:error] [pid 858085:tid 858332] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzjAtbv2vrjByhUpy-gAAdAI"]
[Mon Jul 20 06:13:02.582408 2026] [security2:error] [pid 858085:tid 858332] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzjAtbv2vrjByhUpy-AAAdAg"]
[Mon Jul 20 06:13:02.876583 2026] [security2:error] [pid 858085:tid 858163] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpzGwAALEw"]
[Mon Jul 20 06:13:02.876767 2026] [security2:error] [pid 858085:tid 858260] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpzGwAALEw"]
[Mon Jul 20 06:13:03.016902 2026] [security2:error] [pid 858085:tid 858310] [client 185.132.186.78:64727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/mu-plugins/admin.php"] [unique_id "al4QzzAtbv2vrjByhUpzHgAAAF4"]
[Mon Jul 20 06:13:03.038536 2026] [security2:error] [pid 858085:tid 858097] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIAAAEAo"]
[Mon Jul 20 06:13:03.038740 2026] [security2:error] [pid 858085:tid 858232] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIAAAEAo"]
[Mon Jul 20 06:13:03.080227 2026] [security2:error] [pid 858085:tid 858274] [client 45.116.69.230:58680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIgAAADo"]
[Mon Jul 20 06:13:03.080407 2026] [security2:error] [pid 858085:tid 858274] [client 45.116.69.230:58680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIgAAADo"]
[Mon Jul 20 06:13:03.123563 2026] [security2:error] [pid 858085:tid 858272] [client 112.213.160.112:31030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzJAAAADg"]
[Mon Jul 20 06:13:03.123715 2026] [security2:error] [pid 858085:tid 858272] [client 112.213.160.112:31030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzJAAAADg"]
[Mon Jul 20 06:13:03.317560 2026] [proxy:error] [pid 858085:tid 858224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:13:03.317638 2026] [proxy_http:error] [pid 858085:tid 858224] [client 205.210.31.168:63658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:13:03.318062 2026] [proxy:error] [pid 858085:tid 858224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:13:03.318102 2026] [proxy_http:error] [pid 858085:tid 858224] [client 205.210.31.168:63658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:13:03.691916 2026] [security2:error] [pid 843279:tid 843469] [client 178.152.178.232:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9GwAAAMA"]
[Mon Jul 20 06:13:03.692042 2026] [security2:error] [pid 843279:tid 843469] [client 178.152.178.232:36813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9GwAAAMA"]
[Mon Jul 20 06:13:03.710568 2026] [security2:error] [pid 858085:tid 858321] [client 14.225.17.146:57088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4QzzAtbv2vrjByhUpzQgAAAGk"], referer: http://mtlegnews.gov/WORDPRESS
[Mon Jul 20 06:13:03.998035 2026] [security2:error] [pid 858085:tid 858276] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QzzAtbv2vrjByhUpzOgAAADw"]
[Mon Jul 20 06:13:04.107409 2026] [security2:error] [pid 843279:tid 843535] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9FgABATM"], referer: http://ali-alghanim.net/WORDPRESS
[Mon Jul 20 06:13:04.283139 2026] [security2:error] [pid 858085:tid 858312] [client 57.141.18.58:45276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyRgAAYC0"]
[Mon Jul 20 06:13:04.460888 2026] [security2:error] [pid 858085:tid 858245] [client 64.23.150.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.nyradigitalsolutions.com"] [uri "/index.php"] [unique_id "al4Q0DAtbv2vrjByhUpzcgAAAB0"], referer: https://mail.nyradigitalsolutions.com/
[Mon Jul 20 06:13:04.473062 2026] [security2:error] [pid 858085:tid 858094] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0DAtbv2vrjByhUpzdQAATQc"]
[Mon Jul 20 06:13:04.473309 2026] [security2:error] [pid 858085:tid 858293] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0DAtbv2vrjByhUpzdQAATQc"]
[Mon Jul 20 06:13:04.503875 2026] [security2:error] [pid 858085:tid 858265] [client 64.225.75.246:53082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.75.225.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uwannaempanada.com"] [uri "/info.php"] [unique_id "al4Q0DAtbv2vrjByhUpzeAAAADE"]
[Mon Jul 20 06:13:04.608071 2026] [security2:error] [pid 843279:tid 843412] [client 57.141.18.58:45284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qy_qvKNcW5yy5T2C8pgAAhyU"]
[Mon Jul 20 06:13:04.750033 2026] [security2:error] [pid 858085:tid 858146] [remote 182.77.62.24:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q0DAtbv2vrjByhUpziAAAGTs"]
[Mon Jul 20 06:13:04.763691 2026] [security2:error] [pid 858085:tid 858155] [remote 115.74.105.156:41726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q0DAtbv2vrjByhUpzigAAYUQ"]
[Mon Jul 20 06:13:04.799525 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.60:34964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpybAAAd0o"]
[Mon Jul 20 06:13:04.871415 2026] [security2:error] [pid 858085:tid 858298] [client 50.116.65.227:37900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q0DAtbv2vrjByhUpzlQAAAFI"]
[Mon Jul 20 06:13:04.881672 2026] [security2:error] [pid 858085:tid 858302] [client 50.116.65.227:11310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q0DAtbv2vrjByhUpzlgAAAEY"]
[Mon Jul 20 06:13:04.988509 2026] [security2:error] [pid 858085:tid 858227] [client 185.132.186.88:45747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/class-IXR-cilent.php"] [unique_id "al4Q0DAtbv2vrjByhUpzmQAAAAs"]
[Mon Jul 20 06:13:05.033826 2026] [security2:error] [pid 843279:tid 843536] [client 57.141.18.19:40632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzPqvKNcW5yy5T2C8tAABAm4"]
[Mon Jul 20 06:13:05.125573 2026] [security2:error] [pid 858085:tid 858282] [client 14.225.17.146:57128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4QzjAtbv2vrjByhUpzCAAAAEI"], referer: http://healthylifegourmet.org/WORDPRESS
[Mon Jul 20 06:13:05.182277 2026] [security2:error] [pid 858085:tid 858133] [remote 115.74.105.156:41726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q0TAtbv2vrjByhUpzpwAALC4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:13:05.310960 2026] [security2:error] [pid 858085:tid 858151] [remote 182.77.62.24:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q0TAtbv2vrjByhUpzrAAAMUA"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:13:05.383620 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.53:64364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyjgAAFE0"]
[Mon Jul 20 06:13:05.708056 2026] [security2:error] [pid 858085:tid 858258] [client 43.205.139.3:46142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0TAtbv2vrjByhUpzyAAAACo"]
[Mon Jul 20 06:13:05.708220 2026] [security2:error] [pid 858085:tid 858258] [client 43.205.139.3:46142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0TAtbv2vrjByhUpzyAAAACo"]
[Mon Jul 20 06:13:06.064402 2026] [security2:error] [pid 843279:tid 843520] [client 57.141.18.115:35408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzfqvKNcW5yy5T2C8zAAA8k0"]
[Mon Jul 20 06:13:06.215651 2026] [security2:error] [pid 858085:tid 858297] [client 14.225.17.146:56299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz2gAAAFE"], referer: http://myspineworld.com/WORDPRESS
[Mon Jul 20 06:13:06.485338 2026] [security2:error] [pid 858085:tid 858252] [client 17.241.219.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mezzacraft.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz5gAAACQ"]
[Mon Jul 20 06:13:06.529892 2026] [security2:error] [pid 843279:tid 843489] [client 57.141.18.49:50210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzfqvKNcW5yy5T2C83QAA1Bs"]
[Mon Jul 20 06:13:06.662223 2026] [security2:error] [pid 858085:tid 858286] [client 50.116.65.227:37912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q0jAtbv2vrjByhUpz_QAAAEY"]
[Mon Jul 20 06:13:06.677010 2026] [security2:error] [pid 858085:tid 858275] [client 50.116.65.227:11332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q0jAtbv2vrjByhUpz_gAAADs"]
[Mon Jul 20 06:13:06.763454 2026] [security2:error] [pid 843279:tid 843446] [client 57.141.18.85:34110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzvqvKNcW5yy5T2C85gAAqVw"]
[Mon Jul 20 06:13:06.779156 2026] [security2:error] [pid 858085:tid 858326] [client 14.225.17.146:58031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Q0TAtbv2vrjByhUpzoQAAAG4"], referer: http://lelandumc.org/WORDPRESS
[Mon Jul 20 06:13:06.939393 2026] [security2:error] [pid 858085:tid 858302] [client 17.241.227.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUp0AwAAAFY"]
[Mon Jul 20 06:13:06.960801 2026] [security2:error] [pid 858085:tid 858255] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz9gAAACc"]
[Mon Jul 20 06:13:07.229479 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:58040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0GAAAABM"], referer: https://myspineworld.com/WORDPRESS
[Mon Jul 20 06:13:07.859420 2026] [security2:error] [pid 858085:tid 858238] [client 158.173.89.95:53653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q0zAtbv2vrjByhUp0QgAAABY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:07.945480 2026] [security2:error] [pid 858085:tid 858330] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0LQAAAHI"]
[Mon Jul 20 06:13:08.052702 2026] [security2:error] [pid 843279:tid 843472] [client 57.141.18.82:25394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9GQAAwxU"]
[Mon Jul 20 06:13:08.079075 2026] [security2:error] [pid 858085:tid 858204] [remote 194.164.192.228:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q1DAtbv2vrjByhUp0TAAAfHU"]
[Mon Jul 20 06:13:08.165849 2026] [security2:error] [pid 858085:tid 858269] [client 14.225.17.146:56258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4Q0TAtbv2vrjByhUpz1gAAADU"], referer: http://latiendadejorge.com.gt/WORDPRESS
[Mon Jul 20 06:13:08.187146 2026] [security2:error] [pid 843279:tid 843436] [client 50.116.65.227:37918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q1PqvKNcW5yy5T2C9ewAAAJ8"]
[Mon Jul 20 06:13:08.197162 2026] [security2:error] [pid 843279:tid 843498] [client 50.116.65.227:11348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q1PqvKNcW5yy5T2C9fQAAAOs"]
[Mon Jul 20 06:13:08.215679 2026] [security2:error] [pid 858085:tid 858266] [client 13.201.64.214:32380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Q1DAtbv2vrjByhUp0UwAAADI"]
[Mon Jul 20 06:13:08.254935 2026] [security2:error] [pid 843279:tid 843470] [client 158.173.166.181:22245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9fwAAAME"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:08.316930 2026] [security2:error] [pid 858085:tid 858294] [client 103.77.203.233:53737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1DAtbv2vrjByhUp0VwAAAE4"]
[Mon Jul 20 06:13:08.317138 2026] [security2:error] [pid 858085:tid 858294] [client 103.77.203.233:53737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1DAtbv2vrjByhUp0VwAAAE4"]
[Mon Jul 20 06:13:08.356806 2026] [security2:error] [pid 858085:tid 858231] [client 14.225.17.146:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0IAAAAA8"]
[Mon Jul 20 06:13:08.508172 2026] [security2:error] [pid 858085:tid 858116] [remote 194.164.192.228:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q1DAtbv2vrjByhUp0XQAABh0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:13:08.736465 2026] [security2:error] [pid 858085:tid 858201] [remote 111.225.149.135:23670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2021/10/dac-commments-predeadline-july-2021.pdf"] [unique_id "al4Q1DAtbv2vrjByhUp0aQAAKnI"]
[Mon Jul 20 06:13:08.868428 2026] [security2:error] [pid 843279:tid 843528] [client 104.234.53.85:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9kwAAAPo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:09.004507 2026] [security2:error] [pid 843279:tid 843502] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9hwAAAOE"]
[Mon Jul 20 06:13:09.067726 2026] [security2:error] [pid 858085:tid 858289] [client 185.132.186.80:38953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/about/function.php%20"] [unique_id "al4Q1TAtbv2vrjByhUp0dgAAAEk"]
[Mon Jul 20 06:13:09.141770 2026] [security2:error] [pid 858085:tid 858276] [client 13.201.64.214:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Q1TAtbv2vrjByhUp0egAAADw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:13:09.274148 2026] [security2:error] [pid 858085:tid 858337] [client 14.225.17.146:58103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0QAAAAHk"], referer: http://solkeetw.com/WORDPRESS
[Mon Jul 20 06:13:09.449963 2026] [security2:error] [pid 858085:tid 858293] [client 104.28.159.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onpoint-evsolutions.com"] [uri "/wp-login.php"] [unique_id "al4Q1TAtbv2vrjByhUp0gwAAAE0"]
[Mon Jul 20 06:13:09.451853 2026] [security2:error] [pid 858085:tid 858324] [client 104.28.159.66:48311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atozgroup.biz"] [uri "/wp-login.php"] [unique_id "al4Q1TAtbv2vrjByhUp0hQAAAGw"]
[Mon Jul 20 06:13:09.912897 2026] [security2:error] [pid 843279:tid 843463] [client 50.116.65.227:35722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9oQAAALo"]
[Mon Jul 20 06:13:10.027148 2026] [security2:error] [pid 858085:tid 858230] [client 14.225.17.146:52596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4Q1TAtbv2vrjByhUp0kQAAAA4"], referer: http://backandneckpainrelieflaceychiropractor.com/WORDPRESS
[Mon Jul 20 06:13:10.572404 2026] [security2:error] [pid 843279:tid 843315] [remote 97.74.87.194:33892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9xAAAwCI"]
[Mon Jul 20 06:13:10.669375 2026] [security2:error] [pid 843279:tid 843468] [client 50.116.65.227:35734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9twAAAL8"]
[Mon Jul 20 06:13:10.797496 2026] [security2:error] [pid 858085:tid 858303] [client 171.60.139.123:52435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1jAtbv2vrjByhUp0yQAAAFc"]
[Mon Jul 20 06:13:10.797603 2026] [security2:error] [pid 858085:tid 858303] [client 171.60.139.123:52435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1jAtbv2vrjByhUp0yQAAAFc"]
[Mon Jul 20 06:13:10.804769 2026] [security2:error] [pid 843279:tid 843480] [client 181.224.94.124:19011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9ygAAAMs"]
[Mon Jul 20 06:13:10.804908 2026] [security2:error] [pid 843279:tid 843480] [client 181.224.94.124:19011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9ygAAAMs"]
[Mon Jul 20 06:13:10.827022 2026] [security2:error] [pid 858085:tid 858247] [client 57.141.18.46:23818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz7QAAH1k"]
[Mon Jul 20 06:13:10.842124 2026] [security2:error] [pid 843279:tid 843528] [client 50.116.65.227:35772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9xgAAAPo"]
[Mon Jul 20 06:13:10.925983 2026] [security2:error] [pid 858085:tid 858154] [remote 205.196.217.58:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4Q1jAtbv2vrjByhUp0zgAAXUM"]
[Mon Jul 20 06:13:10.999199 2026] [security2:error] [pid 843279:tid 843407] [remote 97.74.87.194:33892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4Q1vqvKNcW5yy5T2C90gAAk34"], referer: https://fbvrealtors.com/wp-login.php
[Mon Jul 20 06:13:11.012350 2026] [security2:error] [pid 843279:tid 843465] [client 185.132.186.94:41819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/install.php"] [unique_id "al4Q1_qvKNcW5yy5T2C90wAAALw"]
[Mon Jul 20 06:13:11.019294 2026] [security2:error] [pid 858085:tid 858228] [client 50.116.65.227:35788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Q1jAtbv2vrjByhUp0ywAAAAw"]
[Mon Jul 20 06:13:11.128978 2026] [security2:error] [pid 858085:tid 858189] [remote 205.196.217.58:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4Q1zAtbv2vrjByhUp02QAAVWY"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 06:13:11.156253 2026] [security2:error] [pid 843279:tid 843371] [remote 47.242.45.34:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.45.242.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4Q1_qvKNcW5yy5T2C91wAA7Fo"]
[Mon Jul 20 06:13:11.156472 2026] [security2:error] [pid 843279:tid 843514] [client 47.242.45.34:58194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-5ab144f7.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4Q1_qvKNcW5yy5T2C91wAA7Fo"]
[Mon Jul 20 06:13:11.183502 2026] [security2:error] [pid 858085:tid 858274] [client 106.192.104.4:49599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1zAtbv2vrjByhUp03AAAADo"]
[Mon Jul 20 06:13:11.183648 2026] [security2:error] [pid 858085:tid 858274] [client 106.192.104.4:49599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1zAtbv2vrjByhUp03AAAADo"]
[Mon Jul 20 06:13:11.623838 2026] [security2:error] [pid 843279:tid 843532] [client 114.119.152.108:54919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/grantees"] [unique_id "al4Q1_qvKNcW5yy5T2C95QAAAP4"], referer: https://adambergeron.com/grantees?topic%5B0%5D=26&topic%5B1%5D=123&topic%5B2%5D=35
[Mon Jul 20 06:13:11.666084 2026] [security2:error] [pid 843279:tid 843450] [client 57.141.18.79:29012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q0vqvKNcW5yy5T2C9YwAArWk"]
[Mon Jul 20 06:13:11.666084 2026] [security2:error] [pid 858085:tid 858157] [remote 216.73.217.138:33152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Q1zAtbv2vrjByhUp07AAALEY"]
[Mon Jul 20 06:13:11.972890 2026] [security2:error] [pid 843279:tid 843511] [client 104.234.53.64:45283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Q1_qvKNcW5yy5T2C96AAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:12.370339 2026] [security2:error] [pid 858085:tid 858269] [client 27.96.94.195:38279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1FQAAADU"]
[Mon Jul 20 06:13:12.371071 2026] [security2:error] [pid 858085:tid 858269] [client 27.96.94.195:38279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1FQAAADU"]
[Mon Jul 20 06:13:12.495416 2026] [security2:error] [pid 858085:tid 858227] [client 64.225.75.246:37856] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/"] [unique_id "al4Q2DAtbv2vrjByhUp1GAAAAAs"]
[Mon Jul 20 06:13:12.825930 2026] [security2:error] [pid 858085:tid 858252] [client 41.173.37.102:6938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KAAAACQ"]
[Mon Jul 20 06:13:12.826078 2026] [security2:error] [pid 858085:tid 858252] [client 41.173.37.102:6938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KAAAACQ"]
[Mon Jul 20 06:13:12.870410 2026] [security2:error] [pid 858085:tid 858316] [client 103.141.108.143:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KQAAAGQ"]
[Mon Jul 20 06:13:12.870967 2026] [security2:error] [pid 858085:tid 858316] [client 103.141.108.143:62386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KQAAAGQ"]
[Mon Jul 20 06:13:12.958879 2026] [security2:error] [pid 858085:tid 858256] [client 185.132.186.79:53049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/PHPMailer/xleet.php"] [unique_id "al4Q2DAtbv2vrjByhUp1LQAAACg"]
[Mon Jul 20 06:13:12.979917 2026] [fcgid:warn] [pid 843279:tid 843446] (70014)End of file found: [client 206.189.19.19:47978] mod_fcgid: can't get data from http client
[Mon Jul 20 06:13:13.229370 2026] [security2:error] [pid 843279:tid 843457] [client 103.153.183.69:13446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fvar/www/html/.env"] [unique_id "al4Q2fqvKNcW5yy5T2C-CAAAALQ"], referer: https://www.reddit.com/
[Mon Jul 20 06:13:13.496807 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.65:50370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9jwAAlAg"]
[Mon Jul 20 06:13:13.561495 2026] [security2:error] [pid 858085:tid 858274] [client 114.119.139.123:63723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.secretkeynumerology.com"] [uri "/wpautoterms/terms-and-conditions-2"] [unique_id "al4Q2TAtbv2vrjByhUp1UQAAADo"], referer: https://www.secretkeynumerology.com/wpautoterms/terms-and-conditions-2
[Mon Jul 20 06:13:13.597846 2026] [security2:error] [pid 858085:tid 858134] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1UwAAVi8"]
[Mon Jul 20 06:13:13.597994 2026] [security2:error] [pid 858085:tid 858302] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1UwAAVi8"]
[Mon Jul 20 06:13:13.609920 2026] [security2:error] [pid 843279:tid 843420] [client 103.153.183.69:13446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fvar/www/.env"] [unique_id "al4Q2fqvKNcW5yy5T2C-DwAAAI8"], referer: https://www.bing.com/search?q=u93koc
[Mon Jul 20 06:13:13.643843 2026] [security2:error] [pid 858085:tid 858087] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1VwAAaAA"]
[Mon Jul 20 06:13:13.643997 2026] [security2:error] [pid 858085:tid 858320] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1VwAAaAA"]
[Mon Jul 20 06:13:13.654146 2026] [security2:error] [pid 858085:tid 858291] [client 64.225.75.246:37872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/"] [unique_id "al4Q2TAtbv2vrjByhUp1WAAAAEs"]
[Mon Jul 20 06:13:13.793439 2026] [security2:error] [pid 858085:tid 858297] [client 112.213.160.112:8360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1aQAAAFE"]
[Mon Jul 20 06:13:13.793533 2026] [security2:error] [pid 858085:tid 858297] [client 112.213.160.112:8360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1aQAAAFE"]
[Mon Jul 20 06:13:13.813832 2026] [security2:error] [pid 858085:tid 858334] [client 45.116.69.230:59206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1bQAAAHY"]
[Mon Jul 20 06:13:13.813911 2026] [security2:error] [pid 858085:tid 858334] [client 45.116.69.230:59206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1bQAAAHY"]
[Mon Jul 20 06:13:13.894955 2026] [security2:error] [pid 843279:tid 843300] [remote 62.193.192.55:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q2fqvKNcW5yy5T2C-FAAAqxM"]
[Mon Jul 20 06:13:14.023392 2026] [security2:error] [pid 858085:tid 858241] [client 50.116.65.227:32318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4Q2jAtbv2vrjByhUp1dAAAABk"]
[Mon Jul 20 06:13:14.035044 2026] [security2:error] [pid 858085:tid 858322] [client 50.116.65.227:35814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4Q2jAtbv2vrjByhUp1dgAAAGo"]
[Mon Jul 20 06:13:14.057180 2026] [security2:error] [pid 858085:tid 858259] [client 104.234.53.90:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Q2jAtbv2vrjByhUp1eQAAACs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:14.075691 2026] [security2:error] [pid 843279:tid 843329] [remote 62.193.192.55:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q2vqvKNcW5yy5T2C-FwAAhTA"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:13:14.111263 2026] [security2:error] [pid 843279:tid 843493] [client 57.141.18.75:37972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9pQAA2HY"]
[Mon Jul 20 06:13:14.220755 2026] [security2:error] [pid 858085:tid 858309] [client 98.159.234.160:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q2jAtbv2vrjByhUp1ggAAAF0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:14.495183 2026] [security2:error] [pid 858085:tid 858294] [client 64.225.75.246:37886] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Q2jAtbv2vrjByhUp1kwAAAE4"]
[Mon Jul 20 06:13:14.544602 2026] [security2:error] [pid 858085:tid 858246] [client 57.141.18.116:52792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1TAtbv2vrjByhUp0mQAAHkk"]
[Mon Jul 20 06:13:14.748388 2026] [security2:error] [pid 843279:tid 843472] [client 57.141.18.123:35356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9uAAAw0I"]
[Mon Jul 20 06:13:14.854485 2026] [security2:error] [pid 858085:tid 858253] [client 43.156.36.169:37046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Q2jAtbv2vrjByhUp1mAAAACU"]
[Mon Jul 20 06:13:14.905709 2026] [security2:error] [pid 858085:tid 858259] [client 185.132.186.74:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/doc.php"] [unique_id "al4Q2jAtbv2vrjByhUp1pgAAACs"]
[Mon Jul 20 06:13:15.186230 2026] [security2:error] [pid 858085:tid 858342] [client 57.141.18.45:44564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1jAtbv2vrjByhUp0uAAAfls"]
[Mon Jul 20 06:13:15.586134 2026] [security2:error] [pid 843279:tid 843434] [client 64.225.75.246:37894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Q2_qvKNcW5yy5T2C-PwAAAJ0"]
[Mon Jul 20 06:13:15.906415 2026] [security2:error] [pid 843279:tid 843441] [client 57.141.18.88:61604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1_qvKNcW5yy5T2C93wAApCg"]
[Mon Jul 20 06:13:16.269956 2026] [security2:error] [pid 843279:tid 843474] [client 158.173.241.141:21283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-SwAAAMU"], referer: http://sesamegreenbeans.com/tag/Japan/
[Mon Jul 20 06:13:16.303932 2026] [security2:error] [pid 858085:tid 858237] [client 57.141.18.123:35370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1zAtbv2vrjByhUp07wAAFTk"]
[Mon Jul 20 06:13:16.666157 2026] [security2:error] [pid 843279:tid 843428] [client 65.1.132.125:18412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-WwAAAJc"]
[Mon Jul 20 06:13:16.666309 2026] [security2:error] [pid 843279:tid 843428] [client 65.1.132.125:18412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-WwAAAJc"]
[Mon Jul 20 06:13:16.810209 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.94:40812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2DAtbv2vrjByhUp1CgAAd10"]
[Mon Jul 20 06:13:16.848909 2026] [security2:error] [pid 843279:tid 843503] [client 185.132.186.56:29569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/f35_SpaceTn.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-YwAAAOI"]
[Mon Jul 20 06:13:16.954220 2026] [security2:error] [pid 858085:tid 858328] [client 50.116.65.227:32328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q3DAtbv2vrjByhUp2DwAAAHA"]
[Mon Jul 20 06:13:16.966247 2026] [security2:error] [pid 858085:tid 858224] [client 50.116.65.227:35828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q3DAtbv2vrjByhUp2EAAAAAg"]
[Mon Jul 20 06:13:17.184137 2026] [security2:error] [pid 858085:tid 858231] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "darkknightsolutions.com"] [uri "/index.php"] [unique_id "al4Q2jAtbv2vrjByhUp1owAAAA8"]
[Mon Jul 20 06:13:17.520351 2026] [security2:error] [pid 858085:tid 858238] [client 57.141.18.0:48022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2DAtbv2vrjByhUp1JQAAFiA"]
[Mon Jul 20 06:13:17.794393 2026] [security2:error] [pid 858085:tid 858179] [remote 72.167.132.114:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q3TAtbv2vrjByhUp2NwAAV1w"]
[Mon Jul 20 06:13:18.018828 2026] [security2:error] [pid 843279:tid 843468] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q3fqvKNcW5yy5T2C-cAAAAL8"]
[Mon Jul 20 06:13:18.088985 2026] [security2:error] [pid 858085:tid 858169] [remote 72.167.132.114:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q3jAtbv2vrjByhUp2QwAAXlI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:13:18.281261 2026] [security2:error] [pid 858085:tid 858218] [client 57.141.18.98:29858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2TAtbv2vrjByhUp1WgAAAl4"]
[Mon Jul 20 06:13:18.563821 2026] [autoindex:error] [pid 858085:tid 858269] [client 198.235.24.173:61874] AH01276: Cannot serve directory /home2/oejeekmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.oej.eek.mybluehost.me/
[Mon Jul 20 06:13:18.804296 2026] [security2:error] [pid 858085:tid 858324] [client 185.132.186.72:33777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/sunrise/bypass.php"] [unique_id "al4Q3jAtbv2vrjByhUp2dgAAAGw"]
[Mon Jul 20 06:13:18.913866 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3vqvKNcW5yy5T2C-kAAAAJk"]
[Mon Jul 20 06:13:18.914037 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:54286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3vqvKNcW5yy5T2C-kAAAAJk"]
[Mon Jul 20 06:13:18.990185 2026] [security2:error] [pid 858085:tid 858288] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4Q3jAtbv2vrjByhUp2fgAAAEg"], referer: https://www.google.com/
[Mon Jul 20 06:13:19.460196 2026] [security2:error] [pid 858085:tid 858263] [client 104.234.53.56:31803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Q3zAtbv2vrjByhUp2jQAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:19.588142 2026] [security2:error] [pid 858085:tid 858305] [client 57.141.18.83:42022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2jAtbv2vrjByhUp1oQAAWRY"]
[Mon Jul 20 06:13:19.705395 2026] [security2:error] [pid 858085:tid 858204] [remote 57.141.18.26:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5970053"] [unique_id "al4Q3zAtbv2vrjByhUp2owAADXU"]
[Mon Jul 20 06:13:20.094248 2026] [security2:error] [pid 843279:tid 843423] [client 57.141.18.96:41146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2_qvKNcW5yy5T2C-KwAAknA"]
[Mon Jul 20 06:13:20.610015 2026] [security2:error] [pid 858085:tid 858262] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q3zAtbv2vrjByhUp2swAAAC4"]
[Mon Jul 20 06:13:20.689993 2026] [security2:error] [pid 858085:tid 858291] [client 104.234.53.56:31803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q4DAtbv2vrjByhUp24AAAAEs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:21.031291 2026] [security2:error] [pid 858085:tid 858226] [client 57.141.18.8:43342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2zAtbv2vrjByhUp14wAACjI"]
[Mon Jul 20 06:13:21.052718 2026] [security2:error] [pid 858085:tid 858130] [remote 5.161.225.162:34938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Q4TAtbv2vrjByhUp28gAAbys"]
[Mon Jul 20 06:13:21.147015 2026] [security2:error] [pid 858085:tid 858239] [client 57.141.18.33:53096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3DAtbv2vrjByhUp16wAAFxA"]
[Mon Jul 20 06:13:21.272739 2026] [security2:error] [pid 843279:tid 843464] [client 57.141.18.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-xQAAALs"]
[Mon Jul 20 06:13:21.302657 2026] [security2:error] [pid 858085:tid 858281] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q4TAtbv2vrjByhUp28wAAAEE"]
[Mon Jul 20 06:13:21.320886 2026] [security2:error] [pid 843279:tid 843527] [client 181.224.94.124:45407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-yAAAAPk"]
[Mon Jul 20 06:13:21.321057 2026] [security2:error] [pid 843279:tid 843527] [client 181.224.94.124:45407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-yAAAAPk"]
[Mon Jul 20 06:13:21.348563 2026] [security2:error] [pid 858085:tid 858229] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3BAAAAA0"], referer: https://www.bing.com/search?q=o958a9
[Mon Jul 20 06:13:21.459466 2026] [security2:error] [pid 858085:tid 858279] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3DAAAAD8"], referer: https://www.bing.com/search?q=g2hrym
[Mon Jul 20 06:13:21.460079 2026] [security2:error] [pid 858085:tid 858246] [client 145.239.10.137:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sumnn.com"] [uri "/class.php"] [unique_id "al4Q4TAtbv2vrjByhUp3DQAAAB4"], referer: http://sumnn.com/class.php
[Mon Jul 20 06:13:21.508636 2026] [security2:error] [pid 843279:tid 843495] [client 171.60.139.123:52899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-ywAAANo"]
[Mon Jul 20 06:13:21.508815 2026] [security2:error] [pid 843279:tid 843495] [client 171.60.139.123:52899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-ywAAANo"]
[Mon Jul 20 06:13:21.559182 2026] [security2:error] [pid 858085:tid 858218] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3GAAAAAI"], referer: https://www.reddit.com/
[Mon Jul 20 06:13:21.596765 2026] [security2:error] [pid 858085:tid 858230] [client 57.141.18.113:44196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3DAtbv2vrjByhUp2BAAADko"]
[Mon Jul 20 06:13:21.661007 2026] [security2:error] [pid 858085:tid 858226] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3JAAAAAo"], referer: https://www.reddit.com/
[Mon Jul 20 06:13:21.765270 2026] [security2:error] [pid 858085:tid 858101] [remote 5.161.225.162:34938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Q4TAtbv2vrjByhUp3KgAAQg4"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:13:21.831019 2026] [security2:error] [pid 858085:tid 858313] [client 185.132.186.67:34779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/fixed.php"] [unique_id "al4Q4TAtbv2vrjByhUp3MgAAAGE"]
[Mon Jul 20 06:13:21.831458 2026] [security2:error] [pid 858085:tid 858253] [client 57.141.18.93:35044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3DAtbv2vrjByhUp2DQAAJUg"]
[Mon Jul 20 06:13:22.036408 2026] [access_compat:error] [pid 843279:tid 843442] [client 206.189.19.19:49194] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Mon Jul 20 06:13:22.300983 2026] [security2:error] [pid 843279:tid 843443] [client 106.192.104.4:50099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4vqvKNcW5yy5T2C-4gAAAKY"]
[Mon Jul 20 06:13:22.301105 2026] [security2:error] [pid 843279:tid 843443] [client 106.192.104.4:50099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4vqvKNcW5yy5T2C-4gAAAKY"]
[Mon Jul 20 06:13:22.354432 2026] [security2:error] [pid 843279:tid 843483] [client 50.116.65.227:43000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q4vqvKNcW5yy5T2C-4wAAAM4"]
[Mon Jul 20 06:13:22.365654 2026] [security2:error] [pid 843279:tid 843496] [client 50.116.65.227:52616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q4vqvKNcW5yy5T2C-5QAAANs"]
[Mon Jul 20 06:13:22.380063 2026] [core:error] [pid 843279:tid 843476] [client 181.41.206.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:22.380100 2026] [core:error] [pid 843279:tid 843476] [client 181.41.206.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:22.530162 2026] [security2:error] [pid 858085:tid 858340] [client 57.141.18.25:63932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3TAtbv2vrjByhUp2MgAAfBs"]
[Mon Jul 20 06:13:22.608140 2026] [security2:error] [pid 843279:tid 843538] [client 57.141.18.79:55706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3fqvKNcW5yy5T2C-dgABBBQ"]
[Mon Jul 20 06:13:22.613910 2026] [security2:error] [pid 843279:tid 843481] [client 57.141.18.29:31490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3fqvKNcW5yy5T2C-dQAAzHw"]
[Mon Jul 20 06:13:22.676546 2026] [security2:error] [pid 858085:tid 858276] [client 57.141.18.12:43206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3TAtbv2vrjByhUp2PAAAPDw"]
[Mon Jul 20 06:13:22.973238 2026] [security2:error] [pid 858085:tid 858301] [client 14.182.195.220:52056] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Q4jAtbv2vrjByhUp3XgAAAFU"]
[Mon Jul 20 06:13:23.463305 2026] [security2:error] [pid 858085:tid 858242] [client 41.173.37.102:7444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gAAAABo"]
[Mon Jul 20 06:13:23.463402 2026] [security2:error] [pid 858085:tid 858242] [client 41.173.37.102:7444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gAAAABo"]
[Mon Jul 20 06:13:23.475697 2026] [security2:error] [pid 843279:tid 843487] [client 27.96.94.195:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4_qvKNcW5yy5T2C_CAAAANI"]
[Mon Jul 20 06:13:23.476255 2026] [security2:error] [pid 843279:tid 843487] [client 27.96.94.195:37294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4_qvKNcW5yy5T2C_CAAAANI"]
[Mon Jul 20 06:13:23.487695 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.29:31498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3vqvKNcW5yy5T2C-jgAAlHs"]
[Mon Jul 20 06:13:23.649181 2026] [security2:error] [pid 858085:tid 858284] [client 103.141.108.143:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3jAAAAEQ"]
[Mon Jul 20 06:13:23.649493 2026] [security2:error] [pid 858085:tid 858284] [client 103.141.108.143:62867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3jAAAAEQ"]
[Mon Jul 20 06:13:23.769733 2026] [security2:error] [pid 858085:tid 858330] [client 185.132.186.83:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/themes.php"] [unique_id "al4Q4zAtbv2vrjByhUp3kQAAAHI"]
[Mon Jul 20 06:13:23.833121 2026] [security2:error] [pid 858085:tid 858302] [client 104.28.249.140:42898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adastra.love"] [uri "/graphql"] [unique_id "al4Q4zAtbv2vrjByhUp3lAAAAFY"]
[Mon Jul 20 06:13:23.889789 2026] [security2:error] [pid 858085:tid 858269] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gQAAADU"], referer: http://adastra.love/rclone.conf
[Mon Jul 20 06:13:24.236299 2026] [security2:error] [pid 858085:tid 858141] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3swAAYDY"]
[Mon Jul 20 06:13:24.236516 2026] [security2:error] [pid 858085:tid 858312] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3swAAYDY"]
[Mon Jul 20 06:13:24.271071 2026] [security2:error] [pid 858085:tid 858277] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3nwAAAD0"]
[Mon Jul 20 06:13:24.299400 2026] [security2:error] [pid 858085:tid 858294] [client 57.141.18.79:51418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3zAtbv2vrjByhUp2sAAATgo"]
[Mon Jul 20 06:13:24.344285 2026] [security2:error] [pid 843279:tid 843447] [client 104.28.249.140:42891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.env.example"] [unique_id "al4Q5PqvKNcW5yy5T2C_LAAAAKo"]
[Mon Jul 20 06:13:24.381585 2026] [security2:error] [pid 843279:tid 843439] [client 112.213.160.112:30906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5PqvKNcW5yy5T2C_LgAAAKI"]
[Mon Jul 20 06:13:24.381728 2026] [security2:error] [pid 843279:tid 843439] [client 112.213.160.112:30906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5PqvKNcW5yy5T2C_LgAAAKI"]
[Mon Jul 20 06:13:24.441436 2026] [security2:error] [pid 858085:tid 858198] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3vAAAKm8"]
[Mon Jul 20 06:13:24.441567 2026] [security2:error] [pid 858085:tid 858258] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3vAAAKm8"]
[Mon Jul 20 06:13:24.477431 2026] [security2:error] [pid 858085:tid 858303] [client 45.116.69.230:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3wQAAAFc"]
[Mon Jul 20 06:13:24.478988 2026] [security2:error] [pid 858085:tid 858303] [client 45.116.69.230:59723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3wQAAAFc"]
[Mon Jul 20 06:13:24.528111 2026] [security2:error] [pid 858085:tid 858310] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3rwAAAF4"], referer: http://adastra.love/.gitlab-ci.yml
[Mon Jul 20 06:13:24.632592 2026] [security2:error] [pid 858085:tid 858337] [client 104.28.249.140:42895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adastra.love"] [uri "/api/graphql"] [unique_id "al4Q5DAtbv2vrjByhUp3zQAAAHk"]
[Mon Jul 20 06:13:24.671798 2026] [security2:error] [pid 858085:tid 858333] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3uAAAAHU"], referer: http://adastra.love/.git/config
[Mon Jul 20 06:13:24.687666 2026] [security2:error] [pid 858085:tid 858095] [remote 192.178.4.102:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ashleystrain.com"] [uri "/"] [unique_id "al4Q5DAtbv2vrjByhUp30QAAZAg"]
[Mon Jul 20 06:13:24.776727 2026] [security2:error] [pid 858085:tid 858341] [client 57.141.18.10:52338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4DAtbv2vrjByhUp20wAAfSk"]
[Mon Jul 20 06:13:24.800361 2026] [security2:error] [pid 858085:tid 858330] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3wwAAAHI"], referer: http://adastra.love/.gitconfig
[Mon Jul 20 06:13:24.833099 2026] [security2:error] [pid 858085:tid 858288] [client 57.141.18.77:38860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4DAtbv2vrjByhUp21AAASH4"]
[Mon Jul 20 06:13:25.020858 2026] [security2:error] [pid 858085:tid 858202] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env.bak"] [unique_id "al4Q5TAtbv2vrjByhUp33gAAIHM"], referer: http://adastra.love/.env.bak
[Mon Jul 20 06:13:25.157662 2026] [security2:error] [pid 843279:tid 843515] [client 104.28.249.140:42889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adastra.love"] [uri "/v1/graphql"] [unique_id "al4Q5fqvKNcW5yy5T2C_PQAAAO0"]
[Mon Jul 20 06:13:25.249550 2026] [security2:error] [pid 843279:tid 843517] [client 57.141.18.14:42102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4PqvKNcW5yy5T2C-vwAA72c"]
[Mon Jul 20 06:13:25.319352 2026] [security2:error] [pid 843279:tid 843329] [remote 188.40.28.4:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Q5fqvKNcW5yy5T2C_QwABATA"]
[Mon Jul 20 06:13:25.329460 2026] [security2:error] [pid 858085:tid 858222] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp36QAAAAY"]
[Mon Jul 20 06:13:25.398316 2026] [security2:error] [pid 858085:tid 858315] [client 14.225.17.146:56886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp39AAAAGM"], referer: http://northbrookcpa.ca/WordPress
[Mon Jul 20 06:13:25.436957 2026] [security2:error] [pid 858085:tid 858292] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4Q5TAtbv2vrjByhUp3_AAAAEw"], referer: https://twitter.com/
[Mon Jul 20 06:13:25.587687 2026] [security2:error] [pid 843279:tid 843390] [remote 188.40.28.4:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Q5fqvKNcW5yy5T2C_SgAAvG0"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:13:25.698141 2026] [security2:error] [pid 858085:tid 858211] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env"] [unique_id "al4Q5TAtbv2vrjByhUp4FAAAN3w"], referer: http://adastra.love/.env
[Mon Jul 20 06:13:25.709071 2026] [security2:error] [pid 858085:tid 858339] [client 185.132.186.65:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/fix/bypass.php"] [unique_id "al4Q5TAtbv2vrjByhUp4FwAAAHs"]
[Mon Jul 20 06:13:25.842382 2026] [security2:error] [pid 858085:tid 858297] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp4CQAAAFE"], referer: http://adastra.love/.env.local
[Mon Jul 20 06:13:25.961209 2026] [security2:error] [pid 858085:tid 858295] [client 14.225.17.146:49180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp4HAAAAE8"], referer: http://dnsplumbing.com/WordPress
[Mon Jul 20 06:13:25.986888 2026] [security2:error] [pid 843279:tid 843432] [client 57.141.18.79:51430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-zgAAmyI"]
[Mon Jul 20 06:13:26.132501 2026] [security2:error] [pid 858085:tid 858137] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/api/.env"] [unique_id "al4Q5jAtbv2vrjByhUp4MAAASzI"], referer: http://adastra.love/api/.env
[Mon Jul 20 06:13:26.201247 2026] [security2:error] [pid 843279:tid 843523] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5fqvKNcW5yy5T2C_VQAAAPU"], referer: http://adastra.love/.env.production
[Mon Jul 20 06:13:26.284092 2026] [security2:error] [pid 858085:tid 858103] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/backend/.env"] [unique_id "al4Q5jAtbv2vrjByhUp4OAAAJhA"], referer: http://adastra.love/backend/.env
[Mon Jul 20 06:13:26.435881 2026] [security2:error] [pid 858085:tid 858118] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env.old"] [unique_id "al4Q5jAtbv2vrjByhUp4QQAAdx8"], referer: http://adastra.love/.env.old
[Mon Jul 20 06:13:26.435889 2026] [security2:error] [pid 858085:tid 858148] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env.backup"] [unique_id "al4Q5jAtbv2vrjByhUp4QgAAdz0"], referer: http://adastra.love/.env.backup
[Mon Jul 20 06:13:26.475925 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:55783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Q5vqvKNcW5yy5T2C_WAAAAIU"], referer: http://savilerowtravel.com/WordPress
[Mon Jul 20 06:13:26.785342 2026] [security2:error] [pid 858085:tid 858343] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4TAAAAH8"]
[Mon Jul 20 06:13:26.884596 2026] [security2:error] [pid 858085:tid 858300] [client 193.37.33.186:54441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "realscapetours.com"] [uri "/wp-login.php"] [unique_id "al4Q5jAtbv2vrjByhUp4ZwAAAFQ"]
[Mon Jul 20 06:13:26.919879 2026] [security2:error] [pid 858085:tid 858316] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4UwAAAGQ"], referer: http://adastra.love/admin/.env
[Mon Jul 20 06:13:27.053250 2026] [security2:error] [pid 858085:tid 858123] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/config/.env"] [unique_id "al4Q5zAtbv2vrjByhUp4cAAAHSQ"], referer: http://adastra.love/config/.env
[Mon Jul 20 06:13:27.053321 2026] [security2:error] [pid 858085:tid 858247] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4YgAAAB8"], referer: http://adastra.love/secrets.yml
[Mon Jul 20 06:13:27.235396 2026] [security2:error] [pid 843279:tid 843527] [client 104.28.249.140:42904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/firebase-adminsdk.json"] [unique_id "al4Q5_qvKNcW5yy5T2C_dQAAAPk"]
[Mon Jul 20 06:13:27.434104 2026] [security2:error] [pid 858085:tid 858267] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4gwAAADM"]
[Mon Jul 20 06:13:27.488763 2026] [security2:error] [pid 858085:tid 858335] [client 2.50.155.88:55182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.155.50.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4kQAAAHc"]
[Mon Jul 20 06:13:27.488902 2026] [security2:error] [pid 858085:tid 858335] [client 2.50.155.88:55182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4kQAAAHc"]
[Mon Jul 20 06:13:27.493297 2026] [security2:error] [pid 858085:tid 858338] [client 14.225.17.146:49454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4igAAAHo"], referer: https://savilerowtravel.com/WordPress
[Mon Jul 20 06:13:27.655836 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.107:41368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4zAtbv2vrjByhUp3bwAAHDM"]
[Mon Jul 20 06:13:27.660991 2026] [security2:error] [pid 858085:tid 858297] [client 185.132.186.53:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/category-double.php"] [unique_id "al4Q5zAtbv2vrjByhUp4oQAAAFE"]
[Mon Jul 20 06:13:27.723615 2026] [security2:error] [pid 858085:tid 858234] [client 14.225.17.146:49617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4oAAAABI"], referer: http://katsklar.com/WordPress
[Mon Jul 20 06:13:27.731417 2026] [security2:error] [pid 858085:tid 858239] [client 104.28.249.140:42936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/terraform.tfstate"] [unique_id "al4Q5zAtbv2vrjByhUp4pgAAABc"]
[Mon Jul 20 06:13:27.822376 2026] [security2:error] [pid 858085:tid 858294] [client 3.109.4.218:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4rAAAAE4"]
[Mon Jul 20 06:13:27.822485 2026] [security2:error] [pid 858085:tid 858294] [client 3.109.4.218:52820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4rAAAAE4"]
[Mon Jul 20 06:13:27.926290 2026] [security2:error] [pid 858085:tid 858276] [client 57.141.18.17:50352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gwAAPFc"]
[Mon Jul 20 06:13:27.999482 2026] [security2:error] [pid 858085:tid 858223] [client 104.28.249.140:42887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.ssh/id_ecdsa"] [unique_id "al4Q5zAtbv2vrjByhUp4vwAAAAc"]
[Mon Jul 20 06:13:27.999560 2026] [security2:error] [pid 858085:tid 858223] [client 104.28.249.140:42887] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adastra.love"] [uri "/.ssh/id_ecdsa"] [unique_id "al4Q5zAtbv2vrjByhUp4vwAAAAc"]
[Mon Jul 20 06:13:28.100718 2026] [security2:error] [pid 858085:tid 858301] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4swAAAFU"]
[Mon Jul 20 06:13:28.228345 2026] [security2:error] [pid 843279:tid 843525] [client 57.141.18.13:22616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4_qvKNcW5yy5T2C_HQAA92E"]
[Mon Jul 20 06:13:28.232096 2026] [security2:error] [pid 843279:tid 843464] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5_qvKNcW5yy5T2C_hQAAALs"], referer: http://adastra.love/.npmrc
[Mon Jul 20 06:13:28.234842 2026] [security2:error] [pid 858085:tid 858270] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4vAAAADY"], referer: http://adastra.love/.boto
[Mon Jul 20 06:13:28.260904 2026] [authz_core:error] [pid 858085:tid 858224] [client 104.28.249.140:0] AH01630: client denied by server configuration: /home3/adastrb8/public_html/.htpasswd, referer: http://adastra.love/.htpasswd
[Mon Jul 20 06:13:28.381368 2026] [security2:error] [pid 858085:tid 858230] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6DAtbv2vrjByhUp4yQAAAA4"], referer: http://adastra.love/.s3cfg
[Mon Jul 20 06:13:28.543632 2026] [security2:error] [pid 858085:tid 858131] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.ssh/id_rsa"] [unique_id "al4Q6DAtbv2vrjByhUp48gAAEyw"], referer: http://adastra.love/.ssh/id_rsa
[Mon Jul 20 06:13:28.691967 2026] [security2:error] [pid 843279:tid 843492] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_kQAAANc"], referer: http://adastra.love/.svn/entries
[Mon Jul 20 06:13:28.723834 2026] [security2:error] [pid 858085:tid 858237] [client 50.116.65.227:52676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Q6DAtbv2vrjByhUp4_gAAABU"]
[Mon Jul 20 06:13:28.733931 2026] [security2:error] [pid 843279:tid 843512] [client 50.116.65.227:52686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Q6PqvKNcW5yy5T2C_mAAAAOo"]
[Mon Jul 20 06:13:28.838727 2026] [security2:error] [pid 858085:tid 858117] [remote 173.212.252.15:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Q6DAtbv2vrjByhUp5AwAAbx4"]
[Mon Jul 20 06:13:28.866673 2026] [security2:error] [pid 843279:tid 843476] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_lgAAAMc"], referer: http://adastra.love/docker-compose.yaml
[Mon Jul 20 06:13:28.870647 2026] [security2:error] [pid 843279:tid 843436] [client 104.28.249.140:42921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/id_ed25519"] [unique_id "al4Q6PqvKNcW5yy5T2C_nAAAAJ8"]
[Mon Jul 20 06:13:28.875447 2026] [security2:error] [pid 858085:tid 858261] [client 74.208.214.194:37818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Q6DAtbv2vrjByhUp5CgAAAC0"]
[Mon Jul 20 06:13:28.882415 2026] [security2:error] [pid 858085:tid 858275] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6DAtbv2vrjByhUp49wAAADs"], referer: http://adastra.love/.ssh/id_ed25519
[Mon Jul 20 06:13:29.039659 2026] [security2:error] [pid 858085:tid 858199] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.ssh/id_dsa"] [unique_id "al4Q6TAtbv2vrjByhUp5FQAAe3A"], referer: http://adastra.love/.ssh/id_dsa
[Mon Jul 20 06:13:29.100278 2026] [security2:error] [pid 843279:tid 843438] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_nQAAAKE"]
[Mon Jul 20 06:13:29.105109 2026] [security2:error] [pid 858085:tid 858095] [remote 41.186.86.12:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5GgAAWAg"]
[Mon Jul 20 06:13:29.126968 2026] [security2:error] [pid 858085:tid 858128] [remote 173.212.252.15:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5HAAABCk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:13:29.134784 2026] [security2:error] [pid 858085:tid 858292] [client 114.119.142.140:33037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zonemist.com"] [uri "/wp-content/uploads/2020/04/Untitled.001.jpeg"] [unique_id "al4Q6TAtbv2vrjByhUp5HgAAAEw"], referer: https://www.zonemist.com/zonemist-generators/sea-water-anolyte-generators/
[Mon Jul 20 06:13:29.244169 2026] [security2:error] [pid 858085:tid 858318] [client 104.234.53.52:25105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Q6TAtbv2vrjByhUp5IAAAAGY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:29.325203 2026] [security2:error] [pid 858085:tid 858323] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5GQAAAGs"], referer: http://adastra.love/.ssh/authorized_keys
[Mon Jul 20 06:13:29.487151 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.34:44100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp34AAAFAI"]
[Mon Jul 20 06:13:29.494140 2026] [security2:error] [pid 858085:tid 858248] [client 103.77.203.233:54829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6TAtbv2vrjByhUp5PQAAACA"]
[Mon Jul 20 06:13:29.494422 2026] [security2:error] [pid 858085:tid 858248] [client 103.77.203.233:54829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6TAtbv2vrjByhUp5PQAAACA"]
[Mon Jul 20 06:13:29.583858 2026] [security2:error] [pid 858085:tid 858284] [client 57.141.18.94:61582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp36gAARH8"]
[Mon Jul 20 06:13:29.606598 2026] [security2:error] [pid 858085:tid 858274] [client 185.132.186.70:47481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/admin.php"] [unique_id "al4Q6TAtbv2vrjByhUp5SgAAADo"]
[Mon Jul 20 06:13:29.679603 2026] [security2:error] [pid 843279:tid 843518] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6fqvKNcW5yy5T2C_rAAAAPA"], referer: http://adastra.love/.ssh/config
[Mon Jul 20 06:13:29.696533 2026] [security2:error] [pid 858085:tid 858091] [remote 41.186.86.12:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5TwAAUgQ"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:13:29.708998 2026] [security2:error] [pid 858085:tid 858280] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5NAAAAEA"], referer: http://adastra.love/server.key
[Mon Jul 20 06:13:29.715200 2026] [security2:error] [pid 858085:tid 858096] [remote 45.90.123.233:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5UQAAHQk"]
[Mon Jul 20 06:13:29.773948 2026] [security2:error] [pid 858085:tid 858289] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5QQAAAEk"], referer: http://adastra.love/.ssh/known_hosts
[Mon Jul 20 06:13:29.847946 2026] [security2:error] [pid 858085:tid 858288] [client 206.189.19.19:60818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/.env"] [unique_id "al4Q6TAtbv2vrjByhUp5WQAAAEg"]
[Mon Jul 20 06:13:29.870160 2026] [security2:error] [pid 858085:tid 858272] [client 104.234.53.52:25105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5WgAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:29.947119 2026] [security2:error] [pid 858085:tid 858211] [remote 45.90.123.233:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5XwAATnw"], referer: https://709fx.com/wp-login.php
[Mon Jul 20 06:13:29.960454 2026] [security2:error] [pid 858085:tid 858217] [client 104.28.249.140:42932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/ssl/server.key"] [unique_id "al4Q6TAtbv2vrjByhUp5YAAAAAE"]
[Mon Jul 20 06:13:30.004831 2026] [security2:error] [pid 843279:tid 843446] [client 14.225.17.146:56953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_oQAAAKk"], referer: http://travelbyfire.com/WordPress
[Mon Jul 20 06:13:30.073602 2026] [security2:error] [pid 858085:tid 858145] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/id_dsa"] [unique_id "al4Q6jAtbv2vrjByhUp5ZwAALDo"], referer: http://adastra.love/id_dsa
[Mon Jul 20 06:13:30.073760 2026] [security2:error] [pid 858085:tid 858188] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/id_rsa"] [unique_id "al4Q6jAtbv2vrjByhUp5aAAALGU"], referer: http://adastra.love/id_rsa
[Mon Jul 20 06:13:30.091681 2026] [ssl:error] [pid 858085:tid 858237] [client 104.48.69.105:42316] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:13:30.163386 2026] [autoindex:error] [pid 858085:tid 858235] [client 66.249.89.7:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:13:30.403135 2026] [security2:error] [pid 858085:tid 858286] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5bQAAAEY"], referer: http://adastra.love/id_ecdsa
[Mon Jul 20 06:13:30.541871 2026] [security2:error] [pid 858085:tid 858292] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5fgAAAEw"], referer: http://adastra.love/localhost.key
[Mon Jul 20 06:13:30.552083 2026] [security2:error] [pid 858085:tid 858277] [client 104.28.249.140:42908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.openclaw/openclaw.json"] [unique_id "al4Q6jAtbv2vrjByhUp5jQAAAD0"]
[Mon Jul 20 06:13:30.553825 2026] [security2:error] [pid 858085:tid 858197] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/key.pem"] [unique_id "al4Q6jAtbv2vrjByhUp5jgAAa24"], referer: http://adastra.love/key.pem
[Mon Jul 20 06:13:30.603775 2026] [security2:error] [pid 858085:tid 858268] [client 57.141.18.12:22448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4NAAANGE"]
[Mon Jul 20 06:13:30.678495 2026] [security2:error] [pid 858085:tid 858234] [client 14.225.17.146:49632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5JwAAABI"], referer: http://goyalsatyam.com/WordPress
[Mon Jul 20 06:13:30.710954 2026] [security2:error] [pid 858085:tid 858240] [client 57.141.18.53:22252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4OQAAGHg"]
[Mon Jul 20 06:13:30.911083 2026] [security2:error] [pid 858085:tid 858319] [client 104.28.249.140:42501] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/.hermes/.env"] [unique_id "al4Q6jAtbv2vrjByhUp5rQAAAGc"]
[Mon Jul 20 06:13:31.006776 2026] [security2:error] [pid 858085:tid 858248] [client 14.225.17.146:52632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5rwAAACA"], referer: https://travelbyfire.com/WordPress
[Mon Jul 20 06:13:31.021815 2026] [security2:error] [pid 843279:tid 843484] [client 14.225.17.146:49531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4Q6fqvKNcW5yy5T2C_pgAAAM8"], referer: http://soloceos.com/WordPress
[Mon Jul 20 06:13:31.032021 2026] [security2:error] [pid 858085:tid 858232] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5oAAAABA"], referer: http://adastra.love/host.key
[Mon Jul 20 06:13:31.059879 2026] [security2:error] [pid 858085:tid 858292] [client 50.116.65.227:31520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q6zAtbv2vrjByhUp5ugAAAEw"]
[Mon Jul 20 06:13:31.074849 2026] [security2:error] [pid 858085:tid 858277] [client 50.116.65.227:47514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q6zAtbv2vrjByhUp5vgAAAD0"]
[Mon Jul 20 06:13:31.118157 2026] [security2:error] [pid 858085:tid 858231] [client 104.28.249.140:42918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/.codex/config.toml"] [unique_id "al4Q6zAtbv2vrjByhUp5xAAAAA8"]
[Mon Jul 20 06:13:31.201046 2026] [security2:error] [pid 858085:tid 858176] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/privatekey.key"] [unique_id "al4Q6zAtbv2vrjByhUp5zAAAe1k"], referer: http://adastra.love/privatekey.key
[Mon Jul 20 06:13:31.352071 2026] [security2:error] [pid 858085:tid 858104] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.openclaw/.env"] [unique_id "al4Q6zAtbv2vrjByhUp51wAAexE"], referer: http://adastra.love/.openclaw/.env
[Mon Jul 20 06:13:31.372015 2026] [security2:error] [pid 843279:tid 843430] [client 103.153.183.69:4880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..%ef%bc%8f..%ef%bc%8fvar/www/html/wp-config.php"] [unique_id "al4Q6_qvKNcW5yy5T2C_0gAAAJk"], referer: https://www.bing.com/search?q=fct02d
[Mon Jul 20 06:13:31.392803 2026] [security2:error] [pid 858085:tid 858225] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp5vQAAAAk"], referer: http://adastra.love/private-key
[Mon Jul 20 06:13:31.445901 2026] [security2:error] [pid 858085:tid 858222] [client 14.225.17.146:60111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5NQAAAAY"], referer: http://areitoproducciones.com/WordPress
[Mon Jul 20 06:13:31.545841 2026] [security2:error] [pid 858085:tid 858337] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp50AAAAHk"], referer: http://adastra.love/ssl/localhost.key
[Mon Jul 20 06:13:31.549290 2026] [security2:error] [pid 858085:tid 858287] [client 185.132.186.103:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/blog/signatur.php"] [unique_id "al4Q6zAtbv2vrjByhUp53wAAAEc"]
[Mon Jul 20 06:13:31.696100 2026] [security2:error] [pid 858085:tid 858280] [client 74.208.214.194:37824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Q6zAtbv2vrjByhUp57gAAAEA"]
[Mon Jul 20 06:13:31.896129 2026] [security2:error] [pid 858085:tid 858340] [client 181.224.94.124:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6zAtbv2vrjByhUp6AwAAAHw"]
[Mon Jul 20 06:13:31.896254 2026] [security2:error] [pid 858085:tid 858340] [client 181.224.94.124:29152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6zAtbv2vrjByhUp6AwAAAHw"]
[Mon Jul 20 06:13:31.926236 2026] [security2:error] [pid 858085:tid 858288] [client 46.110.96.34:20248] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4Q6zAtbv2vrjByhUp6BQAAAEg"]
[Mon Jul 20 06:13:32.027710 2026] [security2:error] [pid 858085:tid 858219] [client 57.141.18.43:29940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4qQAAA0Y"]
[Mon Jul 20 06:13:32.032889 2026] [security2:error] [pid 858085:tid 858328] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp58wAAAHA"], referer: http://adastra.love/.aider.conf.yml
[Mon Jul 20 06:13:32.153669 2026] [security2:error] [pid 858085:tid 858249] [client 171.60.139.123:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7DAtbv2vrjByhUp6EQAAACE"]
[Mon Jul 20 06:13:32.153794 2026] [security2:error] [pid 858085:tid 858249] [client 171.60.139.123:53372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7DAtbv2vrjByhUp6EQAAACE"]
[Mon Jul 20 06:13:32.154032 2026] [security2:error] [pid 843279:tid 843524] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q6_qvKNcW5yy5T2C_4QAAAPY"]
[Mon Jul 20 06:13:32.169610 2026] [security2:error] [pid 843279:tid 843525] [client 104.234.53.55:44955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q7PqvKNcW5yy5T2C_6QAAAPc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:32.635136 2026] [security2:error] [pid 843279:tid 843479] [client 104.28.249.140:15606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adastra.love"] [uri "/wp-config.php.bak"] [unique_id "al4Q7PqvKNcW5yy5T2C_8gAAAMo"]
[Mon Jul 20 06:13:32.721473 2026] [security2:error] [pid 843279:tid 843435] [client 14.225.17.146:55156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Q7PqvKNcW5yy5T2C_8AAAAJ4"], referer: http://tntcatholic.com/WordPress
[Mon Jul 20 06:13:32.755328 2026] [security2:error] [pid 858085:tid 858269] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7DAtbv2vrjByhUp6JAAAADU"], referer: http://adastra.love/.hermes/config.yaml
[Mon Jul 20 06:13:32.902237 2026] [security2:error] [pid 843279:tid 843359] [remote 123.207.84.151:34124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.84.207.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4Q7PqvKNcW5yy5T2C_9wAAhk4"]
[Mon Jul 20 06:13:32.922480 2026] [security2:error] [pid 858085:tid 858334] [client 37.139.53.5:52058] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7DAtbv2vrjByhUp6QwAAAHY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:32.922589 2026] [security2:error] [pid 858085:tid 858334] [client 37.139.53.5:52058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7DAtbv2vrjByhUp6QwAAAHY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:32.968415 2026] [security2:error] [pid 843279:tid 843463] [client 57.141.18.20:28814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_oAAAujw"]
[Mon Jul 20 06:13:32.982024 2026] [security2:error] [pid 843279:tid 843482] [client 104.28.249.140:15608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adastra.love"] [uri "/wp-config.php.old"] [unique_id "al4Q7PqvKNcW5yy5T2C_-QAAAM0"]
[Mon Jul 20 06:13:33.164745 2026] [security2:error] [pid 858085:tid 858230] [client 106.192.104.4:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7TAtbv2vrjByhUp6VQAAAA4"]
[Mon Jul 20 06:13:33.164923 2026] [security2:error] [pid 858085:tid 858230] [client 106.192.104.4:50596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7TAtbv2vrjByhUp6VQAAAA4"]
[Mon Jul 20 06:13:33.211923 2026] [core:error] [pid 858085:tid 858325] [client 14.225.17.146:63338] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WordPress
[Mon Jul 20 06:13:33.211950 2026] [core:error] [pid 858085:tid 858325] [client 14.225.17.146:63338] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WordPress
[Mon Jul 20 06:13:33.220589 2026] [security2:error] [pid 843279:tid 843449] [client 77.75.76.161:13377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jmq.beb.mybluehost.me"] [uri "/website_9cef8506/category/news/"] [unique_id "al4Q7fqvKNcW5yy5T2DABAAAAKw"]
[Mon Jul 20 06:13:33.220717 2026] [security2:error] [pid 843279:tid 843449] [client 77.75.76.161:13377] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jmq.beb.mybluehost.me"] [uri "/website_9cef8506/category/news/"] [unique_id "al4Q7fqvKNcW5yy5T2DABAAAAKw"]
[Mon Jul 20 06:13:33.265626 2026] [security2:error] [pid 858085:tid 858165] [remote 110.249.202.3:21034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/meeting-info/"] [unique_id "al4Q7TAtbv2vrjByhUp6XAAASE4"]
[Mon Jul 20 06:13:33.346010 2026] [security2:error] [pid 843279:tid 843534] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7fqvKNcW5yy5T2C__wAAAQA"], referer: http://adastra.love/.bashrc
[Mon Jul 20 06:13:33.381024 2026] [security2:error] [pid 843279:tid 843377] [remote 123.207.84.151:34124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.84.207.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4Q7fqvKNcW5yy5T2DABwAA42A"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:13:33.454963 2026] [security2:error] [pid 858085:tid 858272] [client 104.28.249.140:42929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/storage/logs/laravel.log"] [unique_id "al4Q7TAtbv2vrjByhUp6aQAAADg"]
[Mon Jul 20 06:13:33.455072 2026] [security2:error] [pid 858085:tid 858272] [client 104.28.249.140:42929] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adastra.love"] [uri "/storage/logs/laravel.log"] [unique_id "al4Q7TAtbv2vrjByhUp6aQAAADg"]
[Mon Jul 20 06:13:33.475366 2026] [security2:error] [pid 858085:tid 858258] [client 185.132.186.66:35671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/db.php"] [unique_id "al4Q7TAtbv2vrjByhUp6awAAACo"]
[Mon Jul 20 06:13:33.530650 2026] [security2:error] [pid 858085:tid 858332] [client 104.28.249.140:42913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/.env.php.bak"] [unique_id "al4Q7TAtbv2vrjByhUp6bQAAAHQ"]
[Mon Jul 20 06:13:33.675603 2026] [security2:error] [pid 858085:tid 858214] [remote 188.166.241.141:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Q7TAtbv2vrjByhUp6fwAAPH8"]
[Mon Jul 20 06:13:33.723551 2026] [security2:error] [pid 843279:tid 843526] [client 104.28.249.140:21557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/config/.env.php"] [unique_id "al4Q7fqvKNcW5yy5T2DAFgAAAPg"]
[Mon Jul 20 06:13:33.877203 2026] [security2:error] [pid 858085:tid 858333] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6eAAAAHU"], referer: http://adastra.love/.bash_profile
[Mon Jul 20 06:13:33.878479 2026] [security2:error] [pid 843279:tid 843439] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7fqvKNcW5yy5T2DAEQAAAKI"], referer: http://adastra.love/.zshrc
[Mon Jul 20 06:13:34.065684 2026] [security2:error] [pid 858085:tid 858209] [remote 188.166.241.141:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Q7jAtbv2vrjByhUp6oAAAC3o"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:13:34.092855 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.13:22180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5fAAABTI"]
[Mon Jul 20 06:13:34.093030 2026] [security2:error] [pid 858085:tid 858338] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6kAAAAHo"], referer: http://adastra.love/.profile
[Mon Jul 20 06:13:34.121805 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:7898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ogAAACU"]
[Mon Jul 20 06:13:34.121912 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:7898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ogAAACU"]
[Mon Jul 20 06:13:34.122332 2026] [security2:error] [pid 858085:tid 858238] [client 170.199.228.120:16191] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ngAAABY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:34.140965 2026] [security2:error] [pid 843279:tid 843499] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q7fqvKNcW5yy5T2DAIAAAAN4"]
[Mon Jul 20 06:13:34.146199 2026] [security2:error] [pid 858085:tid 858313] [client 132.145.20.138:0] ModSecurity: Warning. Matched phrase "Scanbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6gQAAAGE"]
[Mon Jul 20 06:13:34.147895 2026] [security2:error] [pid 858085:tid 858327] [client 132.145.20.138:56152] ModSecurity: Warning. Matched phrase "Scanbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whiteoutcb.com"] [uri "/"] [unique_id "al4Q7TAtbv2vrjByhUp6ewAAAG8"]
[Mon Jul 20 06:13:34.161046 2026] [security2:error] [pid 843279:tid 843365] [remote 154.66.198.148:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Q7vqvKNcW5yy5T2DAKAAA0lQ"]
[Mon Jul 20 06:13:34.177704 2026] [security2:error] [pid 858085:tid 858263] [client 14.225.17.146:53148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp59QAAAC8"], referer: http://talknutritionwithlesley.com/WordPress
[Mon Jul 20 06:13:34.197884 2026] [security2:error] [pid 858085:tid 858267] [client 104.28.249.140:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/configuration.php.bak"] [unique_id "al4Q7jAtbv2vrjByhUp6qQAAADM"]
[Mon Jul 20 06:13:34.283223 2026] [security2:error] [pid 843279:tid 843525] [client 103.141.108.143:63350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7vqvKNcW5yy5T2DALgAAAPc"]
[Mon Jul 20 06:13:34.284210 2026] [security2:error] [pid 858085:tid 858233] [client 198.44.157.34:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6sQAAABE"]
[Mon Jul 20 06:13:34.284293 2026] [security2:error] [pid 858085:tid 858233] [client 198.44.157.34:46394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6sQAAABE"]
[Mon Jul 20 06:13:34.284434 2026] [security2:error] [pid 843279:tid 843525] [client 103.141.108.143:63350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7vqvKNcW5yy5T2DALgAAAPc"]
[Mon Jul 20 06:13:34.315258 2026] [security2:error] [pid 858085:tid 858160] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/core/.env"] [unique_id "al4Q7jAtbv2vrjByhUp6tgAAIEk"], referer: http://adastra.love/core/.env
[Mon Jul 20 06:13:34.440943 2026] [security2:error] [pid 858085:tid 858284] [client 104.28.249.140:21563] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/.env.swp"] [unique_id "al4Q7jAtbv2vrjByhUp6wQAAAEQ"]
[Mon Jul 20 06:13:34.441886 2026] [security2:error] [pid 858085:tid 858259] [client 104.28.249.140:21575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/config.php.bak"] [unique_id "al4Q7jAtbv2vrjByhUp6wgAAACs"]
[Mon Jul 20 06:13:34.467699 2026] [security2:error] [pid 858085:tid 858135] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/laravel/.env"] [unique_id "al4Q7jAtbv2vrjByhUp6xgAAYzA"], referer: http://adastra.love/laravel/.env
[Mon Jul 20 06:13:34.599796 2026] [security2:error] [pid 858085:tid 858238] [client 170.199.228.120:16191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ngAAABY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:34.599841 2026] [security2:error] [pid 858085:tid 858238] [client 170.199.228.120:16191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ngAAABY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:34.716535 2026] [security2:error] [pid 858085:tid 858184] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp61wAAHmE"]
[Mon Jul 20 06:13:34.716759 2026] [security2:error] [pid 858085:tid 858246] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp61wAAHmE"]
[Mon Jul 20 06:13:34.792810 2026] [security2:error] [pid 858085:tid 858326] [client 57.141.18.49:52564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5qwAAbko"]
[Mon Jul 20 06:13:34.935934 2026] [security2:error] [pid 858085:tid 858286] [client 57.141.18.78:26204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp5tgAARks"]
[Mon Jul 20 06:13:35.000793 2026] [security2:error] [pid 858085:tid 858253] [client 112.213.160.112:8253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp65QAAACU"]
[Mon Jul 20 06:13:35.000906 2026] [security2:error] [pid 858085:tid 858253] [client 112.213.160.112:8253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp65QAAACU"]
[Mon Jul 20 06:13:35.067709 2026] [security2:error] [pid 858085:tid 858249] [client 206.189.19.19:60842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q7jAtbv2vrjByhUp64AAAACE"]
[Mon Jul 20 06:13:35.112284 2026] [security2:error] [pid 858085:tid 858103] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66gAAIBA"]
[Mon Jul 20 06:13:35.112416 2026] [security2:error] [pid 858085:tid 858248] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66gAAIBA"]
[Mon Jul 20 06:13:35.122377 2026] [security2:error] [pid 858085:tid 858292] [client 45.116.69.230:60240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66wAAAEw"]
[Mon Jul 20 06:13:35.122475 2026] [security2:error] [pid 858085:tid 858292] [client 45.116.69.230:60240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66wAAAEw"]
[Mon Jul 20 06:13:35.357576 2026] [security2:error] [pid 843279:tid 843352] [remote 154.66.198.148:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Q7_qvKNcW5yy5T2DASwAAkEc"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:13:35.420158 2026] [security2:error] [pid 858085:tid 858257] [client 185.132.186.88:21119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/security.php"] [unique_id "al4Q7zAtbv2vrjByhUp7AQAAACk"]
[Mon Jul 20 06:13:35.612907 2026] [security2:error] [pid 858085:tid 858273] [client 57.141.18.41:30640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp55wAAORs"]
[Mon Jul 20 06:13:35.759219 2026] [security2:error] [pid 858085:tid 858293] [client 206.189.19.19:60844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q7zAtbv2vrjByhUp7CQAAAE0"]
[Mon Jul 20 06:13:35.760029 2026] [security2:error] [pid 843279:tid 843418] [client 178.152.178.232:37436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVQAAAI0"]
[Mon Jul 20 06:13:35.760139 2026] [security2:error] [pid 843279:tid 843418] [client 178.152.178.232:37436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVQAAAI0"]
[Mon Jul 20 06:13:35.798098 2026] [security2:error] [pid 843279:tid 843420] [client 27.96.94.195:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVgAAAI8"]
[Mon Jul 20 06:13:35.798269 2026] [security2:error] [pid 843279:tid 843420] [client 27.96.94.195:37442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVgAAAI8"]
[Mon Jul 20 06:13:35.852041 2026] [security2:error] [pid 858085:tid 858265] [client 57.141.18.53:30362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp5-QAAMSo"]
[Mon Jul 20 06:13:35.926883 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:53254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4Q7zAtbv2vrjByhUp7DwAAAEk"], referer: http://massagelacey.com/WordPress
[Mon Jul 20 06:13:36.167476 2026] [security2:error] [pid 858085:tid 858280] [client 104.234.53.77:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7MgAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:36.399559 2026] [security2:error] [pid 858085:tid 858225] [client 206.189.19.19:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7NAAAAAk"]
[Mon Jul 20 06:13:36.627529 2026] [security2:error] [pid 858085:tid 858156] [remote 8.217.108.67:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q8DAtbv2vrjByhUp7UQAAEUU"]
[Mon Jul 20 06:13:36.801061 2026] [ssl:error] [pid 858085:tid 858220] [client 104.48.69.105:42328] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:13:36.854350 2026] [security2:error] [pid 858085:tid 858303] [client 14.225.17.146:60275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7WQAAAFc"]
[Mon Jul 20 06:13:36.921523 2026] [security2:error] [pid 858085:tid 858312] [client 57.141.18.76:34094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7DAtbv2vrjByhUp6QgAAYBc"]
[Mon Jul 20 06:13:37.034845 2026] [security2:error] [pid 858085:tid 858311] [client 206.189.19.19:60866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7XAAAAF8"]
[Mon Jul 20 06:13:37.234016 2026] [security2:error] [pid 843279:tid 843536] [client 14.225.17.146:49906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAfgAAAQI"], referer: http://claysharecon.com/WordPress
[Mon Jul 20 06:13:37.248909 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.73:55846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6YQAAHHA"]
[Mon Jul 20 06:13:37.365606 2026] [security2:error] [pid 843279:tid 843464] [client 185.132.186.55:32671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/include/install.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAgwAAALs"]
[Mon Jul 20 06:13:37.540601 2026] [security2:error] [pid 858085:tid 858183] [remote 8.217.108.67:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q8TAtbv2vrjByhUp7gAAAImA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:13:37.635357 2026] [security2:error] [pid 858085:tid 858282] [client 57.141.18.77:50046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6hQAAQhY"]
[Mon Jul 20 06:13:37.664153 2026] [security2:error] [pid 843279:tid 843497] [client 206.189.19.19:60880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAhwAAANw"]
[Mon Jul 20 06:13:37.895651 2026] [ssl:error] [pid 858085:tid 858308] [client 104.48.69.105:42336] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:13:37.986515 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.22:57896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7jAtbv2vrjByhUp6nwAAFCY"]
[Mon Jul 20 06:13:38.301768 2026] [core:error] [pid 858085:tid 858304] [client 158.173.167.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:38.301793 2026] [core:error] [pid 858085:tid 858304] [client 158.173.167.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:38.342431 2026] [security2:error] [pid 843279:tid 843494] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8vqvKNcW5yy5T2DAlQAAANk"]
[Mon Jul 20 06:13:38.434358 2026] [security2:error] [pid 858085:tid 858233] [client 113.160.97.242:57604] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Q8jAtbv2vrjByhUp7qwAAABE"]
[Mon Jul 20 06:13:38.783856 2026] [security2:error] [pid 858085:tid 858237] [client 65.1.132.125:55018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8jAtbv2vrjByhUp7vwAAABU"]
[Mon Jul 20 06:13:38.783952 2026] [security2:error] [pid 858085:tid 858237] [client 65.1.132.125:55018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8jAtbv2vrjByhUp7vwAAABU"]
[Mon Jul 20 06:13:39.154443 2026] [security2:error] [pid 858085:tid 858264] [client 57.141.18.59:32924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7zAtbv2vrjByhUp67gAAMGI"]
[Mon Jul 20 06:13:39.258066 2026] [security2:error] [pid 858085:tid 858325] [client 50.116.65.227:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q8zAtbv2vrjByhUp75AAAAG0"]
[Mon Jul 20 06:13:39.271651 2026] [security2:error] [pid 858085:tid 858258] [client 50.116.65.227:57394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q8zAtbv2vrjByhUp75gAAACo"]
[Mon Jul 20 06:13:39.312615 2026] [security2:error] [pid 858085:tid 858277] [client 185.132.186.104:48463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/gm.php"] [unique_id "al4Q8zAtbv2vrjByhUp76wAAAD0"]
[Mon Jul 20 06:13:39.332735 2026] [security2:error] [pid 858085:tid 858303] [client 14.225.17.146:53599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4Q8zAtbv2vrjByhUp71wAAAFc"], referer: http://myspineworld.com/WordPress
[Mon Jul 20 06:13:39.453718 2026] [security2:error] [pid 858085:tid 858287] [client 50.116.65.227:57408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Q8zAtbv2vrjByhUp78AAAAEc"]
[Mon Jul 20 06:13:39.463906 2026] [security2:error] [pid 843279:tid 843413] [client 50.116.65.227:57412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Q8_qvKNcW5yy5T2DAugAAAIg"]
[Mon Jul 20 06:13:39.955674 2026] [security2:error] [pid 858085:tid 858289] [client 103.77.203.233:55369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8zAtbv2vrjByhUp8CAAAAEk"]
[Mon Jul 20 06:13:39.955796 2026] [security2:error] [pid 858085:tid 858289] [client 103.77.203.233:55369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8zAtbv2vrjByhUp8CAAAAEk"]
[Mon Jul 20 06:13:40.152729 2026] [security2:error] [pid 858085:tid 858327] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Q8zAtbv2vrjByhUp8BgAAAG8"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:13:40.238679 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.86:32325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA0AAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:40.252436 2026] [security2:error] [pid 843279:tid 843311] [remote 217.61.143.92:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA0QAAtx4"]
[Mon Jul 20 06:13:40.329339 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:63386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Q9DAtbv2vrjByhUp8FQAAABk"], referer: https://myspineworld.com/WordPress
[Mon Jul 20 06:13:40.489474 2026] [security2:error] [pid 843279:tid 843396] [remote 217.61.143.92:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA2AAA_3M"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:13:40.566884 2026] [security2:error] [pid 858085:tid 858341] [client 57.141.18.82:25340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7UwAAfV8"]
[Mon Jul 20 06:13:40.738432 2026] [security2:error] [pid 858085:tid 858217] [client 14.225.17.146:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Q8zAtbv2vrjByhUp77wAAAAE"], referer: http://iagdevelopments.com/WordPress
[Mon Jul 20 06:13:40.832897 2026] [security2:error] [pid 843279:tid 843430] [client 57.141.18.57:44444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8PqvKNcW5yy5T2DAdwAAmRw"]
[Mon Jul 20 06:13:40.871142 2026] [security2:error] [pid 843279:tid 843317] [remote 217.61.143.92:48810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA5gAA8SQ"]
[Mon Jul 20 06:13:40.871374 2026] [security2:error] [pid 843279:tid 843519] [client 217.61.143.92:48810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA5gAA8SQ"]
[Mon Jul 20 06:13:41.066595 2026] [security2:error] [pid 858085:tid 858337] [client 57.141.18.94:46424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8TAtbv2vrjByhUp7bwAAeWs"]
[Mon Jul 20 06:13:41.278731 2026] [security2:error] [pid 843279:tid 843449] [client 185.132.186.71:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-language-pack.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA7gAAAKw"]
[Mon Jul 20 06:13:41.345659 2026] [security2:error] [pid 843279:tid 843486] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA7AAAANE"]
[Mon Jul 20 06:13:41.688835 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:50959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Q9TAtbv2vrjByhUp8YwAAADY"], referer: https://iagdevelopments.com/WordPress
[Mon Jul 20 06:13:41.762780 2026] [security2:error] [pid 858085:tid 858294] [client 206.189.19.19:42420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.19.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/info.php"] [unique_id "al4Q9TAtbv2vrjByhUp8dgAAAE4"]
[Mon Jul 20 06:13:41.763110 2026] [security2:error] [pid 843279:tid 843461] [client 57.141.18.22:56384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAkQAAuAg"]
[Mon Jul 20 06:13:41.924566 2026] [security2:error] [pid 843279:tid 843447] [client 57.141.18.92:32306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8vqvKNcW5yy5T2DAnAAAqhE"]
[Mon Jul 20 06:13:42.292071 2026] [security2:error] [pid 843279:tid 843472] [client 14.225.17.146:57633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4Q9vqvKNcW5yy5T2DA_wAAAMM"], referer: http://xp-design.co/WordPress
[Mon Jul 20 06:13:42.434871 2026] [security2:error] [pid 843279:tid 843466] [client 181.224.94.124:38962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9vqvKNcW5yy5T2DBDwAAAL0"]
[Mon Jul 20 06:13:42.435027 2026] [security2:error] [pid 843279:tid 843466] [client 181.224.94.124:38962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9vqvKNcW5yy5T2DBDwAAAL0"]
[Mon Jul 20 06:13:42.750327 2026] [security2:error] [pid 843279:tid 843422] [client 57.141.18.17:37230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8_qvKNcW5yy5T2DAtwAAkUI"]
[Mon Jul 20 06:13:43.021015 2026] [security2:error] [pid 843279:tid 843533] [client 171.60.139.123:53847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBKAAAAP8"]
[Mon Jul 20 06:13:43.024507 2026] [security2:error] [pid 843279:tid 843533] [client 171.60.139.123:53847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBKAAAAP8"]
[Mon Jul 20 06:13:43.222476 2026] [security2:error] [pid 858085:tid 858286] [client 185.132.186.58:32795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/content-type.php"] [unique_id "al4Q9zAtbv2vrjByhUp8uQAAAEY"]
[Mon Jul 20 06:13:43.271204 2026] [security2:error] [pid 843279:tid 843530] [client 14.225.17.146:50975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA9gAAAPw"], referer: http://cephasnext.com/WordPress
[Mon Jul 20 06:13:43.497866 2026] [security2:error] [pid 858085:tid 858253] [client 14.225.17.146:53836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Q9zAtbv2vrjByhUp8wAAAACU"], referer: http://sesamegreenbeans.com/WordPress
[Mon Jul 20 06:13:43.671962 2026] [security2:error] [pid 858085:tid 858303] [client 57.141.18.121:62622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q9DAtbv2vrjByhUp8HQAAVzk"]
[Mon Jul 20 06:13:43.770138 2026] [security2:error] [pid 843279:tid 843437] [client 175.44.42.146:54526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBMwAAALM"], referer: http://www.osdzc.com/
[Mon Jul 20 06:13:43.801458 2026] [security2:error] [pid 858085:tid 858247] [client 106.192.104.4:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9zAtbv2vrjByhUp83wAAAB8"]
[Mon Jul 20 06:13:43.805450 2026] [security2:error] [pid 858085:tid 858247] [client 106.192.104.4:51090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9zAtbv2vrjByhUp83wAAAB8"]
[Mon Jul 20 06:13:43.998972 2026] [security2:error] [pid 843279:tid 843476] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBOgAAAMc"]
[Mon Jul 20 06:13:44.034865 2026] [security2:error] [pid 843279:tid 843414] [client 99.245.0.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBOAAAiUo"]
[Mon Jul 20 06:13:44.408562 2026] [security2:error] [pid 843279:tid 843440] [client 57.141.18.84:22762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA6gAAoyE"]
[Mon Jul 20 06:13:44.463568 2026] [security2:error] [pid 858085:tid 858143] [remote 52.167.144.168:9915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4Q-DAtbv2vrjByhUp9DgAAHjg"]
[Mon Jul 20 06:13:44.527806 2026] [security2:error] [pid 858085:tid 858265] [client 14.225.17.146:64807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Q-DAtbv2vrjByhUp9CwAAADE"], referer: https://sesamegreenbeans.com/WordPress
[Mon Jul 20 06:13:44.677563 2026] [security2:error] [pid 858085:tid 858340] [client 14.225.17.146:52921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4Q9zAtbv2vrjByhUp8xAAAAHw"], referer: http://hammadownenterprises.com/WordPress
[Mon Jul 20 06:13:44.709968 2026] [security2:error] [pid 843279:tid 843392] [remote 173.249.4.11:35752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q-PqvKNcW5yy5T2DBSwAAuG8"]
[Mon Jul 20 06:13:44.710151 2026] [security2:error] [pid 843279:tid 843461] [client 173.249.4.11:35752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q-PqvKNcW5yy5T2DBSwAAuG8"]
[Mon Jul 20 06:13:44.754916 2026] [security2:error] [pid 858085:tid 858324] [client 41.173.37.102:8349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-DAtbv2vrjByhUp9HAAAAGw"]
[Mon Jul 20 06:13:44.755036 2026] [security2:error] [pid 858085:tid 858324] [client 41.173.37.102:8349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-DAtbv2vrjByhUp9HAAAAGw"]
[Mon Jul 20 06:13:44.994878 2026] [security2:error] [pid 858085:tid 858339] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q-DAtbv2vrjByhUp9IwAAAHs"]
[Mon Jul 20 06:13:45.032701 2026] [security2:error] [pid 858085:tid 858310] [client 103.141.108.143:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9LQAAAF4"]
[Mon Jul 20 06:13:45.032913 2026] [security2:error] [pid 858085:tid 858310] [client 103.141.108.143:63830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9LQAAAF4"]
[Mon Jul 20 06:13:45.173646 2026] [security2:error] [pid 858085:tid 858227] [client 185.132.186.72:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-walker-comment-client.php"] [unique_id "al4Q-TAtbv2vrjByhUp9OgAAAAs"]
[Mon Jul 20 06:13:45.374946 2026] [security2:error] [pid 858085:tid 858090] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9SgAAZgM"]
[Mon Jul 20 06:13:45.375106 2026] [security2:error] [pid 858085:tid 858318] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9SgAAZgM"]
[Mon Jul 20 06:13:45.614642 2026] [security2:error] [pid 858085:tid 858343] [client 14.225.17.146:54086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9SAAAAH8"], referer: http://tacticaltreeoperations.com/WordPress
[Mon Jul 20 06:13:45.664880 2026] [security2:error] [pid 858085:tid 858265] [client 112.213.160.112:31066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WAAAADE"]
[Mon Jul 20 06:13:45.665001 2026] [security2:error] [pid 858085:tid 858265] [client 112.213.160.112:31066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WAAAADE"]
[Mon Jul 20 06:13:45.725892 2026] [security2:error] [pid 858085:tid 858307] [client 45.116.69.230:60767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WgAAAFs"]
[Mon Jul 20 06:13:45.726006 2026] [security2:error] [pid 858085:tid 858307] [client 45.116.69.230:60767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WgAAAFs"]
[Mon Jul 20 06:13:45.871421 2026] [security2:error] [pid 843279:tid 843351] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-fqvKNcW5yy5T2DBaQAA00Y"]
[Mon Jul 20 06:13:45.871613 2026] [security2:error] [pid 843279:tid 843488] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-fqvKNcW5yy5T2DBaQAA00Y"]
[Mon Jul 20 06:13:46.009172 2026] [security2:error] [pid 858085:tid 858223] [client 27.96.94.195:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9cQAAAAc"]
[Mon Jul 20 06:13:46.009354 2026] [security2:error] [pid 858085:tid 858223] [client 27.96.94.195:37680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9cQAAAAc"]
[Mon Jul 20 06:13:46.030233 2026] [lsapi:warn] [pid 858085:tid 858245] [client 14.225.17.146:60923] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:46.030267 2026] [lsapi:warn] [pid 858085:tid 858245] [client 14.225.17.146:60923] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:46.038372 2026] [security2:error] [pid 858085:tid 858290] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9ZAAAAEo"]
[Mon Jul 20 06:13:46.040011 2026] [security2:error] [pid 843279:tid 843530] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-fqvKNcW5yy5T2DBZwAAAPw"], referer: http://adastra.love/dashboard
[Mon Jul 20 06:13:46.125080 2026] [lsapi:warn] [pid 858085:tid 858238] [client 50.116.65.227:57506] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:46.125120 2026] [lsapi:warn] [pid 858085:tid 858238] [client 50.116.65.227:57506] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:46.140237 2026] [security2:error] [pid 858085:tid 858245] [client 14.225.17.146:60923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Q-jAtbv2vrjByhUp9cwAAAB0"], referer: http://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:46.150460 2026] [security2:error] [pid 858085:tid 858283] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9bAAAAEM"], referer: http://adastra.love/admin
[Mon Jul 20 06:13:46.161998 2026] [security2:error] [pid 858085:tid 858335] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9bQAAAHc"], referer: http://adastra.love/login
[Mon Jul 20 06:13:46.256060 2026] [security2:error] [pid 858085:tid 858308] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9bwAAAFw"], referer: http://adastra.love/console
[Mon Jul 20 06:13:46.485422 2026] [security2:error] [pid 843279:tid 843458] [client 216.73.217.138:56706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Q-vqvKNcW5yy5T2DBdgAAtQw"]
[Mon Jul 20 06:13:46.619315 2026] [security2:error] [pid 858085:tid 858282] [client 178.152.178.232:36752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9kQAAAEI"]
[Mon Jul 20 06:13:46.619464 2026] [security2:error] [pid 858085:tid 858282] [client 178.152.178.232:36752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9kQAAAEI"]
[Mon Jul 20 06:13:47.040495 2026] [security2:error] [pid 843279:tid 843422] [client 185.132.186.77:59303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/about/goods.php"] [unique_id "al4Q-_qvKNcW5yy5T2DBlgAAAJE"]
[Mon Jul 20 06:13:47.052114 2026] [lsapi:warn] [pid 858085:tid 858294] [client 14.225.17.146:54148] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:47.052136 2026] [lsapi:warn] [pid 858085:tid 858294] [client 14.225.17.146:54148] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:47.125822 2026] [lsapi:warn] [pid 858085:tid 858314] [client 50.116.65.227:57534] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:47.125849 2026] [lsapi:warn] [pid 858085:tid 858314] [client 50.116.65.227:57534] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:47.136438 2026] [security2:error] [pid 858085:tid 858294] [client 14.225.17.146:54148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp9rwAAAE4"], referer: https://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:47.334860 2026] [security2:error] [pid 843279:tid 843474] [client 50.116.65.227:35050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4Q-_qvKNcW5yy5T2DBmwAAAMU"]
[Mon Jul 20 06:13:47.343139 2026] [security2:error] [pid 858085:tid 858245] [client 14.225.17.146:53456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp9uwAAAB0"], referer: http://mcg.homes/WordPress
[Mon Jul 20 06:13:47.346538 2026] [security2:error] [pid 843279:tid 843417] [client 50.116.65.227:57550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4Q-_qvKNcW5yy5T2DBnAAAAIw"]
[Mon Jul 20 06:13:47.389951 2026] [security2:error] [pid 858085:tid 858326] [client 14.225.17.146:64931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WQAAAG4"], referer: http://koaconsultants.com/WordPress
[Mon Jul 20 06:13:47.832619 2026] [security2:error] [pid 858085:tid 858341] [client 45.157.112.60:21303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q-zAtbv2vrjByhUp92gAAAH0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:48.011601 2026] [security2:error] [pid 858085:tid 858301] [client 14.225.17.146:59474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp92wAAAFU"], referer: http://detroitcsc.com/WordPress
[Mon Jul 20 06:13:48.432426 2026] [security2:error] [pid 843279:tid 843411] [client 63.135.161.174:26827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.161.135.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4Q_PqvKNcW5yy5T2DBuAAAAIY"], referer: https://www.bing.com/
[Mon Jul 20 06:13:48.487002 2026] [security2:error] [pid 843279:tid 843523] [client 52.233.165.60:3584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Q_PqvKNcW5yy5T2DBuwAAAPU"]
[Mon Jul 20 06:13:48.524490 2026] [security2:error] [pid 843279:tid 843452] [client 14.225.17.146:54136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4Q-vqvKNcW5yy5T2DBkgAAAK8"], referer: http://reosportsboats.com/WordPress
[Mon Jul 20 06:13:48.565611 2026] [security2:error] [pid 858085:tid 858312] [client 14.225.17.146:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4Q-jAtbv2vrjByhUp9pwAAAGA"], referer: http://swafforddetailing.com/WordPress
[Mon Jul 20 06:13:48.635674 2026] [security2:error] [pid 843279:tid 843431] [client 52.233.165.60:3584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Q_PqvKNcW5yy5T2DBvgAAAJo"]
[Mon Jul 20 06:13:48.842843 2026] [security2:error] [pid 858085:tid 858341] [client 185.132.186.61:48625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/file/function.php"] [unique_id "al4Q_DAtbv2vrjByhUp-CgAAAH0"]
[Mon Jul 20 06:13:48.893832 2026] [security2:error] [pid 858085:tid 858322] [client 51.143.183.75:24257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Q_DAtbv2vrjByhUp-EwAAAGo"]
[Mon Jul 20 06:13:49.026952 2026] [security2:error] [pid 858085:tid 858226] [client 51.143.183.75:24257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Q_TAtbv2vrjByhUp-HgAAAAo"]
[Mon Jul 20 06:13:49.043178 2026] [security2:error] [pid 858085:tid 858284] [client 50.116.65.227:11544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Q_TAtbv2vrjByhUp-IAAAAEQ"]
[Mon Jul 20 06:13:49.053170 2026] [security2:error] [pid 858085:tid 858245] [client 50.116.65.227:11558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Q_TAtbv2vrjByhUp-IgAAAB0"]
[Mon Jul 20 06:13:49.489446 2026] [security2:error] [pid 858085:tid 858231] [client 14.225.17.146:53488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-NQAAAA8"], referer: https://reosportsboats.com/WordPress
[Mon Jul 20 06:13:49.568352 2026] [security2:error] [pid 858085:tid 858095] [remote 162.19.86.63:42812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-QAAAZAg"]
[Mon Jul 20 06:13:49.576142 2026] [security2:error] [pid 858085:tid 858092] [remote 152.228.213.32:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-PwAAKQU"]
[Mon Jul 20 06:13:49.584361 2026] [security2:error] [pid 858085:tid 858267] [client 43.205.139.3:38144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_TAtbv2vrjByhUp-RwAAADM"]
[Mon Jul 20 06:13:49.584457 2026] [security2:error] [pid 858085:tid 858267] [client 43.205.139.3:38144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_TAtbv2vrjByhUp-RwAAADM"]
[Mon Jul 20 06:13:49.761652 2026] [security2:error] [pid 858085:tid 858334] [client 206.189.19.19:35058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/"] [unique_id "al4Q_TAtbv2vrjByhUp-VAAAAHY"]
[Mon Jul 20 06:13:49.763977 2026] [security2:error] [pid 858085:tid 858111] [remote 152.228.213.32:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-UgAADhg"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:13:49.785142 2026] [security2:error] [pid 858085:tid 858091] [remote 162.19.86.63:42812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-VQAAWQQ"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:13:50.075293 2026] [security2:error] [pid 843279:tid 843473] [client 14.225.17.146:58543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Q_PqvKNcW5yy5T2DBvwAAAMQ"], referer: http://colinkeyphotography.com/WordPress
[Mon Jul 20 06:13:50.414051 2026] [security2:error] [pid 858085:tid 858293] [client 74.7.230.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-NgAAAE0"]
[Mon Jul 20 06:13:50.425862 2026] [security2:error] [pid 858085:tid 858319] [client 74.7.230.53:44466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abilite.uk"] [uri "/robots.txt"] [unique_id "al4Q_TAtbv2vrjByhUp-MQAAZ3U"]
[Mon Jul 20 06:13:50.515353 2026] [security2:error] [pid 858085:tid 858283] [client 103.77.203.233:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_jAtbv2vrjByhUp-eQAAAEM"]
[Mon Jul 20 06:13:50.515524 2026] [security2:error] [pid 858085:tid 858283] [client 103.77.203.233:55910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_jAtbv2vrjByhUp-eQAAAEM"]
[Mon Jul 20 06:13:50.544635 2026] [security2:error] [pid 858085:tid 858320] [client 114.119.144.64:52899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.koaconsultants.com"] [uri "/robots.txt"] [unique_id "al4Q_jAtbv2vrjByhUp-fAAAAGg"], referer: http://www.koaconsultants.com/robots.txt
[Mon Jul 20 06:13:50.641956 2026] [security2:error] [pid 843279:tid 843485] [client 185.132.186.53:23159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/function/goods.php"] [unique_id "al4Q_vqvKNcW5yy5T2DB6wAAANA"]
[Mon Jul 20 06:13:50.660958 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.69:43088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp9tgAABVw"]
[Mon Jul 20 06:13:50.769317 2026] [security2:error] [pid 843279:tid 843513] [client 206.189.19.19:35066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/"] [unique_id "al4Q_vqvKNcW5yy5T2DB8gAAAOs"]
[Mon Jul 20 06:13:50.807368 2026] [security2:error] [pid 858085:tid 858277] [client 63.135.161.171:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.161.135.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4Q_jAtbv2vrjByhUp-iQAAAD0"]
[Mon Jul 20 06:13:50.996022 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:58432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4Q_jAtbv2vrjByhUp-kQAAAEk"], referer: http://eduardsales.com/WordPress
[Mon Jul 20 06:13:51.179965 2026] [security2:error] [pid 843279:tid 843510] [client 14.225.17.146:50221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Q__qvKNcW5yy5T2DB-wAAAOg"], referer: http://alaraycreative.com/WordPress
[Mon Jul 20 06:13:51.440118 2026] [security2:error] [pid 858085:tid 858251] [client 57.141.18.76:34576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp93QAAI14"]
[Mon Jul 20 06:13:51.583494 2026] [security2:error] [pid 858085:tid 858283] [client 104.28.249.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q_zAtbv2vrjByhUp-qAAAAEM"], referer: http://adastra.love/app
[Mon Jul 20 06:13:51.598293 2026] [security2:error] [pid 858085:tid 858315] [client 104.28.249.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q_zAtbv2vrjByhUp-qgAAAGM"], referer: http://adastra.love/settings
[Mon Jul 20 06:13:51.769847 2026] [security2:error] [pid 858085:tid 858275] [client 206.189.19.19:35068] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/wp-json/batch/v1"] [unique_id "al4Q_zAtbv2vrjByhUp-wQAAADs"]
[Mon Jul 20 06:13:51.827209 2026] [security2:error] [pid 858085:tid 858269] [client 57.141.18.95:52458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_DAtbv2vrjByhUp98AAANXc"]
[Mon Jul 20 06:13:51.903020 2026] [autoindex:error] [pid 843279:tid 843470] [client 167.86.82.167:51748] AH01276: Cannot serve directory /home1/zanjanfr/public_html/terrapro/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:13:52.127732 2026] [security2:error] [pid 858085:tid 858238] [client 14.225.17.146:58471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-LgAAABY"], referer: http://gearwaterproof.com/WordPress
[Mon Jul 20 06:13:52.303895 2026] [security2:error] [pid 858085:tid 858297] [client 74.7.227.179:39966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RADAtbv2vrjByhUp-4gAAURI"], referer: https://tejasenvironmental.com/p=721097
[Mon Jul 20 06:13:52.349041 2026] [security2:error] [pid 858085:tid 858281] [client 57.141.18.100:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_DAtbv2vrjByhUp-CwAAQR4"]
[Mon Jul 20 06:13:52.410109 2026] [security2:error] [pid 843279:tid 843457] [client 66.249.73.68:52408] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "w.saphansiam.org"] [uri "/robots.txt"] [unique_id "al4RAPqvKNcW5yy5T2DCGQAAALQ"]
[Mon Jul 20 06:13:52.438542 2026] [security2:error] [pid 858085:tid 858277] [client 185.132.186.64:44693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/bypass.php"] [unique_id "al4RADAtbv2vrjByhUp-7QAAAD0"]
[Mon Jul 20 06:13:52.530803 2026] [security2:error] [pid 858085:tid 858282] [client 158.173.166.181:21279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RADAtbv2vrjByhUp-8wAAAEI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:52.600733 2026] [security2:error] [pid 858085:tid 858259] [client 51.68.236.64:15187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4RADAtbv2vrjByhUp-_QAAACs"]
[Mon Jul 20 06:13:52.600844 2026] [security2:error] [pid 858085:tid 858259] [client 51.68.236.64:15187] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4RADAtbv2vrjByhUp-_QAAACs"]
[Mon Jul 20 06:13:52.769909 2026] [security2:error] [pid 858085:tid 858271] [client 206.189.19.19:35070] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/wp-json/batch/v1"] [unique_id "al4RADAtbv2vrjByhUp_BQAAADc"]
[Mon Jul 20 06:13:52.941859 2026] [security2:error] [pid 858085:tid 858339] [client 181.224.94.124:6956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RADAtbv2vrjByhUp_DgAAAHs"]
[Mon Jul 20 06:13:52.942047 2026] [security2:error] [pid 858085:tid 858339] [client 181.224.94.124:6956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RADAtbv2vrjByhUp_DgAAAHs"]
[Mon Jul 20 06:13:53.049786 2026] [security2:error] [pid 858085:tid 858314] [client 57.141.18.80:39062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-PAAAYg8"]
[Mon Jul 20 06:13:53.094933 2026] [security2:error] [pid 843279:tid 843411] [client 14.225.17.146:53493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4Q_vqvKNcW5yy5T2DB9wAAAIY"], referer: http://younutrition.gr/WordPress
[Mon Jul 20 06:13:53.566399 2026] [security2:error] [pid 858085:tid 858248] [client 14.225.17.146:59338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4RADAtbv2vrjByhUp-1gAAACA"], referer: http://headachescarpaltunnelfibromyalgia.com/WordPress
[Mon Jul 20 06:13:53.588244 2026] [security2:error] [pid 843279:tid 843419] [client 57.141.18.118:37402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_vqvKNcW5yy5T2DB4AAAjmQ"]
[Mon Jul 20 06:13:53.768846 2026] [security2:error] [pid 858085:tid 858312] [client 171.60.139.123:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RATAtbv2vrjByhUp_NgAAAGA"]
[Mon Jul 20 06:13:53.768974 2026] [security2:error] [pid 858085:tid 858312] [client 171.60.139.123:54323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RATAtbv2vrjByhUp_NgAAAGA"]
[Mon Jul 20 06:13:53.867194 2026] [security2:error] [pid 858085:tid 858333] [client 104.234.53.50:39445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RATAtbv2vrjByhUp_PwAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:54.239972 2026] [security2:error] [pid 858085:tid 858253] [client 185.132.186.84:21247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_WAAAACU"]
[Mon Jul 20 06:13:54.265935 2026] [security2:error] [pid 858085:tid 858252] [client 57.141.18.94:33050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_jAtbv2vrjByhUp-jwAAJFM"]
[Mon Jul 20 06:13:54.438014 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_XAAAAAU"]
[Mon Jul 20 06:13:54.758454 2026] [security2:error] [pid 858085:tid 858315] [client 106.192.104.4:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RAjAtbv2vrjByhUp_gQAAAGM"]
[Mon Jul 20 06:13:54.758555 2026] [security2:error] [pid 858085:tid 858315] [client 106.192.104.4:51785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RAjAtbv2vrjByhUp_gQAAAGM"]
[Mon Jul 20 06:13:54.825505 2026] [security2:error] [pid 858085:tid 858341] [client 104.234.53.47:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RAjAtbv2vrjByhUp_hAAAAH0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:55.219470 2026] [security2:error] [pid 858085:tid 858255] [client 50.116.65.227:36564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RAzAtbv2vrjByhUp_ngAAACc"]
[Mon Jul 20 06:13:55.231417 2026] [security2:error] [pid 858085:tid 858306] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_jAAAAFo"]
[Mon Jul 20 06:13:55.235696 2026] [security2:error] [pid 843279:tid 843420] [client 50.116.65.227:11678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RA_qvKNcW5yy5T2DCUAAAAI8"]
[Mon Jul 20 06:13:55.381326 2026] [security2:error] [pid 843279:tid 843427] [client 14.225.17.146:60000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4RA_qvKNcW5yy5T2DCUQAAAJY"], referer: http://alchemygroup.ca/WordPress
[Mon Jul 20 06:13:55.389348 2026] [security2:error] [pid 858085:tid 858260] [client 41.173.37.102:8807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_qgAAACw"]
[Mon Jul 20 06:13:55.389458 2026] [security2:error] [pid 858085:tid 858260] [client 41.173.37.102:8807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_qgAAACw"]
[Mon Jul 20 06:13:55.732280 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:64314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vAAAAHU"]
[Mon Jul 20 06:13:55.732865 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:64314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vAAAAHU"]
[Mon Jul 20 06:13:55.758454 2026] [security2:error] [pid 858085:tid 858122] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vgAAHSM"]
[Mon Jul 20 06:13:55.758573 2026] [security2:error] [pid 858085:tid 858245] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vgAAHSM"]
[Mon Jul 20 06:13:55.928693 2026] [security2:error] [pid 858085:tid 858253] [client 104.234.53.47:52495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RAzAtbv2vrjByhUp_xQAAACU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:55.941520 2026] [security2:error] [pid 858085:tid 858318] [client 57.141.18.106:55998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RADAtbv2vrjByhUp--AAAZig"]
[Mon Jul 20 06:13:56.030708 2026] [security2:error] [pid 858085:tid 858302] [client 185.132.186.104:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-network-query-stat.php"] [unique_id "al4RBDAtbv2vrjByhUp_ywAAAFY"]
[Mon Jul 20 06:13:56.359470 2026] [security2:error] [pid 858085:tid 858339] [client 14.225.17.146:58993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_hQAAAHs"], referer: http://phillipbloch.com/WordPress
[Mon Jul 20 06:13:56.363608 2026] [security2:error] [pid 858085:tid 858338] [client 112.213.160.112:30893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RBDAtbv2vrjByhUp_4AAAAHo"]
[Mon Jul 20 06:13:56.363710 2026] [security2:error] [pid 858085:tid 858338] [client 112.213.160.112:30893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RBDAtbv2vrjByhUp_4AAAAHo"]
[Mon Jul 20 06:13:56.363896 2026] [security2:error] [pid 843279:tid 843524] [client 45.116.69.230:61274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCbgAAAPY"]
[Mon Jul 20 06:13:56.364000 2026] [security2:error] [pid 843279:tid 843524] [client 45.116.69.230:61274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCbgAAAPY"]
[Mon Jul 20 06:13:56.544825 2026] [security2:error] [pid 858085:tid 858142] [remote 103.75.185.95:44058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4RBDAtbv2vrjByhUp_6QAADzc"]
[Mon Jul 20 06:13:56.551249 2026] [security2:error] [pid 843279:tid 843305] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCcwAArxg"]
[Mon Jul 20 06:13:56.551408 2026] [security2:error] [pid 843279:tid 843452] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCcwAArxg"]
[Mon Jul 20 06:13:56.558938 2026] [security2:error] [pid 858085:tid 858290] [client 57.141.18.85:26078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RATAtbv2vrjByhUp_HAAASiU"]
[Mon Jul 20 06:13:56.901535 2026] [security2:error] [pid 858085:tid 858289] [client 57.141.18.49:63666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RATAtbv2vrjByhUp_LAAASWQ"]
[Mon Jul 20 06:13:57.242656 2026] [security2:error] [pid 858085:tid 858140] [remote 110.249.202.99:53114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/REV-legal-memo-litigation-background-criteria-june-2020.pdf"] [unique_id "al4RBTAtbv2vrjByhUqAEAAAQjU"]
[Mon Jul 20 06:13:57.303847 2026] [security2:error] [pid 858085:tid 858302] [client 158.173.89.95:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RBTAtbv2vrjByhUqAFAAAAFY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:57.527737 2026] [security2:error] [pid 858085:tid 858141] [remote 103.75.185.95:44058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4RBTAtbv2vrjByhUqAJQAAPTY"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:13:57.608100 2026] [security2:error] [pid 858085:tid 858273] [client 57.141.18.13:48400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_WQAAOXY"]
[Mon Jul 20 06:13:57.652213 2026] [security2:error] [pid 858085:tid 858226] [client 27.96.94.195:37055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RBTAtbv2vrjByhUqANwAAAAo"]
[Mon Jul 20 06:13:57.652377 2026] [security2:error] [pid 858085:tid 858226] [client 27.96.94.195:37055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RBTAtbv2vrjByhUqANwAAAAo"]
[Mon Jul 20 06:13:57.703042 2026] [security2:error] [pid 858085:tid 858316] [client 14.225.17.146:58804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4RBTAtbv2vrjByhUqAGwAAAGQ"], referer: http://webgardensbypaula.com/WordPress
[Mon Jul 20 06:13:57.704284 2026] [security2:error] [pid 858085:tid 858249] [client 14.225.17.146:53362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4RBTAtbv2vrjByhUqAIAAAACE"], referer: http://ccsdifference.com/WordPress
[Mon Jul 20 06:13:57.828416 2026] [security2:error] [pid 843279:tid 843443] [client 185.132.186.74:59641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al4RBfqvKNcW5yy5T2DCigAAAKY"]
[Mon Jul 20 06:13:57.832816 2026] [security2:error] [pid 858085:tid 858176] [remote 100.42.189.89:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4RBTAtbv2vrjByhUqAPAAANVk"]
[Mon Jul 20 06:13:57.853308 2026] [security2:error] [pid 858085:tid 858267] [client 57.141.18.38:36138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_bgAAM34"]
[Mon Jul 20 06:13:57.933294 2026] [security2:error] [pid 843279:tid 843489] [client 103.153.183.69:3802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fsrv/.env"] [unique_id "al4RBfqvKNcW5yy5T2DCiwAAANQ"], referer: https://twitter.com/
[Mon Jul 20 06:13:58.024866 2026] [security2:error] [pid 843279:tid 843536] [client 103.153.183.69:3802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fhome/.env"] [unique_id "al4RBvqvKNcW5yy5T2DCjQAAAQI"], referer: https://duckduckgo.com/?q=8xmzn
[Mon Jul 20 06:13:58.103846 2026] [security2:error] [pid 858085:tid 858129] [remote 100.42.189.89:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4RBjAtbv2vrjByhUqARgAAACo"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 06:13:58.629099 2026] [security2:error] [pid 858085:tid 858317] [client 57.141.18.86:29370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RAzAtbv2vrjByhUp_qQAAZXo"]
[Mon Jul 20 06:13:58.735854 2026] [security2:error] [pid 843279:tid 843432] [client 14.225.17.146:64838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4RBvqvKNcW5yy5T2DCpwAAAJs"], referer: https://ccsdifference.com/WordPress
[Mon Jul 20 06:13:58.926905 2026] [security2:error] [pid 858085:tid 858326] [client 50.116.65.227:56626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RBjAtbv2vrjByhUqAcAAAAG4"]
[Mon Jul 20 06:13:58.935507 2026] [security2:error] [pid 858085:tid 858238] [client 50.116.65.227:56634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RBjAtbv2vrjByhUqAcQAAABY"]
[Mon Jul 20 06:13:59.451493 2026] [security2:error] [pid 858085:tid 858322] [client 57.141.18.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAhQAAAGo"]
[Mon Jul 20 06:13:59.721103 2026] [security2:error] [pid 858085:tid 858279] [client 98.159.234.160:29495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RBzAtbv2vrjByhUqAoQAAAD8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:59.805945 2026] [security2:error] [pid 858085:tid 858275] [client 57.141.18.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAmwAAADs"]
[Mon Jul 20 06:13:59.825559 2026] [security2:error] [pid 843279:tid 843462] [client 57.141.18.103:51902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBPqvKNcW5yy5T2DCbwAAuUI"]
[Mon Jul 20 06:14:00.529445 2026] [security2:error] [pid 858085:tid 858216] [client 43.205.139.3:14470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RCDAtbv2vrjByhUqAzQAAAAA"]
[Mon Jul 20 06:14:00.529557 2026] [security2:error] [pid 858085:tid 858216] [client 43.205.139.3:14470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RCDAtbv2vrjByhUqAzQAAAAA"]
[Mon Jul 20 06:14:00.548969 2026] [security2:error] [pid 858085:tid 858114] [remote 51.222.168.34:33632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.californiaperfumecompany.com"] [uri "/collector/cal_questions.html"] [unique_id "al4RCDAtbv2vrjByhUqAzgAAaBs"]
[Mon Jul 20 06:14:00.549208 2026] [security2:error] [pid 858085:tid 858320] [client 51.222.168.34:33632] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.californiaperfumecompany.com"] [uri "/collector/cal_questions.html"] [unique_id "al4RCDAtbv2vrjByhUqAzgAAaBs"]
[Mon Jul 20 06:14:00.640853 2026] [security2:error] [pid 858085:tid 858298] [client 185.132.186.59:49487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugin-install.php"] [unique_id "al4RCDAtbv2vrjByhUqA0QAAAFI"]
[Mon Jul 20 06:14:00.982563 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RCPqvKNcW5yy5T2DC3QAAAJA"]
[Mon Jul 20 06:14:00.982674 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:56455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RCPqvKNcW5yy5T2DC3QAAAJA"]
[Mon Jul 20 06:14:01.058962 2026] [security2:error] [pid 858085:tid 858232] [client 14.225.17.146:52410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqA3wAAABA"], referer: http://cheesewithjam.com/WordPress
[Mon Jul 20 06:14:01.107166 2026] [security2:error] [pid 858085:tid 858301] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqA2wAAAFU"]
[Mon Jul 20 06:14:01.206422 2026] [security2:error] [pid 858085:tid 858163] [remote 91.142.222.105:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4RCTAtbv2vrjByhUqA_gAAc0w"]
[Mon Jul 20 06:14:01.430179 2026] [security2:error] [pid 843279:tid 843470] [client 14.225.17.146:61621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4RCPqvKNcW5yy5T2DCzwAAAME"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WordPress
[Mon Jul 20 06:14:01.524322 2026] [security2:error] [pid 858085:tid 858192] [remote 91.142.222.105:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4RCTAtbv2vrjByhUqBFwAAaWk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:14:01.698047 2026] [security2:error] [pid 843279:tid 843446] [client 14.225.17.146:64845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4RB_qvKNcW5yy5T2DCvgAAAKk"], referer: http://guidehunting.com/WordPress
[Mon Jul 20 06:14:01.775669 2026] [security2:error] [pid 858085:tid 858230] [client 14.225.17.146:51401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4RCTAtbv2vrjByhUqBAAAAAA4"], referer: http://waterproofgoods.com/WordPress
[Mon Jul 20 06:14:02.446643 2026] [security2:error] [pid 858085:tid 858231] [client 185.132.186.104:42503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-session-tokens-https.php"] [unique_id "al4RCjAtbv2vrjByhUqBUAAAAA8"]
[Mon Jul 20 06:14:02.451134 2026] [security2:error] [pid 843279:tid 843427] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RCvqvKNcW5yy5T2DDBAAAAJY"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:14:02.477805 2026] [security2:error] [pid 858085:tid 858343] [client 50.116.65.227:19780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4RCjAtbv2vrjByhUqBUwAAAH8"]
[Mon Jul 20 06:14:02.492426 2026] [security2:error] [pid 858085:tid 858233] [client 50.116.65.227:56716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4RCjAtbv2vrjByhUqBVgAAAC8"]
[Mon Jul 20 06:14:02.555709 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4RCvqvKNcW5yy5T2DDBwAAhXA"], referer: http://assasalnazaha.com/WordPress
[Mon Jul 20 06:14:02.612608 2026] [security2:error] [pid 858085:tid 858290] [client 14.225.17.146:51883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4RCjAtbv2vrjByhUqBRwAAAEo"], referer: http://latiendadejorge.com.gt/WordPress
[Mon Jul 20 06:14:02.871227 2026] [security2:error] [pid 858085:tid 858316] [client 14.225.17.146:52457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RCjAtbv2vrjByhUqBWwAAAGQ"], referer: https://guidehunting.com/WordPress
[Mon Jul 20 06:14:03.187848 2026] [security2:error] [pid 843279:tid 843521] [client 104.234.53.64:33457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RC_qvKNcW5yy5T2DDJQAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:03.508357 2026] [security2:error] [pid 843279:tid 843457] [client 181.224.94.124:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RC_qvKNcW5yy5T2DDLwAAALQ"]
[Mon Jul 20 06:14:03.508492 2026] [security2:error] [pid 843279:tid 843457] [client 181.224.94.124:13184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RC_qvKNcW5yy5T2DDLwAAALQ"]
[Mon Jul 20 06:14:03.713411 2026] [security2:error] [pid 858085:tid 858332] [client 57.141.18.22:43138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAjQAAdEE"]
[Mon Jul 20 06:14:03.740886 2026] [security2:error] [pid 858085:tid 858308] [client 14.225.17.146:64387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBnAAAAFw"], referer: http://processorstudio.com/WordPress
[Mon Jul 20 06:14:04.009709 2026] [security2:error] [pid 858085:tid 858260] [client 57.141.18.28:44752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAnAAALAA"]
[Mon Jul 20 06:14:04.023933 2026] [security2:error] [pid 858085:tid 858337] [client 57.141.18.46:26504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAngAAeRY"]
[Mon Jul 20 06:14:04.249026 2026] [security2:error] [pid 858085:tid 858284] [client 185.132.186.101:47913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/load.php"] [unique_id "al4RDDAtbv2vrjByhUqBtAAAAEQ"]
[Mon Jul 20 06:14:04.328237 2026] [security2:error] [pid 858085:tid 858287] [client 14.225.17.146:52404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBoAAAAEc"], referer: http://onewingpictures.com/WordPress
[Mon Jul 20 06:14:04.351907 2026] [security2:error] [pid 858085:tid 858250] [client 47.128.56.171:11304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musichaven.info"] [uri "/robots.txt"] [unique_id "al4RDDAtbv2vrjByhUqBuQAAACI"]
[Mon Jul 20 06:14:04.352272 2026] [security2:error] [pid 843279:tid 843478] [client 57.141.18.55:55134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCPqvKNcW5yy5T2DCwwAAyWI"]
[Mon Jul 20 06:14:04.498983 2026] [security2:error] [pid 843279:tid 843420] [client 171.60.139.123:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RDPqvKNcW5yy5T2DDSgAAAI8"]
[Mon Jul 20 06:14:04.499139 2026] [security2:error] [pid 843279:tid 843420] [client 171.60.139.123:54804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RDPqvKNcW5yy5T2DDSgAAAI8"]
[Mon Jul 20 06:14:04.520713 2026] [security2:error] [pid 858085:tid 858304] [client 57.141.18.40:56578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqAtwAAWAg"]
[Mon Jul 20 06:14:04.597295 2026] [security2:error] [pid 843279:tid 843467] [client 14.225.17.146:51547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4RDPqvKNcW5yy5T2DDTAAAAL4"], referer: https://processorstudio.com/WordPress
[Mon Jul 20 06:14:04.688519 2026] [security2:error] [pid 858085:tid 858318] [client 57.141.18.100:59230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqAwwAAZgQ"]
[Mon Jul 20 06:14:04.799077 2026] [security2:error] [pid 858085:tid 858293] [client 14.225.17.146:64330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBpAAAAE0"]
[Mon Jul 20 06:14:05.145642 2026] [security2:error] [pid 858085:tid 858241] [client 57.141.18.81:42218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqA5gAAGTg"]
[Mon Jul 20 06:14:05.441783 2026] [security2:error] [pid 858085:tid 858319] [client 57.141.18.87:60646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCTAtbv2vrjByhUqBEgAAZ0I"]
[Mon Jul 20 06:14:05.482491 2026] [core:error] [pid 858085:tid 858193] [remote 205.210.31.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webmail.ardhalwafaa.com/
[Mon Jul 20 06:14:05.482511 2026] [core:error] [pid 858085:tid 858193] [remote 205.210.31.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webmail.ardhalwafaa.com/
[Mon Jul 20 06:14:06.013960 2026] [security2:error] [pid 858085:tid 858317] [client 14.225.17.146:64456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4RDTAtbv2vrjByhUqB_gAAAGU"], referer: http://lifeisbetterlakeside.com/WordPress
[Mon Jul 20 06:14:06.044039 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:9267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCDAAAACU"]
[Mon Jul 20 06:14:06.044167 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:9267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCDAAAACU"]
[Mon Jul 20 06:14:06.067345 2026] [security2:error] [pid 858085:tid 858320] [client 185.132.186.64:36377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/firewall.php7"] [unique_id "al4RDjAtbv2vrjByhUqCEQAAAGg"]
[Mon Jul 20 06:14:06.136445 2026] [security2:error] [pid 843279:tid 843504] [client 106.192.104.4:52445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RDvqvKNcW5yy5T2DDdQAAAOM"]
[Mon Jul 20 06:14:06.136537 2026] [security2:error] [pid 843279:tid 843504] [client 106.192.104.4:52445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RDvqvKNcW5yy5T2DDdQAAAOM"]
[Mon Jul 20 06:14:06.156125 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.63:45350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCjAtbv2vrjByhUqBMgAACV4"]
[Mon Jul 20 06:14:06.274016 2026] [security2:error] [pid 843279:tid 843309] [remote 57.141.18.15:24088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5168046"] [unique_id "al4RDvqvKNcW5yy5T2DDdwAA8Bw"]
[Mon Jul 20 06:14:06.364788 2026] [security2:error] [pid 858085:tid 858191] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCIwAAR2g"]
[Mon Jul 20 06:14:06.364968 2026] [security2:error] [pid 858085:tid 858287] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCIwAAR2g"]
[Mon Jul 20 06:14:06.590411 2026] [security2:error] [pid 858085:tid 858286] [client 103.141.108.143:64810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCKwAAAEY"]
[Mon Jul 20 06:14:06.590566 2026] [security2:error] [pid 858085:tid 858286] [client 103.141.108.143:64810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCKwAAAEY"]
[Mon Jul 20 06:14:07.132554 2026] [security2:error] [pid 843279:tid 843523] [client 112.213.160.112:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDlgAAAPU"]
[Mon Jul 20 06:14:07.132703 2026] [security2:error] [pid 843279:tid 843523] [client 112.213.160.112:8220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDlgAAAPU"]
[Mon Jul 20 06:14:07.150559 2026] [security2:error] [pid 858085:tid 858326] [client 114.119.141.100:64927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4RDzAtbv2vrjByhUqCRAAAAG4"], referer: https://newstral.com/en/article/en/981559845/memorial-allen-fireall
[Mon Jul 20 06:14:07.194362 2026] [security2:error] [pid 843279:tid 843419] [client 45.116.69.230:61790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDmgAAAI4"]
[Mon Jul 20 06:14:07.194461 2026] [security2:error] [pid 843279:tid 843419] [client 45.116.69.230:61790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDmgAAAI4"]
[Mon Jul 20 06:14:07.290109 2026] [security2:error] [pid 843279:tid 843289] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDnwAApgg"]
[Mon Jul 20 06:14:07.290269 2026] [security2:error] [pid 843279:tid 843443] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDnwAApgg"]
[Mon Jul 20 06:14:07.377535 2026] [security2:error] [pid 843279:tid 843466] [client 57.141.18.62:27446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RC_qvKNcW5yy5T2DDKQAAvVE"]
[Mon Jul 20 06:14:07.576425 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:51531] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:07.576460 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:51531] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:07.611692 2026] [security2:error] [pid 858085:tid 858336] [client 57.141.18.41:39660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBlQAAeCo"]
[Mon Jul 20 06:14:07.840220 2026] [security2:error] [pid 843279:tid 843411] [client 14.225.17.146:52219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4RD_qvKNcW5yy5T2DDqQAAAIY"], referer: http://ncsynchro.com/WordPress
[Mon Jul 20 06:14:08.168314 2026] [security2:error] [pid 858085:tid 858262] [client 13.38.42.252:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.42.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4REDAtbv2vrjByhUqCeAAAAC4"]
[Mon Jul 20 06:14:08.186740 2026] [security2:error] [pid 843279:tid 843494] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4RDvqvKNcW5yy5T2DDiQAAANk"]
[Mon Jul 20 06:14:08.254064 2026] [security2:error] [pid 858085:tid 858156] [remote 182.77.62.24:38796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4REDAtbv2vrjByhUqChAAAFEU"]
[Mon Jul 20 06:14:08.254213 2026] [security2:error] [pid 858085:tid 858236] [client 182.77.62.24:38796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4REDAtbv2vrjByhUqChAAAFEU"]
[Mon Jul 20 06:14:08.327328 2026] [security2:error] [pid 858085:tid 858229] [client 185.132.186.76:33771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/crystal/lrs_dage.php"] [unique_id "al4REDAtbv2vrjByhUqCjwAAAA0"]
[Mon Jul 20 06:14:08.438811 2026] [security2:error] [pid 858085:tid 858310] [client 14.225.17.146:58392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4RDjAtbv2vrjByhUqCMwAAAF4"], referer: http://fluidtemple.org/WordPress
[Mon Jul 20 06:14:08.746599 2026] [security2:error] [pid 858085:tid 858264] [client 13.38.42.252:19286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.42.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4REDAtbv2vrjByhUqCpQAAADA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:14:09.498951 2026] [security2:error] [pid 843279:tid 843427] [client 14.225.17.146:51619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4REPqvKNcW5yy5T2DDtAAAAJY"], referer: http://balticsteelmgmt.com/WordPress
[Mon Jul 20 06:14:09.499429 2026] [security2:error] [pid 858085:tid 858295] [client 110.249.202.93:10450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/robots.txt"] [unique_id "al4RETAtbv2vrjByhUqCyAAAAE8"]
[Mon Jul 20 06:14:09.587566 2026] [security2:error] [pid 843279:tid 843475] [client 57.141.18.114:53448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RDfqvKNcW5yy5T2DDYwAAxh4"]
[Mon Jul 20 06:14:09.740464 2026] [security2:error] [pid 843279:tid 843310] [remote 147.50.252.213:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4REfqvKNcW5yy5T2DD3QAA7R0"]
[Mon Jul 20 06:14:09.899827 2026] [security2:error] [pid 843279:tid 843524] [client 14.225.17.146:53319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4REfqvKNcW5yy5T2DD2gAAAPY"], referer: http://grecruit.online/WordPress
[Mon Jul 20 06:14:10.203532 2026] [security2:error] [pid 843279:tid 843314] [remote 147.50.252.213:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4REvqvKNcW5yy5T2DD7wABASE"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:14:10.464176 2026] [security2:error] [pid 858085:tid 858304] [client 50.116.65.227:43686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4REjAtbv2vrjByhUqDBwAAAFg"]
[Mon Jul 20 06:14:10.477208 2026] [security2:error] [pid 858085:tid 858298] [client 50.116.65.227:52852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4REjAtbv2vrjByhUqDCAAAAAA"]
[Mon Jul 20 06:14:10.499260 2026] [security2:error] [pid 858085:tid 858269] [client 104.234.53.71:33271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4REjAtbv2vrjByhUqDAwAAADU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:10.932879 2026] [security2:error] [pid 858085:tid 858339] [client 14.225.17.146:60778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4REjAtbv2vrjByhUqDEwAAAHs"], referer: http://thefriendlyspreadsheet.com/WordPress
[Mon Jul 20 06:14:10.999091 2026] [security2:error] [pid 843279:tid 843419] [client 14.225.17.146:51471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4REfqvKNcW5yy5T2DD0QAAAI4"], referer: http://bigwormfishing.com/WordPress
[Mon Jul 20 06:14:11.249816 2026] [security2:error] [pid 858085:tid 858232] [client 185.132.186.96:21549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/pdf.php"] [unique_id "al4REzAtbv2vrjByhUqDJwAAABA"]
[Mon Jul 20 06:14:11.304112 2026] [security2:error] [pid 843279:tid 843445] [client 27.96.94.195:38243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEFgAAAKg"]
[Mon Jul 20 06:14:11.304262 2026] [security2:error] [pid 843279:tid 843445] [client 27.96.94.195:38243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEFgAAAKg"]
[Mon Jul 20 06:14:11.352160 2026] [security2:error] [pid 858085:tid 858228] [client 14.225.17.146:53357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4RETAtbv2vrjByhUqC3gAAAAw"], referer: http://idigress.group/WordPress
[Mon Jul 20 06:14:11.406251 2026] [security2:error] [pid 858085:tid 858302] [client 43.205.139.3:40696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4REzAtbv2vrjByhUqDMgAAAFY"]
[Mon Jul 20 06:14:11.406359 2026] [security2:error] [pid 858085:tid 858302] [client 43.205.139.3:40696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4REzAtbv2vrjByhUqDMgAAAFY"]
[Mon Jul 20 06:14:11.495503 2026] [security2:error] [pid 843279:tid 843457] [client 14.225.17.146:62746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4RE_qvKNcW5yy5T2DEIAAAALQ"], referer: http://friendlyspreadsheet.com/WordPress
[Mon Jul 20 06:14:11.589139 2026] [security2:error] [pid 858085:tid 858327] [client 14.225.17.146:60628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4REzAtbv2vrjByhUqDOwAAAG8"], referer: http://nikkidesigns.net/WordPress
[Mon Jul 20 06:14:11.677447 2026] [security2:error] [pid 843279:tid 843429] [client 103.77.203.233:57069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEJAAAAJg"]
[Mon Jul 20 06:14:11.677598 2026] [security2:error] [pid 843279:tid 843429] [client 103.77.203.233:57069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEJAAAAJg"]
[Mon Jul 20 06:14:11.770016 2026] [security2:error] [pid 858085:tid 858338] [client 57.141.18.43:32396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RDzAtbv2vrjByhUqCUgAAeg0"]
[Mon Jul 20 06:14:11.913811 2026] [security2:error] [pid 858085:tid 858226] [client 57.141.18.2:29390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RDzAtbv2vrjByhUqCVgAACgE"]
[Mon Jul 20 06:14:11.978822 2026] [security2:error] [pid 858085:tid 858341] [client 14.225.17.146:60753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4REzAtbv2vrjByhUqDSgAAAH0"], referer: https://bigwormfishing.com/WordPress
[Mon Jul 20 06:14:12.310224 2026] [security2:error] [pid 858085:tid 858342] [client 57.141.18.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RFDAtbv2vrjByhUqDXQAAAH4"]
[Mon Jul 20 06:14:12.418279 2026] [security2:error] [pid 843279:tid 843518] [client 57.141.18.100:59250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RD_qvKNcW5yy5T2DDsQAA8DM"]
[Mon Jul 20 06:14:12.674485 2026] [security2:error] [pid 858085:tid 858318] [client 14.225.17.146:60494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4RFDAtbv2vrjByhUqDhAAAAGY"], referer: https://friendlyspreadsheet.com/WordPress
[Mon Jul 20 06:14:13.048168 2026] [security2:error] [pid 858085:tid 858237] [client 185.132.186.75:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/as.php"] [unique_id "al4RFTAtbv2vrjByhUqDsAAAABU"]
[Mon Jul 20 06:14:13.236913 2026] [security2:error] [pid 858085:tid 858329] [client 57.141.18.105:38894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REDAtbv2vrjByhUqCqQAAcTs"]
[Mon Jul 20 06:14:13.299387 2026] [security2:error] [pid 858085:tid 858249] [client 57.141.18.68:23040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REDAtbv2vrjByhUqCtgAAIV8"]
[Mon Jul 20 06:14:14.073684 2026] [security2:error] [pid 858085:tid 858230] [client 181.224.94.124:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RFjAtbv2vrjByhUqD8wAAAA4"]
[Mon Jul 20 06:14:14.073808 2026] [security2:error] [pid 858085:tid 858230] [client 181.224.94.124:61200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RFjAtbv2vrjByhUqD8wAAAA4"]
[Mon Jul 20 06:14:14.473115 2026] [security2:error] [pid 858085:tid 858087] [remote 57.141.18.82:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4RFjAtbv2vrjByhUqEDAAAZQA"]
[Mon Jul 20 06:14:14.847815 2026] [security2:error] [pid 858085:tid 858256] [client 185.132.186.91:61889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/item.php"] [unique_id "al4RFjAtbv2vrjByhUqEJgAAACg"]
[Mon Jul 20 06:14:15.152726 2026] [security2:error] [pid 843279:tid 843449] [client 171.60.139.123:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RF_qvKNcW5yy5T2DEcQAAAKw"]
[Mon Jul 20 06:14:15.152921 2026] [security2:error] [pid 843279:tid 843449] [client 171.60.139.123:55286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RF_qvKNcW5yy5T2DEcQAAAKw"]
[Mon Jul 20 06:14:15.239004 2026] [security2:error] [pid 843279:tid 843421] [client 57.141.18.103:37238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REvqvKNcW5yy5T2DEBAAAkEs"]
[Mon Jul 20 06:14:15.370166 2026] [security2:error] [pid 858085:tid 858301] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqEOgAAAFU"]
[Mon Jul 20 06:14:15.504489 2026] [security2:error] [pid 858085:tid 858323] [client 49.13.163.121:47037] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4RFTAtbv2vrjByhUqD7AAAAGs"]
[Mon Jul 20 06:14:15.658343 2026] [security2:error] [pid 843279:tid 843484] [client 57.141.18.114:53458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RE_qvKNcW5yy5T2DEEAAAzxk"]
[Mon Jul 20 06:14:15.678055 2026] [security2:error] [pid 858085:tid 858250] [client 14.225.17.146:64547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4RFjAtbv2vrjByhUqD_gAAACI"], referer: http://inspirespublishing.com/WordPress
[Mon Jul 20 06:14:15.753849 2026] [security2:error] [pid 858085:tid 858223] [client 14.225.17.146:61433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqEQQAAAAc"], referer: http://aljosour-alarabia.com/WordPress
[Mon Jul 20 06:14:15.794557 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.45:43838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REzAtbv2vrjByhUqDKQAACUI"]
[Mon Jul 20 06:14:15.853371 2026] [security2:error] [pid 858085:tid 858175] [remote 152.228.213.32:40540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RFzAtbv2vrjByhUqEXwAAD1g"]
[Mon Jul 20 06:14:15.898862 2026] [security2:error] [pid 858085:tid 858245] [client 14.225.17.146:62913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqETwAAAB0"], referer: http://worbals.com/WordPress
[Mon Jul 20 06:14:16.013109 2026] [security2:error] [pid 858085:tid 858111] [remote 193.70.112.205:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4RFzAtbv2vrjByhUqEaAAAEhg"]
[Mon Jul 20 06:14:16.048540 2026] [security2:error] [pid 858085:tid 858195] [remote 152.228.213.32:40540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RGDAtbv2vrjByhUqEcAAATWw"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:14:16.512970 2026] [security2:error] [pid 858085:tid 858310] [client 106.192.104.4:52950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEigAAAF4"]
[Mon Jul 20 06:14:16.513103 2026] [security2:error] [pid 858085:tid 858310] [client 106.192.104.4:52950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEigAAAF4"]
[Mon Jul 20 06:14:16.522984 2026] [security2:error] [pid 858085:tid 858204] [remote 193.70.112.205:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4RGDAtbv2vrjByhUqEjAAAanU"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:14:16.600008 2026] [security2:error] [pid 843279:tid 843450] [client 14.225.17.146:64492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4RF_qvKNcW5yy5T2DEcgAAAK0"], referer: http://dadanetnet.net/WordPress
[Mon Jul 20 06:14:16.645137 2026] [security2:error] [pid 858085:tid 858222] [client 185.132.186.67:52955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/wp-conflg.php"] [unique_id "al4RGDAtbv2vrjByhUqEkwAAAAY"]
[Mon Jul 20 06:14:16.645889 2026] [security2:error] [pid 843279:tid 843533] [client 41.173.37.102:9722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RGPqvKNcW5yy5T2DEkAAAAP8"]
[Mon Jul 20 06:14:16.645996 2026] [security2:error] [pid 843279:tid 843533] [client 41.173.37.102:9722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RGPqvKNcW5yy5T2DEkAAAAP8"]
[Mon Jul 20 06:14:16.808416 2026] [security2:error] [pid 858085:tid 858320] [client 57.141.18.69:47288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFDAtbv2vrjByhUqDbQAAaGI"]
[Mon Jul 20 06:14:16.892860 2026] [security2:error] [pid 858085:tid 858334] [client 14.225.17.146:61554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4RGDAtbv2vrjByhUqEngAAAHY"], referer: http://solkeetw.com/WordPress
[Mon Jul 20 06:14:16.901627 2026] [security2:error] [pid 858085:tid 858163] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEpQAATkw"]
[Mon Jul 20 06:14:16.901824 2026] [security2:error] [pid 858085:tid 858294] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEpQAATkw"]
[Mon Jul 20 06:14:16.944694 2026] [security2:error] [pid 843279:tid 843448] [client 14.225.17.146:62706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4RGPqvKNcW5yy5T2DEjgAAAKs"], referer: http://healthylifegourmet.org/WordPress
[Mon Jul 20 06:14:17.070641 2026] [security2:error] [pid 843279:tid 843513] [client 57.141.18.57:31124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFPqvKNcW5yy5T2DEPQAA6wU"]
[Mon Jul 20 06:14:17.211937 2026] [security2:error] [pid 843279:tid 843437] [client 103.141.108.143:65291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEnAAAAKA"]
[Mon Jul 20 06:14:17.212980 2026] [security2:error] [pid 843279:tid 843437] [client 103.141.108.143:65291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEnAAAAKA"]
[Mon Jul 20 06:14:17.719266 2026] [security2:error] [pid 858085:tid 858302] [client 50.116.65.227:52966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RGTAtbv2vrjByhUqE0gAAAFY"]
[Mon Jul 20 06:14:17.730635 2026] [security2:error] [pid 858085:tid 858230] [client 50.116.65.227:52974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RGTAtbv2vrjByhUqE1AAAAA4"]
[Mon Jul 20 06:14:17.796031 2026] [security2:error] [pid 858085:tid 858301] [client 112.213.160.112:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE2wAAAFU"]
[Mon Jul 20 06:14:17.796165 2026] [security2:error] [pid 858085:tid 858301] [client 112.213.160.112:8663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE2wAAAFU"]
[Mon Jul 20 06:14:17.813065 2026] [security2:error] [pid 843279:tid 843473] [client 45.116.69.230:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEpQAAAMQ"]
[Mon Jul 20 06:14:17.813248 2026] [security2:error] [pid 843279:tid 843473] [client 45.116.69.230:62312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEpQAAAMQ"]
[Mon Jul 20 06:14:17.977844 2026] [security2:error] [pid 858085:tid 858162] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE4QAAEUs"]
[Mon Jul 20 06:14:17.977965 2026] [security2:error] [pid 858085:tid 858233] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE4QAAEUs"]
[Mon Jul 20 06:14:18.064065 2026] [security2:error] [pid 858085:tid 858253] [client 65.1.132.125:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RGjAtbv2vrjByhUqE5QAAACU"]
[Mon Jul 20 06:14:18.064194 2026] [security2:error] [pid 858085:tid 858253] [client 65.1.132.125:56258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RGjAtbv2vrjByhUqE5QAAACU"]
[Mon Jul 20 06:14:18.067730 2026] [security2:error] [pid 843279:tid 843338] [remote 173.249.4.11:31029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4RGvqvKNcW5yy5T2DEqAAAsTk"]
[Mon Jul 20 06:14:18.199919 2026] [security2:error] [pid 858085:tid 858336] [client 50.116.65.227:43694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RGjAtbv2vrjByhUqE6AAAAHg"]
[Mon Jul 20 06:14:18.212446 2026] [security2:error] [pid 858085:tid 858261] [client 50.116.65.227:52986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RGjAtbv2vrjByhUqE6wAAAC0"]
[Mon Jul 20 06:14:18.414644 2026] [security2:error] [pid 843279:tid 843404] [remote 173.249.4.11:31029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4RGvqvKNcW5yy5T2DEuAAA7Xs"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:14:18.425281 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.77:24566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFTAtbv2vrjByhUqD2AAAKX4"]
[Mon Jul 20 06:14:18.451199 2026] [security2:error] [pid 858085:tid 858269] [client 185.132.186.86:44657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/install.php"] [unique_id "al4RGjAtbv2vrjByhUqE9wAAADU"]
[Mon Jul 20 06:14:18.468100 2026] [security2:error] [pid 843279:tid 843485] [client 14.225.17.146:64667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4RGfqvKNcW5yy5T2DElwAAANA"], referer: http://chestermonty.com/WordPress
[Mon Jul 20 06:14:18.799237 2026] [security2:error] [pid 858085:tid 858216] [client 57.141.18.95:21428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFjAtbv2vrjByhUqD9AAAAD0"]
[Mon Jul 20 06:14:19.333309 2026] [security2:error] [pid 843279:tid 843490] [client 57.141.18.25:43468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFvqvKNcW5yy5T2DEXgAA1XQ"]
[Mon Jul 20 06:14:19.364627 2026] [core:error] [pid 843279:tid 843532] [client 205.210.31.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:19.364653 2026] [core:error] [pid 843279:tid 843532] [client 205.210.31.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:19.404690 2026] [security2:error] [pid 858085:tid 858222] [client 14.225.17.146:52064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFKAAAAAY"], referer: https://chestermonty.com/WordPress
[Mon Jul 20 06:14:19.491953 2026] [security2:error] [pid 858085:tid 858260] [client 27.96.94.195:37957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RGzAtbv2vrjByhUqFMQAAACw"]
[Mon Jul 20 06:14:19.492073 2026] [security2:error] [pid 858085:tid 858260] [client 27.96.94.195:37957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RGzAtbv2vrjByhUqFMQAAACw"]
[Mon Jul 20 06:14:19.522936 2026] [security2:error] [pid 858085:tid 858278] [client 14.225.17.146:54213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFMAAAAD4"], referer: http://grndl.com/WordPress
[Mon Jul 20 06:14:20.243539 2026] [security2:error] [pid 858085:tid 858217] [client 185.132.186.91:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/db.php"] [unique_id "al4RHDAtbv2vrjByhUqFZgAAAAE"]
[Mon Jul 20 06:14:20.717149 2026] [security2:error] [pid 858085:tid 858290] [client 57.141.18.29:31628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqEYgAASg0"]
[Mon Jul 20 06:14:20.891121 2026] [security2:error] [pid 843279:tid 843422] [client 32.193.54.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koaconsultants.com"] [uri "/index.php"] [unique_id "al4RHPqvKNcW5yy5T2DE4QAAAJE"]
[Mon Jul 20 06:14:21.090630 2026] [security2:error] [pid 843279:tid 843519] [client 13.201.64.214:41942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RHfqvKNcW5yy5T2DE7wAAAPE"]
[Mon Jul 20 06:14:21.090756 2026] [security2:error] [pid 843279:tid 843519] [client 13.201.64.214:41942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RHfqvKNcW5yy5T2DE7wAAAPE"]
[Mon Jul 20 06:14:21.380028 2026] [security2:error] [pid 843279:tid 843367] [remote 57.141.18.69:32858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4RHfqvKNcW5yy5T2DE_gAAqVY"]
[Mon Jul 20 06:14:21.615769 2026] [security2:error] [pid 858085:tid 858328] [client 104.234.53.91:31023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RHTAtbv2vrjByhUqFpAAAAHA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:21.946209 2026] [security2:error] [pid 858085:tid 858173] [remote 111.225.149.201:38310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/map-comments-october-30-2021-predeadline.pdf"] [unique_id "al4RHTAtbv2vrjByhUqFvAAAKVY"]
[Mon Jul 20 06:14:21.952926 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.61:35578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGTAtbv2vrjByhUqEvwAADWM"]
[Mon Jul 20 06:14:22.045553 2026] [security2:error] [pid 858085:tid 858232] [client 185.132.186.103:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/fan.php"] [unique_id "al4RHjAtbv2vrjByhUqFxQAAABA"]
[Mon Jul 20 06:14:22.340196 2026] [security2:error] [pid 858085:tid 858301] [client 13.201.64.214:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RHjAtbv2vrjByhUqF3QAAAFU"]
[Mon Jul 20 06:14:22.340274 2026] [security2:error] [pid 858085:tid 858301] [client 13.201.64.214:41954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RHjAtbv2vrjByhUqF3QAAAFU"]
[Mon Jul 20 06:14:22.355207 2026] [security2:error] [pid 858085:tid 858314] [client 104.234.53.91:31023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RHjAtbv2vrjByhUqF3AAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:22.360865 2026] [security2:error] [pid 843279:tid 843426] [client 103.77.203.233:57612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RHvqvKNcW5yy5T2DFDwAAAJU"]
[Mon Jul 20 06:14:22.361189 2026] [security2:error] [pid 843279:tid 843426] [client 103.77.203.233:57612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RHvqvKNcW5yy5T2DFDwAAAJU"]
[Mon Jul 20 06:14:22.673290 2026] [security2:error] [pid 858085:tid 858194] [remote 216.73.216.55:47397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4RHjAtbv2vrjByhUqF9wAAGWs"]
[Mon Jul 20 06:14:22.787916 2026] [security2:error] [pid 858085:tid 858228] [client 57.141.18.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqF9gAAAAw"]
[Mon Jul 20 06:14:23.405912 2026] [core:error] [pid 858085:tid 858336] [client 185.253.160.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:23.405945 2026] [core:error] [pid 858085:tid 858336] [client 185.253.160.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:23.649133 2026] [security2:error] [pid 858085:tid 858240] [client 57.141.18.8:55240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFGgAAGFc"]
[Mon Jul 20 06:14:23.831041 2026] [security2:error] [pid 858085:tid 858319] [client 57.141.18.58:59100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFJQAAZzw"]
[Mon Jul 20 06:14:23.839596 2026] [security2:error] [pid 858085:tid 858296] [client 185.132.186.100:49047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/colors.php"] [unique_id "al4RHzAtbv2vrjByhUqGhgAAAFA"]
[Mon Jul 20 06:14:24.190683 2026] [security2:error] [pid 858085:tid 858263] [client 57.141.18.58:59104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFQQAALxY"]
[Mon Jul 20 06:14:24.337851 2026] [security2:error] [pid 858085:tid 858264] [client 14.225.17.146:51236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqF-AAAADA"], referer: http://vinovinhowine.com/WordPress
[Mon Jul 20 06:14:24.610984 2026] [security2:error] [pid 858085:tid 858245] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4RIDAtbv2vrjByhUqG1AAAAB0"], referer: https://www.google.com/
[Mon Jul 20 06:14:24.611737 2026] [security2:error] [pid 858085:tid 858265] [client 181.224.94.124:22861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RIDAtbv2vrjByhUqG1QAAADE"]
[Mon Jul 20 06:14:24.611828 2026] [security2:error] [pid 858085:tid 858265] [client 181.224.94.124:22861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RIDAtbv2vrjByhUqG1QAAADE"]
[Mon Jul 20 06:14:24.643056 2026] [security2:error] [pid 858085:tid 858252] [client 14.225.17.146:64135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4RIDAtbv2vrjByhUqGxQAAACQ"], referer: http://ksands.co.uk/WordPress
[Mon Jul 20 06:14:24.752966 2026] [security2:error] [pid 858085:tid 858233] [client 104.234.53.56:48813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RIDAtbv2vrjByhUqG2AAAABE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:25.017557 2026] [security2:error] [pid 858085:tid 858327] [client 177.4.176.37:28123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4RIDAtbv2vrjByhUqG5QAAAG8"]
[Mon Jul 20 06:14:25.222715 2026] [security2:error] [pid 858085:tid 858301] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4RITAtbv2vrjByhUqHCgAAAFU"], referer: https://www.google.com/
[Mon Jul 20 06:14:25.307730 2026] [security2:error] [pid 843279:tid 843315] [remote 57.141.18.119:20822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHfqvKNcW5yy5T2DE7gAA2yI"]
[Mon Jul 20 06:14:25.598181 2026] [security2:error] [pid 858085:tid 858327] [client 74.208.214.194:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RITAtbv2vrjByhUqHJAAAAG8"]
[Mon Jul 20 06:14:25.621596 2026] [security2:error] [pid 858085:tid 858242] [client 50.116.65.227:58056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4RITAtbv2vrjByhUqHJgAAABo"]
[Mon Jul 20 06:14:25.632758 2026] [security2:error] [pid 858085:tid 858295] [client 50.116.65.227:53310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4RITAtbv2vrjByhUqHKgAAAE8"]
[Mon Jul 20 06:14:25.636633 2026] [security2:error] [pid 858085:tid 858241] [client 185.132.186.77:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/mah.php"] [unique_id "al4RITAtbv2vrjByhUqHKwAAABk"]
[Mon Jul 20 06:14:25.646225 2026] [security2:error] [pid 858085:tid 858273] [client 14.225.17.146:52075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGIAAAADk"], referer: http://bruceledewitz.com/WordPress
[Mon Jul 20 06:14:25.648125 2026] [security2:error] [pid 858085:tid 858261] [client 104.234.53.56:48813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RITAtbv2vrjByhUqHLAAAAC0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:25.768019 2026] [security2:error] [pid 858085:tid 858210] [remote 50.28.1.50:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4RITAtbv2vrjByhUqHPQAAD3s"]
[Mon Jul 20 06:14:25.852494 2026] [security2:error] [pid 858085:tid 858282] [client 171.60.139.123:55767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RITAtbv2vrjByhUqHQgAAAEI"]
[Mon Jul 20 06:14:25.852660 2026] [security2:error] [pid 858085:tid 858282] [client 171.60.139.123:55767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RITAtbv2vrjByhUqHQgAAAEI"]
[Mon Jul 20 06:14:26.007123 2026] [security2:error] [pid 858085:tid 858262] [client 74.7.227.151:44870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4RITAtbv2vrjByhUqHGQAALho"], referer: https://overloadcomedy.com/wp-content/uploads/essential-addons-elementor/eael-4528.js?ver=1760353471
[Mon Jul 20 06:14:26.063211 2026] [security2:error] [pid 858085:tid 858316] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4RIjAtbv2vrjByhUqHTwAAAGQ"], referer: https://duckduckgo.com/?q=px7e3
[Mon Jul 20 06:14:26.128868 2026] [security2:error] [pid 858085:tid 858273] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/passwd"] [unique_id "al4RIjAtbv2vrjByhUqHVgAAADk"], referer: https://www.bing.com/search?q=b2ad22
[Mon Jul 20 06:14:26.237296 2026] [security2:error] [pid 858085:tid 858101] [remote 50.28.1.50:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4RIjAtbv2vrjByhUqHYAAAQw4"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:14:26.275450 2026] [security2:error] [pid 858085:tid 858258] [client 104.234.53.74:45195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RIjAtbv2vrjByhUqHYwAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:26.324608 2026] [security2:error] [pid 858085:tid 858310] [client 74.7.230.3:39688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "mazzucelli.com"] [uri "/robots.txt"] [unique_id "al4RIjAtbv2vrjByhUqHaQAAAF4"]
[Mon Jul 20 06:14:26.503780 2026] [security2:error] [pid 858085:tid 858280] [client 57.141.18.35:55612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqFzwAAQEY"]
[Mon Jul 20 06:14:26.729323 2026] [security2:error] [pid 858085:tid 858230] [client 57.141.18.44:34810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqF4AAADhs"]
[Mon Jul 20 06:14:27.269690 2026] [security2:error] [pid 858085:tid 858335] [client 74.7.230.3:37476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4RIjAtbv2vrjByhUqHcwAAd3Y"]
[Mon Jul 20 06:14:27.272043 2026] [security2:error] [pid 858085:tid 858335] [client 74.7.230.3:37476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4RIjAtbv2vrjByhUqHcAAAdxE"], referer: http://mazzucelli.com/robots.txt
[Mon Jul 20 06:14:27.289872 2026] [security2:error] [pid 858085:tid 858235] [client 104.234.53.83:46807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RIzAtbv2vrjByhUqHvgAAABM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:27.298992 2026] [security2:error] [pid 858085:tid 858265] [client 41.173.37.102:10170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHwQAAADE"]
[Mon Jul 20 06:14:27.299078 2026] [security2:error] [pid 858085:tid 858265] [client 41.173.37.102:10170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHwQAAADE"]
[Mon Jul 20 06:14:27.433642 2026] [security2:error] [pid 858085:tid 858250] [client 185.132.186.66:57097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/waf_defender.php"] [unique_id "al4RIzAtbv2vrjByhUqHygAAACI"]
[Mon Jul 20 06:14:27.449402 2026] [security2:error] [pid 858085:tid 858133] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHywAAUy4"]
[Mon Jul 20 06:14:27.449569 2026] [security2:error] [pid 858085:tid 858299] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHywAAUy4"]
[Mon Jul 20 06:14:27.609886 2026] [security2:error] [pid 858085:tid 858338] [client 57.141.18.73:60120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGKQAAel8"]
[Mon Jul 20 06:14:27.748200 2026] [security2:error] [pid 858085:tid 858228] [client 57.141.18.27:51222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGLQAADH4"]
[Mon Jul 20 06:14:27.797704 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH7gAAAHU"]
[Mon Jul 20 06:14:27.797815 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:49377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH7gAAAHU"]
[Mon Jul 20 06:14:27.806744 2026] [security2:error] [pid 858085:tid 858264] [client 106.192.104.4:53493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH8QAAADA"]
[Mon Jul 20 06:14:27.806840 2026] [security2:error] [pid 858085:tid 858264] [client 106.192.104.4:53493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH8QAAADA"]
[Mon Jul 20 06:14:28.110531 2026] [security2:error] [pid 858085:tid 858243] [client 50.116.65.227:53338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RJDAtbv2vrjByhUqIDAAAABs"]
[Mon Jul 20 06:14:28.120402 2026] [security2:error] [pid 858085:tid 858329] [client 50.116.65.227:53350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RJDAtbv2vrjByhUqIDgAAAHE"]
[Mon Jul 20 06:14:28.155810 2026] [security2:error] [pid 858085:tid 858224] [client 57.141.18.14:31724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGfgAACFg"]
[Mon Jul 20 06:14:28.193441 2026] [security2:error] [pid 858085:tid 858124] [remote 100.42.189.89:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIFAAAcyU"]
[Mon Jul 20 06:14:28.259118 2026] [security2:error] [pid 858085:tid 858190] [remote 47.86.33.52:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIIQAAJmc"]
[Mon Jul 20 06:14:28.390653 2026] [security2:error] [pid 858085:tid 858187] [remote 18.61.192.253:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIKQAAU2Q"]
[Mon Jul 20 06:14:28.427491 2026] [security2:error] [pid 858085:tid 858156] [remote 100.42.189.89:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIMAAAdkU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:14:28.465165 2026] [security2:error] [pid 858085:tid 858245] [client 112.213.160.112:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqINgAAAB0"]
[Mon Jul 20 06:14:28.465272 2026] [security2:error] [pid 858085:tid 858245] [client 112.213.160.112:8291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqINgAAAB0"]
[Mon Jul 20 06:14:28.536230 2026] [security2:error] [pid 858085:tid 858316] [client 45.116.69.230:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIPAAAAGQ"]
[Mon Jul 20 06:14:28.536390 2026] [security2:error] [pid 858085:tid 858316] [client 45.116.69.230:62841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIPAAAAGQ"]
[Mon Jul 20 06:14:28.671987 2026] [security2:error] [pid 858085:tid 858273] [client 50.116.65.227:53358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqINwAAADk"]
[Mon Jul 20 06:14:28.695584 2026] [security2:error] [pid 858085:tid 858307] [client 57.141.18.22:26772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RIDAtbv2vrjByhUqGtAAAW1w"]
[Mon Jul 20 06:14:28.728579 2026] [security2:error] [pid 858085:tid 858145] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIUwAAcTo"]
[Mon Jul 20 06:14:28.728774 2026] [security2:error] [pid 858085:tid 858329] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIUwAAcTo"]
[Mon Jul 20 06:14:28.872307 2026] [security2:error] [pid 858085:tid 858115] [remote 18.61.192.253:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIYAAADRw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:14:28.918403 2026] [security2:error] [pid 858085:tid 858263] [client 50.116.65.227:53362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqITQAAAC8"]
[Mon Jul 20 06:14:28.953793 2026] [security2:error] [pid 858085:tid 858210] [remote 5.161.225.162:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIZQAABHs"]
[Mon Jul 20 06:14:28.979071 2026] [security2:error] [pid 858085:tid 858321] [client 14.225.17.146:64059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4RIzAtbv2vrjByhUqH3QAAAGk"], referer: http://cloudspacesgroup.com/WordPress
[Mon Jul 20 06:14:29.136411 2026] [security2:error] [pid 858085:tid 858167] [remote 47.86.33.52:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIbAAAWFA"], referer: https://mail.grndl.com/wp-login.php
[Mon Jul 20 06:14:29.231503 2026] [security2:error] [pid 858085:tid 858259] [client 185.132.186.88:34427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/ectoplasm/content.php"] [unique_id "al4RJTAtbv2vrjByhUqIfQAAACs"]
[Mon Jul 20 06:14:29.243885 2026] [security2:error] [pid 858085:tid 858141] [remote 5.161.225.162:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIfwAAAjY"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:14:29.271948 2026] [security2:error] [pid 858085:tid 858258] [client 14.225.17.146:60726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4RJTAtbv2vrjByhUqIegAAACo"], referer: http://daseighty.net/WordPress
[Mon Jul 20 06:14:29.274199 2026] [security2:error] [pid 858085:tid 858095] [remote 124.55.178.99:54444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIgAAARwg"]
[Mon Jul 20 06:14:29.306153 2026] [security2:error] [pid 858085:tid 858294] [client 14.225.17.146:51167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4RIzAtbv2vrjByhUqH3AAAAE4"], referer: http://superiorcopywriting.com/WordPress
[Mon Jul 20 06:14:29.653872 2026] [security2:error] [pid 858085:tid 858328] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/shadow"] [unique_id "al4RJTAtbv2vrjByhUqIoAAAAHA"], referer: https://twitter.com/
[Mon Jul 20 06:14:29.688442 2026] [security2:error] [pid 858085:tid 858131] [remote 124.55.178.99:54444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIpAAAGSw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:14:30.551030 2026] [security2:error] [pid 858085:tid 858325] [client 14.225.17.146:51020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqIZwAAAG0"], referer: http://adirondackengineering.com/WordPress
[Mon Jul 20 06:14:30.649388 2026] [security2:error] [pid 858085:tid 858152] [remote 72.167.132.114:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJjAtbv2vrjByhUqI5AAAZ0E"]
[Mon Jul 20 06:14:30.733569 2026] [security2:error] [pid 858085:tid 858258] [client 27.96.94.195:37865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI7wAAACo"]
[Mon Jul 20 06:14:30.733720 2026] [security2:error] [pid 858085:tid 858258] [client 27.96.94.195:37865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI7wAAACo"]
[Mon Jul 20 06:14:30.736713 2026] [security2:error] [pid 858085:tid 858217] [client 178.152.178.232:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI8AAAAAE"]
[Mon Jul 20 06:14:30.736829 2026] [security2:error] [pid 858085:tid 858217] [client 178.152.178.232:36567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI8AAAAAE"]
[Mon Jul 20 06:14:30.767294 2026] [security2:error] [pid 858085:tid 858270] [client 34.201.171.57:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4RJjAtbv2vrjByhUqI1AAAADY"]
[Mon Jul 20 06:14:30.770509 2026] [security2:error] [pid 858085:tid 858286] [client 34.201.171.57:59210] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-stuffed-shells-caracoles-rellenos"] [unique_id "al4RJjAtbv2vrjByhUqIzQAAAEY"]
[Mon Jul 20 06:14:30.813436 2026] [security2:error] [pid 858085:tid 858278] [client 14.225.17.146:50098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4RJjAtbv2vrjByhUqI4wAAAD4"], referer: http://partnerselectricalllc.com/WordPress
[Mon Jul 20 06:14:30.899034 2026] [core:error] [pid 858085:tid 858252] [client 158.173.74.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:30.899057 2026] [core:error] [pid 858085:tid 858252] [client 158.173.74.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:30.916645 2026] [security2:error] [pid 858085:tid 858195] [remote 72.167.132.114:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJjAtbv2vrjByhUqJAgAAXmw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:14:31.025617 2026] [security2:error] [pid 858085:tid 858251] [client 185.132.186.79:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/install.php"] [unique_id "al4RJzAtbv2vrjByhUqJDQAAACM"]
[Mon Jul 20 06:14:31.091884 2026] [security2:error] [pid 858085:tid 858238] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/hosts"] [unique_id "al4RJzAtbv2vrjByhUqJEQAAABY"], referer: https://www.google.com/search?q=roehh4
[Mon Jul 20 06:14:31.896651 2026] [security2:error] [pid 858085:tid 858207] [remote 20.153.140.50:60860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJzAtbv2vrjByhUqJUwAAZ3g"]
[Mon Jul 20 06:14:31.988593 2026] [security2:error] [pid 858085:tid 858203] [remote 45.90.123.233:38430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4RJzAtbv2vrjByhUqJXAAANHQ"]
[Mon Jul 20 06:14:32.000378 2026] [security2:error] [pid 858085:tid 858272] [client 103.153.183.69:45262] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//....//proc/self/environ"] [unique_id "al4RJzAtbv2vrjByhUqJXwAAADg"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:14:32.195819 2026] [security2:error] [pid 858085:tid 858159] [remote 45.90.123.233:38430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4RKDAtbv2vrjByhUqJbQAAXUg"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:14:32.432649 2026] [security2:error] [pid 858085:tid 858311] [client 57.141.18.125:42930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RIzAtbv2vrjByhUqH0QAAX2I"]
[Mon Jul 20 06:14:32.434162 2026] [security2:error] [pid 858085:tid 858315] [client 181.123.115.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJawAAAGM"]
[Mon Jul 20 06:14:32.448110 2026] [security2:error] [pid 858085:tid 858165] [remote 20.153.140.50:60860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RKDAtbv2vrjByhUqJiAAACE4"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:14:32.821348 2026] [security2:error] [pid 858085:tid 858234] [client 185.132.186.77:25453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/thickbox/about.php"] [unique_id "al4RKDAtbv2vrjByhUqJowAAABI"]
[Mon Jul 20 06:14:32.891007 2026] [security2:error] [pid 858085:tid 858320] [client 110.249.202.27:40156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4RKDAtbv2vrjByhUqJqgAAAGg"]
[Mon Jul 20 06:14:32.905669 2026] [security2:error] [pid 858085:tid 858218] [client 103.77.203.233:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RKDAtbv2vrjByhUqJqwAAAAI"]
[Mon Jul 20 06:14:32.905802 2026] [security2:error] [pid 858085:tid 858218] [client 103.77.203.233:58160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RKDAtbv2vrjByhUqJqwAAAAI"]
[Mon Jul 20 06:14:33.060187 2026] [security2:error] [pid 858085:tid 858283] [client 74.208.214.194:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RKTAtbv2vrjByhUqJtQAAAEM"]
[Mon Jul 20 06:14:33.200423 2026] [security2:error] [pid 858085:tid 858249] [client 57.141.18.60:41596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqIMwAAIW4"]
[Mon Jul 20 06:14:33.280503 2026] [security2:error] [pid 858085:tid 858286] [client 3.149.57.90:24828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJnAAAAEY"], referer: https://windowtx.com
[Mon Jul 20 06:14:33.364709 2026] [security2:error] [pid 858085:tid 858329] [client 65.1.132.125:16604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RKTAtbv2vrjByhUqJzQAAAHE"]
[Mon Jul 20 06:14:33.364857 2026] [security2:error] [pid 858085:tid 858329] [client 65.1.132.125:16604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RKTAtbv2vrjByhUqJzQAAAHE"]
[Mon Jul 20 06:14:33.466290 2026] [security2:error] [pid 858085:tid 858311] [client 103.153.183.69:10532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4RKTAtbv2vrjByhUqJ1QAAAF8"], referer: https://www.google.com/search?q=9vaucj
[Mon Jul 20 06:14:33.622068 2026] [security2:error] [pid 858085:tid 858281] [client 103.153.183.69:10532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4RKTAtbv2vrjByhUqJ4AAAAEE"], referer: https://www.facebook.com/
[Mon Jul 20 06:14:34.158597 2026] [security2:error] [pid 858085:tid 858096] [remote 18.61.192.253:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4RKjAtbv2vrjByhUqKFAAAIQk"]
[Mon Jul 20 06:14:34.280622 2026] [security2:error] [pid 858085:tid 858267] [client 57.141.18.32:60350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJTAtbv2vrjByhUqIjwAAMzg"]
[Mon Jul 20 06:14:34.532190 2026] [security2:error] [pid 858085:tid 858260] [client 100.26.198.54:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4RKTAtbv2vrjByhUqJ8AAAACw"]
[Mon Jul 20 06:14:34.543594 2026] [security2:error] [pid 858085:tid 858253] [client 100.26.198.54:40438] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-stuffed-shells-caracoles-rellenos/"] [unique_id "al4RKTAtbv2vrjByhUqJ5AAAACU"]
[Mon Jul 20 06:14:34.631427 2026] [security2:error] [pid 858085:tid 858224] [client 185.132.186.73:56559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/content.php"] [unique_id "al4RKjAtbv2vrjByhUqKLwAAAAg"]
[Mon Jul 20 06:14:34.641359 2026] [security2:error] [pid 858085:tid 858116] [remote 18.61.192.253:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4RKjAtbv2vrjByhUqKMAAAZR0"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:14:34.720969 2026] [security2:error] [pid 858085:tid 858308] [client 57.141.18.15:65236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJTAtbv2vrjByhUqItgAAXBs"]
[Mon Jul 20 06:14:34.874628 2026] [security2:error] [pid 858085:tid 858218] [client 50.116.65.227:10090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2025/02/IMG_9124.jpeg"] [unique_id "al4RKjAtbv2vrjByhUqKRwAAAFQ"]
[Mon Jul 20 06:14:35.107809 2026] [security2:error] [pid 858085:tid 858338] [client 181.224.94.124:51191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RKzAtbv2vrjByhUqKZAAAAHo"]
[Mon Jul 20 06:14:35.107920 2026] [security2:error] [pid 858085:tid 858338] [client 181.224.94.124:51191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RKzAtbv2vrjByhUqKZAAAAHo"]
[Mon Jul 20 06:14:35.177210 2026] [security2:error] [pid 858085:tid 858218] [client 50.116.65.227:21770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RKzAtbv2vrjByhUqKcQAAAAI"]
[Mon Jul 20 06:14:35.191773 2026] [security2:error] [pid 858085:tid 858279] [client 50.116.65.227:10138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RKzAtbv2vrjByhUqKdQAAAD8"]
[Mon Jul 20 06:14:35.230873 2026] [security2:error] [pid 858085:tid 858206] [remote 72.167.132.114:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4RKzAtbv2vrjByhUqKeQAACnc"]
[Mon Jul 20 06:14:35.445105 2026] [security2:error] [pid 858085:tid 858203] [remote 72.167.132.114:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4RKzAtbv2vrjByhUqKjgAAK3Q"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:14:35.833221 2026] [security2:error] [pid 858085:tid 858334] [client 57.141.18.46:31482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJzAtbv2vrjByhUqJFAAAdjA"]
[Mon Jul 20 06:14:35.847713 2026] [security2:error] [pid 858085:tid 858257] [client 103.112.236.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RKzAtbv2vrjByhUqKlAAAKTo"]
[Mon Jul 20 06:14:36.097218 2026] [security2:error] [pid 858085:tid 858276] [client 57.141.18.56:51022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJzAtbv2vrjByhUqJLwAAPGk"]
[Mon Jul 20 06:14:36.429406 2026] [security2:error] [pid 858085:tid 858221] [client 185.132.186.86:49561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/icascreenshots.php"] [unique_id "al4RLDAtbv2vrjByhUqK6AAAAAU"]
[Mon Jul 20 06:14:36.449775 2026] [security2:error] [pid 858085:tid 858304] [client 158.173.166.181:58187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RLDAtbv2vrjByhUqK6QAAAFg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:36.528804 2026] [security2:error] [pid 858085:tid 858274] [client 171.60.139.123:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RLDAtbv2vrjByhUqK8QAAADo"]
[Mon Jul 20 06:14:36.528920 2026] [security2:error] [pid 858085:tid 858274] [client 171.60.139.123:56252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RLDAtbv2vrjByhUqK8QAAADo"]
[Mon Jul 20 06:14:36.821875 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:55992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4RLDAtbv2vrjByhUqK9wAAADY"]
[Mon Jul 20 06:14:36.831244 2026] [security2:error] [pid 858085:tid 858328] [client 45.157.112.60:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RLDAtbv2vrjByhUqLBQAAAHA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:36.880723 2026] [security2:error] [pid 858085:tid 858248] [client 57.141.18.74:43846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJagAAIH0"]
[Mon Jul 20 06:14:37.059586 2026] [security2:error] [pid 858085:tid 858288] [client 57.141.18.95:30266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJewAASHs"]
[Mon Jul 20 06:14:37.342196 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.56:51032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJkAAAHAg"]
[Mon Jul 20 06:14:37.877196 2026] [security2:error] [pid 858085:tid 858218] [client 50.116.65.227:10172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RLTAtbv2vrjByhUqLZgAAAAI"]
[Mon Jul 20 06:14:37.889540 2026] [security2:error] [pid 858085:tid 858283] [client 50.116.65.227:10186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RLTAtbv2vrjByhUqLZwAAAEM"]
[Mon Jul 20 06:14:37.990199 2026] [security2:error] [pid 858085:tid 858100] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLTAtbv2vrjByhUqLbAAABA0"]
[Mon Jul 20 06:14:37.990348 2026] [security2:error] [pid 858085:tid 858220] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLTAtbv2vrjByhUqLbAAABA0"]
[Mon Jul 20 06:14:38.016909 2026] [security2:error] [pid 858085:tid 858236] [client 41.173.37.102:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLcAAAABQ"]
[Mon Jul 20 06:14:38.017038 2026] [security2:error] [pid 858085:tid 858236] [client 41.173.37.102:10623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLcAAAABQ"]
[Mon Jul 20 06:14:38.225129 2026] [security2:error] [pid 858085:tid 858277] [client 106.192.104.4:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLiAAAAD0"]
[Mon Jul 20 06:14:38.225251 2026] [security2:error] [pid 858085:tid 858277] [client 106.192.104.4:53957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLiAAAAD0"]
[Mon Jul 20 06:14:38.233113 2026] [security2:error] [pid 858085:tid 858330] [client 185.132.186.67:30959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/bypass.php"] [unique_id "al4RLjAtbv2vrjByhUqLiQAAAHI"]
[Mon Jul 20 06:14:38.455579 2026] [security2:error] [pid 858085:tid 858258] [client 103.141.108.143:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLnQAAACo"]
[Mon Jul 20 06:14:38.456139 2026] [security2:error] [pid 858085:tid 858258] [client 103.141.108.143:49868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLnQAAACo"]
[Mon Jul 20 06:14:38.858930 2026] [security2:error] [pid 858085:tid 858339] [client 47.128.122.122:25006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLswAAe0Q"]
[Mon Jul 20 06:14:39.029019 2026] [security2:error] [pid 858085:tid 858297] [client 14.225.17.146:54698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLxAAAAFE"], referer: http://dereckcastellon.com/WordPress
[Mon Jul 20 06:14:39.176596 2026] [security2:error] [pid 858085:tid 858298] [client 45.116.69.230:63363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1AAAAFI"]
[Mon Jul 20 06:14:39.176682 2026] [security2:error] [pid 858085:tid 858298] [client 45.116.69.230:63363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1AAAAFI"]
[Mon Jul 20 06:14:39.217215 2026] [security2:error] [pid 858085:tid 858307] [client 112.213.160.112:31145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1wAAAFs"]
[Mon Jul 20 06:14:39.217330 2026] [security2:error] [pid 858085:tid 858307] [client 112.213.160.112:31145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1wAAAFs"]
[Mon Jul 20 06:14:39.234809 2026] [security2:error] [pid 858085:tid 858299] [client 57.141.18.19:36714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKjAtbv2vrjByhUqKJgAAU34"]
[Mon Jul 20 06:14:39.239376 2026] [security2:error] [pid 858085:tid 858331] [client 57.141.18.6:61170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKjAtbv2vrjByhUqKJQAAc1Y"]
[Mon Jul 20 06:14:39.538177 2026] [security2:error] [pid 858085:tid 858168] [remote 162.19.86.63:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RLzAtbv2vrjByhUqL9AAAGFE"]
[Mon Jul 20 06:14:39.730764 2026] [security2:error] [pid 858085:tid 858214] [remote 162.19.86.63:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RLzAtbv2vrjByhUqMAQAAcn8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:14:39.845995 2026] [security2:error] [pid 858085:tid 858102] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqMEQAAUg8"]
[Mon Jul 20 06:14:39.846159 2026] [security2:error] [pid 858085:tid 858298] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqMEQAAUg8"]
[Mon Jul 20 06:14:40.037853 2026] [security2:error] [pid 858085:tid 858267] [client 57.141.18.94:27438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKzAtbv2vrjByhUqKcgAAM0M"]
[Mon Jul 20 06:14:40.043382 2026] [security2:error] [pid 858085:tid 858238] [client 185.132.186.67:35795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rk2.php"] [unique_id "al4RMDAtbv2vrjByhUqMGwAAABY"]
[Mon Jul 20 06:14:40.271365 2026] [security2:error] [pid 858085:tid 858302] [client 66.249.73.200:39832] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.grant-mechanical.com"] [uri "/robots.txt"] [unique_id "al4RMDAtbv2vrjByhUqMKQAAAFY"]
[Mon Jul 20 06:14:40.794727 2026] [security2:error] [pid 858085:tid 858257] [client 14.225.17.146:62329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4RLzAtbv2vrjByhUqL0AAAACk"], referer: http://according2plant.com/WordPress
[Mon Jul 20 06:14:41.140703 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:54792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4RMDAtbv2vrjByhUqMZgAAABk"]
[Mon Jul 20 06:14:41.251368 2026] [security2:error] [pid 858085:tid 858152] [remote 97.74.93.24:34456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4RMTAtbv2vrjByhUqMfQAAX0E"]
[Mon Jul 20 06:14:41.595796 2026] [security2:error] [pid 858085:tid 858331] [client 178.152.178.232:36326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RMTAtbv2vrjByhUqMmwAAAHM"]
[Mon Jul 20 06:14:41.595892 2026] [security2:error] [pid 858085:tid 858331] [client 178.152.178.232:36326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RMTAtbv2vrjByhUqMmwAAAHM"]
[Mon Jul 20 06:14:41.735238 2026] [security2:error] [pid 858085:tid 858244] [client 52.109.124.141:12320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4RMTAtbv2vrjByhUqMpAAAABw"]
[Mon Jul 20 06:14:41.853030 2026] [security2:error] [pid 858085:tid 858264] [client 185.132.186.66:64203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/ocean/alam.php"] [unique_id "al4RMTAtbv2vrjByhUqMsAAAADA"]
[Mon Jul 20 06:14:41.934371 2026] [security2:error] [pid 858085:tid 858306] [client 52.109.124.141:12320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4RMTAtbv2vrjByhUqMuAAAAFo"]
[Mon Jul 20 06:14:41.953812 2026] [security2:error] [pid 858085:tid 858200] [remote 97.74.93.24:34456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4RMTAtbv2vrjByhUqMugAAVHE"], referer: https://mail.sk-financial.com/wp-login.php
[Mon Jul 20 06:14:41.956355 2026] [security2:error] [pid 858085:tid 858258] [client 14.225.17.146:61883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4RMDAtbv2vrjByhUqMMAAAACo"], referer: http://omenana.com/WordPress
[Mon Jul 20 06:14:42.052917 2026] [security2:error] [pid 858085:tid 858243] [client 57.141.18.5:58198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLTAtbv2vrjByhUqLKAAAGxg"]
[Mon Jul 20 06:14:42.177970 2026] [security2:error] [pid 858085:tid 858260] [client 52.59.238.198:22212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqMygAAACw"]
[Mon Jul 20 06:14:42.215270 2026] [security2:error] [pid 858085:tid 858223] [client 14.225.17.146:59055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4RMDAtbv2vrjByhUqMRQAAAAc"], referer: http://margaretspeckogawa.com/WordPress
[Mon Jul 20 06:14:42.320160 2026] [security2:error] [pid 858085:tid 858234] [client 57.141.18.37:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLTAtbv2vrjByhUqLRAAAEl8"]
[Mon Jul 20 06:14:42.329560 2026] [security2:error] [pid 858085:tid 858270] [client 52.111.227.28:33026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4RMjAtbv2vrjByhUqM1wAAADY"]
[Mon Jul 20 06:14:42.411245 2026] [security2:error] [pid 858085:tid 858221] [client 52.111.227.28:33026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4RMjAtbv2vrjByhUqM4QAAAAU"]
[Mon Jul 20 06:14:42.459039 2026] [security2:error] [pid 858085:tid 858171] [remote 95.217.78.234:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqM5gAAP1Q"]
[Mon Jul 20 06:14:42.696253 2026] [security2:error] [pid 858085:tid 858147] [remote 95.217.78.234:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqM-AAAMzw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:14:42.763638 2026] [security2:error] [pid 858085:tid 858287] [client 34.34.225.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earle-brown.org"] [uri "/index.php"] [unique_id "al4RLzAtbv2vrjByhUqMGgAARy0"]
[Mon Jul 20 06:14:42.768557 2026] [security2:error] [pid 858085:tid 858236] [client 63.179.149.246:42650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqM_AAAABQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:14:42.892228 2026] [security2:error] [pid 858085:tid 858217] [client 50.116.65.227:22596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RMjAtbv2vrjByhUqNCgAAAAE"]
[Mon Jul 20 06:14:42.904652 2026] [security2:error] [pid 858085:tid 858322] [client 50.116.65.227:50620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RMjAtbv2vrjByhUqNCwAAAGo"]
[Mon Jul 20 06:14:43.198955 2026] [security2:error] [pid 858085:tid 858090] [remote 34.34.225.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earle-brown.org"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNFAAAcQM"]
[Mon Jul 20 06:14:43.269742 2026] [security2:error] [pid 858085:tid 858290] [client 14.225.17.146:59160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4RMTAtbv2vrjByhUqMsQAAAEo"], referer: http://blaizeaccountingservices.com/WordPress
[Mon Jul 20 06:14:43.487183 2026] [security2:error] [pid 858085:tid 858337] [client 103.77.203.233:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RMzAtbv2vrjByhUqNNQAAAHk"]
[Mon Jul 20 06:14:43.487312 2026] [security2:error] [pid 858085:tid 858337] [client 103.77.203.233:58935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RMzAtbv2vrjByhUqNNQAAAHk"]
[Mon Jul 20 06:14:43.551633 2026] [security2:error] [pid 858085:tid 858281] [client 57.141.18.106:64896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLugAAQQc"]
[Mon Jul 20 06:14:43.649568 2026] [security2:error] [pid 858085:tid 858221] [client 185.132.186.100:42767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/b.php"] [unique_id "al4RMzAtbv2vrjByhUqNSAAAAAU"]
[Mon Jul 20 06:14:43.668224 2026] [security2:error] [pid 858085:tid 858287] [client 14.225.17.146:64010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNPAAAAEc"], referer: http://nextlevelpressurewashing.com/WordPress
[Mon Jul 20 06:14:43.719253 2026] [security2:error] [pid 858085:tid 858224] [client 14.225.17.146:65048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNRwAAAAg"]
[Mon Jul 20 06:14:43.738099 2026] [security2:error] [pid 858085:tid 858249] [client 57.141.18.116:53442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLyAAAIT8"]
[Mon Jul 20 06:14:44.156501 2026] [security2:error] [pid 858085:tid 858287] [client 185.192.69.16:33231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/000.php"] [unique_id "al4RNDAtbv2vrjByhUqNcgAAAEc"]
[Mon Jul 20 06:14:44.196189 2026] [security2:error] [pid 858085:tid 858183] [remote 173.249.4.11:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNeAAAGWA"]
[Mon Jul 20 06:14:44.251566 2026] [security2:error] [pid 858085:tid 858248] [client 3.109.4.218:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNeQAAACA"]
[Mon Jul 20 06:14:44.251744 2026] [security2:error] [pid 858085:tid 858248] [client 3.109.4.218:56006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNeQAAACA"]
[Mon Jul 20 06:14:44.423362 2026] [security2:error] [pid 858085:tid 858212] [remote 152.228.213.32:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNjAAAV30"]
[Mon Jul 20 06:14:44.504172 2026] [security2:error] [pid 858085:tid 858233] [client 14.225.17.146:64004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNgAAAABE"], referer: http://secretkeynumerology.com/WordPress
[Mon Jul 20 06:14:44.606031 2026] [security2:error] [pid 858085:tid 858264] [client 185.192.69.22:21193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-admin/css/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNmAAAADA"]
[Mon Jul 20 06:14:44.618280 2026] [security2:error] [pid 858085:tid 858210] [remote 152.228.213.32:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNmQAAf3s"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:14:44.664604 2026] [security2:error] [pid 858085:tid 858268] [client 27.96.94.195:38099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNoAAAADQ"]
[Mon Jul 20 06:14:44.665833 2026] [security2:error] [pid 858085:tid 858268] [client 27.96.94.195:38099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNoAAAADQ"]
[Mon Jul 20 06:14:44.686007 2026] [security2:error] [pid 858085:tid 858099] [remote 152.53.111.131:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNogAALgw"]
[Mon Jul 20 06:14:44.862848 2026] [security2:error] [pid 858085:tid 858274] [client 14.225.17.146:54582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNjQAAADo"], referer: http://backandneckpainrelieflaceychiropractor.com/WordPress
[Mon Jul 20 06:14:44.930612 2026] [security2:error] [pid 858085:tid 858164] [remote 152.53.111.131:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNuwAAJU0"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 06:14:45.054962 2026] [security2:error] [pid 858085:tid 858343] [client 185.192.69.32:35773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-content/plugins/index.php"] [unique_id "al4RNTAtbv2vrjByhUqNyQAAAH8"]
[Mon Jul 20 06:14:45.128055 2026] [security2:error] [pid 858085:tid 858296] [client 98.159.234.160:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RNTAtbv2vrjByhUqN0wAAAFA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:45.244682 2026] [security2:error] [pid 858085:tid 858186] [remote 173.249.4.11:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RNTAtbv2vrjByhUqN3AAAEmM"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 06:14:45.459863 2026] [security2:error] [pid 858085:tid 858223] [client 185.132.186.72:26889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/past.php"] [unique_id "al4RNTAtbv2vrjByhUqN9QAAAAc"]
[Mon Jul 20 06:14:45.527201 2026] [security2:error] [pid 858085:tid 858218] [client 14.225.17.146:50772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RNTAtbv2vrjByhUqN6wAAAAI"], referer: https://secretkeynumerology.com/WordPress
[Mon Jul 20 06:14:45.549485 2026] [security2:error] [pid 858085:tid 858225] [client 185.192.69.18:22033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-content/index.php"] [unique_id "al4RNTAtbv2vrjByhUqOAQAAAAk"]
[Mon Jul 20 06:14:45.601342 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:36105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RNTAtbv2vrjByhUqOAwAAAEo"]
[Mon Jul 20 06:14:45.601499 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:36105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RNTAtbv2vrjByhUqOAwAAAEo"]
[Mon Jul 20 06:14:45.916015 2026] [security2:error] [pid 858085:tid 858142] [remote 57.141.18.30:65178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5942486"] [unique_id "al4RNTAtbv2vrjByhUqOGwAAGzc"]
[Mon Jul 20 06:14:46.004792 2026] [security2:error] [pid 858085:tid 858269] [client 185.192.69.28:62055] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4RNjAtbv2vrjByhUqOHwAAADU"]
[Mon Jul 20 06:14:46.039275 2026] [security2:error] [pid 858085:tid 858237] [client 14.225.17.146:62402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNoQAAABU"], referer: http://momheadquarters.com/WordPress
[Mon Jul 20 06:14:46.530531 2026] [security2:error] [pid 858085:tid 858273] [client 14.225.17.146:49357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4RNTAtbv2vrjByhUqN_QAAADk"], referer: http://ancestralidadytrance.space/WordPress
[Mon Jul 20 06:14:46.663391 2026] [security2:error] [pid 858085:tid 858292] [client 158.173.89.95:31269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RNjAtbv2vrjByhUqOVgAAAEw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:46.769256 2026] [security2:error] [pid 858085:tid 858173] [remote 157.66.26.183:44856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RNjAtbv2vrjByhUqOXQAAcVY"]
[Mon Jul 20 06:14:46.769478 2026] [security2:error] [pid 858085:tid 858329] [client 157.66.26.183:44856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RNjAtbv2vrjByhUqOXQAAcVY"]
[Mon Jul 20 06:14:47.212562 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.80:36582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RMjAtbv2vrjByhUqM3AAADXU"]
[Mon Jul 20 06:14:47.242616 2026] [security2:error] [pid 858085:tid 858262] [client 171.60.139.123:56737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RNzAtbv2vrjByhUqOhgAAAC4"]
[Mon Jul 20 06:14:47.242764 2026] [security2:error] [pid 858085:tid 858262] [client 171.60.139.123:56737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RNzAtbv2vrjByhUqOhgAAAC4"]
[Mon Jul 20 06:14:47.263021 2026] [security2:error] [pid 858085:tid 858236] [client 185.132.186.58:44555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/as.php"] [unique_id "al4RNzAtbv2vrjByhUqOiAAAABQ"]
[Mon Jul 20 06:14:47.305885 2026] [security2:error] [pid 858085:tid 858250] [client 57.141.18.45:40212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RMjAtbv2vrjByhUqM5QAAImE"]
[Mon Jul 20 06:14:47.417901 2026] [security2:error] [pid 858085:tid 858238] [client 50.116.65.227:50696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RNzAtbv2vrjByhUqOlAAAABY"]
[Mon Jul 20 06:14:47.427297 2026] [security2:error] [pid 858085:tid 858288] [client 50.116.65.227:50706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RNzAtbv2vrjByhUqOlgAAAEg"]
[Mon Jul 20 06:14:47.820931 2026] [security2:error] [pid 858085:tid 858102] [remote 5.161.225.162:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4RNzAtbv2vrjByhUqOvgAAGg8"]
[Mon Jul 20 06:14:47.821131 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:63828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4RNzAtbv2vrjByhUqOmgAAABk"]
[Mon Jul 20 06:14:47.938836 2026] [security2:error] [pid 858085:tid 858098] [remote 81.173.115.7:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RNzAtbv2vrjByhUqOxAAAVQs"]
[Mon Jul 20 06:14:47.983795 2026] [security2:error] [pid 858085:tid 858136] [remote 57.141.18.74:41256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5326337"] [unique_id "al4RNzAtbv2vrjByhUqOxQAAPDE"]
[Mon Jul 20 06:14:48.122993 2026] [security2:error] [pid 858085:tid 858197] [remote 81.173.115.7:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RODAtbv2vrjByhUqO0AAAG24"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:14:48.263847 2026] [security2:error] [pid 858085:tid 858222] [client 52.167.144.166:57306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daseighty.net"] [uri "/gallery/main.php"] [unique_id "al4RODAtbv2vrjByhUqO3AAAAAY"]
[Mon Jul 20 06:14:48.421810 2026] [security2:error] [pid 858085:tid 858320] [client 114.119.154.65:36129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toddnielsen.com"] [uri "/virtual-ceocoo-service/"] [unique_id "al4RODAtbv2vrjByhUqO6AAAAGg"], referer: http://toddnielsen.com/leadership-traits-2/leadership-trait-to-ponder-simplicity
[Mon Jul 20 06:14:48.572856 2026] [security2:error] [pid 858085:tid 858241] [client 41.173.37.102:11069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO9AAAABk"]
[Mon Jul 20 06:14:48.572948 2026] [security2:error] [pid 858085:tid 858241] [client 41.173.37.102:11069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO9AAAABk"]
[Mon Jul 20 06:14:48.650506 2026] [security2:error] [pid 858085:tid 858198] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO-QAAWG8"]
[Mon Jul 20 06:14:48.650744 2026] [security2:error] [pid 858085:tid 858304] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO-QAAWG8"]
[Mon Jul 20 06:14:48.784033 2026] [security2:error] [pid 858085:tid 858280] [client 104.234.53.52:33875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RODAtbv2vrjByhUqO_AAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:48.850394 2026] [security2:error] [pid 858085:tid 858112] [remote 152.228.213.32:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqPEgAAXBk"]
[Mon Jul 20 06:14:48.850533 2026] [security2:error] [pid 858085:tid 858308] [client 152.228.213.32:52170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqPEgAAXBk"]
[Mon Jul 20 06:14:49.038167 2026] [security2:error] [pid 858085:tid 858295] [client 104.234.53.52:33875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ROTAtbv2vrjByhUqPJQAAAE8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:49.066908 2026] [security2:error] [pid 858085:tid 858342] [client 185.132.186.102:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/sst.php"] [unique_id "al4ROTAtbv2vrjByhUqPKQAAAH4"]
[Mon Jul 20 06:14:49.144024 2026] [security2:error] [pid 858085:tid 858271] [client 46.110.96.34:18088] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4ROTAtbv2vrjByhUqPLgAAADc"]
[Mon Jul 20 06:14:49.147979 2026] [security2:error] [pid 858085:tid 858288] [client 103.141.108.143:50347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPMAAAAEg"]
[Mon Jul 20 06:14:49.148627 2026] [security2:error] [pid 858085:tid 858288] [client 103.141.108.143:50347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPMAAAAEg"]
[Mon Jul 20 06:14:49.355792 2026] [security2:error] [pid 858085:tid 858340] [client 14.225.17.146:57204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqO3QAAAHw"], referer: http://getgarrison.com/WordPress
[Mon Jul 20 06:14:49.441037 2026] [security2:error] [pid 858085:tid 858275] [client 57.141.18.113:21940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNXwAAO0A"]
[Mon Jul 20 06:14:49.784730 2026] [security2:error] [pid 858085:tid 858317] [client 45.116.69.230:63898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPXwAAAGU"]
[Mon Jul 20 06:14:49.784837 2026] [security2:error] [pid 858085:tid 858317] [client 45.116.69.230:63898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPXwAAAGU"]
[Mon Jul 20 06:14:49.960473 2026] [security2:error] [pid 858085:tid 858260] [client 112.213.160.112:8553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPbQAAACw"]
[Mon Jul 20 06:14:49.960605 2026] [security2:error] [pid 858085:tid 858260] [client 112.213.160.112:8553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPbQAAACw"]
[Mon Jul 20 06:14:50.034145 2026] [security2:error] [pid 858085:tid 858281] [client 57.141.18.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ROTAtbv2vrjByhUqPagAAAEE"]
[Mon Jul 20 06:14:50.069853 2026] [security2:error] [pid 858085:tid 858187] [remote 5.161.225.162:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ROjAtbv2vrjByhUqPdgAAQ2Q"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:14:50.093506 2026] [security2:error] [pid 858085:tid 858156] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4ROjAtbv2vrjByhUqPegAAakU"]
[Mon Jul 20 06:14:50.339142 2026] [security2:error] [pid 858085:tid 858119] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4ROjAtbv2vrjByhUqPkQAAciA"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 06:14:50.406079 2026] [security2:error] [pid 858085:tid 858339] [client 106.192.104.4:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlAAAAHs"]
[Mon Jul 20 06:14:50.406179 2026] [security2:error] [pid 858085:tid 858339] [client 106.192.104.4:54496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlAAAAHs"]
[Mon Jul 20 06:14:50.518103 2026] [security2:error] [pid 858085:tid 858159] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlwAABkg"]
[Mon Jul 20 06:14:50.518248 2026] [security2:error] [pid 858085:tid 858222] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlwAABkg"]
[Mon Jul 20 06:14:50.807702 2026] [security2:error] [pid 858085:tid 858224] [client 57.141.18.63:64848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNvgAACFs"]
[Mon Jul 20 06:14:50.875351 2026] [security2:error] [pid 858085:tid 858324] [client 185.132.186.62:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/edit-tags.php"] [unique_id "al4ROjAtbv2vrjByhUqPtAAAAGw"]
[Mon Jul 20 06:14:51.220601 2026] [security2:error] [pid 858085:tid 858121] [remote 78.46.157.202:35796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqPzAAAWCI"]
[Mon Jul 20 06:14:51.433616 2026] [security2:error] [pid 858085:tid 858089] [remote 78.46.157.202:35796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP4wAAAAI"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:14:51.454395 2026] [security2:error] [pid 858085:tid 858326] [client 57.141.18.114:23990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNTAtbv2vrjByhUqN_AAAbnI"]
[Mon Jul 20 06:14:51.511081 2026] [security2:error] [pid 858085:tid 858087] [remote 152.228.213.32:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP5wAAUAA"]
[Mon Jul 20 06:14:51.511303 2026] [security2:error] [pid 858085:tid 858253] [client 50.116.65.227:57810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ROzAtbv2vrjByhUqP6QAAACU"]
[Mon Jul 20 06:14:51.522961 2026] [security2:error] [pid 858085:tid 858236] [client 50.116.65.227:34620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ROzAtbv2vrjByhUqP6gAAAGE"]
[Mon Jul 20 06:14:51.642816 2026] [security2:error] [pid 858085:tid 858312] [client 27.96.94.195:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ROzAtbv2vrjByhUqP7wAAAGA"]
[Mon Jul 20 06:14:51.643595 2026] [security2:error] [pid 858085:tid 858312] [client 27.96.94.195:37194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ROzAtbv2vrjByhUqP7wAAAGA"]
[Mon Jul 20 06:14:51.671373 2026] [security2:error] [pid 858085:tid 858098] [remote 167.233.114.32:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP8wAAZws"]
[Mon Jul 20 06:14:51.716377 2026] [security2:error] [pid 858085:tid 858193] [remote 152.228.213.32:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP9wAAdWo"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:14:51.876702 2026] [security2:error] [pid 858085:tid 858106] [remote 167.233.114.32:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqQCAAAIxM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:14:52.146104 2026] [security2:error] [pid 858085:tid 858299] [client 14.225.17.146:54519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4ROjAtbv2vrjByhUqPtgAAAFM"], referer: http://christiancountytrumpet.com/WordPress
[Mon Jul 20 06:14:52.449501 2026] [security2:error] [pid 858085:tid 858223] [client 57.141.18.92:63312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNjAtbv2vrjByhUqOQgAAB0Q"]
[Mon Jul 20 06:14:52.455046 2026] [security2:error] [pid 858085:tid 858310] [client 57.141.18.3:63888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNjAtbv2vrjByhUqOQQAAXiM"]
[Mon Jul 20 06:14:52.676327 2026] [security2:error] [pid 858085:tid 858276] [client 185.132.186.71:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wsax.php"] [unique_id "al4RPDAtbv2vrjByhUqQSAAAADw"]
[Mon Jul 20 06:14:52.724920 2026] [security2:error] [pid 858085:tid 858301] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4RPDAtbv2vrjByhUqQTwAAAFU"]
[Mon Jul 20 06:14:52.774223 2026] [security2:error] [pid 858085:tid 858309] [client 70.115.45.82:43988] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4RPDAtbv2vrjByhUqQSgAAAF0"]
[Mon Jul 20 06:14:52.809276 2026] [security2:error] [pid 858085:tid 858305] [client 57.141.18.95:40538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNjAtbv2vrjByhUqOZgAAWXk"]
[Mon Jul 20 06:14:52.914551 2026] [security2:error] [pid 858085:tid 858258] [client 57.141.18.83:64508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNzAtbv2vrjByhUqOcwAAKjo"]
[Mon Jul 20 06:14:53.001551 2026] [core:error] [pid 858085:tid 858283] [client 79.127.181.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:53.001579 2026] [core:error] [pid 858085:tid 858283] [client 79.127.181.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:53.086704 2026] [security2:error] [pid 858085:tid 858342] [client 104.234.53.63:57319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RPDAtbv2vrjByhUqQZQAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:53.374103 2026] [security2:error] [pid 858085:tid 858149] [remote 117.0.21.154:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQhgAAQT4"]
[Mon Jul 20 06:14:53.445626 2026] [security2:error] [pid 858085:tid 858250] [client 57.141.18.65:29260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNzAtbv2vrjByhUqOrgAAIlU"]
[Mon Jul 20 06:14:53.467842 2026] [security2:error] [pid 858085:tid 858132] [remote 5.161.225.162:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQmQAAdy0"]
[Mon Jul 20 06:14:53.719632 2026] [security2:error] [pid 858085:tid 858334] [client 14.225.17.146:63954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4RPTAtbv2vrjByhUqQeQAAAHY"]
[Mon Jul 20 06:14:53.878030 2026] [security2:error] [pid 858085:tid 858213] [remote 117.0.21.154:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQuwAAf34"], referer: https://mail.holistichealthmassagenz.com/wp-login.php
[Mon Jul 20 06:14:53.895119 2026] [security2:error] [pid 858085:tid 858148] [remote 5.161.225.162:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQvAAAHD0"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:14:53.959714 2026] [security2:error] [pid 858085:tid 858242] [client 57.141.18.4:62366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqO3gAAGgw"]
[Mon Jul 20 06:14:53.963891 2026] [security2:error] [pid 858085:tid 858159] [remote 72.167.132.114:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQxAAAW0g"]
[Mon Jul 20 06:14:54.033037 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RPjAtbv2vrjByhUqQywAAADo"]
[Mon Jul 20 06:14:54.033450 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:59584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RPjAtbv2vrjByhUqQywAAADo"]
[Mon Jul 20 06:14:54.174982 2026] [security2:error] [pid 858085:tid 858330] [client 85.204.70.96:33812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4RPjAtbv2vrjByhUqQzgAAAHI"]
[Mon Jul 20 06:14:54.200525 2026] [security2:error] [pid 858085:tid 858234] [client 57.141.18.14:38384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqO6QAAEhc"]
[Mon Jul 20 06:14:54.358805 2026] [security2:error] [pid 858085:tid 858262] [client 14.224.227.113:55614] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4RPjAtbv2vrjByhUqQ3wAAAC4"]
[Mon Jul 20 06:14:54.397706 2026] [security2:error] [pid 858085:tid 858192] [remote 72.167.132.114:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RPjAtbv2vrjByhUqQ4gAAf2k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:14:54.460035 2026] [security2:error] [pid 858085:tid 858236] [client 85.204.70.96:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.karimnawfal.com"] [uri "/xmlrpc.php"] [unique_id "al4RPjAtbv2vrjByhUqQ6QAAABQ"]
[Mon Jul 20 06:14:54.475583 2026] [security2:error] [pid 858085:tid 858302] [client 185.132.186.77:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/bless.php%20"] [unique_id "al4RPjAtbv2vrjByhUqQ7AAAAFY"]
[Mon Jul 20 06:14:54.549076 2026] [security2:error] [pid 858085:tid 858328] [client 57.141.18.76:36068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqPJAAAcE8"]
[Mon Jul 20 06:14:54.805966 2026] [security2:error] [pid 858085:tid 858246] [client 14.225.17.146:57380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqRAwAAAB4"], referer: http://dasmarque.com/WordPress
[Mon Jul 20 06:14:55.014646 2026] [security2:error] [pid 858085:tid 858296] [client 85.204.70.96:33826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqRHAAAAFA"]
[Mon Jul 20 06:14:55.034437 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.0:63952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROTAtbv2vrjByhUqPVgAAKTs"]
[Mon Jul 20 06:14:55.186400 2026] [security2:error] [pid 858085:tid 858258] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqRBwAAACo"]
[Mon Jul 20 06:14:55.236257 2026] [security2:error] [pid 858085:tid 858219] [client 178.152.178.232:36065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqRNQAAAAM"]
[Mon Jul 20 06:14:55.236450 2026] [security2:error] [pid 858085:tid 858219] [client 178.152.178.232:36065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqRNQAAAAM"]
[Mon Jul 20 06:14:55.276585 2026] [security2:error] [pid 858085:tid 858220] [client 43.205.139.3:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqROQAAAAQ"]
[Mon Jul 20 06:14:55.276705 2026] [security2:error] [pid 858085:tid 858220] [client 43.205.139.3:36822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqROQAAAAQ"]
[Mon Jul 20 06:14:55.286330 2026] [security2:error] [pid 858085:tid 858277] [client 85.204.70.96:33836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqROwAAAD0"]
[Mon Jul 20 06:14:55.352826 2026] [security2:error] [pid 858085:tid 858341] [client 57.141.18.90:36100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROjAtbv2vrjByhUqPcwAAfVw"]
[Mon Jul 20 06:14:55.489390 2026] [security2:error] [pid 858085:tid 858293] [client 74.7.227.179:53194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RPzAtbv2vrjByhUqRQgAATVk"], referer: https://tejasenvironmental.com/p=141246
[Mon Jul 20 06:14:55.491816 2026] [security2:error] [pid 858085:tid 858327] [client 70.115.45.82:44506] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/2025/12/23/the-last-fisher-of-oporoza-by-tomilola-adejumo/"] [unique_id "al4RPjAtbv2vrjByhUqQ_wAAAG8"]
[Mon Jul 20 06:14:55.545329 2026] [security2:error] [pid 858085:tid 858320] [client 85.204.70.96:33852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqRUwAAAGg"]
[Mon Jul 20 06:14:55.693454 2026] [security2:error] [pid 858085:tid 858337] [client 44.245.170.32:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4RPzAtbv2vrjByhUqRYAAAAHk"]
[Mon Jul 20 06:14:55.790543 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:65347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4RPTAtbv2vrjByhUqQegAAADY"], referer: http://drewsasburyparkbeachhouse.com/WordPress
[Mon Jul 20 06:14:55.816117 2026] [security2:error] [pid 858085:tid 858330] [client 85.204.70.96:33866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqRZQAAAHI"]
[Mon Jul 20 06:14:56.011132 2026] [security2:error] [pid 858085:tid 858280] [client 3.75.183.99:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRdAAAAEA"]
[Mon Jul 20 06:14:56.081714 2026] [security2:error] [pid 858085:tid 858323] [client 85.204.70.96:33876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqReAAAAGs"]
[Mon Jul 20 06:14:56.146333 2026] [security2:error] [pid 858085:tid 858325] [client 181.224.94.124:46889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRegAAAG0"]
[Mon Jul 20 06:14:56.146464 2026] [security2:error] [pid 858085:tid 858325] [client 181.224.94.124:46889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRegAAAG0"]
[Mon Jul 20 06:14:56.208453 2026] [security2:error] [pid 858085:tid 858282] [client 14.225.17.146:56436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqQ5AAAAEI"], referer: http://qualitycoatingsinspection.com/WordPress
[Mon Jul 20 06:14:56.231925 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.44:42952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROzAtbv2vrjByhUqPygAADRo"]
[Mon Jul 20 06:14:56.289267 2026] [security2:error] [pid 858085:tid 858234] [client 185.132.186.67:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/system_cache.php"] [unique_id "al4RQDAtbv2vrjByhUqRgwAAABI"]
[Mon Jul 20 06:14:56.337019 2026] [security2:error] [pid 858085:tid 858241] [client 104.234.53.63:57319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRhwAAABk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:56.348788 2026] [security2:error] [pid 858085:tid 858310] [client 85.204.70.96:33886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqRiQAAAF4"]
[Mon Jul 20 06:14:56.436325 2026] [security2:error] [pid 858085:tid 858240] [client 57.141.18.74:37178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROzAtbv2vrjByhUqP2wAAGEY"]
[Mon Jul 20 06:14:56.583997 2026] [security2:error] [pid 858085:tid 858329] [client 63.179.149.246:24052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRpAAAAHE"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:14:56.584646 2026] [security2:error] [pid 858085:tid 858251] [client 51.161.37.89:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "technicalseohouse.com"] [uri "/sitemap_index.xml"] [unique_id "al4RQDAtbv2vrjByhUqRogAAACM"]
[Mon Jul 20 06:14:56.596430 2026] [security2:error] [pid 858085:tid 858327] [client 51.161.37.89:15684] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "technicalseohouse.com"] [uri "/sitemap_index.xml"] [unique_id "al4RQDAtbv2vrjByhUqRnQAAbxg"]
[Mon Jul 20 06:14:56.623019 2026] [security2:error] [pid 858085:tid 858312] [client 85.204.70.96:33902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqRqAAAAGA"]
[Mon Jul 20 06:14:56.716688 2026] [security2:error] [pid 858085:tid 858339] [client 82.156.3.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RQDAtbv2vrjByhUqRmAAAexk"]
[Mon Jul 20 06:14:56.803687 2026] [security2:error] [pid 858085:tid 858149] [remote 100.42.189.89:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRtAAAJT4"]
[Mon Jul 20 06:14:56.803812 2026] [security2:error] [pid 858085:tid 858253] [client 100.42.189.89:39364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRtAAAJT4"]
[Mon Jul 20 06:14:56.896221 2026] [security2:error] [pid 858085:tid 858281] [client 85.204.70.96:33908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqRwgAAAEE"]
[Mon Jul 20 06:14:56.929496 2026] [security2:error] [pid 858085:tid 858276] [client 104.234.53.48:39133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRxgAAADw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:56.950433 2026] [security2:error] [pid 858085:tid 858249] [client 51.161.37.89:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "technicalseohouse.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RQDAtbv2vrjByhUqRwwAAACE"]
[Mon Jul 20 06:14:56.951958 2026] [security2:error] [pid 858085:tid 858216] [client 57.141.18.89:33910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROzAtbv2vrjByhUqQBwAAAHs"]
[Mon Jul 20 06:14:56.955723 2026] [security2:error] [pid 858085:tid 858254] [client 51.161.37.89:15696] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "technicalseohouse.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RQDAtbv2vrjByhUqRvwAAJmc"]
[Mon Jul 20 06:14:56.981455 2026] [autoindex:error] [pid 858085:tid 858240] [client 198.235.24.40:59316] AH01276: Cannot serve directory /home3/represh9/public_html/representgrace/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://representgrace.representgrace.com/
[Mon Jul 20 06:14:57.037847 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.037873 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.116937 2026] [security2:error] [pid 858085:tid 858242] [client 14.225.17.146:63948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4RPzAtbv2vrjByhUqRQAAAABo"], referer: http://outlookturf.com/WordPress
[Mon Jul 20 06:14:57.166198 2026] [security2:error] [pid 858085:tid 858234] [client 14.225.17.146:65253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4RQTAtbv2vrjByhUqRzwAAABI"], referer: https://qualitycoatingsinspection.com/WordPress
[Mon Jul 20 06:14:57.190582 2026] [core:error] [pid 858085:tid 858276] [client 14.225.17.146:54933] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.190607 2026] [core:error] [pid 858085:tid 858276] [client 14.225.17.146:54933] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.193581 2026] [security2:error] [pid 858085:tid 858305] [client 85.204.70.96:33922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqR4QAAAFk"]
[Mon Jul 20 06:14:57.343563 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.343580 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.343637 2026] [core:error] [pid 858085:tid 858325] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.343650 2026] [core:error] [pid 858085:tid 858325] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.459178 2026] [security2:error] [pid 858085:tid 858235] [client 85.204.70.96:33924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqR_gAAABM"]
[Mon Jul 20 06:14:57.467014 2026] [autoindex:error] [pid 858085:tid 858256] [client 91.90.122.10:19844] AH01276: Cannot serve directory /home3/kybxxpmy/public_html/website_0ad88c1f/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:14:57.538321 2026] [security2:error] [pid 858085:tid 858159] [remote 100.42.189.89:39386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RQTAtbv2vrjByhUqSBgAAR0g"]
[Mon Jul 20 06:14:57.538449 2026] [security2:error] [pid 858085:tid 858287] [client 100.42.189.89:39386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RQTAtbv2vrjByhUqSBgAAR0g"]
[Mon Jul 20 06:14:57.718689 2026] [security2:error] [pid 858085:tid 858223] [client 85.204.70.96:33926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqSFAAAAAc"]
[Mon Jul 20 06:14:57.988330 2026] [security2:error] [pid 858085:tid 858234] [client 85.204.70.96:33936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqSKgAAABI"]
[Mon Jul 20 06:14:58.090803 2026] [security2:error] [pid 858085:tid 858313] [client 185.132.186.63:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/files.php"] [unique_id "al4RQjAtbv2vrjByhUqSNwAAAGE"]
[Mon Jul 20 06:14:58.156841 2026] [security2:error] [pid 858085:tid 858273] [client 171.60.139.123:57228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RQjAtbv2vrjByhUqSPQAAADk"]
[Mon Jul 20 06:14:58.156963 2026] [security2:error] [pid 858085:tid 858273] [client 171.60.139.123:57228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RQjAtbv2vrjByhUqSPQAAADk"]
[Mon Jul 20 06:14:58.254455 2026] [security2:error] [pid 858085:tid 858322] [client 85.204.70.96:33948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4RQjAtbv2vrjByhUqSTAAAAGo"]
[Mon Jul 20 06:14:58.315981 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.55:44546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPTAtbv2vrjByhUqQbgAABUA"]
[Mon Jul 20 06:14:58.527649 2026] [security2:error] [pid 858085:tid 858248] [client 85.204.70.96:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4RQjAtbv2vrjByhUqSWQAAACA"]
[Mon Jul 20 06:14:58.608147 2026] [security2:error] [pid 858085:tid 858229] [client 14.225.17.146:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4RQjAtbv2vrjByhUqSVQAAAA0"], referer: http://betterbonddogtraining.com/WordPress
[Mon Jul 20 06:14:58.800535 2026] [security2:error] [pid 858085:tid 858221] [client 85.204.70.96:33962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4RQjAtbv2vrjByhUqSawAAAAU"]
[Mon Jul 20 06:14:58.850201 2026] [security2:error] [pid 858085:tid 858103] [remote 57.141.18.37:27032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6349154"] [unique_id "al4RQjAtbv2vrjByhUqSbwAAcxA"]
[Mon Jul 20 06:14:59.066945 2026] [security2:error] [pid 858085:tid 858326] [client 85.204.70.96:33968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4RQzAtbv2vrjByhUqSggAAAG4"]
[Mon Jul 20 06:14:59.090804 2026] [core:error] [pid 858085:tid 858228] [client 205.210.31.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:59.090826 2026] [core:error] [pid 858085:tid 858228] [client 205.210.31.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:59.170632 2026] [security2:error] [pid 858085:tid 858230] [client 41.173.37.102:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSjQAAAA4"]
[Mon Jul 20 06:14:59.170735 2026] [security2:error] [pid 858085:tid 858230] [client 41.173.37.102:11526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSjQAAAA4"]
[Mon Jul 20 06:14:59.193337 2026] [security2:error] [pid 858085:tid 858106] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSkwAACBM"]
[Mon Jul 20 06:14:59.193537 2026] [security2:error] [pid 858085:tid 858224] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSkwAACBM"]
[Mon Jul 20 06:14:59.223052 2026] [security2:error] [pid 858085:tid 858096] [remote 113.160.142.119:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4RQzAtbv2vrjByhUqSmAAATQk"]
[Mon Jul 20 06:14:59.446561 2026] [security2:error] [pid 858085:tid 858227] [client 57.141.18.49:22278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqQzAAACwc"]
[Mon Jul 20 06:14:59.478960 2026] [security2:error] [pid 858085:tid 858320] [client 104.234.53.64:23661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RQzAtbv2vrjByhUqSpwAAAGg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:59.501119 2026] [security2:error] [pid 858085:tid 858286] [client 14.225.17.146:55141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4RQzAtbv2vrjByhUqSnQAAAEY"], referer: http://thesoloceos.com/WordPress
[Mon Jul 20 06:14:59.735520 2026] [security2:error] [pid 858085:tid 858322] [client 85.208.96.194:30344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4RQzAtbv2vrjByhUqSvQAAAGo"]
[Mon Jul 20 06:14:59.735626 2026] [security2:error] [pid 858085:tid 858322] [client 85.208.96.194:30344] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4RQzAtbv2vrjByhUqSvQAAAGo"]
[Mon Jul 20 06:14:59.749498 2026] [security2:error] [pid 858085:tid 858240] [client 65.1.132.125:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RQzAtbv2vrjByhUqSwwAAABg"]
[Mon Jul 20 06:14:59.870494 2026] [security2:error] [pid 858085:tid 858229] [client 103.141.108.143:50831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSywAAAA0"]
[Mon Jul 20 06:14:59.871854 2026] [security2:error] [pid 858085:tid 858229] [client 103.141.108.143:50831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSywAAAA0"]
[Mon Jul 20 06:14:59.893810 2026] [security2:error] [pid 858085:tid 858320] [client 185.132.186.90:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/tflow/admin-footer.php"] [unique_id "al4RQzAtbv2vrjByhUqSzAAAAGg"]
[Mon Jul 20 06:15:00.126764 2026] [security2:error] [pid 858085:tid 858138] [remote 113.160.142.119:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4RRDAtbv2vrjByhUqS2QAAYjM"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 06:15:00.132650 2026] [security2:error] [pid 858085:tid 858275] [client 85.208.96.196:13678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/diffuser-options-for-young-living-premium-starter-kit/"] [unique_id "al4RRDAtbv2vrjByhUqS3AAAADs"]
[Mon Jul 20 06:15:00.132746 2026] [security2:error] [pid 858085:tid 858275] [client 85.208.96.196:13678] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/diffuser-options-for-young-living-premium-starter-kit/"] [unique_id "al4RRDAtbv2vrjByhUqS3AAAADs"]
[Mon Jul 20 06:15:00.171861 2026] [security2:error] [pid 858085:tid 858175] [remote 188.166.241.141:39076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4RRDAtbv2vrjByhUqS4AAAclg"]
[Mon Jul 20 06:15:00.446140 2026] [security2:error] [pid 858085:tid 858343] [client 57.141.18.90:32512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqRFgAAfw8"]
[Mon Jul 20 06:15:00.489373 2026] [security2:error] [pid 858085:tid 858335] [client 45.116.69.230:64431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqS-gAAAHc"]
[Mon Jul 20 06:15:00.489671 2026] [security2:error] [pid 858085:tid 858335] [client 45.116.69.230:64431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqS-gAAAHc"]
[Mon Jul 20 06:15:00.523788 2026] [security2:error] [pid 858085:tid 858218] [client 14.225.17.146:58643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqS9QAAAAI"], referer: https://thesoloceos.com/WordPress
[Mon Jul 20 06:15:00.557541 2026] [security2:error] [pid 858085:tid 858156] [remote 188.166.241.141:39076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4RRDAtbv2vrjByhUqTAQAAfUU"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:15:00.619181 2026] [security2:error] [pid 858085:tid 858267] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqS0QAAMzU"], referer: http://ardhalwafaa.com/WordPress
[Mon Jul 20 06:15:00.627021 2026] [security2:error] [pid 858085:tid 858338] [client 106.192.104.4:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTDQAAAHo"]
[Mon Jul 20 06:15:00.627150 2026] [security2:error] [pid 858085:tid 858338] [client 106.192.104.4:54970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTDQAAAHo"]
[Mon Jul 20 06:15:00.692342 2026] [security2:error] [pid 858085:tid 858316] [client 50.116.65.227:29988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4RRDAtbv2vrjByhUqTEwAAAGQ"]
[Mon Jul 20 06:15:00.706817 2026] [security2:error] [pid 858085:tid 858303] [client 50.116.65.227:22852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4RRDAtbv2vrjByhUqTGAAAAFc"]
[Mon Jul 20 06:15:00.730626 2026] [security2:error] [pid 858085:tid 858259] [client 112.213.160.112:8513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTHwAAACs"]
[Mon Jul 20 06:15:00.730798 2026] [security2:error] [pid 858085:tid 858259] [client 112.213.160.112:8513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTHwAAACs"]
[Mon Jul 20 06:15:01.299158 2026] [security2:error] [pid 858085:tid 858100] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RRTAtbv2vrjByhUqTTAAAbQ0"]
[Mon Jul 20 06:15:01.299346 2026] [security2:error] [pid 858085:tid 858325] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RRTAtbv2vrjByhUqTTAAAbQ0"]
[Mon Jul 20 06:15:01.451158 2026] [security2:error] [pid 858085:tid 858151] [remote 5.161.225.162:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RRTAtbv2vrjByhUqTWgAAJkA"]
[Mon Jul 20 06:15:01.534388 2026] [security2:error] [pid 858085:tid 858199] [remote 47.86.33.52:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4RRTAtbv2vrjByhUqTXgAABXA"]
[Mon Jul 20 06:15:01.595943 2026] [security2:error] [pid 858085:tid 858304] [client 57.141.18.24:62682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPzAtbv2vrjByhUqRbQAAWDI"]
[Mon Jul 20 06:15:01.699434 2026] [security2:error] [pid 858085:tid 858337] [client 185.132.186.80:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/footer-default.php"] [unique_id "al4RRTAtbv2vrjByhUqTbQAAAHk"]
[Mon Jul 20 06:15:01.789842 2026] [security2:error] [pid 858085:tid 858105] [remote 5.161.225.162:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RRTAtbv2vrjByhUqTdwAAARI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:01.937300 2026] [security2:error] [pid 858085:tid 858309] [client 14.225.17.146:56370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqS-QAAAF0"], referer: http://eframiproperties.com/WordPress
[Mon Jul 20 06:15:02.253885 2026] [security2:error] [pid 858085:tid 858302] [client 57.141.18.81:25284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQDAtbv2vrjByhUqRqgAAVkM"]
[Mon Jul 20 06:15:02.323560 2026] [security2:error] [pid 858085:tid 858220] [client 57.141.18.45:29026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQDAtbv2vrjByhUqRqQAABHE"]
[Mon Jul 20 06:15:02.617721 2026] [security2:error] [pid 858085:tid 858252] [client 14.225.17.146:57660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4RRjAtbv2vrjByhUqTugAAACQ"], referer: http://alrowad-hub.net/WordPress
[Mon Jul 20 06:15:02.713726 2026] [security2:error] [pid 858085:tid 858317] [client 57.141.18.30:49840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQTAtbv2vrjByhUqR6AAAZXg"]
[Mon Jul 20 06:15:02.766218 2026] [security2:error] [pid 858085:tid 858219] [client 27.96.94.195:37943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT2wAAAAM"]
[Mon Jul 20 06:15:02.766357 2026] [security2:error] [pid 858085:tid 858219] [client 27.96.94.195:37943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT2wAAAAM"]
[Mon Jul 20 06:15:02.789537 2026] [security2:error] [pid 858085:tid 858319] [client 178.152.178.232:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT3gAAAGc"]
[Mon Jul 20 06:15:02.789692 2026] [security2:error] [pid 858085:tid 858319] [client 178.152.178.232:36832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT3gAAAGc"]
[Mon Jul 20 06:15:02.828246 2026] [security2:error] [pid 858085:tid 858231] [client 14.225.17.146:50862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4RRTAtbv2vrjByhUqTMwAAAA8"], referer: http://amalia-capital.com/WordPress
[Mon Jul 20 06:15:02.986421 2026] [security2:error] [pid 858085:tid 858256] [client 66.249.65.39:37484] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.treehousecraft.com"] [uri "/robots.txt"] [unique_id "al4RRjAtbv2vrjByhUqT-AAAACg"]
[Mon Jul 20 06:15:03.309650 2026] [security2:error] [pid 858085:tid 858118] [remote 45.90.123.233:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUGQAACB8"]
[Mon Jul 20 06:15:03.389548 2026] [security2:error] [pid 858085:tid 858190] [remote 47.86.33.52:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUIgAAJ2c"], referer: https://technicalseohouse.com/wp-login.php
[Mon Jul 20 06:15:03.458165 2026] [security2:error] [pid 858085:tid 858210] [remote 188.40.28.4:45624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUJQAABns"]
[Mon Jul 20 06:15:03.493853 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.23:28070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQjAtbv2vrjByhUqSSAAACTc"]
[Mon Jul 20 06:15:03.592964 2026] [security2:error] [pid 858085:tid 858182] [remote 124.55.178.99:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUMAAALl8"]
[Mon Jul 20 06:15:03.688340 2026] [security2:error] [pid 858085:tid 858340] [client 185.132.186.67:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/about.php"] [unique_id "al4RRzAtbv2vrjByhUqUNQAAAHw"]
[Mon Jul 20 06:15:03.961538 2026] [security2:error] [pid 858085:tid 858273] [client 104.234.53.60:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RRzAtbv2vrjByhUqUVgAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:04.045239 2026] [security2:error] [pid 858085:tid 858119] [remote 124.55.178.99:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUWgAAbiA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:04.052459 2026] [security2:error] [pid 858085:tid 858300] [client 57.141.18.22:64280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQjAtbv2vrjByhUqScwAAVCw"]
[Mon Jul 20 06:15:04.128615 2026] [security2:error] [pid 858085:tid 858187] [remote 45.90.123.233:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUXQAAVWQ"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:15:04.143474 2026] [security2:error] [pid 858085:tid 858178] [remote 188.40.28.4:45624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUXgAAbVs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:15:04.148306 2026] [security2:error] [pid 858085:tid 858336] [client 43.205.139.3:26246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUXwAAAHg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:15:04.555992 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:60143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RSDAtbv2vrjByhUqUggAAADo"]
[Mon Jul 20 06:15:04.556101 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:60143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RSDAtbv2vrjByhUqUggAAADo"]
[Mon Jul 20 06:15:04.687546 2026] [security2:error] [pid 858085:tid 858307] [client 57.141.18.80:40058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQzAtbv2vrjByhUqSrgAAWxo"]
[Mon Jul 20 06:15:05.240627 2026] [security2:error] [pid 858085:tid 858154] [remote 173.212.252.15:34234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4RSTAtbv2vrjByhUqUwgAAL0M"]
[Mon Jul 20 06:15:05.418047 2026] [security2:error] [pid 858085:tid 858252] [client 27.34.73.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4RRzAtbv2vrjByhUqUDQAAACQ"]
[Mon Jul 20 06:15:05.497239 2026] [security2:error] [pid 858085:tid 858277] [client 185.132.186.78:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-meta-request.php"] [unique_id "al4RSTAtbv2vrjByhUqU2wAAAD0"]
[Mon Jul 20 06:15:05.683492 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.79:31618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqTBwAAKXw"]
[Mon Jul 20 06:15:05.844735 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.97:62798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqTJAAADUg"]
[Mon Jul 20 06:15:05.866803 2026] [security2:error] [pid 858085:tid 858335] [client 14.225.17.146:56390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4RSDAtbv2vrjByhUqUjgAAAHc"], referer: http://idigress.studio/WordPress
[Mon Jul 20 06:15:06.022328 2026] [security2:error] [pid 858085:tid 858342] [client 14.225.17.146:57577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU-wAAAH4"], referer: http://aandarealtygroup.com/WordPress
[Mon Jul 20 06:15:06.153945 2026] [security2:error] [pid 858085:tid 858143] [remote 115.74.105.156:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RSjAtbv2vrjByhUqVFwAATDg"]
[Mon Jul 20 06:15:06.158124 2026] [security2:error] [pid 858085:tid 858234] [client 57.141.18.15:49952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRTAtbv2vrjByhUqTNgAAEgw"]
[Mon Jul 20 06:15:06.288667 2026] [security2:error] [pid 858085:tid 858243] [client 65.1.132.125:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVJgAAABs"]
[Mon Jul 20 06:15:06.288804 2026] [security2:error] [pid 858085:tid 858243] [client 65.1.132.125:52498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVJgAAABs"]
[Mon Jul 20 06:15:06.314877 2026] [security2:error] [pid 858085:tid 858333] [client 50.116.65.227:22954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RSjAtbv2vrjByhUqVJwAAAHU"]
[Mon Jul 20 06:15:06.325074 2026] [security2:error] [pid 858085:tid 858319] [client 50.116.65.227:22964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RSjAtbv2vrjByhUqVKAAAAGc"]
[Mon Jul 20 06:15:06.691818 2026] [security2:error] [pid 858085:tid 858334] [client 57.141.18.53:21224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRTAtbv2vrjByhUqThAAAdgY"]
[Mon Jul 20 06:15:06.695905 2026] [security2:error] [pid 858085:tid 858310] [client 181.224.94.124:34670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVQwAAAF4"]
[Mon Jul 20 06:15:06.696036 2026] [security2:error] [pid 858085:tid 858310] [client 181.224.94.124:34670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVQwAAAF4"]
[Mon Jul 20 06:15:07.533499 2026] [security2:error] [pid 858085:tid 858260] [client 14.225.17.146:57581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU_AAAACw"], referer: http://nomorewetsheets.net/WordPress
[Mon Jul 20 06:15:07.637259 2026] [security2:error] [pid 858085:tid 858208] [remote 57.141.18.121:29402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRjAtbv2vrjByhUqT7AAADnk"]
[Mon Jul 20 06:15:07.667157 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:57983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4RSjAtbv2vrjByhUqVQQAAABM"], referer: http://entuvy.com/WordPress
[Mon Jul 20 06:15:07.888767 2026] [http2:info] [pid 871012:tid 871012] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:15:07.911166 2026] [security2:error] [pid 871012:tid 871147] [client 185.132.186.100:52959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/cloud.php"] [unique_id "al4RS7wiU-Jh5ncAILE9vQAAAQ4"]
[Mon Jul 20 06:15:07.931953 2026] [security2:error] [pid 858085:tid 858222] [client 14.225.17.146:58341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU7AAAAAY"], referer: http://keywayconstructionclt.com/WordPress
[Mon Jul 20 06:15:08.115524 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:56451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4RS7wiU-Jh5ncAILE9vgAAARE"]
[Mon Jul 20 06:15:08.233472 2026] [security2:error] [pid 871012:tid 871040] [remote 72.167.132.114:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTLwiU-Jh5ncAILE9-gABJRo"]
[Mon Jul 20 06:15:08.532816 2026] [security2:error] [pid 871012:tid 871051] [remote 72.167.132.114:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTLwiU-Jh5ncAILE-FgABLCU"], referer: https://rcq.nst.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:08.558806 2026] [security2:error] [pid 871012:tid 871169] [client 50.116.65.227:30016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RTLwiU-Jh5ncAILE-GAAAASQ"]
[Mon Jul 20 06:15:08.569270 2026] [security2:error] [pid 871012:tid 871159] [client 50.116.65.227:22990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RTLwiU-Jh5ncAILE-GQAAASA"]
[Mon Jul 20 06:15:08.746102 2026] [security2:error] [pid 871012:tid 871262] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-DAAAAYE"]
[Mon Jul 20 06:15:08.842942 2026] [security2:error] [pid 871012:tid 871176] [client 14.225.17.146:56443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-LwAAASs"], referer: https://keywayconstructionclt.com/WordPress
[Mon Jul 20 06:15:08.933234 2026] [security2:error] [pid 871012:tid 871267] [client 171.60.139.123:57727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RTLwiU-Jh5ncAILE-QAAAAYY"]
[Mon Jul 20 06:15:08.933385 2026] [security2:error] [pid 871012:tid 871267] [client 171.60.139.123:57727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RTLwiU-Jh5ncAILE-QAAAAYY"]
[Mon Jul 20 06:15:09.655664 2026] [security2:error] [pid 858085:tid 858170] [remote 57.141.18.107:52686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSDAtbv2vrjByhUqUjQAAelM"]
[Mon Jul 20 06:15:09.710847 2026] [security2:error] [pid 871012:tid 871259] [client 185.132.186.62:60553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/edit-widgets/bypass.php"] [unique_id "al4RTbwiU-Jh5ncAILE-eAAAAX4"]
[Mon Jul 20 06:15:09.780028 2026] [security2:error] [pid 871012:tid 871224] [client 23.94.28.190:56366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mezzacraft.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "al4RTbwiU-Jh5ncAILE-gwAAAVs"]
[Mon Jul 20 06:15:09.792607 2026] [security2:error] [pid 871012:tid 871097] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-hgABI1M"]
[Mon Jul 20 06:15:09.792768 2026] [security2:error] [pid 871012:tid 871168] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-hgABI1M"]
[Mon Jul 20 06:15:09.847502 2026] [security2:error] [pid 871012:tid 871204] [client 14.225.17.146:57931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-QQAAAUc"], referer: http://mobilesurvsolutions.com/WordPress
[Mon Jul 20 06:15:09.897051 2026] [security2:error] [pid 871012:tid 871267] [client 41.173.37.102:11975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-jwAAAYY"]
[Mon Jul 20 06:15:09.897155 2026] [security2:error] [pid 871012:tid 871267] [client 41.173.37.102:11975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-jwAAAYY"]
[Mon Jul 20 06:15:10.162536 2026] [security2:error] [pid 858085:tid 858088] [remote 57.141.18.92:36454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqUuwAAOAE"]
[Mon Jul 20 06:15:10.292797 2026] [security2:error] [pid 871012:tid 871113] [remote 160.187.68.132:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTrwiU-Jh5ncAILE-qgABEmM"]
[Mon Jul 20 06:15:10.368969 2026] [security2:error] [pid 871012:tid 871159] [client 66.249.64.232:37685] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "50.116.65.227"] [uri "/robots.txt"] [unique_id "al4RTrwiU-Jh5ncAILE-tAAAARo"]
[Mon Jul 20 06:15:10.534364 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RTrwiU-Jh5ncAILE-wQAAARU"]
[Mon Jul 20 06:15:10.535372 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RTrwiU-Jh5ncAILE-wQAAARU"]
[Mon Jul 20 06:15:10.844299 2026] [security2:error] [pid 858085:tid 858152] [remote 57.141.18.101:35676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU4AAAL0E"]
[Mon Jul 20 06:15:10.980429 2026] [security2:error] [pid 871012:tid 871138] [remote 160.187.68.132:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTrwiU-Jh5ncAILE-7wABb3w"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:11.126209 2026] [security2:error] [pid 858085:tid 858139] [remote 57.141.18.32:28050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU9wAAbzQ"]
[Mon Jul 20 06:15:11.227333 2026] [security2:error] [pid 871012:tid 871168] [client 45.116.69.230:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE--gAAASM"]
[Mon Jul 20 06:15:11.227434 2026] [security2:error] [pid 871012:tid 871168] [client 45.116.69.230:64972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE--gAAASM"]
[Mon Jul 20 06:15:11.310222 2026] [security2:error] [pid 871012:tid 871017] [remote 194.164.192.228:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4RT7wiU-Jh5ncAILE_AAABEQM"]
[Mon Jul 20 06:15:11.337005 2026] [security2:error] [pid 871012:tid 871270] [client 14.225.17.146:57134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4RTrwiU-Jh5ncAILE-nQAAAYk"]
[Mon Jul 20 06:15:11.373546 2026] [security2:error] [pid 871012:tid 871246] [client 106.192.104.4:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE_CAAAAXE"]
[Mon Jul 20 06:15:11.373730 2026] [security2:error] [pid 871012:tid 871246] [client 106.192.104.4:55470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE_CAAAAXE"]
[Mon Jul 20 06:15:11.428842 2026] [security2:error] [pid 871012:tid 871187] [client 158.173.241.141:47053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE-_AAAATY"], referer: http://sesamegreenbeans.com/planning-for-rugby-world-cup-france-2023/
[Mon Jul 20 06:15:11.469380 2026] [security2:error] [pid 871012:tid 871225] [client 185.132.186.74:47131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ubh/adminfus.php"] [unique_id "al4RT7wiU-Jh5ncAILE_EAAAAVw"]
[Mon Jul 20 06:15:11.497396 2026] [security2:error] [pid 871012:tid 871028] [remote 194.164.192.228:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4RT7wiU-Jh5ncAILE_EwABaQ4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:15:11.692876 2026] [security2:error] [pid 871012:tid 871159] [client 74.208.214.194:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RT7wiU-Jh5ncAILE_FwAAARo"]
[Mon Jul 20 06:15:11.751569 2026] [security2:error] [pid 871012:tid 871020] [remote 182.77.62.24:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RT7wiU-Jh5ncAILE_HAABQwY"]
[Mon Jul 20 06:15:11.953910 2026] [security2:error] [pid 871012:tid 871169] [client 34.223.60.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE_JAAAASQ"]
[Mon Jul 20 06:15:12.079906 2026] [security2:error] [pid 871012:tid 871181] [client 50.116.65.227:26540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4RULwiU-Jh5ncAILE_NwAAATA"]
[Mon Jul 20 06:15:12.091773 2026] [security2:error] [pid 871012:tid 871202] [client 50.116.65.227:29992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4RULwiU-Jh5ncAILE_OAAAAT4"]
[Mon Jul 20 06:15:12.266484 2026] [security2:error] [pid 871012:tid 871054] [remote 182.77.62.24:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RULwiU-Jh5ncAILE_RwABKig"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:12.519208 2026] [security2:error] [pid 871012:tid 871067] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RULwiU-Jh5ncAILE_WgABhTU"]
[Mon Jul 20 06:15:12.519348 2026] [security2:error] [pid 871012:tid 871266] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RULwiU-Jh5ncAILE_WgABhTU"]
[Mon Jul 20 06:15:12.702195 2026] [proxy:error] [pid 871012:tid 871260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.706572 2026] [proxy_http:error] [pid 871012:tid 871260] [client 137.184.90.71:44340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:12.708345 2026] [proxy:error] [pid 871012:tid 871260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.708413 2026] [proxy_http:error] [pid 871012:tid 871260] [client 137.184.90.71:44340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:12.742615 2026] [security2:error] [pid 858085:tid 858149] [remote 57.141.18.56:39234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSjAtbv2vrjByhUqVUwAAIj4"]
[Mon Jul 20 06:15:12.754039 2026] [proxy:error] [pid 871012:tid 871206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.754114 2026] [proxy_http:error] [pid 871012:tid 871206] [client 137.184.90.71:44348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.thechancersband.com/
[Mon Jul 20 06:15:12.754696 2026] [proxy:error] [pid 871012:tid 871206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.754722 2026] [proxy_http:error] [pid 871012:tid 871206] [client 137.184.90.71:44348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.thechancersband.com/
[Mon Jul 20 06:15:12.841526 2026] [security2:error] [pid 871012:tid 871182] [client 114.119.144.42:21849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "itekphonerepair.com"] [uri "/"] [unique_id "al4RULwiU-Jh5ncAILE_eAAAATE"], referer: https://moitruongxanh.top/ceua/jjworld%E7%AB%9E%E6%8A%80%E4%B8%96%E7%95%8C-0e07494507/
[Mon Jul 20 06:15:12.871980 2026] [core:error] [pid 871012:tid 871229] [client 137.184.90.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:12.872002 2026] [core:error] [pid 871012:tid 871229] [client 137.184.90.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:13.232641 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.85:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/webdb.php"] [unique_id "al4RUbwiU-Jh5ncAILE_lAAAAVQ"]
[Mon Jul 20 06:15:13.325095 2026] [security2:error] [pid 871012:tid 871248] [client 13.215.47.127:15370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RUbwiU-Jh5ncAILE_oAAAAXM"]
[Mon Jul 20 06:15:13.392215 2026] [security2:error] [pid 871012:tid 871150] [client 27.96.94.195:38092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_pgAAARE"]
[Mon Jul 20 06:15:13.392351 2026] [security2:error] [pid 871012:tid 871150] [client 27.96.94.195:38092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_pgAAARE"]
[Mon Jul 20 06:15:13.440978 2026] [security2:error] [pid 871012:tid 871257] [client 50.116.65.227:30004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4RUbwiU-Jh5ncAILE_qgAAAXw"]
[Mon Jul 20 06:15:13.443580 2026] [security2:error] [pid 871012:tid 871186] [client 14.225.17.146:57990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE_KAAAATU"], referer: http://recruitinginsight.us/WordPress
[Mon Jul 20 06:15:13.483239 2026] [security2:error] [pid 871012:tid 871202] [client 178.152.178.232:36976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_qwAAAUU"]
[Mon Jul 20 06:15:13.490461 2026] [security2:error] [pid 871012:tid 871202] [client 178.152.178.232:36976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_qwAAAUU"]
[Mon Jul 20 06:15:13.826276 2026] [security2:error] [pid 871012:tid 871196] [client 14.225.17.146:58716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4RUbwiU-Jh5ncAILE_vQAAAT8"], referer: http://whiteoutcb.com/WordPress
[Mon Jul 20 06:15:14.061468 2026] [security2:error] [pid 871012:tid 871215] [client 14.225.17.146:52816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RULwiU-Jh5ncAILE_VgAAAVI"], referer: http://nurturemarple.co.uk/WordPress
[Mon Jul 20 06:15:14.134291 2026] [security2:error] [pid 871012:tid 871148] [client 57.141.18.60:43622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RS7wiU-Jh5ncAILE9wgABD38"]
[Mon Jul 20 06:15:14.278210 2026] [security2:error] [pid 871012:tid 871265] [client 13.229.83.156:61934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RUrwiU-Jh5ncAILE_9AAAAYQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:15:14.298037 2026] [security2:error] [pid 871012:tid 871199] [client 57.141.18.97:44594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE96gABQhQ"]
[Mon Jul 20 06:15:14.529850 2026] [security2:error] [pid 871012:tid 871204] [client 14.225.17.146:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_5QAAAUc"]
[Mon Jul 20 06:15:14.582490 2026] [security2:error] [pid 871012:tid 871230] [client 52.167.144.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_9QABYXI"]
[Mon Jul 20 06:15:14.591670 2026] [security2:error] [pid 871012:tid 871185] [client 50.116.65.227:30026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_7AAAATQ"]
[Mon Jul 20 06:15:14.721058 2026] [security2:error] [pid 871012:tid 871146] [client 57.141.18.14:43656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-FQABDSQ"]
[Mon Jul 20 06:15:14.811566 2026] [security2:error] [pid 871012:tid 871262] [client 50.116.65.227:30036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILFABQAAAYE"]
[Mon Jul 20 06:15:15.034209 2026] [security2:error] [pid 871012:tid 871258] [client 14.225.17.146:56946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILFAFgAAAX0"], referer: https://nurturemarple.co.uk/WordPress
[Mon Jul 20 06:15:15.087292 2026] [security2:error] [pid 871012:tid 871253] [client 185.132.186.83:44291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/wp-login.php"] [unique_id "al4RU7wiU-Jh5ncAILFAJAAAAXg"]
[Mon Jul 20 06:15:15.116130 2026] [security2:error] [pid 871012:tid 871182] [client 103.77.203.233:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RU7wiU-Jh5ncAILFAJgAAATE"]
[Mon Jul 20 06:15:15.116467 2026] [security2:error] [pid 871012:tid 871182] [client 103.77.203.233:60703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RU7wiU-Jh5ncAILFAJgAAATE"]
[Mon Jul 20 06:15:15.282259 2026] [security2:error] [pid 871012:tid 871171] [client 57.141.18.125:49564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTbwiU-Jh5ncAILE-UQABJj0"]
[Mon Jul 20 06:15:15.577640 2026] [security2:error] [pid 858085:tid 858156] [remote 8.217.108.67:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4RUzAtbv2vrjByhUqVXAAAcEU"]
[Mon Jul 20 06:15:15.703436 2026] [security2:error] [pid 871012:tid 871245] [client 57.141.18.87:22538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTbwiU-Jh5ncAILE-dQABcE4"]
[Mon Jul 20 06:15:15.762201 2026] [security2:error] [pid 871012:tid 871217] [client 14.225.17.146:55002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_9wAAAVQ"], referer: http://sarahsnyder.net/WordPress
[Mon Jul 20 06:15:15.886745 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:26558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RU7wiU-Jh5ncAILFAWgAAAXg"]
[Mon Jul 20 06:15:15.897208 2026] [security2:error] [pid 871012:tid 871265] [client 50.116.65.227:30054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RU7wiU-Jh5ncAILFAWwAAATE"]
[Mon Jul 20 06:15:15.979381 2026] [security2:error] [pid 871012:tid 871169] [client 57.141.18.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RU7wiU-Jh5ncAILFAVgAAASQ"]
[Mon Jul 20 06:15:16.011563 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:30058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RVLwiU-Jh5ncAILFAYwAAATo"]
[Mon Jul 20 06:15:16.023509 2026] [security2:error] [pid 871012:tid 871250] [client 50.116.65.227:30062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RVLwiU-Jh5ncAILFAZAAAAXU"]
[Mon Jul 20 06:15:16.495208 2026] [security2:error] [pid 871012:tid 871192] [client 57.141.18.15:47464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTrwiU-Jh5ncAILE-xQABO20"]
[Mon Jul 20 06:15:16.717774 2026] [security2:error] [pid 871012:tid 871261] [client 14.225.17.146:57095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4RVLwiU-Jh5ncAILFAiQAAAYA"], referer: https://sarahsnyder.net/WordPress
[Mon Jul 20 06:15:16.822211 2026] [proxy:error] [pid 871012:tid 871243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822254 2026] [proxy_http:error] [pid 871012:tid 871243] [client 94.154.43.188:38424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.822320 2026] [proxy:error] [pid 871012:tid 871148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822360 2026] [proxy_http:error] [pid 871012:tid 871148] [client 94.154.43.188:38436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.822760 2026] [proxy:error] [pid 871012:tid 871148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822781 2026] [proxy_http:error] [pid 871012:tid 871148] [client 94.154.43.188:38436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.822857 2026] [proxy:error] [pid 871012:tid 871243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822883 2026] [proxy_http:error] [pid 871012:tid 871243] [client 94.154.43.188:38424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.888822 2026] [security2:error] [pid 871012:tid 871186] [client 185.132.186.81:40951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/admin.php"] [unique_id "al4RVLwiU-Jh5ncAILFAqAAAATU"]
[Mon Jul 20 06:15:16.898809 2026] [security2:error] [pid 871012:tid 871208] [client 57.141.18.117:25440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE-8QABS34"]
[Mon Jul 20 06:15:17.111618 2026] [security2:error] [pid 871012:tid 871170] [client 14.225.17.146:57339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4RVLwiU-Jh5ncAILFArwAAASU"], referer: http://samdothan.org/WordPress
[Mon Jul 20 06:15:17.145764 2026] [security2:error] [pid 871012:tid 871100] [remote 57.141.18.37:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2887329"] [unique_id "al4RVbwiU-Jh5ncAILFAvAABMVY"]
[Mon Jul 20 06:15:17.254147 2026] [security2:error] [pid 871012:tid 871181] [client 181.224.94.124:26117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAwwAAATA"]
[Mon Jul 20 06:15:17.254253 2026] [security2:error] [pid 871012:tid 871181] [client 181.224.94.124:26117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAwwAAATA"]
[Mon Jul 20 06:15:17.277237 2026] [security2:error] [pid 871012:tid 871209] [client 13.201.64.214:35046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAxgAAAUw"]
[Mon Jul 20 06:15:17.277353 2026] [security2:error] [pid 871012:tid 871209] [client 13.201.64.214:35046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAxgAAAUw"]
[Mon Jul 20 06:15:17.472591 2026] [security2:error] [pid 871012:tid 871155] [client 114.119.154.39:36871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nwcarvingacademy.com"] [uri "/classes/videos.html"] [unique_id "al4RVbwiU-Jh5ncAILFA0QAAARY"], referer: http://www.nwcarvingacademy.com/classes/videos.html
[Mon Jul 20 06:15:17.996685 2026] [security2:error] [pid 871012:tid 871188] [client 57.141.18.22:26628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RULwiU-Jh5ncAILE_QAABNyU"]
[Mon Jul 20 06:15:18.473897 2026] [security2:error] [pid 871012:tid 871267] [client 57.141.18.66:50274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RULwiU-Jh5ncAILE_ZwABhjc"]
[Mon Jul 20 06:15:18.513246 2026] [security2:error] [pid 871012:tid 871175] [client 14.225.17.146:57823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4RVbwiU-Jh5ncAILFAxwAAASo"], referer: http://lutheranphilosopher.com/WordPress
[Mon Jul 20 06:15:18.523821 2026] [security2:error] [pid 871012:tid 871179] [client 14.225.17.146:58275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFBEAAAAS4"], referer: https://north-woods-engineering.com/WordPress
[Mon Jul 20 06:15:18.566851 2026] [core:error] [pid 871012:tid 871240] [client 14.225.17.146:58491] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:18.566872 2026] [core:error] [pid 871012:tid 871240] [client 14.225.17.146:58491] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:18.579861 2026] [security2:error] [pid 871012:tid 871236] [client 14.225.17.146:58241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFA-gAAAWc"]
[Mon Jul 20 06:15:18.867786 2026] [security2:error] [pid 871012:tid 871169] [client 14.225.17.146:58420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFBKwAAASQ"], referer: http://laceycaraccident.com/WordPress
[Mon Jul 20 06:15:19.141701 2026] [security2:error] [pid 871012:tid 871176] [client 185.132.186.87:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/item.php"] [unique_id "al4RV7wiU-Jh5ncAILFBRQAAASs"]
[Mon Jul 20 06:15:19.155538 2026] [autoindex:error] [pid 871012:tid 871208] [client 167.86.107.171:65343] AH01276: Cannot serve directory /home2/santabea/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:15:19.482062 2026] [security2:error] [pid 871012:tid 871157] [client 57.141.18.13:57624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RUbwiU-Jh5ncAILE_tQABGFg"]
[Mon Jul 20 06:15:19.649295 2026] [security2:error] [pid 871012:tid 871226] [client 171.60.139.123:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RV7wiU-Jh5ncAILFBbAAAAV0"]
[Mon Jul 20 06:15:19.649457 2026] [security2:error] [pid 871012:tid 871226] [client 171.60.139.123:58216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RV7wiU-Jh5ncAILFBbAAAAV0"]
[Mon Jul 20 06:15:20.167015 2026] [security2:error] [pid 871012:tid 871041] [remote 5.161.225.162:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RWLwiU-Jh5ncAILFBkAABgRs"]
[Mon Jul 20 06:15:20.437138 2026] [security2:error] [pid 871012:tid 871064] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrQABGzI"]
[Mon Jul 20 06:15:20.437295 2026] [security2:error] [pid 871012:tid 871160] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrQABGzI"]
[Mon Jul 20 06:15:20.458580 2026] [security2:error] [pid 871012:tid 871070] [remote 115.74.105.156:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrwABZjg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:15:20.469440 2026] [security2:error] [pid 871012:tid 871154] [client 41.173.37.102:12426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrgAAARU"]
[Mon Jul 20 06:15:20.469551 2026] [security2:error] [pid 871012:tid 871154] [client 41.173.37.102:12426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrgAAARU"]
[Mon Jul 20 06:15:20.506025 2026] [security2:error] [pid 871012:tid 871172] [client 14.225.17.146:58764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4RV7wiU-Jh5ncAILFBYwAAASc"], referer: http://intelligentengineeringsolutions.com/WordPress
[Mon Jul 20 06:15:20.692266 2026] [security2:error] [pid 871012:tid 871184] [client 57.141.18.4:39480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILFABwABM3c"]
[Mon Jul 20 06:15:20.805503 2026] [security2:error] [pid 871012:tid 871266] [client 158.173.166.181:58613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RWLwiU-Jh5ncAILFByQAAAYU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:20.881151 2026] [security2:error] [pid 871012:tid 871150] [client 13.201.64.214:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBzwAAARE"]
[Mon Jul 20 06:15:20.881250 2026] [security2:error] [pid 871012:tid 871150] [client 13.201.64.214:57550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBzwAAARE"]
[Mon Jul 20 06:15:20.924121 2026] [security2:error] [pid 871012:tid 871140] [remote 173.212.252.15:39194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4RWLwiU-Jh5ncAILFB1AABiH4"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 06:15:20.946457 2026] [security2:error] [pid 871012:tid 871167] [client 185.132.186.65:44721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/xsec.php"] [unique_id "al4RWLwiU-Jh5ncAILFB1gAAASI"]
[Mon Jul 20 06:15:21.041476 2026] [security2:error] [pid 871012:tid 871228] [client 104.234.53.47:32273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RWbwiU-Jh5ncAILFB3wAAAV8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:21.292227 2026] [security2:error] [pid 871012:tid 871199] [client 14.225.17.146:56775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4RWLwiU-Jh5ncAILFBgQAAAUI"], referer: http://effingweirdmuseums.com/WordPress
[Mon Jul 20 06:15:21.304095 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFB9AAAARU"]
[Mon Jul 20 06:15:21.304194 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFB9AAAARU"]
[Mon Jul 20 06:15:21.695202 2026] [proxy:warn] [pid 871012:tid 871251] [client 45.205.1.223:55066] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 06:15:21.722386 2026] [core:error] [pid 871012:tid 871212] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:21.722409 2026] [core:error] [pid 871012:tid 871212] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:21.722543 2026] [security2:error] [pid 871012:tid 871212] [client 45.205.1.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4RWbwiU-Jh5ncAILFCGAAAAU8"]
[Mon Jul 20 06:15:21.726528 2026] [security2:error] [pid 871012:tid 871251] [client 45.205.1.223:55066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/400.shtml"] [unique_id "al4RWbwiU-Jh5ncAILFCEwAAAXY"]
[Mon Jul 20 06:15:21.915239 2026] [security2:error] [pid 871012:tid 871104] [remote 5.161.225.162:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RWbwiU-Jh5ncAILFCLQABD1o"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:21.938231 2026] [security2:error] [pid 871012:tid 871191] [client 45.116.69.230:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFCLgAAATo"]
[Mon Jul 20 06:15:21.938346 2026] [security2:error] [pid 871012:tid 871191] [client 45.116.69.230:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFCLgAAATo"]
[Mon Jul 20 06:15:22.172835 2026] [security2:error] [pid 871012:tid 871215] [client 14.225.17.146:57437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4RWrwiU-Jh5ncAILFCPAAAAVI"], referer: https://effingweirdmuseums.com/WordPress
[Mon Jul 20 06:15:22.259909 2026] [security2:error] [pid 871012:tid 871234] [client 14.225.17.146:57165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4RWbwiU-Jh5ncAILFB4QAAAWU"], referer: http://sarahholyfield.com/WordPress
[Mon Jul 20 06:15:22.319668 2026] [security2:error] [pid 871012:tid 871216] [client 106.192.104.4:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RWrwiU-Jh5ncAILFCSQAAAVM"]
[Mon Jul 20 06:15:22.319814 2026] [security2:error] [pid 871012:tid 871216] [client 106.192.104.4:55971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RWrwiU-Jh5ncAILFCSQAAAVM"]
[Mon Jul 20 06:15:22.774707 2026] [security2:error] [pid 871012:tid 871256] [client 185.132.186.83:40653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/Marvins.php"] [unique_id "al4RWrwiU-Jh5ncAILFCZgAAAXs"]
[Mon Jul 20 06:15:22.838761 2026] [security2:error] [pid 871012:tid 871153] [client 57.141.18.96:54448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RVLwiU-Jh5ncAILFAigABFEY"]
[Mon Jul 20 06:15:23.035768 2026] [security2:error] [pid 871012:tid 871136] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RW7wiU-Jh5ncAILFCfwABIno"]
[Mon Jul 20 06:15:23.035924 2026] [security2:error] [pid 871012:tid 871167] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RW7wiU-Jh5ncAILFCfwABIno"]
[Mon Jul 20 06:15:23.247285 2026] [security2:error] [pid 871012:tid 871154] [client 52.109.124.141:14338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4RW7wiU-Jh5ncAILFCiAAAARU"]
[Mon Jul 20 06:15:23.257589 2026] [security2:error] [pid 871012:tid 871177] [client 51.15.140.81:43454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5024.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4RW7wiU-Jh5ncAILFCigAAASw"]
[Mon Jul 20 06:15:23.409852 2026] [security2:error] [pid 871012:tid 871258] [client 104.234.53.65:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RW7wiU-Jh5ncAILFClAAAAX0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:23.428422 2026] [security2:error] [pid 871012:tid 871235] [client 52.109.124.141:14338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4RW7wiU-Jh5ncAILFCmQAAAWY"]
[Mon Jul 20 06:15:23.953266 2026] [security2:error] [pid 871012:tid 871254] [client 14.225.17.146:57758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4RWrwiU-Jh5ncAILFCfAAAAXk"], referer: http://retzkolonglogistics.com/WordPress
[Mon Jul 20 06:15:24.178201 2026] [security2:error] [pid 871012:tid 871189] [client 50.116.65.227:58002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RXLwiU-Jh5ncAILFC2wAAATg"]
[Mon Jul 20 06:15:24.188226 2026] [security2:error] [pid 871012:tid 871243] [client 50.116.65.227:25038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RXLwiU-Jh5ncAILFC3wAAAW4"]
[Mon Jul 20 06:15:24.282949 2026] [security2:error] [pid 871012:tid 871146] [client 57.141.18.56:60736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFA-AABDWA"]
[Mon Jul 20 06:15:24.309825 2026] [security2:error] [pid 871012:tid 871270] [client 27.96.94.195:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RXLwiU-Jh5ncAILFC8AAAAYk"]
[Mon Jul 20 06:15:24.310422 2026] [security2:error] [pid 871012:tid 871270] [client 27.96.94.195:37524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RXLwiU-Jh5ncAILFC8AAAAYk"]
[Mon Jul 20 06:15:24.552584 2026] [security2:error] [pid 871012:tid 871226] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RXLwiU-Jh5ncAILFC7QAAAV0"]
[Mon Jul 20 06:15:24.580994 2026] [security2:error] [pid 871012:tid 871213] [client 185.132.186.69:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd-1/kurd.php"] [unique_id "al4RXLwiU-Jh5ncAILFDBAAAAVA"]
[Mon Jul 20 06:15:24.919198 2026] [proxy:warn] [pid 871012:tid 871178] [client 45.205.1.223:55070] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 06:15:24.941698 2026] [core:error] [pid 871012:tid 871260] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:24.941718 2026] [core:error] [pid 871012:tid 871260] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:24.941836 2026] [security2:error] [pid 871012:tid 871260] [client 45.205.1.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4RXLwiU-Jh5ncAILFDHwAAAX8"]
[Mon Jul 20 06:15:24.943394 2026] [security2:error] [pid 871012:tid 871178] [client 45.205.1.223:55070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/400.shtml"] [unique_id "al4RXLwiU-Jh5ncAILFDHAAAAS0"]
[Mon Jul 20 06:15:25.157192 2026] [security2:error] [pid 871012:tid 871259] [client 14.225.17.146:58123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4RW7wiU-Jh5ncAILFCrwAAAX4"], referer: http://709fx.com/WordPress
[Mon Jul 20 06:15:25.264242 2026] [security2:error] [pid 871012:tid 871081] [remote 188.166.241.141:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RXbwiU-Jh5ncAILFDOgABcUM"]
[Mon Jul 20 06:15:25.633802 2026] [security2:error] [pid 871012:tid 871171] [client 103.77.203.233:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RXbwiU-Jh5ncAILFDVwAAASY"]
[Mon Jul 20 06:15:25.633920 2026] [security2:error] [pid 871012:tid 871171] [client 103.77.203.233:61260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RXbwiU-Jh5ncAILFDVwAAASY"]
[Mon Jul 20 06:15:25.689937 2026] [security2:error] [pid 871012:tid 871089] [remote 188.166.241.141:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RXbwiU-Jh5ncAILFDYAABXUs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:15:25.770965 2026] [security2:error] [pid 871012:tid 871147] [client 57.141.18.22:33464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RV7wiU-Jh5ncAILFBWAABDkI"]
[Mon Jul 20 06:15:26.000476 2026] [security2:error] [pid 871012:tid 871261] [client 45.157.112.60:48777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RXbwiU-Jh5ncAILFDewAAAYA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:26.157061 2026] [core:error] [pid 871012:tid 871213] [client 14.225.17.146:64414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WordPress
[Mon Jul 20 06:15:26.157108 2026] [core:error] [pid 871012:tid 871213] [client 14.225.17.146:64414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WordPress
[Mon Jul 20 06:15:26.360309 2026] [security2:error] [pid 871012:tid 871194] [client 63.177.52.239:22868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDjwAAAT0"]
[Mon Jul 20 06:15:26.360447 2026] [security2:error] [pid 871012:tid 871194] [client 63.177.52.239:22868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDjwAAAT0"]
[Mon Jul 20 06:15:26.376624 2026] [security2:error] [pid 871012:tid 871269] [client 185.132.186.93:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/tflow/install.php"] [unique_id "al4RXrwiU-Jh5ncAILFDkAAAAYg"]
[Mon Jul 20 06:15:26.423596 2026] [security2:error] [pid 871012:tid 871055] [remote 103.187.169.251:54994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDlwABgyk"]
[Mon Jul 20 06:15:26.423770 2026] [security2:error] [pid 871012:tid 871264] [client 103.187.169.251:54994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDlwABgyk"]
[Mon Jul 20 06:15:26.808105 2026] [security2:error] [pid 871012:tid 871266] [client 180.102.110.173:48804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/how-to-create-textures-with-acrylic-paint-a-guide-for-artists/"] [unique_id "al4RXrwiU-Jh5ncAILFDvAAAAYU"]
[Mon Jul 20 06:15:26.808251 2026] [security2:error] [pid 871012:tid 871266] [client 180.102.110.173:48804] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/how-to-create-textures-with-acrylic-paint-a-guide-for-artists/"] [unique_id "al4RXrwiU-Jh5ncAILFDvAAAAYU"]
[Mon Jul 20 06:15:26.817493 2026] [security2:error] [pid 871012:tid 871219] [client 57.141.18.59:54472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RWLwiU-Jh5ncAILFBqwABVh8"]
[Mon Jul 20 06:15:26.944395 2026] [security2:error] [pid 871012:tid 871208] [client 14.225.17.146:64608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RXrwiU-Jh5ncAILFDsgAAAUs"], referer: http://mezzacraft.com/WordPress
[Mon Jul 20 06:15:26.957058 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:64385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4RXbwiU-Jh5ncAILFDagAAARE"], referer: http://ravmike.com/WordPress
[Mon Jul 20 06:15:27.388363 2026] [security2:error] [pid 871012:tid 871220] [client 104.234.53.48:62503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RX7wiU-Jh5ncAILFD4QAAAVc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:27.574440 2026] [security2:error] [pid 871012:tid 871234] [client 104.234.53.48:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RX7wiU-Jh5ncAILFD9gAAAWU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:27.756629 2026] [security2:error] [pid 871012:tid 871225] [client 181.224.94.124:29548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RX7wiU-Jh5ncAILFECQAAAVw"]
[Mon Jul 20 06:15:27.756801 2026] [security2:error] [pid 871012:tid 871225] [client 181.224.94.124:29548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RX7wiU-Jh5ncAILFECQAAAVw"]
[Mon Jul 20 06:15:27.865934 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:49278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4RX7wiU-Jh5ncAILFECwAAARE"], referer: https://ravmike.com/WordPress
[Mon Jul 20 06:15:27.910092 2026] [security2:error] [pid 871012:tid 871154] [client 50.116.65.227:58012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4RX7wiU-Jh5ncAILFEDgAAARU"]
[Mon Jul 20 06:15:27.914307 2026] [security2:error] [pid 871012:tid 871224] [client 14.225.17.146:64323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4RX7wiU-Jh5ncAILFECgAAAVs"]
[Mon Jul 20 06:15:27.928166 2026] [security2:error] [pid 871012:tid 871180] [client 57.141.18.22:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RWbwiU-Jh5ncAILFCIgABL18"]
[Mon Jul 20 06:15:28.174994 2026] [security2:error] [pid 871012:tid 871237] [client 185.132.186.94:34555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/radio.php"] [unique_id "al4RYLwiU-Jh5ncAILFEHAAAAWg"]
[Mon Jul 20 06:15:28.215197 2026] [security2:error] [pid 871012:tid 871202] [client 13.201.64.214:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RYLwiU-Jh5ncAILFEIgAAAUU"]
[Mon Jul 20 06:15:28.215288 2026] [security2:error] [pid 871012:tid 871202] [client 13.201.64.214:34210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RYLwiU-Jh5ncAILFEIgAAAUU"]
[Mon Jul 20 06:15:29.751514 2026] [security2:error] [pid 871012:tid 871145] [client 57.141.18.15:23934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RW7wiU-Jh5ncAILFCmgABDHg"]
[Mon Jul 20 06:15:29.964519 2026] [security2:error] [pid 871012:tid 871269] [client 14.225.17.146:60155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4RYbwiU-Jh5ncAILFEgAAAAYg"], referer: http://transparentservices.online/WordPress
[Mon Jul 20 06:15:29.974811 2026] [security2:error] [pid 871012:tid 871168] [client 185.132.186.60:29499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/fileman.php"] [unique_id "al4RYbwiU-Jh5ncAILFEpgAAASM"]
[Mon Jul 20 06:15:30.067776 2026] [security2:error] [pid 871012:tid 871198] [client 104.234.53.86:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RYrwiU-Jh5ncAILFEsgAAAUE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:30.366818 2026] [security2:error] [pid 871012:tid 871143] [client 171.60.139.123:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RYrwiU-Jh5ncAILFE0AAAAQo"]
[Mon Jul 20 06:15:30.368608 2026] [security2:error] [pid 871012:tid 871143] [client 171.60.139.123:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RYrwiU-Jh5ncAILFE0AAAAQo"]
[Mon Jul 20 06:15:30.871117 2026] [security2:error] [pid 871012:tid 871114] [remote 20.153.140.50:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4RYrwiU-Jh5ncAILFE9wABD2Q"]
[Mon Jul 20 06:15:31.055726 2026] [security2:error] [pid 871012:tid 871197] [client 41.173.37.102:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RY7wiU-Jh5ncAILFFCAAAAUA"]
[Mon Jul 20 06:15:31.055857 2026] [security2:error] [pid 871012:tid 871197] [client 41.173.37.102:12880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RY7wiU-Jh5ncAILFFCAAAAUA"]
[Mon Jul 20 06:15:31.141122 2026] [security2:error] [pid 871012:tid 871213] [client 98.159.234.160:55213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RY7wiU-Jh5ncAILFFCwAAAVA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:31.146498 2026] [security2:error] [pid 871012:tid 871151] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RYrwiU-Jh5ncAILFFBQABEhw"]
[Mon Jul 20 06:15:31.437573 2026] [security2:error] [pid 871012:tid 871050] [remote 20.153.140.50:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4RY7wiU-Jh5ncAILFFHgABPiQ"], referer: https://soloceos.com/wp-login.php
[Mon Jul 20 06:15:31.459311 2026] [security2:error] [pid 871012:tid 871201] [client 57.141.18.12:56460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RXbwiU-Jh5ncAILFDKwABREA"]
[Mon Jul 20 06:15:31.483432 2026] [security2:error] [pid 871012:tid 871226] [client 50.116.65.227:40908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RY7wiU-Jh5ncAILFFIwAAAV0"]
[Mon Jul 20 06:15:31.494476 2026] [security2:error] [pid 871012:tid 871202] [client 50.116.65.227:33584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RY7wiU-Jh5ncAILFFJQAAAUU"]
[Mon Jul 20 06:15:31.769884 2026] [security2:error] [pid 871012:tid 871184] [client 185.132.186.77:44917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/wp-ss.php"] [unique_id "al4RY7wiU-Jh5ncAILFFPwAAATM"]
[Mon Jul 20 06:15:32.009813 2026] [security2:error] [pid 871012:tid 871269] [client 103.141.108.143:52299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFUgAAAYg"]
[Mon Jul 20 06:15:32.010430 2026] [security2:error] [pid 871012:tid 871269] [client 103.141.108.143:52299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFUgAAAYg"]
[Mon Jul 20 06:15:32.399526 2026] [core:error] [pid 871012:tid 871175] [client 14.225.17.146:55184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:32.399556 2026] [core:error] [pid 871012:tid 871175] [client 14.225.17.146:55184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:32.402425 2026] [security2:error] [pid 871012:tid 871251] [client 67.203.61.163:38966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RZLwiU-Jh5ncAILFFbAAAAXY"], referer: https://mourgroup.com/
[Mon Jul 20 06:15:32.557575 2026] [security2:error] [pid 871012:tid 871241] [client 45.116.69.230:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFegAAAWw"]
[Mon Jul 20 06:15:32.557727 2026] [security2:error] [pid 871012:tid 871241] [client 45.116.69.230:49643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFegAAAWw"]
[Mon Jul 20 06:15:33.165950 2026] [security2:error] [pid 871012:tid 871145] [client 106.192.104.4:56470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFFowAAAQw"]
[Mon Jul 20 06:15:33.166190 2026] [security2:error] [pid 871012:tid 871145] [client 106.192.104.4:56470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFFowAAAQw"]
[Mon Jul 20 06:15:33.202339 2026] [security2:error] [pid 871012:tid 871187] [client 14.225.17.146:60001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4RY7wiU-Jh5ncAILFFLAAAATY"], referer: http://nwcarvingacademy.com/WordPress
[Mon Jul 20 06:15:33.571938 2026] [security2:error] [pid 871012:tid 871143] [client 185.132.186.69:42065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/xsec1.php"] [unique_id "al4RZbwiU-Jh5ncAILFFwgAAAQo"]
[Mon Jul 20 06:15:33.803645 2026] [security2:error] [pid 871012:tid 871061] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFF2AABdS8"]
[Mon Jul 20 06:15:33.803844 2026] [security2:error] [pid 871012:tid 871250] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFF2AABdS8"]
[Mon Jul 20 06:15:33.987745 2026] [security2:error] [pid 871012:tid 871161] [client 185.163.52.152:12424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RZbwiU-Jh5ncAILFF5wAAARw"], referer: https://mourgroup.com/
[Mon Jul 20 06:15:34.183163 2026] [security2:error] [pid 871012:tid 871196] [client 57.141.18.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFF7wAAAT8"]
[Mon Jul 20 06:15:34.267958 2026] [security2:error] [pid 871012:tid 871240] [client 14.225.17.146:53170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFF7QAAAWs"], referer: https://nwcarvingacademy.com/WordPress
[Mon Jul 20 06:15:34.484134 2026] [security2:error] [pid 871012:tid 871212] [client 57.141.18.2:52368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RYLwiU-Jh5ncAILFEEAABT1Q"]
[Mon Jul 20 06:15:34.500154 2026] [security2:error] [pid 871012:tid 871143] [client 14.225.17.146:55348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFGCgAAAQo"], referer: http://39ishlife.com/WordPress
[Mon Jul 20 06:15:34.540150 2026] [security2:error] [pid 871012:tid 871103] [remote 173.212.252.15:45206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RZrwiU-Jh5ncAILFGFgABY1k"]
[Mon Jul 20 06:15:34.734443 2026] [security2:error] [pid 871012:tid 871101] [remote 8.217.108.67:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4RZrwiU-Jh5ncAILFGKAABSFc"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:15:34.775375 2026] [security2:error] [pid 871012:tid 871264] [client 104.234.53.59:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RZrwiU-Jh5ncAILFGMQAAAYM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:34.775767 2026] [security2:error] [pid 871012:tid 871244] [client 178.152.178.232:36442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RZrwiU-Jh5ncAILFGMgAAAW8"]
[Mon Jul 20 06:15:34.775849 2026] [security2:error] [pid 871012:tid 871244] [client 178.152.178.232:36442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RZrwiU-Jh5ncAILFGMgAAAW8"]
[Mon Jul 20 06:15:35.382064 2026] [security2:error] [pid 871012:tid 871223] [client 185.132.186.78:58023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin.php%20"] [unique_id "al4RZ7wiU-Jh5ncAILFGXAAAAVo"]
[Mon Jul 20 06:15:35.407777 2026] [security2:error] [pid 871012:tid 871224] [client 14.225.17.146:49448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4RZ7wiU-Jh5ncAILFGWQAAAVs"], referer: https://39ishlife.com/WordPress
[Mon Jul 20 06:15:35.783037 2026] [security2:error] [pid 871012:tid 871252] [client 57.141.18.79:21826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RYbwiU-Jh5ncAILFEdQABdzM"]
[Mon Jul 20 06:15:36.093005 2026] [security2:error] [pid 871012:tid 871145] [client 14.225.17.146:52667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4RZ7wiU-Jh5ncAILFGiwAAAQw"], referer: http://nextlvlmarketingco.com/WordPress
[Mon Jul 20 06:15:36.120786 2026] [security2:error] [pid 871012:tid 871268] [client 158.173.89.95:35961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RaLwiU-Jh5ncAILFGmQAAAYc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:36.202626 2026] [security2:error] [pid 871012:tid 871175] [client 103.77.203.233:61828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RaLwiU-Jh5ncAILFGoAAAASo"]
[Mon Jul 20 06:15:36.202805 2026] [security2:error] [pid 871012:tid 871175] [client 103.77.203.233:61828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RaLwiU-Jh5ncAILFGoAAAASo"]
[Mon Jul 20 06:15:36.321059 2026] [security2:error] [pid 871012:tid 871154] [client 13.229.223.11:44070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RaLwiU-Jh5ncAILFGqAAAARU"]
[Mon Jul 20 06:15:36.362959 2026] [security2:error] [pid 871012:tid 871104] [remote 100.42.189.89:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RaLwiU-Jh5ncAILFGrQABbFo"]
[Mon Jul 20 06:15:36.554117 2026] [security2:error] [pid 871012:tid 871092] [remote 100.42.189.89:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RaLwiU-Jh5ncAILFGvgABO04"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:15:36.691159 2026] [security2:error] [pid 871012:tid 871237] [client 14.225.17.146:63589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4RaLwiU-Jh5ncAILFGtwAAAWg"], referer: http://maxenengineering.com/WordPress
[Mon Jul 20 06:15:37.059145 2026] [security2:error] [pid 871012:tid 871206] [client 14.225.17.146:60261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4RZ7wiU-Jh5ncAILFGbQAAAUk"], referer: http://windowtx.com/WordPress
[Mon Jul 20 06:15:37.061538 2026] [security2:error] [pid 871012:tid 871062] [remote 45.90.123.233:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4RabwiU-Jh5ncAILFG6gABXzA"]
[Mon Jul 20 06:15:37.169028 2026] [security2:error] [pid 871012:tid 871237] [client 185.132.186.63:35353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/hong1.php"] [unique_id "al4RabwiU-Jh5ncAILFG_gAAAWg"]
[Mon Jul 20 06:15:37.413931 2026] [security2:error] [pid 871012:tid 871060] [remote 45.90.123.233:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4RabwiU-Jh5ncAILFHEAABUi4"], referer: https://mail.cathybuffini.com/wp-login.php
[Mon Jul 20 06:15:37.444074 2026] [security2:error] [pid 871012:tid 871144] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4RaLwiU-Jh5ncAILFG1gABCwU"], referer: http://ali-alghanim.net/WordPress
[Mon Jul 20 06:15:37.685870 2026] [security2:error] [pid 871012:tid 871157] [client 14.225.17.146:63188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4RabwiU-Jh5ncAILFHFAAAARg"], referer: https://maxenengineering.com/WordPress
[Mon Jul 20 06:15:38.043410 2026] [security2:error] [pid 871012:tid 871180] [client 18.141.57.241:43366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RabwiU-Jh5ncAILFHCQAAAS8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:15:38.289583 2026] [security2:error] [pid 871012:tid 871205] [client 181.224.94.124:37409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RarwiU-Jh5ncAILFHRwAAAUg"]
[Mon Jul 20 06:15:38.289727 2026] [security2:error] [pid 871012:tid 871205] [client 181.224.94.124:37409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RarwiU-Jh5ncAILFHRwAAAUg"]
[Mon Jul 20 06:15:38.683138 2026] [security2:error] [pid 871012:tid 871168] [client 103.153.183.69:13918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//....//var/www/html/config.php"] [unique_id "al4RarwiU-Jh5ncAILFHYQAAASM"], referer: https://duckduckgo.com/?q=fcw6a
[Mon Jul 20 06:15:38.754065 2026] [security2:error] [pid 871012:tid 871244] [client 14.225.17.146:50341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4RabwiU-Jh5ncAILFG-wAAAW8"], referer: http://ironcitywellness.com/WordPress
[Mon Jul 20 06:15:38.970670 2026] [security2:error] [pid 871012:tid 871243] [client 185.132.186.61:39279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/byps.php"] [unique_id "al4RarwiU-Jh5ncAILFHegAAAW4"]
[Mon Jul 20 06:15:39.092128 2026] [security2:error] [pid 871012:tid 871240] [client 64.7.220.66:57107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4RarwiU-Jh5ncAILFHeAAAAWs"]
[Mon Jul 20 06:15:39.144362 2026] [security2:error] [pid 871012:tid 871192] [client 13.201.64.214:38636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHhQAAATs"]
[Mon Jul 20 06:15:39.144530 2026] [security2:error] [pid 871012:tid 871192] [client 13.201.64.214:38636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHhQAAATs"]
[Mon Jul 20 06:15:39.194759 2026] [security2:error] [pid 871012:tid 871177] [client 14.225.17.146:63549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4RabwiU-Jh5ncAILFHCAAAASw"], referer: http://narv.co/WordPress
[Mon Jul 20 06:15:39.302820 2026] [security2:error] [pid 871012:tid 871161] [client 50.116.65.227:31578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ra7wiU-Jh5ncAILFHmAAAARw"]
[Mon Jul 20 06:15:39.314992 2026] [security2:error] [pid 871012:tid 871169] [client 50.116.65.227:56588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ra7wiU-Jh5ncAILFHmwAAARQ"]
[Mon Jul 20 06:15:39.735927 2026] [security2:error] [pid 871012:tid 871118] [remote 152.228.213.32:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHugABLWg"]
[Mon Jul 20 06:15:39.921879 2026] [security2:error] [pid 871012:tid 871016] [remote 152.228.213.32:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHzQABcwI"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:15:40.129136 2026] [security2:error] [pid 871012:tid 871219] [client 74.208.214.194:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RbLwiU-Jh5ncAILFH1QAAAVY"]
[Mon Jul 20 06:15:40.216035 2026] [security2:error] [pid 871012:tid 871241] [client 14.225.17.146:63321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4RbLwiU-Jh5ncAILFH0QAAAWw"], referer: https://narv.co/WordPress
[Mon Jul 20 06:15:40.888841 2026] [security2:error] [pid 871012:tid 871180] [client 14.225.17.146:63113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHpQAAAS8"], referer: http://expertcultures.com/WordPress
[Mon Jul 20 06:15:41.141250 2026] [security2:error] [pid 871012:tid 871237] [client 104.234.53.78:48025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RbbwiU-Jh5ncAILFIKgAAAWg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:41.201513 2026] [security2:error] [pid 871012:tid 871232] [client 51.158.58.168:56778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5028.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4RbbwiU-Jh5ncAILFILwAAAWM"]
[Mon Jul 20 06:15:41.220337 2026] [security2:error] [pid 871012:tid 871159] [client 171.60.139.123:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIMQAAARo"]
[Mon Jul 20 06:15:41.220508 2026] [security2:error] [pid 871012:tid 871159] [client 171.60.139.123:59210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIMQAAARo"]
[Mon Jul 20 06:15:41.232102 2026] [security2:error] [pid 871012:tid 871188] [client 57.141.18.50:65392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFGNgABN2Y"]
[Mon Jul 20 06:15:41.334536 2026] [security2:error] [pid 871012:tid 871204] [client 161.123.181.219:33139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4RbbwiU-Jh5ncAILFINQAAAUc"]
[Mon Jul 20 06:15:41.442812 2026] [proxy:error] [pid 871012:tid 871270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:41.442905 2026] [proxy_http:error] [pid 871012:tid 871270] [client 205.210.31.50:64880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:41.443952 2026] [proxy:error] [pid 871012:tid 871270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:41.443998 2026] [proxy_http:error] [pid 871012:tid 871270] [client 205.210.31.50:64880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:41.546822 2026] [security2:error] [pid 871012:tid 871212] [client 114.119.148.10:58637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bandsir.com"] [uri "/novel/add_tag_counter/1131"] [unique_id "al4RbbwiU-Jh5ncAILFIUAAAAU8"], referer: https://www.bandsir.com/novel/add_tag_counter/1131?category_id=111000
[Mon Jul 20 06:15:41.641897 2026] [security2:error] [pid 871012:tid 871247] [client 14.225.17.146:59934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4RbLwiU-Jh5ncAILFH1gAAAXI"], referer: http://olearyplumbingllc.com/WordPress
[Mon Jul 20 06:15:41.710186 2026] [security2:error] [pid 871012:tid 871177] [client 41.173.37.102:13325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIXwAAASw"]
[Mon Jul 20 06:15:41.710290 2026] [security2:error] [pid 871012:tid 871177] [client 41.173.37.102:13325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIXwAAASw"]
[Mon Jul 20 06:15:41.751183 2026] [security2:error] [pid 871012:tid 871125] [remote 68.178.160.25:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIYAABM28"]
[Mon Jul 20 06:15:41.751403 2026] [security2:error] [pid 871012:tid 871184] [client 68.178.160.25:56186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIYAABM28"]
[Mon Jul 20 06:15:41.844273 2026] [security2:error] [pid 871012:tid 871181] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIVQABMHc"]
[Mon Jul 20 06:15:42.518561 2026] [security2:error] [pid 871012:tid 871250] [client 14.225.17.146:49933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4RbrwiU-Jh5ncAILFIlgAAAXU"], referer: http://mtlegnews.gov/WordPress
[Mon Jul 20 06:15:42.741422 2026] [security2:error] [pid 871012:tid 871197] [client 103.141.108.143:52783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RbrwiU-Jh5ncAILFIrAAAAUA"]
[Mon Jul 20 06:15:42.741779 2026] [security2:error] [pid 871012:tid 871197] [client 103.141.108.143:52783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RbrwiU-Jh5ncAILFIrAAAAUA"]
[Mon Jul 20 06:15:42.865977 2026] [security2:error] [pid 871012:tid 871243] [client 185.132.186.73:24149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/crystal/sad.php"] [unique_id "al4RbrwiU-Jh5ncAILFItQAAAW4"]
[Mon Jul 20 06:15:42.872815 2026] [security2:error] [pid 871012:tid 871214] [client 14.225.17.146:56645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4RbbwiU-Jh5ncAILFISgAAAVE"], referer: http://ghivs.com/WordPress
[Mon Jul 20 06:15:43.095329 2026] [security2:error] [pid 871012:tid 871180] [client 14.225.17.146:56862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RbrwiU-Jh5ncAILFItAAAAS8"]
[Mon Jul 20 06:15:43.153963 2026] [security2:error] [pid 871012:tid 871229] [client 57.141.18.74:22590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RaLwiU-Jh5ncAILFG3AABYAg"]
[Mon Jul 20 06:15:43.167626 2026] [security2:error] [pid 871012:tid 871153] [client 104.234.53.76:33143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Rb7wiU-Jh5ncAILFIzQAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:43.216915 2026] [security2:error] [pid 871012:tid 871230] [client 45.116.69.230:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI0QAAAWE"]
[Mon Jul 20 06:15:43.217062 2026] [security2:error] [pid 871012:tid 871230] [client 45.116.69.230:50187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI0QAAAWE"]
[Mon Jul 20 06:15:43.428352 2026] [security2:error] [pid 871012:tid 871112] [remote 167.233.114.32:34392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI6QABSmI"]
[Mon Jul 20 06:15:43.428473 2026] [security2:error] [pid 871012:tid 871207] [client 167.233.114.32:34392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI6QABSmI"]
[Mon Jul 20 06:15:43.445093 2026] [security2:error] [pid 871012:tid 871179] [client 14.225.17.146:53843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI2QAAAS4"]
[Mon Jul 20 06:15:43.800451 2026] [security2:error] [pid 871012:tid 871236] [client 106.192.104.4:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFJAQAAAWc"]
[Mon Jul 20 06:15:43.800592 2026] [security2:error] [pid 871012:tid 871236] [client 106.192.104.4:56982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFJAQAAAWc"]
[Mon Jul 20 06:15:43.845995 2026] [security2:error] [pid 871012:tid 871257] [client 14.225.17.146:56834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI6gAAAXw"], referer: http://uritems.net/WordPress
[Mon Jul 20 06:15:43.887842 2026] [security2:error] [pid 871012:tid 871155] [client 216.73.217.138:50118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI_AABFkY"]
[Mon Jul 20 06:15:44.181370 2026] [security2:error] [pid 871012:tid 871219] [client 142.252.156.67:12666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RcLwiU-Jh5ncAILFJHgABVhA"], referer: https://mourgroup.com/
[Mon Jul 20 06:15:44.198959 2026] [security2:error] [pid 871012:tid 871216] [client 14.225.17.146:59944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFJDQAAAVM"], referer: http://falconarrowshop.com/WordPress
[Mon Jul 20 06:15:44.369016 2026] [security2:error] [pid 871012:tid 871130] [remote 124.55.178.99:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4RcLwiU-Jh5ncAILFJOwABbnQ"]
[Mon Jul 20 06:15:44.509939 2026] [security2:error] [pid 871012:tid 871031] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RcLwiU-Jh5ncAILFJRgABfxE"]
[Mon Jul 20 06:15:44.510096 2026] [security2:error] [pid 871012:tid 871260] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RcLwiU-Jh5ncAILFJRgABfxE"]
[Mon Jul 20 06:15:44.603862 2026] [security2:error] [pid 871012:tid 871109] [remote 8.217.108.67:23166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RcLwiU-Jh5ncAILFJTwABgl8"]
[Mon Jul 20 06:15:44.662011 2026] [security2:error] [pid 871012:tid 871198] [client 185.132.186.102:46453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-packages.min.php"] [unique_id "al4RcLwiU-Jh5ncAILFJWQAAAUE"]
[Mon Jul 20 06:15:44.814514 2026] [security2:error] [pid 871012:tid 871035] [remote 124.55.178.99:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4RcLwiU-Jh5ncAILFJZAABORU"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:15:45.485031 2026] [security2:error] [pid 871012:tid 871162] [client 178.152.178.232:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RcbwiU-Jh5ncAILFJlAAAAR0"]
[Mon Jul 20 06:15:45.485130 2026] [security2:error] [pid 871012:tid 871162] [client 178.152.178.232:36851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RcbwiU-Jh5ncAILFJlAAAAR0"]
[Mon Jul 20 06:15:45.552937 2026] [security2:error] [pid 871012:tid 871232] [client 14.225.17.146:50920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4RcLwiU-Jh5ncAILFJIAAAAWM"], referer: http://slutilities.com/WordPress
[Mon Jul 20 06:15:45.813315 2026] [security2:error] [pid 871012:tid 871156] [client 57.141.18.70:53354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHvQABF0A"]
[Mon Jul 20 06:15:45.860660 2026] [security2:error] [pid 871012:tid 871169] [client 14.225.17.146:50923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4RcLwiU-Jh5ncAILFJKAAAASQ"], referer: http://aberballet.co.uk/WordPress
[Mon Jul 20 06:15:46.188039 2026] [security2:error] [pid 871012:tid 871204] [client 50.116.65.227:56724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RcrwiU-Jh5ncAILFJ0AAAAUc"]
[Mon Jul 20 06:15:46.196115 2026] [security2:error] [pid 871012:tid 871150] [client 14.224.227.113:54305] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4RcrwiU-Jh5ncAILFJ0QAAARE"]
[Mon Jul 20 06:15:46.197878 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:56736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RcrwiU-Jh5ncAILFJ0wAAAXg"]
[Mon Jul 20 06:15:46.440696 2026] [security2:error] [pid 871012:tid 871232] [client 185.132.186.90:38097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/patterns/content-type.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ6wAAAWM"]
[Mon Jul 20 06:15:46.473868 2026] [security2:error] [pid 871012:tid 871244] [client 27.96.94.195:37677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ8AAAAW8"]
[Mon Jul 20 06:15:46.474028 2026] [security2:error] [pid 871012:tid 871244] [client 27.96.94.195:37677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ8AAAAW8"]
[Mon Jul 20 06:15:46.693582 2026] [security2:error] [pid 871012:tid 871263] [client 50.116.65.227:31594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RcrwiU-Jh5ncAILFJ-wAAAYI"]
[Mon Jul 20 06:15:46.704473 2026] [security2:error] [pid 871012:tid 871259] [client 50.116.65.227:56764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RcrwiU-Jh5ncAILFJ_QAAAU8"]
[Mon Jul 20 06:15:46.722429 2026] [security2:error] [pid 871012:tid 871188] [client 50.116.65.227:56760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ8wAAATc"]
[Mon Jul 20 06:15:46.822346 2026] [security2:error] [pid 871012:tid 871257] [client 14.225.17.146:54014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4RcbwiU-Jh5ncAILFJeAAAAXw"], referer: http://maplerespiteservices.com/WordPress
[Mon Jul 20 06:15:46.852189 2026] [security2:error] [pid 871012:tid 871238] [client 103.77.203.233:62380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFKBQAAAWk"]
[Mon Jul 20 06:15:46.852369 2026] [security2:error] [pid 871012:tid 871238] [client 103.77.203.233:62380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFKBQAAAWk"]
[Mon Jul 20 06:15:46.918235 2026] [security2:error] [pid 871012:tid 871268] [client 50.116.65.227:56774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ_wAAAYc"]
[Mon Jul 20 06:15:47.012676 2026] [security2:error] [pid 871012:tid 871095] [remote 188.138.102.156:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKFgABKFE"]
[Mon Jul 20 06:15:47.213864 2026] [security2:error] [pid 871012:tid 871123] [remote 188.138.102.156:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKLQABUG0"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:15:47.992728 2026] [security2:error] [pid 871012:tid 871118] [remote 103.28.36.106:35064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKYAABKWg"]
[Mon Jul 20 06:15:48.096912 2026] [security2:error] [pid 871012:tid 871267] [client 14.225.17.146:53653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFKAQAAAYY"], referer: http://wathenbartlett.co.uk/WordPress
[Mon Jul 20 06:15:48.256823 2026] [security2:error] [pid 871012:tid 871218] [client 185.132.186.60:43111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/class.php"] [unique_id "al4RdLwiU-Jh5ncAILFKfAAAAVU"]
[Mon Jul 20 06:15:48.277000 2026] [security2:error] [pid 871012:tid 871024] [remote 81.173.115.7:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RdLwiU-Jh5ncAILFKfwABgQo"]
[Mon Jul 20 06:15:48.405372 2026] [security2:error] [pid 871012:tid 871031] [remote 103.28.36.106:35064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4RdLwiU-Jh5ncAILFKiQABWhE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:15:48.489066 2026] [security2:error] [pid 871012:tid 871109] [remote 81.173.115.7:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RdLwiU-Jh5ncAILFKjQABdV8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:48.613046 2026] [ssl:error] [pid 871012:tid 871197] [client 66.132.224.229:15818] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.emsbodystorm.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:15:48.653663 2026] [security2:error] [pid 871012:tid 871194] [client 57.141.18.85:61502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RbrwiU-Jh5ncAILFItwABPVw"]
[Mon Jul 20 06:15:48.787652 2026] [security2:error] [pid 871012:tid 871263] [client 181.224.94.124:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RdLwiU-Jh5ncAILFKrQAAAYI"]
[Mon Jul 20 06:15:48.787765 2026] [security2:error] [pid 871012:tid 871263] [client 181.224.94.124:30275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RdLwiU-Jh5ncAILFKrQAAAYI"]
[Mon Jul 20 06:15:48.986506 2026] [security2:error] [pid 871012:tid 871184] [client 14.225.17.146:53512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4RdLwiU-Jh5ncAILFKtwAAATM"], referer: https://wathenbartlett.co.uk/WordPress
[Mon Jul 20 06:15:49.022889 2026] [security2:error] [pid 871012:tid 871228] [client 14.225.17.146:53747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKHQAAAV8"], referer: http://mollycahill.com/WordPress
[Mon Jul 20 06:15:49.036070 2026] [security2:error] [pid 871012:tid 871153] [client 14.225.17.146:53802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFKDQAAARQ"]
[Mon Jul 20 06:15:49.308763 2026] [security2:error] [pid 871012:tid 871269] [client 14.225.17.146:53811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKKgAAAYg"], referer: http://jvcmotorsports.com/WordPress
[Mon Jul 20 06:15:49.386013 2026] [security2:error] [pid 871012:tid 871247] [client 104.234.53.55:31731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RdbwiU-Jh5ncAILFK9wAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:49.658567 2026] [security2:error] [pid 871012:tid 871063] [remote 8.217.108.67:23166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RdbwiU-Jh5ncAILFLBgABRjE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:15:49.796693 2026] [security2:error] [pid 871012:tid 871220] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RdbwiU-Jh5ncAILFLBwABV1A"], referer: http://aleishapenny.ca/WordPress
[Mon Jul 20 06:15:50.045262 2026] [security2:error] [pid 871012:tid 871242] [client 69.91.188.157:23984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4RdbwiU-Jh5ncAILFLIAABbU0"]
[Mon Jul 20 06:15:50.061368 2026] [security2:error] [pid 871012:tid 871211] [client 185.132.186.83:63789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-phpmailer-beta.php"] [unique_id "al4RdrwiU-Jh5ncAILFLOQAAAU4"]
[Mon Jul 20 06:15:50.173256 2026] [security2:error] [pid 871012:tid 871015] [remote 31.207.36.13:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLQQABZQE"]
[Mon Jul 20 06:15:50.183793 2026] [security2:error] [pid 871012:tid 871238] [client 65.1.132.125:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RdrwiU-Jh5ncAILFLQgAAAWk"]
[Mon Jul 20 06:15:50.183942 2026] [security2:error] [pid 871012:tid 871238] [client 65.1.132.125:17568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RdrwiU-Jh5ncAILFLQgAAAWk"]
[Mon Jul 20 06:15:50.487960 2026] [security2:error] [pid 871012:tid 871107] [remote 31.207.36.13:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLXwABJF0"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 06:15:50.592657 2026] [security2:error] [pid 871012:tid 871143] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RdrwiU-Jh5ncAILFLXgABCmg"], referer: https://aleishapenny.ca/WordPress
[Mon Jul 20 06:15:50.596772 2026] [security2:error] [pid 871012:tid 871066] [remote 192.241.143.148:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLZQABUzQ"]
[Mon Jul 20 06:15:50.723295 2026] [security2:error] [pid 871012:tid 871237] [client 57.141.18.78:43928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RcbwiU-Jh5ncAILFJfAABaBY"]
[Mon Jul 20 06:15:50.762309 2026] [security2:error] [pid 871012:tid 871056] [remote 192.241.143.148:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLdQABVSo"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 06:15:50.980834 2026] [security2:error] [pid 871012:tid 871221] [client 220.181.108.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4RdrwiU-Jh5ncAILFLbgAAAVg"]
[Mon Jul 20 06:15:51.190824 2026] [security2:error] [pid 871012:tid 871017] [remote 217.61.143.92:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLmgABOgM"]
[Mon Jul 20 06:15:51.423276 2026] [security2:error] [pid 871012:tid 871043] [remote 217.61.143.92:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLrAABIR0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:15:51.564630 2026] [security2:error] [pid 871012:tid 871222] [client 57.141.18.97:45948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RcbwiU-Jh5ncAILFJugABWQ8"]
[Mon Jul 20 06:15:51.863593 2026] [security2:error] [pid 871012:tid 871237] [client 185.132.186.81:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ms-file.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLzAAAAWg"]
[Mon Jul 20 06:15:51.907313 2026] [security2:error] [pid 871012:tid 871163] [client 171.60.139.123:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLzwAAAR4"]
[Mon Jul 20 06:15:51.907453 2026] [security2:error] [pid 871012:tid 871163] [client 171.60.139.123:59700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLzwAAAR4"]
[Mon Jul 20 06:15:52.299645 2026] [security2:error] [pid 871012:tid 871151] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ReLwiU-Jh5ncAILFL3QABEic"]
[Mon Jul 20 06:15:52.412433 2026] [security2:error] [pid 871012:tid 871185] [client 41.173.37.102:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ReLwiU-Jh5ncAILFL-gAAATQ"]
[Mon Jul 20 06:15:52.412534 2026] [security2:error] [pid 871012:tid 871185] [client 41.173.37.102:13776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ReLwiU-Jh5ncAILFL-gAAATQ"]
[Mon Jul 20 06:15:52.572245 2026] [security2:error] [pid 871012:tid 871226] [client 172.56.252.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4ReLwiU-Jh5ncAILFL3AAAAV0"]
[Mon Jul 20 06:15:52.629367 2026] [security2:error] [pid 871012:tid 871168] [client 57.141.18.73:43442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFKDAABI0o"]
[Mon Jul 20 06:15:53.198069 2026] [security2:error] [pid 871012:tid 871188] [client 77.110.127.138:58766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/feed/2bb5ei2h6jqd.php"] [unique_id "al4RebwiU-Jh5ncAILFMOQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:53.404839 2026] [security2:error] [pid 871012:tid 871160] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMQAAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:53.413378 2026] [security2:error] [pid 871012:tid 871267] [client 103.141.108.143:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMWwAAAYY"]
[Mon Jul 20 06:15:53.413523 2026] [security2:error] [pid 871012:tid 871267] [client 103.141.108.143:53270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMWwAAAYY"]
[Mon Jul 20 06:15:53.492618 2026] [security2:error] [pid 871012:tid 871143] [client 14.225.17.146:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLqwAAAQo"], referer: http://dollpassionista.com/WordPress
[Mon Jul 20 06:15:53.676984 2026] [security2:error] [pid 871012:tid 871212] [client 57.141.18.117:58336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKWgABTzk"]
[Mon Jul 20 06:15:53.724504 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.54:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "al4RebwiU-Jh5ncAILFMcwAAAVQ"]
[Mon Jul 20 06:15:53.833791 2026] [security2:error] [pid 871012:tid 871097] [remote 100.42.189.89:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RebwiU-Jh5ncAILFMgQABf1M"]
[Mon Jul 20 06:15:53.897691 2026] [security2:error] [pid 871012:tid 871242] [client 45.116.69.230:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMigAAAW0"]
[Mon Jul 20 06:15:53.897795 2026] [security2:error] [pid 871012:tid 871242] [client 45.116.69.230:50728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMigAAAW0"]
[Mon Jul 20 06:15:54.097006 2026] [security2:error] [pid 871012:tid 871131] [remote 100.42.189.89:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMlQABS3U"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:54.185263 2026] [security2:error] [pid 871012:tid 871229] [client 14.225.17.146:59368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4RerwiU-Jh5ncAILFMkAAAAWA"], referer: http://ivetstrategies.com/WordPress
[Mon Jul 20 06:15:54.207048 2026] [security2:error] [pid 871012:tid 871175] [client 77.110.127.138:58881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMTAAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:54.249404 2026] [security2:error] [pid 871012:tid 871196] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMUgAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:54.369361 2026] [security2:error] [pid 871012:tid 871066] [remote 192.241.143.148:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMqgABhzQ"]
[Mon Jul 20 06:15:54.438613 2026] [security2:error] [pid 871012:tid 871256] [client 106.192.104.4:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RerwiU-Jh5ncAILFMsgAAAXs"]
[Mon Jul 20 06:15:54.438701 2026] [security2:error] [pid 871012:tid 871256] [client 106.192.104.4:57558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RerwiU-Jh5ncAILFMsgAAAXs"]
[Mon Jul 20 06:15:54.505630 2026] [security2:error] [pid 871012:tid 871155] [client 14.225.17.146:59308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4RerwiU-Jh5ncAILFMpgAAARY"], referer: https://dollpassionista.com/WordPress
[Mon Jul 20 06:15:54.531622 2026] [security2:error] [pid 871012:tid 871056] [remote 192.241.143.148:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMugABZio"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:15:54.851231 2026] [security2:error] [pid 871012:tid 871126] [remote 68.178.160.25:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMzgABanA"]
[Mon Jul 20 06:15:55.144180 2026] [security2:error] [pid 871012:tid 871082] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Re7wiU-Jh5ncAILFM6QABc0Q"]
[Mon Jul 20 06:15:55.144363 2026] [security2:error] [pid 871012:tid 871248] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Re7wiU-Jh5ncAILFM6QABc0Q"]
[Mon Jul 20 06:15:55.167075 2026] [security2:error] [pid 871012:tid 871026] [remote 91.142.222.105:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFM6wABQAw"]
[Mon Jul 20 06:15:55.263585 2026] [security2:error] [pid 871012:tid 871200] [client 110.249.201.65:39290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.drawingthedog.com"] [uri "/robots.txt"] [unique_id "al4Re7wiU-Jh5ncAILFM9AAAAUM"]
[Mon Jul 20 06:15:55.271644 2026] [security2:error] [pid 871012:tid 871092] [remote 68.178.160.25:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFM8wABUU4"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:15:55.423995 2026] [security2:error] [pid 871012:tid 871067] [remote 91.142.222.105:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFNBAABFDU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:15:55.451735 2026] [security2:error] [pid 871012:tid 871266] [client 50.116.65.227:56724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Re7wiU-Jh5ncAILFNBQAAAYU"]
[Mon Jul 20 06:15:55.462010 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:56726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Re7wiU-Jh5ncAILFNCQAAATo"]
[Mon Jul 20 06:15:55.524123 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.85:39215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/av.php"] [unique_id "al4Re7wiU-Jh5ncAILFNDwAAAVQ"]
[Mon Jul 20 06:15:55.633832 2026] [security2:error] [pid 871012:tid 871228] [client 50.116.65.227:54812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Re7wiU-Jh5ncAILFNEwAAAV8"]
[Mon Jul 20 06:15:55.645514 2026] [security2:error] [pid 871012:tid 871163] [client 50.116.65.227:56728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Re7wiU-Jh5ncAILFNFAAAAQ4"]
[Mon Jul 20 06:15:55.780271 2026] [security2:error] [pid 871012:tid 871186] [client 185.223.152.55:51061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "avatrip.co"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4Re7wiU-Jh5ncAILFNHgAAATU"]
[Mon Jul 20 06:15:55.835646 2026] [security2:error] [pid 871012:tid 871045] [remote 103.173.227.188:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.227.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFNIAABJR8"]
[Mon Jul 20 06:15:56.079604 2026] [security2:error] [pid 871012:tid 871151] [client 178.152.178.232:36157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RfLwiU-Jh5ncAILFNRwAAARI"]
[Mon Jul 20 06:15:56.079698 2026] [security2:error] [pid 871012:tid 871151] [client 178.152.178.232:36157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RfLwiU-Jh5ncAILFNRwAAARI"]
[Mon Jul 20 06:15:56.211633 2026] [security2:error] [pid 871012:tid 871249] [client 104.234.53.75:48441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RfLwiU-Jh5ncAILFNlAAAAXQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:56.240106 2026] [security2:error] [pid 871012:tid 871016] [remote 103.173.227.188:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.227.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RfLwiU-Jh5ncAILFNpQABXQI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:56.916331 2026] [security2:error] [pid 871012:tid 871212] [client 14.225.17.146:59320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Re7wiU-Jh5ncAILFNNAAAAU8"], referer: http://adultdaycarereno.com/WordPress
[Mon Jul 20 06:15:57.153580 2026] [security2:error] [pid 871012:tid 871135] [remote 47.86.33.52:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RfbwiU-Jh5ncAILFOGgABI3k"]
[Mon Jul 20 06:15:57.260694 2026] [security2:error] [pid 871012:tid 871203] [client 104.234.53.78:40989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RfbwiU-Jh5ncAILFOIgAAAUY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:57.269870 2026] [security2:error] [pid 871012:tid 871193] [client 103.77.203.233:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOIwAAATw"]
[Mon Jul 20 06:15:57.269955 2026] [security2:error] [pid 871012:tid 871193] [client 103.77.203.233:62938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOIwAAATw"]
[Mon Jul 20 06:15:57.305160 2026] [security2:error] [pid 871012:tid 871259] [client 185.132.186.78:28557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/chosen.php%20"] [unique_id "al4RfbwiU-Jh5ncAILFOJAAAAX4"]
[Mon Jul 20 06:15:57.449267 2026] [security2:error] [pid 871012:tid 871181] [client 27.96.94.195:36967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOMwAAATA"]
[Mon Jul 20 06:15:57.450011 2026] [security2:error] [pid 871012:tid 871181] [client 27.96.94.195:36967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOMwAAATA"]
[Mon Jul 20 06:15:57.819481 2026] [security2:error] [pid 871012:tid 871147] [client 14.225.17.146:59439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4RfbwiU-Jh5ncAILFOTgAAAQ4"], referer: https://adultdaycarereno.com/WordPress
[Mon Jul 20 06:15:58.248039 2026] [security2:error] [pid 871012:tid 871251] [client 14.225.17.146:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4RfLwiU-Jh5ncAILFNtgAAAXY"], referer: http://itdynamix.com/WordPress
[Mon Jul 20 06:15:58.339700 2026] [security2:error] [pid 871012:tid 871082] [remote 188.40.28.4:46416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RfrwiU-Jh5ncAILFOeAABKUQ"]
[Mon Jul 20 06:15:58.339910 2026] [security2:error] [pid 871012:tid 871174] [client 188.40.28.4:46416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RfrwiU-Jh5ncAILFOeAABKUQ"]
[Mon Jul 20 06:15:58.473753 2026] [security2:error] [pid 871012:tid 871092] [remote 47.86.33.52:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RfrwiU-Jh5ncAILFOgAABMk4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:15:58.691806 2026] [security2:error] [pid 871012:tid 871145] [client 57.141.18.101:36200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMgAABDE0"]
[Mon Jul 20 06:15:58.719702 2026] [autoindex:error] [pid 871012:tid 871169] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/
[Mon Jul 20 06:15:58.876422 2026] [security2:error] [pid 871012:tid 871136] [remote 34.21.244.199:12020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RfrwiU-Jh5ncAILFOrQABW3o"]
[Mon Jul 20 06:15:59.054507 2026] [security2:error] [pid 871012:tid 871239] [client 103.153.183.69:60730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../srv/.env"] [unique_id "al4Rf7wiU-Jh5ncAILFOvAAAAWo"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:15:59.143285 2026] [security2:error] [pid 871012:tid 871200] [client 185.132.186.53:52899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/bs1.php"] [unique_id "al4Rf7wiU-Jh5ncAILFOyAAAAUM"]
[Mon Jul 20 06:15:59.219422 2026] [security2:error] [pid 871012:tid 871255] [client 168.144.240.66:49804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nvkdigital.co.uk"] [uri "/license.txt"] [unique_id "al4Rf7wiU-Jh5ncAILFO1AAAAXo"]
[Mon Jul 20 06:15:59.241179 2026] [security2:error] [pid 871012:tid 871019] [remote 34.21.244.199:12020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Rf7wiU-Jh5ncAILFO1QABOQU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:59.266434 2026] [security2:error] [pid 871012:tid 871253] [client 14.225.17.146:52300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Rf7wiU-Jh5ncAILFOvgAAAXg"], referer: https://itdynamix.com/WordPress
[Mon Jul 20 06:15:59.311499 2026] [security2:error] [pid 871012:tid 871164] [client 181.224.94.124:55584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rf7wiU-Jh5ncAILFO2QAAAR8"]
[Mon Jul 20 06:15:59.311583 2026] [security2:error] [pid 871012:tid 871164] [client 181.224.94.124:55584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rf7wiU-Jh5ncAILFO2QAAAR8"]
[Mon Jul 20 06:15:59.734504 2026] [core:error] [pid 871012:tid 871178] [client 14.225.17.146:59849] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WordPress
[Mon Jul 20 06:15:59.734528 2026] [core:error] [pid 871012:tid 871178] [client 14.225.17.146:59849] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WordPress
[Mon Jul 20 06:15:59.945453 2026] [security2:error] [pid 871012:tid 871076] [remote 217.61.143.92:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4Rf7wiU-Jh5ncAILFPEwABXj4"]
[Mon Jul 20 06:16:00.153901 2026] [core:error] [pid 871012:tid 871253] [client 104.223.85.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:00.153920 2026] [core:error] [pid 871012:tid 871253] [client 104.223.85.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:00.175924 2026] [security2:error] [pid 871012:tid 871085] [remote 217.61.143.92:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4RgLwiU-Jh5ncAILFPJAABLEc"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:16:00.762254 2026] [security2:error] [pid 871012:tid 871263] [client 57.141.18.22:61572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Re7wiU-Jh5ncAILFNPgABgjo"]
[Mon Jul 20 06:16:00.780155 2026] [security2:error] [pid 871012:tid 871153] [client 74.7.227.179:44522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RgLwiU-Jh5ncAILFPTwABFFU"], referer: https://tejasenvironmental.com/p=8744
[Mon Jul 20 06:16:00.946106 2026] [security2:error] [pid 871012:tid 871171] [client 185.132.186.55:39135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "al4RgLwiU-Jh5ncAILFPaAAAASY"]
[Mon Jul 20 06:16:01.014268 2026] [security2:error] [pid 871012:tid 871194] [client 3.109.4.218:39144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RgbwiU-Jh5ncAILFPbQAAAT0"]
[Mon Jul 20 06:16:01.014377 2026] [security2:error] [pid 871012:tid 871194] [client 3.109.4.218:39144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RgbwiU-Jh5ncAILFPbQAAAT0"]
[Mon Jul 20 06:16:01.454606 2026] [security2:error] [pid 871012:tid 871164] [client 70.189.175.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4RgbwiU-Jh5ncAILFPhgAAAR8"]
[Mon Jul 20 06:16:01.675344 2026] [security2:error] [pid 871012:tid 871188] [client 57.141.18.123:37916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RfLwiU-Jh5ncAILFN-wABNwE"]
[Mon Jul 20 06:16:01.825396 2026] [security2:error] [pid 871012:tid 871263] [client 103.153.183.69:60730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../home/.env"] [unique_id "al4RgbwiU-Jh5ncAILFPtQAAAYI"], referer: https://www.google.com/search?q=fiqdgg
[Mon Jul 20 06:16:01.889315 2026] [security2:error] [pid 871012:tid 871235] [client 104.234.53.80:35759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RgbwiU-Jh5ncAILFPrgAAAWY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:02.204378 2026] [security2:error] [pid 871012:tid 871145] [client 14.225.17.146:52467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFPywAAAQw"], referer: http://mazzucelli.com/WordPress
[Mon Jul 20 06:16:02.688706 2026] [security2:error] [pid 871012:tid 871016] [remote 20.153.140.50:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RgrwiU-Jh5ncAILFP-wABUAI"]
[Mon Jul 20 06:16:02.755968 2026] [security2:error] [pid 871012:tid 871188] [client 104.234.53.80:35759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RgrwiU-Jh5ncAILFQBQAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:02.766247 2026] [security2:error] [pid 871012:tid 871177] [client 185.132.186.90:30447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/network.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCAAAASw"]
[Mon Jul 20 06:16:02.799865 2026] [security2:error] [pid 871012:tid 871220] [client 171.60.139.123:60209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCwAAAVc"]
[Mon Jul 20 06:16:02.800013 2026] [security2:error] [pid 871012:tid 871220] [client 171.60.139.123:60209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCwAAAVc"]
[Mon Jul 20 06:16:02.859296 2026] [security2:error] [pid 871012:tid 871257] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RgrwiU-Jh5ncAILFQBgABfDI"]
[Mon Jul 20 06:16:02.883855 2026] [security2:error] [pid 871012:tid 871265] [client 57.141.18.96:39034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RfbwiU-Jh5ncAILFOYgABhFo"]
[Mon Jul 20 06:16:03.040601 2026] [security2:error] [pid 871012:tid 871266] [client 41.173.37.102:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQJQAAAYU"]
[Mon Jul 20 06:16:03.040689 2026] [security2:error] [pid 871012:tid 871266] [client 41.173.37.102:14222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQJQAAAYU"]
[Mon Jul 20 06:16:03.076907 2026] [security2:error] [pid 871012:tid 871240] [client 14.225.17.146:52316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFQHQAAAWs"], referer: http://fkconstructionfunding.com/WordPress
[Mon Jul 20 06:16:03.094563 2026] [security2:error] [pid 871012:tid 871019] [remote 20.153.140.50:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQJgABTwU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:16:03.901292 2026] [security2:error] [pid 871012:tid 871181] [client 57.141.18.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQZAAAATA"]
[Mon Jul 20 06:16:03.945165 2026] [security2:error] [pid 871012:tid 871182] [client 14.225.17.146:52513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFPzAAAATE"], referer: http://fineartsfactory.net/WordPress
[Mon Jul 20 06:16:04.062377 2026] [security2:error] [pid 871012:tid 871163] [client 14.225.17.146:50970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQdgAAAR4"], referer: https://fkconstructionfunding.com/WordPress
[Mon Jul 20 06:16:04.131095 2026] [security2:error] [pid 871012:tid 871157] [client 103.141.108.143:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQjwAAARg"]
[Mon Jul 20 06:16:04.132297 2026] [security2:error] [pid 871012:tid 871157] [client 103.141.108.143:53752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQjwAAARg"]
[Mon Jul 20 06:16:04.572863 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtQAAAX8"]
[Mon Jul 20 06:16:04.572991 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtQAAAX8"]
[Mon Jul 20 06:16:04.615207 2026] [security2:error] [pid 871012:tid 871164] [client 106.192.104.4:58048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtwAAAR8"]
[Mon Jul 20 06:16:04.615368 2026] [security2:error] [pid 871012:tid 871164] [client 106.192.104.4:58048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtwAAAR8"]
[Mon Jul 20 06:16:04.731666 2026] [security2:error] [pid 871012:tid 871186] [client 104.234.53.53:43715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RhLwiU-Jh5ncAILFQvQAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:04.776662 2026] [security2:error] [pid 871012:tid 871189] [client 185.132.186.93:42875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/page.php"] [unique_id "al4RhLwiU-Jh5ncAILFQxAAAATg"]
[Mon Jul 20 06:16:04.954783 2026] [security2:error] [pid 871012:tid 871174] [client 14.225.17.146:61665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCQAAASk"], referer: http://www.justinagrayman.com/WordPress
[Mon Jul 20 06:16:05.186790 2026] [security2:error] [pid 871012:tid 871156] [client 50.116.65.227:39516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RhbwiU-Jh5ncAILFQ5wAAARc"]
[Mon Jul 20 06:16:05.201759 2026] [security2:error] [pid 871012:tid 871260] [client 50.116.65.227:37112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RhbwiU-Jh5ncAILFQ6gAAARY"]
[Mon Jul 20 06:16:05.306483 2026] [security2:error] [pid 871012:tid 871207] [client 104.234.53.55:57419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RhbwiU-Jh5ncAILFQ8wAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:05.526813 2026] [security2:error] [pid 871012:tid 871147] [client 54.81.157.232:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4RhLwiU-Jh5ncAILFQ1wAAAQ4"]
[Mon Jul 20 06:16:05.529319 2026] [security2:error] [pid 871012:tid 871266] [client 54.81.157.232:29486] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/pollo-frito-en-freidora-de-aire-air-fryer-fried-chicken"] [unique_id "al4RhLwiU-Jh5ncAILFQ1AAAAYU"]
[Mon Jul 20 06:16:05.768827 2026] [security2:error] [pid 871012:tid 871206] [client 14.225.17.146:52589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RhbwiU-Jh5ncAILFRGAAAAUk"], referer: http://mourgroup.com/WordPress
[Mon Jul 20 06:16:05.769102 2026] [security2:error] [pid 871012:tid 871096] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RhbwiU-Jh5ncAILFRIwABWVI"]
[Mon Jul 20 06:16:05.769308 2026] [security2:error] [pid 871012:tid 871222] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RhbwiU-Jh5ncAILFRIwABWVI"]
[Mon Jul 20 06:16:05.775166 2026] [security2:error] [pid 871012:tid 871235] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4RhbwiU-Jh5ncAILFRJAAAAWY"], referer: https://www.google.com/
[Mon Jul 20 06:16:06.043375 2026] [security2:error] [pid 871012:tid 871154] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/.env"] [unique_id "al4RhrwiU-Jh5ncAILFROQAAARU"], referer: https://twitter.com/
[Mon Jul 20 06:16:06.181206 2026] [security2:error] [pid 871012:tid 871229] [client 57.141.18.60:35750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RgbwiU-Jh5ncAILFPiQABYBA"]
[Mon Jul 20 06:16:06.547374 2026] [security2:error] [pid 871012:tid 871179] [client 65.1.132.125:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRWwAAAS4"]
[Mon Jul 20 06:16:06.547473 2026] [security2:error] [pid 871012:tid 871179] [client 65.1.132.125:33588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRWwAAAS4"]
[Mon Jul 20 06:16:06.664174 2026] [security2:error] [pid 871012:tid 871188] [client 178.152.178.232:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRZgAAATc"]
[Mon Jul 20 06:16:06.664278 2026] [security2:error] [pid 871012:tid 871188] [client 178.152.178.232:37220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRZgAAATc"]
[Mon Jul 20 06:16:06.702812 2026] [security2:error] [pid 871012:tid 871153] [client 104.234.53.55:36403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RhrwiU-Jh5ncAILFRagAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:06.758166 2026] [security2:error] [pid 871012:tid 871261] [client 185.132.186.98:26973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/index.php"] [unique_id "al4RhrwiU-Jh5ncAILFRawAAAYA"]
[Mon Jul 20 06:16:06.995639 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:06.995721 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.51:60520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:06.996553 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:06.996583 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.51:60520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:07.219090 2026] [security2:error] [pid 871012:tid 871125] [remote 57.141.18.45:29074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4110925"] [unique_id "al4Rh7wiU-Jh5ncAILFRmAABEG8"]
[Mon Jul 20 06:16:07.838881 2026] [security2:error] [pid 871012:tid 871213] [client 103.77.203.233:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rh7wiU-Jh5ncAILFRwgAAAVA"]
[Mon Jul 20 06:16:07.839020 2026] [security2:error] [pid 871012:tid 871213] [client 103.77.203.233:63485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rh7wiU-Jh5ncAILFRwgAAAVA"]
[Mon Jul 20 06:16:07.979495 2026] [security2:error] [pid 871012:tid 871148] [client 158.173.166.181:27983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Rh7wiU-Jh5ncAILFR0AAAAQ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:08.034923 2026] [security2:error] [pid 871012:tid 871197] [client 14.225.17.146:58517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4RhrwiU-Jh5ncAILFRVgAAAUA"], referer: http://bnb-engineering.com/WordPress
[Mon Jul 20 06:16:08.135318 2026] [security2:error] [pid 871012:tid 871089] [remote 192.241.143.148:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RiLwiU-Jh5ncAILFR4gABX0s"]
[Mon Jul 20 06:16:08.219797 2026] [security2:error] [pid 871012:tid 871180] [client 3.87.117.29:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4Rh7wiU-Jh5ncAILFRqQAAAS8"]
[Mon Jul 20 06:16:08.268915 2026] [security2:error] [pid 871012:tid 871177] [client 3.87.117.29:39516] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pollo-frito-en-freidora-de-aire-air-fryer-fried-chicken/"] [unique_id "al4Rh7wiU-Jh5ncAILFRpQAAASw"]
[Mon Jul 20 06:16:08.307738 2026] [security2:error] [pid 871012:tid 871058] [remote 192.241.143.148:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RiLwiU-Jh5ncAILFR8AABPSw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:16:08.421518 2026] [security2:error] [pid 871012:tid 871198] [client 27.96.94.195:37507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RiLwiU-Jh5ncAILFR-QAAAUE"]
[Mon Jul 20 06:16:08.421659 2026] [security2:error] [pid 871012:tid 871198] [client 27.96.94.195:37507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RiLwiU-Jh5ncAILFR-QAAAUE"]
[Mon Jul 20 06:16:08.491973 2026] [security2:error] [pid 871012:tid 871144] [client 57.141.18.124:38362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQVwABC30"]
[Mon Jul 20 06:16:08.759507 2026] [security2:error] [pid 871012:tid 871222] [client 185.132.186.95:42969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/chosen.php"] [unique_id "al4RiLwiU-Jh5ncAILFSGgAAAVk"]
[Mon Jul 20 06:16:09.393009 2026] [security2:error] [pid 871012:tid 871118] [remote 57.141.18.9:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4297331"] [unique_id "al4RibwiU-Jh5ncAILFSQAABL2g"]
[Mon Jul 20 06:16:09.430335 2026] [security2:error] [pid 871012:tid 871182] [client 57.141.18.117:33582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RhLwiU-Jh5ncAILFQrAABMWw"]
[Mon Jul 20 06:16:09.756923 2026] [security2:error] [pid 871012:tid 871036] [remote 216.73.217.138:25567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RibwiU-Jh5ncAILFSVQABSRY"]
[Mon Jul 20 06:16:09.820497 2026] [security2:error] [pid 871012:tid 871197] [client 181.224.94.124:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RibwiU-Jh5ncAILFSYgAAAUA"]
[Mon Jul 20 06:16:09.820606 2026] [security2:error] [pid 871012:tid 871197] [client 181.224.94.124:4281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RibwiU-Jh5ncAILFSYgAAAUA"]
[Mon Jul 20 06:16:10.080418 2026] [security2:error] [pid 871012:tid 871081] [remote 57.141.18.18:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5629755"] [unique_id "al4RirwiU-Jh5ncAILFSdwABW0M"]
[Mon Jul 20 06:16:10.287362 2026] [security2:error] [pid 871012:tid 871159] [client 14.225.17.146:61375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSeQAAARo"], referer: http://oldracelimited.com/WordPress
[Mon Jul 20 06:16:10.322015 2026] [security2:error] [pid 871012:tid 871225] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/uploads/"] [unique_id "al4RirwiU-Jh5ncAILFShAAAAVw"]
[Mon Jul 20 06:16:10.528388 2026] [security2:error] [pid 871012:tid 871254] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RirwiU-Jh5ncAILFSmgAAAXk"]
[Mon Jul 20 06:16:10.571730 2026] [security2:error] [pid 871012:tid 871234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSiQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:10.621451 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:25070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSlgAAAXg"]
[Mon Jul 20 06:16:10.691928 2026] [security2:error] [pid 871012:tid 871180] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/"] [unique_id "al4RirwiU-Jh5ncAILFSsgAAAS8"]
[Mon Jul 20 06:16:10.752011 2026] [security2:error] [pid 871012:tid 871251] [client 185.132.186.99:50219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al4RirwiU-Jh5ncAILFSuAAAAXY"]
[Mon Jul 20 06:16:10.784563 2026] [core:error] [pid 871012:tid 871209] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:10.784587 2026] [core:error] [pid 871012:tid 871209] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:10.787838 2026] [security2:error] [pid 871012:tid 871267] [client 50.116.65.227:25082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSrAAAAYY"]
[Mon Jul 20 06:16:10.881009 2026] [security2:error] [pid 871012:tid 871168] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4RirwiU-Jh5ncAILFSygAAASM"], referer: https://duckduckgo.com/?q=lv2g7
[Mon Jul 20 06:16:10.916260 2026] [security2:error] [pid 871012:tid 871157] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4RirwiU-Jh5ncAILFSywAAARg"], referer: https://www.google.com/
[Mon Jul 20 06:16:10.936358 2026] [security2:error] [pid 871012:tid 871236] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RirwiU-Jh5ncAILFSyQAAAWc"]
[Mon Jul 20 06:16:11.081924 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/css/"] [unique_id "al4Ri7wiU-Jh5ncAILFS1AAAATQ"]
[Mon Jul 20 06:16:11.263301 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ri7wiU-Jh5ncAILFS4QAAAWE"]
[Mon Jul 20 06:16:11.448077 2026] [proxy:error] [pid 871012:tid 871226] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.448161 2026] [proxy_http:error] [pid 871012:tid 871226] [client 85.204.70.96:49620] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.448888 2026] [proxy:error] [pid 871012:tid 871226] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.448917 2026] [proxy_http:error] [pid 871012:tid 871226] [client 85.204.70.96:49620] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.477326 2026] [security2:error] [pid 871012:tid 871250] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/ID3/"] [unique_id "al4Ri7wiU-Jh5ncAILFS9AAAAXU"]
[Mon Jul 20 06:16:11.676405 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ri7wiU-Jh5ncAILFS_gAAATI"]
[Mon Jul 20 06:16:11.715342 2026] [proxy:error] [pid 871012:tid 871257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.715427 2026] [proxy_http:error] [pid 871012:tid 871257] [client 85.204.70.96:49636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.715993 2026] [proxy:error] [pid 871012:tid 871257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.716025 2026] [proxy_http:error] [pid 871012:tid 871257] [client 85.204.70.96:49636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.878562 2026] [security2:error] [pid 871012:tid 871154] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/IXR/"] [unique_id "al4Ri7wiU-Jh5ncAILFTEgAAARU"]
[Mon Jul 20 06:16:11.926396 2026] [security2:error] [pid 871012:tid 871242] [client 43.135.130.202:33124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.130.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4Ri7wiU-Jh5ncAILFTFQAAAW0"]
[Mon Jul 20 06:16:11.975017 2026] [security2:error] [pid 871012:tid 871236] [client 85.204.70.96:49642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4Ri7wiU-Jh5ncAILFTGgAAAWc"]
[Mon Jul 20 06:16:12.043168 2026] [security2:error] [pid 871012:tid 871260] [client 65.1.132.125:33598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RjLwiU-Jh5ncAILFTJgAAAX8"]
[Mon Jul 20 06:16:12.043261 2026] [security2:error] [pid 871012:tid 871260] [client 65.1.132.125:33598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RjLwiU-Jh5ncAILFTJgAAAX8"]
[Mon Jul 20 06:16:12.077453 2026] [security2:error] [pid 871012:tid 871187] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjLwiU-Jh5ncAILFTIQAAATY"]
[Mon Jul 20 06:16:12.253557 2026] [security2:error] [pid 871012:tid 871161] [client 85.204.70.96:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RjLwiU-Jh5ncAILFTOAAAARw"]
[Mon Jul 20 06:16:12.270434 2026] [security2:error] [pid 871012:tid 871189] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/Requests/"] [unique_id "al4RjLwiU-Jh5ncAILFTPAAAATg"]
[Mon Jul 20 06:16:12.517147 2026] [proxy:error] [pid 871012:tid 871228] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:12.517230 2026] [proxy_http:error] [pid 871012:tid 871228] [client 85.204.70.96:49668] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:12.517859 2026] [proxy:error] [pid 871012:tid 871228] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:12.517891 2026] [proxy_http:error] [pid 871012:tid 871228] [client 85.204.70.96:49668] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:12.528489 2026] [security2:error] [pid 871012:tid 871173] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjLwiU-Jh5ncAILFTSwAAASg"]
[Mon Jul 20 06:16:12.675313 2026] [security2:error] [pid 871012:tid 871235] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/SimplePie/"] [unique_id "al4RjLwiU-Jh5ncAILFTVwAAAWY"]
[Mon Jul 20 06:16:12.759634 2026] [security2:error] [pid 871012:tid 871267] [client 185.132.186.86:35739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/admin-footer.php"] [unique_id "al4RjLwiU-Jh5ncAILFTYAAAAYY"]
[Mon Jul 20 06:16:12.785493 2026] [security2:error] [pid 871012:tid 871182] [client 85.204.70.96:55260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4RjLwiU-Jh5ncAILFTaAAAATE"]
[Mon Jul 20 06:16:12.808276 2026] [security2:error] [pid 871012:tid 871222] [client 14.225.17.146:60572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTQgAAAVk"], referer: http://overloadcomedy.com/WordPress
[Mon Jul 20 06:16:12.868450 2026] [security2:error] [pid 871012:tid 871200] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjLwiU-Jh5ncAILFTbAAAAUM"]
[Mon Jul 20 06:16:12.886459 2026] [security2:error] [pid 871012:tid 871190] [client 66.249.69.32:49619] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "bundleofjoyandpoop.com"] [uri "/robots.txt"] [unique_id "al4RjLwiU-Jh5ncAILFTdQAAATk"]
[Mon Jul 20 06:16:13.024307 2026] [security2:error] [pid 871012:tid 871257] [client 50.116.65.227:47492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4RjbwiU-Jh5ncAILFTfwAAAXw"]
[Mon Jul 20 06:16:13.025096 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/Text/"] [unique_id "al4RjbwiU-Jh5ncAILFTfgAAAWk"]
[Mon Jul 20 06:16:13.038805 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:25108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4RjbwiU-Jh5ncAILFTgQAAAS0"]
[Mon Jul 20 06:16:13.052484 2026] [security2:error] [pid 871012:tid 871241] [client 85.204.70.96:55270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFThQAAAWw"]
[Mon Jul 20 06:16:13.176867 2026] [security2:error] [pid 871012:tid 871197] [client 45.157.112.60:25209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RjbwiU-Jh5ncAILFTjwAAAUA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:13.233447 2026] [security2:error] [pid 871012:tid 871243] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjbwiU-Jh5ncAILFTkQAAAW4"]
[Mon Jul 20 06:16:13.264863 2026] [security2:error] [pid 871012:tid 871204] [client 14.225.17.146:60818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTdgAAAUc"], referer: http://carolinapressurewashers.com/WordPress
[Mon Jul 20 06:16:13.318565 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.96:55282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFTngAAAVU"]
[Mon Jul 20 06:16:13.382400 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/mu-plugins-old/"] [unique_id "al4RjbwiU-Jh5ncAILFTpAAAAXs"]
[Mon Jul 20 06:16:13.457301 2026] [security2:error] [pid 871012:tid 871206] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RjbwiU-Jh5ncAILFToQABSRw"]
[Mon Jul 20 06:16:13.575013 2026] [security2:error] [pid 871012:tid 871234] [client 85.204.70.96:55288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFTsQAAAWU"]
[Mon Jul 20 06:16:13.597068 2026] [security2:error] [pid 871012:tid 871229] [client 171.60.139.123:60709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RjbwiU-Jh5ncAILFTtAAAAWA"]
[Mon Jul 20 06:16:13.597234 2026] [security2:error] [pid 871012:tid 871229] [client 171.60.139.123:60709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RjbwiU-Jh5ncAILFTtAAAAWA"]
[Mon Jul 20 06:16:13.619834 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjbwiU-Jh5ncAILFTrwAAAUA"]
[Mon Jul 20 06:16:13.639634 2026] [security2:error] [pid 871012:tid 871192] [client 50.116.65.227:25130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RjbwiU-Jh5ncAILFTtQAAATs"]
[Mon Jul 20 06:16:13.649253 2026] [security2:error] [pid 871012:tid 871221] [client 50.116.65.227:25146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RjbwiU-Jh5ncAILFTtwAAAVg"]
[Mon Jul 20 06:16:13.791556 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/themes/classic/inc/"] [unique_id "al4RjbwiU-Jh5ncAILFTwQAAAWk"]
[Mon Jul 20 06:16:13.832213 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.96:55292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFTxgAAAXs"]
[Mon Jul 20 06:16:13.942512 2026] [security2:error] [pid 871012:tid 871253] [client 35.254.54.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTMQAAAXg"]
[Mon Jul 20 06:16:14.021407 2026] [security2:error] [pid 871012:tid 871211] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjbwiU-Jh5ncAILFT2AAAAU4"]
[Mon Jul 20 06:16:14.095572 2026] [security2:error] [pid 871012:tid 871193] [client 85.204.70.96:55302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFT4wAAATw"]
[Mon Jul 20 06:16:14.182880 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "al4RjrwiU-Jh5ncAILFT6QAAARk"]
[Mon Jul 20 06:16:14.255139 2026] [security2:error] [pid 871012:tid 871225] [client 14.225.17.146:51458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFTgAAAAVw"], referer: http://collectingrealestate.com/WordPress
[Mon Jul 20 06:16:14.361103 2026] [security2:error] [pid 871012:tid 871240] [client 85.204.70.96:55314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFT-wAAAWs"]
[Mon Jul 20 06:16:14.410425 2026] [security2:error] [pid 871012:tid 871194] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjrwiU-Jh5ncAILFT_QAAAT0"]
[Mon Jul 20 06:16:14.591140 2026] [security2:error] [pid 871012:tid 871222] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/mu-plugins/"] [unique_id "al4RjrwiU-Jh5ncAILFUFwAAAVk"]
[Mon Jul 20 06:16:14.620957 2026] [security2:error] [pid 871012:tid 871227] [client 85.204.70.96:55322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFUGQAAAV4"]
[Mon Jul 20 06:16:14.764526 2026] [security2:error] [pid 871012:tid 871206] [client 185.132.186.94:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/modules/mod_simplefileuploadv1.3/elements/admin-footer.php"] [unique_id "al4RjrwiU-Jh5ncAILFUIQAAAUk"]
[Mon Jul 20 06:16:14.823404 2026] [security2:error] [pid 871012:tid 871252] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjrwiU-Jh5ncAILFUIgAAAXc"]
[Mon Jul 20 06:16:14.881973 2026] [security2:error] [pid 871012:tid 871143] [client 85.204.70.96:55338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFULwAAAQo"]
[Mon Jul 20 06:16:14.976778 2026] [security2:error] [pid 871012:tid 871247] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al4RjrwiU-Jh5ncAILFUPAAAAXI"]
[Mon Jul 20 06:16:14.982237 2026] [security2:error] [pid 871012:tid 871242] [client 103.141.108.143:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RjrwiU-Jh5ncAILFUPQAAAW0"]
[Mon Jul 20 06:16:14.982984 2026] [security2:error] [pid 871012:tid 871242] [client 103.141.108.143:54249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RjrwiU-Jh5ncAILFUPQAAAW0"]
[Mon Jul 20 06:16:15.042658 2026] [security2:error] [pid 871012:tid 871238] [client 50.116.65.227:47494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Rj7wiU-Jh5ncAILFUPwAAAWk"]
[Mon Jul 20 06:16:15.054944 2026] [security2:error] [pid 871012:tid 871256] [client 50.116.65.227:25168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Rj7wiU-Jh5ncAILFUQgAAAXU"]
[Mon Jul 20 06:16:15.134299 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUSgAAAX8"]
[Mon Jul 20 06:16:15.134408 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUSgAAAX8"]
[Mon Jul 20 06:16:15.148315 2026] [security2:error] [pid 871012:tid 871202] [client 85.204.70.96:55354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUUgAAAUU"]
[Mon Jul 20 06:16:15.166319 2026] [security2:error] [pid 871012:tid 871186] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rj7wiU-Jh5ncAILFUSAAAATU"]
[Mon Jul 20 06:16:15.204634 2026] [security2:error] [pid 871012:tid 871270] [client 57.141.18.115:43640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RibwiU-Jh5ncAILFSagABiXA"]
[Mon Jul 20 06:16:15.306237 2026] [security2:error] [pid 871012:tid 871217] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/blocks/"] [unique_id "al4Rj7wiU-Jh5ncAILFUVwAAAVQ"]
[Mon Jul 20 06:16:15.381480 2026] [security2:error] [pid 871012:tid 871226] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUUwAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:15.413227 2026] [security2:error] [pid 871012:tid 871187] [client 85.204.70.96:55366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUZAAAATY"]
[Mon Jul 20 06:16:15.418641 2026] [security2:error] [pid 871012:tid 871239] [client 106.192.104.4:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUaAAAAWo"]
[Mon Jul 20 06:16:15.418745 2026] [security2:error] [pid 871012:tid 871239] [client 106.192.104.4:34208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUaAAAAWo"]
[Mon Jul 20 06:16:15.527431 2026] [security2:error] [pid 871012:tid 871199] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rj7wiU-Jh5ncAILFUbQAAAUI"]
[Mon Jul 20 06:16:15.538474 2026] [security2:error] [pid 871012:tid 871251] [client 98.159.234.160:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUdwAAAXY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:15.679359 2026] [security2:error] [pid 871012:tid 871268] [client 85.204.70.96:55378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUfwAAAYc"]
[Mon Jul 20 06:16:15.684289 2026] [security2:error] [pid 871012:tid 871194] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/certificates/"] [unique_id "al4Rj7wiU-Jh5ncAILFUgAAAAT0"]
[Mon Jul 20 06:16:15.785335 2026] [security2:error] [pid 871012:tid 871173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUdAAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:15.883835 2026] [security2:error] [pid 871012:tid 871191] [client 14.225.17.146:60591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFTsgAAATo"], referer: http://adastra.love/WordPress
[Mon Jul 20 06:16:15.924474 2026] [security2:error] [pid 871012:tid 871175] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rj7wiU-Jh5ncAILFUlQAAASo"]
[Mon Jul 20 06:16:15.943544 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.96:55380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUmQAAAR4"]
[Mon Jul 20 06:16:16.088962 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/customize/"] [unique_id "al4RkLwiU-Jh5ncAILFUqAAAAWE"]
[Mon Jul 20 06:16:16.253423 2026] [core:error] [pid 871012:tid 871259] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.253457 2026] [core:error] [pid 871012:tid 871259] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.270507 2026] [core:error] [pid 871012:tid 871155] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.270528 2026] [core:error] [pid 871012:tid 871155] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.318303 2026] [security2:error] [pid 871012:tid 871193] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkLwiU-Jh5ncAILFUwAAAATw"]
[Mon Jul 20 06:16:16.349897 2026] [security2:error] [pid 871012:tid 871172] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUogAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:16.476894 2026] [security2:error] [pid 871012:tid 871246] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/fonts/"] [unique_id "al4RkLwiU-Jh5ncAILFUzQAAAXE"]
[Mon Jul 20 06:16:16.547404 2026] [security2:error] [pid 871012:tid 871087] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU0gABf0k"]
[Mon Jul 20 06:16:16.547582 2026] [security2:error] [pid 871012:tid 871260] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU0gABf0k"]
[Mon Jul 20 06:16:16.663639 2026] [security2:error] [pid 871012:tid 871195] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkLwiU-Jh5ncAILFU2AAAAT4"]
[Mon Jul 20 06:16:16.764738 2026] [security2:error] [pid 871012:tid 871147] [client 185.132.186.77:25865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/info.php"] [unique_id "al4RkLwiU-Jh5ncAILFU5wAAAQ4"]
[Mon Jul 20 06:16:16.804089 2026] [security2:error] [pid 871012:tid 871172] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/images/"] [unique_id "al4RkLwiU-Jh5ncAILFU6QAAASc"]
[Mon Jul 20 06:16:16.813331 2026] [security2:error] [pid 871012:tid 871214] [client 41.173.37.102:14636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU6gAAAVE"]
[Mon Jul 20 06:16:16.813406 2026] [security2:error] [pid 871012:tid 871214] [client 41.173.37.102:14636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU6gAAAVE"]
[Mon Jul 20 06:16:16.935504 2026] [security2:error] [pid 871012:tid 871240] [client 74.208.214.194:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RkLwiU-Jh5ncAILFU8wAAAWs"]
[Mon Jul 20 06:16:17.037343 2026] [security2:error] [pid 871012:tid 871182] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkLwiU-Jh5ncAILFU_gAAATE"]
[Mon Jul 20 06:16:17.187903 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/.well-known/"] [unique_id "al4RkbwiU-Jh5ncAILFVCwAAARA"]
[Mon Jul 20 06:16:17.201093 2026] [security2:error] [pid 871012:tid 871270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkLwiU-Jh5ncAILFU7gAAAYk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:17.277887 2026] [security2:error] [pid 871012:tid 871185] [client 178.152.178.232:36168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RkbwiU-Jh5ncAILFVDwAAATQ"]
[Mon Jul 20 06:16:17.278028 2026] [security2:error] [pid 871012:tid 871185] [client 178.152.178.232:36168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RkbwiU-Jh5ncAILFVDwAAATQ"]
[Mon Jul 20 06:16:17.370464 2026] [security2:error] [pid 871012:tid 871147] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkbwiU-Jh5ncAILFVEgAAAQ4"]
[Mon Jul 20 06:16:17.429086 2026] [security2:error] [pid 871012:tid 871232] [client 104.234.53.91:21469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RkbwiU-Jh5ncAILFVGAAAAWM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:17.509259 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/ALFA_DATA/"] [unique_id "al4RkbwiU-Jh5ncAILFVJAAAATI"]
[Mon Jul 20 06:16:17.734646 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkbwiU-Jh5ncAILFVNwAAARA"]
[Mon Jul 20 06:16:17.839228 2026] [security2:error] [pid 871012:tid 871024] [remote 47.86.33.52:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4RkbwiU-Jh5ncAILFVQgABaQo"]
[Mon Jul 20 06:16:17.888669 2026] [security2:error] [pid 871012:tid 871226] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/.well-knownold/"] [unique_id "al4RkbwiU-Jh5ncAILFVRwAAAV0"]
[Mon Jul 20 06:16:17.946028 2026] [security2:error] [pid 871012:tid 871189] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkbwiU-Jh5ncAILFVOQAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:18.073701 2026] [security2:error] [pid 871012:tid 871198] [client 57.141.18.74:30916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTPwABQQs"]
[Mon Jul 20 06:16:18.135456 2026] [security2:error] [pid 871012:tid 871170] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkrwiU-Jh5ncAILFVYQAAASU"]
[Mon Jul 20 06:16:18.296334 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/.well-known/acme-challenge/"] [unique_id "al4RkrwiU-Jh5ncAILFVbAAAATQ"]
[Mon Jul 20 06:16:18.352182 2026] [security2:error] [pid 871012:tid 871256] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkrwiU-Jh5ncAILFVZAAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:18.353453 2026] [security2:error] [pid 871012:tid 871143] [client 103.77.203.233:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RkrwiU-Jh5ncAILFVcgAAAQo"]
[Mon Jul 20 06:16:18.353884 2026] [security2:error] [pid 871012:tid 871143] [client 103.77.203.233:64037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RkrwiU-Jh5ncAILFVcgAAAQo"]
[Mon Jul 20 06:16:18.531324 2026] [security2:error] [pid 871012:tid 871221] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkrwiU-Jh5ncAILFVfAAAAVg"]
[Mon Jul 20 06:16:18.648514 2026] [security2:error] [pid 871012:tid 871056] [remote 47.86.33.52:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4RkrwiU-Jh5ncAILFVkwABfyo"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:16:18.682593 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/cgi-bin/"] [unique_id "al4RkrwiU-Jh5ncAILFVlwAAAUk"]
[Mon Jul 20 06:16:18.753446 2026] [security2:error] [pid 871012:tid 871238] [client 185.132.186.90:45685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/XML/content.php"] [unique_id "al4RkrwiU-Jh5ncAILFVmgAAAWk"]
[Mon Jul 20 06:16:18.851399 2026] [security2:error] [pid 871012:tid 871230] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkrwiU-Jh5ncAILFVkAAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:18.925321 2026] [security2:error] [pid 871012:tid 871214] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkrwiU-Jh5ncAILFVpwAAAVE"]
[Mon Jul 20 06:16:19.080242 2026] [security2:error] [pid 871012:tid 871260] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/index/"] [unique_id "al4Rk7wiU-Jh5ncAILFVvQAAAX8"]
[Mon Jul 20 06:16:19.086711 2026] [security2:error] [pid 871012:tid 871159] [client 57.141.18.6:59280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFThwABGnU"]
[Mon Jul 20 06:16:19.268594 2026] [security2:error] [pid 871012:tid 871217] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rk7wiU-Jh5ncAILFV1AAAAVQ"]
[Mon Jul 20 06:16:19.293179 2026] [security2:error] [pid 871012:tid 871254] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4Rk7wiU-Jh5ncAILFVuwAAAXk"]
[Mon Jul 20 06:16:19.325678 2026] [security2:error] [pid 871012:tid 871209] [client 14.225.17.146:62860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4RkbwiU-Jh5ncAILFVSgAAAUw"], referer: http://bbwipartnerconference.com/WordPress
[Mon Jul 20 06:16:19.411382 2026] [security2:error] [pid 871012:tid 871251] [client 27.96.94.195:36996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Rk7wiU-Jh5ncAILFV4AAAAXY"]
[Mon Jul 20 06:16:19.411562 2026] [security2:error] [pid 871012:tid 871251] [client 27.96.94.195:36996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Rk7wiU-Jh5ncAILFV4AAAAXY"]
[Mon Jul 20 06:16:19.419193 2026] [security2:error] [pid 871012:tid 871174] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/id/"] [unique_id "al4Rk7wiU-Jh5ncAILFV4gAAASk"]
[Mon Jul 20 06:16:19.502301 2026] [security2:error] [pid 871012:tid 871262] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rk7wiU-Jh5ncAILFV0gAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:19.578165 2026] [security2:error] [pid 871012:tid 871243] [client 14.225.17.146:62858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4RkbwiU-Jh5ncAILFVTQAAAW4"], referer: http://careysheatingandcooling.com/WordPress
[Mon Jul 20 06:16:19.642408 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rk7wiU-Jh5ncAILFV9AAAAUs"]
[Mon Jul 20 06:16:19.787780 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/www/"] [unique_id "al4Rk7wiU-Jh5ncAILFWAwAAAUk"]
[Mon Jul 20 06:16:19.918166 2026] [security2:error] [pid 871012:tid 871233] [client 57.141.18.80:33322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFTyQABZDg"]
[Mon Jul 20 06:16:19.978462 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rk7wiU-Jh5ncAILFWCgAAATI"]
[Mon Jul 20 06:16:20.173541 2026] [security2:error] [pid 871012:tid 871241] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/web/"] [unique_id "al4RlLwiU-Jh5ncAILFWHQAAAWw"]
[Mon Jul 20 06:16:20.229055 2026] [security2:error] [pid 871012:tid 871152] [client 57.141.18.116:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjrwiU-Jh5ncAILFT5wABE0M"]
[Mon Jul 20 06:16:20.277315 2026] [security2:error] [pid 871012:tid 871035] [remote 124.55.178.99:38560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RlLwiU-Jh5ncAILFWLQABFRU"]
[Mon Jul 20 06:16:20.355271 2026] [security2:error] [pid 871012:tid 871194] [client 181.224.94.124:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RlLwiU-Jh5ncAILFWNAAAAT0"]
[Mon Jul 20 06:16:20.355417 2026] [security2:error] [pid 871012:tid 871194] [client 181.224.94.124:26677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RlLwiU-Jh5ncAILFWNAAAAT0"]
[Mon Jul 20 06:16:20.444425 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlLwiU-Jh5ncAILFWNQAAAVU"]
[Mon Jul 20 06:16:20.449106 2026] [security2:error] [pid 871012:tid 871252] [client 50.116.65.227:29324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4RlLwiU-Jh5ncAILFWNwAAAXc"]
[Mon Jul 20 06:16:20.460870 2026] [security2:error] [pid 871012:tid 871220] [client 50.116.65.227:54822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4RlLwiU-Jh5ncAILFWOAAAAV4"]
[Mon Jul 20 06:16:20.595833 2026] [security2:error] [pid 871012:tid 871221] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/uploads/"] [unique_id "al4RlLwiU-Jh5ncAILFWRgAAAVg"]
[Mon Jul 20 06:16:20.758130 2026] [security2:error] [pid 871012:tid 871159] [client 185.132.186.68:27829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/pomo/item.php"] [unique_id "al4RlLwiU-Jh5ncAILFWWAAAARo"]
[Mon Jul 20 06:16:20.780348 2026] [security2:error] [pid 871012:tid 871117] [remote 124.55.178.99:38560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RlLwiU-Jh5ncAILFWXAABX2c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:16:20.835618 2026] [security2:error] [pid 871012:tid 871143] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlLwiU-Jh5ncAILFWWgAAAQo"]
[Mon Jul 20 06:16:20.879919 2026] [security2:error] [pid 871012:tid 871155] [client 57.141.18.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rentorangegrove.com"] [uri "/index.php"] [unique_id "al4RlLwiU-Jh5ncAILFWSwAAARY"]
[Mon Jul 20 06:16:20.986934 2026] [security2:error] [pid 871012:tid 871242] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/upload/"] [unique_id "al4RlLwiU-Jh5ncAILFWaAAAAW0"]
[Mon Jul 20 06:16:20.987358 2026] [security2:error] [pid 871012:tid 871085] [remote 51.158.61.221:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RlLwiU-Jh5ncAILFWaQABNEc"]
[Mon Jul 20 06:16:21.192615 2026] [security2:error] [pid 871012:tid 871071] [remote 130.185.118.215:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWgwABhjk"]
[Mon Jul 20 06:16:21.209532 2026] [security2:error] [pid 871012:tid 871202] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlbwiU-Jh5ncAILFWggAAAUU"]
[Mon Jul 20 06:16:21.243942 2026] [security2:error] [pid 871012:tid 871097] [remote 51.158.61.221:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWiAABQ1M"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:16:21.387347 2026] [security2:error] [pid 871012:tid 871034] [remote 130.185.118.215:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWlAABNhQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:16:21.394682 2026] [security2:error] [pid 871012:tid 871241] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/uploads/"] [unique_id "al4RlbwiU-Jh5ncAILFWlQAAAWw"]
[Mon Jul 20 06:16:21.576299 2026] [security2:error] [pid 871012:tid 871207] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlbwiU-Jh5ncAILFWowAAAUo"]
[Mon Jul 20 06:16:21.713734 2026] [security2:error] [pid 871012:tid 871149] [client 216.73.217.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.poopscoopuniversity.com"] [uri "/index.php"] [unique_id "al4RlLwiU-Jh5ncAILFWOgABEHg"]
[Mon Jul 20 06:16:21.719122 2026] [security2:error] [pid 871012:tid 871179] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Admin/uploads/"] [unique_id "al4RlbwiU-Jh5ncAILFWsgAAAS4"]
[Mon Jul 20 06:16:21.724035 2026] [security2:error] [pid 871012:tid 871129] [remote 57.141.18.20:37874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3296202"] [unique_id "al4RlbwiU-Jh5ncAILFWswABJ3M"]
[Mon Jul 20 06:16:21.800526 2026] [security2:error] [pid 871012:tid 871216] [client 14.225.17.146:64597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4RlbwiU-Jh5ncAILFWdAAAAVM"], referer: http://idigress.agency/WordPress
[Mon Jul 20 06:16:21.927853 2026] [security2:error] [pid 871012:tid 871147] [client 57.141.18.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RlbwiU-Jh5ncAILFWiQAAAQ4"]
[Mon Jul 20 06:16:21.928335 2026] [security2:error] [pid 871012:tid 871162] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlbwiU-Jh5ncAILFWvwAAAR0"]
[Mon Jul 20 06:16:21.963154 2026] [security2:error] [pid 871012:tid 871108] [remote 154.66.198.148:2754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWwgABf14"]
[Mon Jul 20 06:16:22.061911 2026] [security2:error] [pid 871012:tid 871155] [client 14.225.17.146:52130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4RlbwiU-Jh5ncAILFWvQAAARY"], referer: http://longevityperformanceclinic.com/WordPress
[Mon Jul 20 06:16:22.084655 2026] [security2:error] [pid 871012:tid 871248] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/"] [unique_id "al4RlrwiU-Jh5ncAILFW2AAAAXM"]
[Mon Jul 20 06:16:22.319507 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlrwiU-Jh5ncAILFW7gAAAXs"]
[Mon Jul 20 06:16:22.392175 2026] [security2:error] [pid 871012:tid 871161] [client 57.141.18.67:55730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RkLwiU-Jh5ncAILFUwwABHAQ"]
[Mon Jul 20 06:16:22.483265 2026] [security2:error] [pid 871012:tid 871092] [remote 38.242.157.30:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFW-gABak4"]
[Mon Jul 20 06:16:22.487349 2026] [security2:error] [pid 871012:tid 871198] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/images/"] [unique_id "al4RlrwiU-Jh5ncAILFW_AAAAUE"]
[Mon Jul 20 06:16:22.668305 2026] [security2:error] [pid 871012:tid 871227] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlrwiU-Jh5ncAILFXEAAAAV4"]
[Mon Jul 20 06:16:22.708242 2026] [security2:error] [pid 871012:tid 871019] [remote 38.242.157.30:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXFwABKgU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:22.750266 2026] [security2:error] [pid 871012:tid 871082] [remote 51.158.61.221:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXIAABXEQ"]
[Mon Jul 20 06:16:22.757109 2026] [security2:error] [pid 871012:tid 871256] [client 185.132.186.79:35597] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-content/1.php%20"] [unique_id "al4RlrwiU-Jh5ncAILFXIQAAAXs"]
[Mon Jul 20 06:16:22.757270 2026] [security2:error] [pid 871012:tid 871256] [client 185.132.186.79:35597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/1.php%20"] [unique_id "al4RlrwiU-Jh5ncAILFXIQAAAXs"]
[Mon Jul 20 06:16:22.792271 2026] [security2:error] [pid 871012:tid 871045] [remote 154.66.198.148:2754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXJQABSh8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:22.809369 2026] [security2:error] [pid 871012:tid 871252] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/assets/"] [unique_id "al4RlrwiU-Jh5ncAILFXJwAAAXc"]
[Mon Jul 20 06:16:22.953486 2026] [security2:error] [pid 871012:tid 871195] [client 13.201.64.214:57100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RlrwiU-Jh5ncAILFXLQAAAT4"]
[Mon Jul 20 06:16:22.953576 2026] [security2:error] [pid 871012:tid 871195] [client 13.201.64.214:57100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RlrwiU-Jh5ncAILFXLQAAAT4"]
[Mon Jul 20 06:16:22.970742 2026] [security2:error] [pid 871012:tid 871057] [remote 51.158.61.221:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXLwABGCs"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:16:23.031368 2026] [security2:error] [pid 871012:tid 871254] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlrwiU-Jh5ncAILFXMAAAAXk"]
[Mon Jul 20 06:16:23.181117 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXAgABNh0"]
[Mon Jul 20 06:16:23.181446 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCAABNms"]
[Mon Jul 20 06:16:23.181536 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDwABNhg"]
[Mon Jul 20 06:16:23.181661 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCwABNhM"]
[Mon Jul 20 06:16:23.181740 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDAABNjA"]
[Mon Jul 20 06:16:23.183905 2026] [security2:error] [pid 871012:tid 871143] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "al4Rl7wiU-Jh5ncAILFXPwAAAQo"]
[Mon Jul 20 06:16:23.193627 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDQABNgI"]
[Mon Jul 20 06:16:23.202333 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXBAABNjU"]
[Mon Jul 20 06:16:23.202616 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXAwABNgM"]
[Mon Jul 20 06:16:23.206058 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCgABNno"]
[Mon Jul 20 06:16:23.215810 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCQABNgw"]
[Mon Jul 20 06:16:23.223376 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDgABNgA"]
[Mon Jul 20 06:16:23.372274 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rl7wiU-Jh5ncAILFXUQAAAUs"]
[Mon Jul 20 06:16:23.512004 2026] [security2:error] [pid 871012:tid 871263] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/upload/image/"] [unique_id "al4Rl7wiU-Jh5ncAILFXXQAAAYI"]
[Mon Jul 20 06:16:23.733820 2026] [security2:error] [pid 871012:tid 871225] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rl7wiU-Jh5ncAILFXawAAAVw"]
[Mon Jul 20 06:16:23.826950 2026] [security2:error] [pid 871012:tid 871222] [client 14.225.17.146:61139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFW9gAAAVk"], referer: http://scott-assist.com/WordPress
[Mon Jul 20 06:16:23.891038 2026] [security2:error] [pid 871012:tid 871216] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/assets/images/"] [unique_id "al4Rl7wiU-Jh5ncAILFXhAAAAVM"]
[Mon Jul 20 06:16:23.983695 2026] [security2:error] [pid 871012:tid 871089] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env"] [unique_id "al4Rl7wiU-Jh5ncAILFXigABeEs"]
[Mon Jul 20 06:16:24.036541 2026] [security2:error] [pid 871012:tid 871058] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.guidehunting.com"] [uri "/graphql"] [unique_id "al4RmLwiU-Jh5ncAILFXkAABNiw"]
[Mon Jul 20 06:16:24.037561 2026] [security2:error] [pid 871012:tid 871139] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env.old"] [unique_id "al4RmLwiU-Jh5ncAILFXjwABNn0"]
[Mon Jul 20 06:16:24.061215 2026] [security2:error] [pid 871012:tid 871071] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.guidehunting.com"] [uri "/.env.production"] [unique_id "al4RmLwiU-Jh5ncAILFXmgABQzk"]
[Mon Jul 20 06:16:24.061422 2026] [security2:error] [pid 871012:tid 871127] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/backend/.env"] [unique_id "al4RmLwiU-Jh5ncAILFXlQABQ3E"]
[Mon Jul 20 06:16:24.061438 2026] [security2:error] [pid 871012:tid 871115] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/api/.env"] [unique_id "al4RmLwiU-Jh5ncAILFXmAABQ2U"]
[Mon Jul 20 06:16:24.062369 2026] [security2:error] [pid 871012:tid 871095] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env.backup"] [unique_id "al4RmLwiU-Jh5ncAILFXmQABQ1E"]
[Mon Jul 20 06:16:24.062383 2026] [security2:error] [pid 871012:tid 871060] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/config/.env"] [unique_id "al4RmLwiU-Jh5ncAILFXmwABQy4"]
[Mon Jul 20 06:16:24.084302 2026] [security2:error] [pid 871012:tid 871244] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXiQABbwg"]
[Mon Jul 20 06:16:24.125261 2026] [security2:error] [pid 871012:tid 871260] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmLwiU-Jh5ncAILFXoQAAAX8"]
[Mon Jul 20 06:16:24.288642 2026] [security2:error] [pid 871012:tid 871212] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Public/"] [unique_id "al4RmLwiU-Jh5ncAILFXrQAAAU8"]
[Mon Jul 20 06:16:24.378311 2026] [security2:error] [pid 871012:tid 871200] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXlgABQ2M"]
[Mon Jul 20 06:16:24.378534 2026] [security2:error] [pid 871012:tid 871200] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXlAABQzM"]
[Mon Jul 20 06:16:24.394233 2026] [security2:error] [pid 871012:tid 871042] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.guidehunting.com"] [uri "/api/graphql"] [unique_id "al4RmLwiU-Jh5ncAILFXuQABIxw"]
[Mon Jul 20 06:16:24.452008 2026] [security2:error] [pid 871012:tid 871229] [client 41.173.37.102:1295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvwAAAWA"]
[Mon Jul 20 06:16:24.452133 2026] [security2:error] [pid 871012:tid 871229] [client 41.173.37.102:1295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvwAAAWA"]
[Mon Jul 20 06:16:24.475770 2026] [security2:error] [pid 871012:tid 871255] [client 171.60.139.123:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXwAAAAXo"]
[Mon Jul 20 06:16:24.475886 2026] [security2:error] [pid 871012:tid 871255] [client 171.60.139.123:61195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXwAAAAXo"]
[Mon Jul 20 06:16:24.539641 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmLwiU-Jh5ncAILFXwQAAARk"]
[Mon Jul 20 06:16:24.737788 2026] [security2:error] [pid 871012:tid 871162] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXuwABHVs"]
[Mon Jul 20 06:16:24.739120 2026] [security2:error] [pid 871012:tid 871162] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvQABHTc"]
[Mon Jul 20 06:16:24.740155 2026] [security2:error] [pid 871012:tid 871162] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvAABHQo"]
[Mon Jul 20 06:16:24.759504 2026] [security2:error] [pid 871012:tid 871195] [client 185.132.186.87:40815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/wp-atom.php"] [unique_id "al4RmLwiU-Jh5ncAILFX0wAAAT4"]
[Mon Jul 20 06:16:24.793908 2026] [security2:error] [pid 871012:tid 871025] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env.bak"] [unique_id "al4RmLwiU-Jh5ncAILFX1QABRgs"]
[Mon Jul 20 06:16:24.843287 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/vendor/"] [unique_id "al4RmLwiU-Jh5ncAILFX2wAAAR4"]
[Mon Jul 20 06:16:25.026040 2026] [security2:error] [pid 871012:tid 871102] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.guidehunting.com"] [uri "/v1/graphql"] [unique_id "al4RmbwiU-Jh5ncAILFX7QABRlg"]
[Mon Jul 20 06:16:25.040404 2026] [security2:error] [pid 871012:tid 871229] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmLwiU-Jh5ncAILFX6QAAAWA"]
[Mon Jul 20 06:16:25.081051 2026] [security2:error] [pid 871012:tid 871018] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/.boto"] [unique_id "al4RmbwiU-Jh5ncAILFX_AABRgQ"]
[Mon Jul 20 06:16:25.081236 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.guidehunting.com"] [uri "/.boto"] [unique_id "al4RmbwiU-Jh5ncAILFX_AABRgQ"]
[Mon Jul 20 06:16:25.081905 2026] [authz_core:error] [pid 871012:tid 871056] [remote 35.245.65.174:33064] AH01630: client denied by server configuration: /home4/guidehun/public_html/.htpasswd
[Mon Jul 20 06:16:25.098069 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFX1AABRmw"]
[Mon Jul 20 06:16:25.186467 2026] [security2:error] [pid 871012:tid 871270] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/local/"] [unique_id "al4RmbwiU-Jh5ncAILFYEQAAAYk"]
[Mon Jul 20 06:16:25.230775 2026] [security2:error] [pid 871012:tid 871196] [client 14.225.17.146:52064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXdQAAAT8"], referer: http://alexsandbergmusic.com/WordPress
[Mon Jul 20 06:16:25.379891 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX7wABRjQ"]
[Mon Jul 20 06:16:25.380593 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX7gABRhE"]
[Mon Jul 20 06:16:25.386205 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX8AABRj8"]
[Mon Jul 20 06:16:25.435277 2026] [security2:error] [pid 871012:tid 871144] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmbwiU-Jh5ncAILFYKAAAAQs"]
[Mon Jul 20 06:16:25.583276 2026] [security2:error] [pid 871012:tid 871171] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/modules/"] [unique_id "al4RmbwiU-Jh5ncAILFYMgAAASY"]
[Mon Jul 20 06:16:25.697386 2026] [security2:error] [pid 871012:tid 871155] [client 104.234.53.59:24167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RmbwiU-Jh5ncAILFYQQAAARY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:25.723320 2026] [security2:error] [pid 871012:tid 871252] [client 103.141.108.143:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYRgAAAXc"]
[Mon Jul 20 06:16:25.723515 2026] [security2:error] [pid 871012:tid 871252] [client 103.141.108.143:54733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYRgAAAXc"]
[Mon Jul 20 06:16:25.776644 2026] [security2:error] [pid 871012:tid 871198] [client 45.116.69.230:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYTAAAAUE"]
[Mon Jul 20 06:16:25.776798 2026] [security2:error] [pid 871012:tid 871198] [client 45.116.69.230:52326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYTAAAAUE"]
[Mon Jul 20 06:16:25.813863 2026] [security2:error] [pid 871012:tid 871223] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmbwiU-Jh5ncAILFYSwAAAVo"]
[Mon Jul 20 06:16:25.985588 2026] [security2:error] [pid 871012:tid 871215] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Site/"] [unique_id "al4RmbwiU-Jh5ncAILFYWgAAAVI"]
[Mon Jul 20 06:16:26.126671 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX9wABRhc"]
[Mon Jul 20 06:16:26.131860 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX-QABRi0"]
[Mon Jul 20 06:16:26.132270 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX_gABRlQ"]
[Mon Jul 20 06:16:26.133213 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX-AABRhA"]
[Mon Jul 20 06:16:26.137174 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX_QABRgc"]
[Mon Jul 20 06:16:26.154906 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX-wABRnY"]
[Mon Jul 20 06:16:26.207275 2026] [security2:error] [pid 871012:tid 871110] [remote 188.166.241.141:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RmrwiU-Jh5ncAILFYZwABiWA"]
[Mon Jul 20 06:16:26.221061 2026] [security2:error] [pid 871012:tid 871239] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmrwiU-Jh5ncAILFYZQAAAWo"]
[Mon Jul 20 06:16:26.225115 2026] [security2:error] [pid 871012:tid 871026] [remote 57.141.18.28:24674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3396212"] [unique_id "al4RmrwiU-Jh5ncAILFYYwABbQw"]
[Mon Jul 20 06:16:26.262499 2026] [security2:error] [pid 871012:tid 871214] [client 14.225.17.146:54392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXhwAAAVE"], referer: http://mrbambooplus.com/WordPress
[Mon Jul 20 06:16:26.321763 2026] [security2:error] [pid 871012:tid 871159] [client 158.173.89.95:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RmrwiU-Jh5ncAILFYbgAAARo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:26.380974 2026] [security2:error] [pid 871012:tid 871078] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/id_rsa"] [unique_id "al4RmrwiU-Jh5ncAILFYfAABYUA"]
[Mon Jul 20 06:16:26.381194 2026] [security2:error] [pid 871012:tid 871078] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.guidehunting.com"] [uri "/.ssh/config"] [unique_id "al4RmrwiU-Jh5ncAILFYgAABYUA"]
[Mon Jul 20 06:16:26.382120 2026] [security2:error] [pid 871012:tid 871064] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.ssh/id_dsa"] [unique_id "al4RmrwiU-Jh5ncAILFYewABYTI"]
[Mon Jul 20 06:16:26.382778 2026] [security2:error] [pid 871012:tid 871133] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.ssh/id_rsa"] [unique_id "al4RmrwiU-Jh5ncAILFYdwABYXc"]
[Mon Jul 20 06:16:26.382934 2026] [security2:error] [pid 871012:tid 871080] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/id_dsa"] [unique_id "al4RmrwiU-Jh5ncAILFYfgABYUI"]
[Mon Jul 20 06:16:26.403067 2026] [security2:error] [pid 871012:tid 871248] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/system/"] [unique_id "al4RmrwiU-Jh5ncAILFYggAAAXM"]
[Mon Jul 20 06:16:26.568684 2026] [security2:error] [pid 871012:tid 871111] [remote 188.166.241.141:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RmrwiU-Jh5ncAILFYjQABEmE"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 06:16:26.627293 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmrwiU-Jh5ncAILFYjwAAARk"]
[Mon Jul 20 06:16:26.679154 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYdgABYRU"]
[Mon Jul 20 06:16:26.679387 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYeQABYTg"]
[Mon Jul 20 06:16:26.679621 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYfwABYRo"]
[Mon Jul 20 06:16:26.679957 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYfQABYSM"]
[Mon Jul 20 06:16:26.681612 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYegABYSc"]
[Mon Jul 20 06:16:26.684276 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYdQABYUM"]
[Mon Jul 20 06:16:26.688013 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYeAABYSk"]
[Mon Jul 20 06:16:26.728219 2026] [security2:error] [pid 871012:tid 871071] [remote 173.212.252.15:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RmrwiU-Jh5ncAILFYoQABRDk"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:16:26.761968 2026] [security2:error] [pid 871012:tid 871208] [client 185.132.186.70:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/pomo/plugins.php"] [unique_id "al4RmrwiU-Jh5ncAILFYpAAAAUs"]
[Mon Jul 20 06:16:26.789122 2026] [security2:error] [pid 871012:tid 871223] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/template/"] [unique_id "al4RmrwiU-Jh5ncAILFYqQAAAVo"]
[Mon Jul 20 06:16:26.852311 2026] [security2:error] [pid 871012:tid 871206] [client 57.141.18.22:24956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RlLwiU-Jh5ncAILFWXwABST4"]
[Mon Jul 20 06:16:27.037233 2026] [security2:error] [pid 871012:tid 871219] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmrwiU-Jh5ncAILFYvgAAAVY"]
[Mon Jul 20 06:16:27.073687 2026] [security2:error] [pid 871012:tid 871144] [client 13.229.223.11:39748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFYygAAAQs"]
[Mon Jul 20 06:16:27.073844 2026] [security2:error] [pid 871012:tid 871144] [client 13.229.223.11:39748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFYygAAAQs"]
[Mon Jul 20 06:16:27.188965 2026] [security2:error] [pid 871012:tid 871266] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/shop/"] [unique_id "al4Rm7wiU-Jh5ncAILFY0gAAAYU"]
[Mon Jul 20 06:16:27.383787 2026] [security2:error] [pid 871012:tid 871107] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFY3wABRV0"]
[Mon Jul 20 06:16:27.383898 2026] [security2:error] [pid 871012:tid 871202] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFY3wABRV0"]
[Mon Jul 20 06:16:27.410458 2026] [security2:error] [pid 871012:tid 871270] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rm7wiU-Jh5ncAILFY3QAAAYk"]
[Mon Jul 20 06:16:27.589923 2026] [security2:error] [pid 871012:tid 871228] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/files/"] [unique_id "al4Rm7wiU-Jh5ncAILFY8AAAAV8"]
[Mon Jul 20 06:16:27.812419 2026] [security2:error] [pid 871012:tid 871268] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rm7wiU-Jh5ncAILFY_QAAAYc"]
[Mon Jul 20 06:16:27.865535 2026] [security2:error] [pid 871012:tid 871151] [client 77.110.127.138:59020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/baking/feed/"] [unique_id "al4Rm7wiU-Jh5ncAILFZAwAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:27.966850 2026] [security2:error] [pid 871012:tid 871183] [client 178.152.178.232:36535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFZDQAAATI"]
[Mon Jul 20 06:16:27.966973 2026] [security2:error] [pid 871012:tid 871183] [client 178.152.178.232:36535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFZDQAAATI"]
[Mon Jul 20 06:16:27.976958 2026] [security2:error] [pid 871012:tid 871192] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/editor/"] [unique_id "al4Rm7wiU-Jh5ncAILFZEgAAATs"]
[Mon Jul 20 06:16:28.051038 2026] [security2:error] [pid 871012:tid 871130] [remote 188.138.102.156:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RnLwiU-Jh5ncAILFZGgABPXQ"]
[Mon Jul 20 06:16:28.082474 2026] [security2:error] [pid 871012:tid 871154] [client 50.116.65.227:29340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4RnLwiU-Jh5ncAILFZHgAAARU"]
[Mon Jul 20 06:16:28.093525 2026] [security2:error] [pid 871012:tid 871252] [client 50.116.65.227:55042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4RnLwiU-Jh5ncAILFZIAAAAXc"]
[Mon Jul 20 06:16:28.166469 2026] [security2:error] [pid 871012:tid 871214] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnLwiU-Jh5ncAILFZIwAAAVE"]
[Mon Jul 20 06:16:28.270415 2026] [security2:error] [pid 871012:tid 871019] [remote 188.138.102.156:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RnLwiU-Jh5ncAILFZMwABhQU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:16:28.368100 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/include/"] [unique_id "al4RnLwiU-Jh5ncAILFZOAAAAXQ"]
[Mon Jul 20 06:16:28.551349 2026] [security2:error] [pid 871012:tid 871252] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnLwiU-Jh5ncAILFZPwAAAXc"]
[Mon Jul 20 06:16:28.691657 2026] [security2:error] [pid 871012:tid 871212] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Assets/"] [unique_id "al4RnLwiU-Jh5ncAILFZUQAAAU8"]
[Mon Jul 20 06:16:28.820009 2026] [security2:error] [pid 871012:tid 871270] [client 14.225.17.146:51360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4RnLwiU-Jh5ncAILFZSwAAAYk"], referer: http://thechancersband.com/WordPress
[Mon Jul 20 06:16:28.880733 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:64596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RnLwiU-Jh5ncAILFZXgAAAYI"]
[Mon Jul 20 06:16:28.881183 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:64596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RnLwiU-Jh5ncAILFZXgAAAYI"]
[Mon Jul 20 06:16:28.933461 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnLwiU-Jh5ncAILFZXAAAAXQ"]
[Mon Jul 20 06:16:29.088998 2026] [security2:error] [pid 871012:tid 871212] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/images/stories/"] [unique_id "al4RnbwiU-Jh5ncAILFZdgAAAU8"]
[Mon Jul 20 06:16:29.319424 2026] [security2:error] [pid 871012:tid 871189] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnbwiU-Jh5ncAILFZiAAAATg"]
[Mon Jul 20 06:16:29.478403 2026] [security2:error] [pid 871012:tid 871247] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/plugins/"] [unique_id "al4RnbwiU-Jh5ncAILFZlQAAAXI"]
[Mon Jul 20 06:16:29.499852 2026] [security2:error] [pid 871012:tid 871190] [client 57.141.18.7:21546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXMwABOSI"]
[Mon Jul 20 06:16:29.631352 2026] [security2:error] [pid 871012:tid 871182] [client 57.141.18.10:59890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXSQABMSA"]
[Mon Jul 20 06:16:29.663464 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnbwiU-Jh5ncAILFZqgAAAXQ"]
[Mon Jul 20 06:16:29.804694 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/php/"] [unique_id "al4RnbwiU-Jh5ncAILFZtQAAAWk"]
[Mon Jul 20 06:16:29.837100 2026] [security2:error] [pid 871012:tid 871181] [client 14.225.17.146:64001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4RnLwiU-Jh5ncAILFZVQAAATA"], referer: http://musichaven.info/WordPress
[Mon Jul 20 06:16:30.024437 2026] [security2:error] [pid 871012:tid 871250] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnbwiU-Jh5ncAILFZwQAAAXU"]
[Mon Jul 20 06:16:30.042898 2026] [security2:error] [pid 871012:tid 871138] [remote 100.42.189.89:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RnrwiU-Jh5ncAILFZygABUXw"]
[Mon Jul 20 06:16:30.174982 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/css/"] [unique_id "al4RnrwiU-Jh5ncAILFZ1wAAARA"]
[Mon Jul 20 06:16:30.291221 2026] [security2:error] [pid 871012:tid 871073] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/privatekey.key"] [unique_id "al4RnrwiU-Jh5ncAILFZ3gABfDs"]
[Mon Jul 20 06:16:30.291409 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.guidehunting.com"] [uri "/privatekey.key"] [unique_id "al4RnrwiU-Jh5ncAILFZ3gABfDs"]
[Mon Jul 20 06:16:30.292745 2026] [security2:error] [pid 871012:tid 871055] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/key.pem"] [unique_id "al4RnrwiU-Jh5ncAILFZ3QABfCk"]
[Mon Jul 20 06:16:30.295398 2026] [security2:error] [pid 871012:tid 871071] [remote 100.42.189.89:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ4AABZzk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:16:30.363451 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnrwiU-Jh5ncAILFZ4gAAAUA"]
[Mon Jul 20 06:16:30.382107 2026] [security2:error] [pid 871012:tid 871076] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.openclaw/.env"] [unique_id "al4RnrwiU-Jh5ncAILFZ6QABfD4"]
[Mon Jul 20 06:16:30.508285 2026] [security2:error] [pid 871012:tid 871234] [client 27.96.94.195:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ-wAAAWU"]
[Mon Jul 20 06:16:30.508435 2026] [security2:error] [pid 871012:tid 871234] [client 27.96.94.195:37604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ-wAAAWU"]
[Mon Jul 20 06:16:30.510521 2026] [security2:error] [pid 871012:tid 871267] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "al4RnrwiU-Jh5ncAILFZ-gAAAYY"]
[Mon Jul 20 06:16:30.619195 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ3AABfEM"]
[Mon Jul 20 06:16:30.619544 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ2QABfBo"]
[Mon Jul 20 06:16:30.620668 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ2wABfCc"]
[Mon Jul 20 06:16:30.620948 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ2gABfCM"]
[Mon Jul 20 06:16:30.733430 2026] [security2:error] [pid 871012:tid 871237] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnrwiU-Jh5ncAILFaEwAAAWg"]
[Mon Jul 20 06:16:30.749546 2026] [ssl:error] [pid 871012:tid 871183] [client 54.86.115.253:2563] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mielsantaengracia.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:16:30.755308 2026] [security2:error] [pid 871012:tid 871163] [client 14.225.17.146:51170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFaFAAAAR4"], referer: https://musichaven.info/WordPress
[Mon Jul 20 06:16:30.871320 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:32367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFaOAAAAYA"]
[Mon Jul 20 06:16:30.871455 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:32367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFaOAAAAYA"]
[Mon Jul 20 06:16:30.884826 2026] [security2:error] [pid 871012:tid 871160] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/cache/"] [unique_id "al4RnrwiU-Jh5ncAILFaOQAAARs"]
[Mon Jul 20 06:16:30.948667 2026] [security2:error] [pid 871012:tid 871240] [client 57.141.18.7:21548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXugABa2Q"]
[Mon Jul 20 06:16:31.014308 2026] [security2:error] [pid 871012:tid 871252] [client 14.225.17.146:51256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ0wAAAXc"], referer: http://techtradeinc.com/WordPress
[Mon Jul 20 06:16:31.107863 2026] [security2:error] [pid 871012:tid 871188] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rn7wiU-Jh5ncAILFaWAAAATc"]
[Mon Jul 20 06:16:31.144077 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ7QABfAg"]
[Mon Jul 20 06:16:31.144923 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ6AABfCw"]
[Mon Jul 20 06:16:31.145034 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ7AABfGI"]
[Mon Jul 20 06:16:31.145176 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ6wABfCU"]
[Mon Jul 20 06:16:31.149590 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ6gABfHE"]
[Mon Jul 20 06:16:31.306720 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/maint/"] [unique_id "al4Rn7wiU-Jh5ncAILFabQAAATQ"]
[Mon Jul 20 06:16:31.422593 2026] [security2:error] [pid 871012:tid 871149] [client 14.251.3.155:61270] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Rn7wiU-Jh5ncAILFadQAAARA"]
[Mon Jul 20 06:16:31.534457 2026] [security2:error] [pid 871012:tid 871156] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rn7wiU-Jh5ncAILFafQAAARc"]
[Mon Jul 20 06:16:31.688586 2026] [security2:error] [pid 871012:tid 871254] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/akismet/"] [unique_id "al4Rn7wiU-Jh5ncAILFaoQAAAXk"]
[Mon Jul 20 06:16:31.824850 2026] [security2:error] [pid 871012:tid 871209] [client 57.141.18.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4RnbwiU-Jh5ncAILFZwwAAAUw"]
[Mon Jul 20 06:16:31.940383 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rn7wiU-Jh5ncAILFatgAAAXs"]
[Mon Jul 20 06:16:31.998758 2026] [security2:error] [pid 871012:tid 871193] [client 185.132.186.89:47597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/install.php"] [unique_id "al4Rn7wiU-Jh5ncAILFawAAAATw"]
[Mon Jul 20 06:16:32.092634 2026] [security2:error] [pid 871012:tid 871186] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/assets/"] [unique_id "al4RoLwiU-Jh5ncAILFazgAAATU"]
[Mon Jul 20 06:16:32.210658 2026] [security2:error] [pid 871012:tid 871225] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gaantfootball.co.uk"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZzQAAAVw"]
[Mon Jul 20 06:16:32.324743 2026] [security2:error] [pid 871012:tid 871247] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RoLwiU-Jh5ncAILFa4wAAAXI"]
[Mon Jul 20 06:16:32.494327 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/block-patterns/"] [unique_id "al4RoLwiU-Jh5ncAILFa8gAAAXQ"]
[Mon Jul 20 06:16:32.557154 2026] [security2:error] [pid 871012:tid 871107] [remote 162.19.86.63:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RoLwiU-Jh5ncAILFa9wABFl0"]
[Mon Jul 20 06:16:32.557329 2026] [security2:error] [pid 871012:tid 871155] [client 162.19.86.63:44012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RoLwiU-Jh5ncAILFa9wABFl0"]
[Mon Jul 20 06:16:32.589056 2026] [security2:error] [pid 871012:tid 871194] [client 14.225.17.146:50574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFa7QAAAT0"], referer: http://taskidsvirginia.com/WordPress
[Mon Jul 20 06:16:32.684124 2026] [security2:error] [pid 871012:tid 871178] [client 57.141.18.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFa9gAAAS0"]
[Mon Jul 20 06:16:32.717348 2026] [security2:error] [pid 871012:tid 871144] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RoLwiU-Jh5ncAILFbAgAAAQs"]
[Mon Jul 20 06:16:32.884183 2026] [security2:error] [pid 871012:tid 871226] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/block-supports/"] [unique_id "al4RoLwiU-Jh5ncAILFbFQAAAV0"]
[Mon Jul 20 06:16:32.894760 2026] [autoindex:error] [pid 871012:tid 871214] [client 213.35.113.47:0] AH01276: Cannot serve directory /home3/ancestx0/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:16:33.113343 2026] [security2:error] [pid 871012:tid 871200] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RobwiU-Jh5ncAILFbHgAAAUM"]
[Mon Jul 20 06:16:33.282667 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/html-api/"] [unique_id "al4RobwiU-Jh5ncAILFbQAAAAUA"]
[Mon Jul 20 06:16:33.524472 2026] [security2:error] [pid 871012:tid 871175] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RobwiU-Jh5ncAILFbTwAAASo"]
[Mon Jul 20 06:16:33.667859 2026] [security2:error] [pid 871012:tid 871232] [client 3.109.4.218:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RobwiU-Jh5ncAILFbXQAAAWM"]
[Mon Jul 20 06:16:33.667976 2026] [security2:error] [pid 871012:tid 871232] [client 3.109.4.218:43998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RobwiU-Jh5ncAILFbXQAAAWM"]
[Mon Jul 20 06:16:33.694514 2026] [security2:error] [pid 871012:tid 871236] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/js/"] [unique_id "al4RobwiU-Jh5ncAILFbYgAAAWc"]
[Mon Jul 20 06:16:33.924468 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RobwiU-Jh5ncAILFbeQAAAVU"]
[Mon Jul 20 06:16:34.001193 2026] [security2:error] [pid 871012:tid 871185] [client 185.132.186.96:48719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/gecko-old.php"] [unique_id "al4RorwiU-Jh5ncAILFbfgAAATQ"]
[Mon Jul 20 06:16:34.024334 2026] [security2:error] [pid 871012:tid 871235] [client 14.225.17.146:64202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFawgAAAWY"], referer: http://floorsourcestock.com/WordPress
[Mon Jul 20 06:16:34.082473 2026] [security2:error] [pid 871012:tid 871229] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/php-compat/"] [unique_id "al4RorwiU-Jh5ncAILFbggAAAWA"]
[Mon Jul 20 06:16:34.196708 2026] [autoindex:error] [pid 871012:tid 871197] [client 213.35.113.47:0] AH01276: Cannot serve directory /home3/ancestx0/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:16:34.206355 2026] [security2:error] [pid 871012:tid 871196] [client 77.110.127.138:59041] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/baking/feed/"] [unique_id "al4RorwiU-Jh5ncAILFbjQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:34.268193 2026] [security2:error] [pid 871012:tid 871192] [client 14.225.17.146:50625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4RorwiU-Jh5ncAILFbfwAAATs"], referer: http://hilltopnurseryinc.com/WordPress
[Mon Jul 20 06:16:34.337415 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RorwiU-Jh5ncAILFbmwAAARA"]
[Mon Jul 20 06:16:34.484248 2026] [security2:error] [pid 871012:tid 871181] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/PHPMailer/"] [unique_id "al4RorwiU-Jh5ncAILFbswAAATA"]
[Mon Jul 20 06:16:34.557998 2026] [security2:error] [pid 871012:tid 871182] [client 136.108.4.202:46970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "ivetstrategies.com"] [uri "/wp-json/batch/v1"] [unique_id "al4RorwiU-Jh5ncAILFbtgAAATE"]
[Mon Jul 20 06:16:34.617733 2026] [security2:error] [pid 871012:tid 871233] [client 136.108.4.202:46970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ivetstrategies.com"] [uri "/"] [unique_id "al4RorwiU-Jh5ncAILFbvQAAAWQ"]
[Mon Jul 20 06:16:34.667686 2026] [security2:error] [pid 871012:tid 871156] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RorwiU-Jh5ncAILFbvwAAARc"]
[Mon Jul 20 06:16:34.719952 2026] [security2:error] [pid 871012:tid 871261] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RorwiU-Jh5ncAILFbuwABgEw"]
[Mon Jul 20 06:16:34.807046 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/pomo/"] [unique_id "al4RorwiU-Jh5ncAILFbygAAARA"]
[Mon Jul 20 06:16:34.807115 2026] [security2:error] [pid 871012:tid 871250] [client 50.116.65.227:54436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RorwiU-Jh5ncAILFbywAAAXU"]
[Mon Jul 20 06:16:34.816834 2026] [security2:error] [pid 871012:tid 871266] [client 50.116.65.227:40202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RorwiU-Jh5ncAILFbzgAAAYU"]
[Mon Jul 20 06:16:34.873671 2026] [security2:error] [pid 871012:tid 871230] [client 14.225.17.146:51132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFbEAAAAWE"], referer: http://securingmemories.com/WordPress
[Mon Jul 20 06:16:35.023712 2026] [security2:error] [pid 871012:tid 871158] [client 171.60.139.123:61697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb4wAAARk"]
[Mon Jul 20 06:16:35.023943 2026] [security2:error] [pid 871012:tid 871158] [client 171.60.139.123:61697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb4wAAARk"]
[Mon Jul 20 06:16:35.028575 2026] [security2:error] [pid 871012:tid 871225] [client 41.173.37.102:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb5AAAAVw"]
[Mon Jul 20 06:16:35.028684 2026] [security2:error] [pid 871012:tid 871225] [client 41.173.37.102:1741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb5AAAAVw"]
[Mon Jul 20 06:16:35.034883 2026] [security2:error] [pid 871012:tid 871205] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RorwiU-Jh5ncAILFb4QAAAUg"]
[Mon Jul 20 06:16:35.205215 2026] [security2:error] [pid 871012:tid 871181] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/random_compat/"] [unique_id "al4Ro7wiU-Jh5ncAILFb-gAAATA"]
[Mon Jul 20 06:16:35.285335 2026] [security2:error] [pid 871012:tid 871207] [client 213.35.113.47:54617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.113.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ancestralidadytrance.space"] [uri "/wp-login.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb_AAAAUo"]
[Mon Jul 20 06:16:35.416167 2026] [security2:error] [pid 871012:tid 871184] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ro7wiU-Jh5ncAILFcDQAAATM"]
[Mon Jul 20 06:16:35.437160 2026] [security2:error] [pid 871012:tid 871249] [client 23.94.28.190:63585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mezzacraft.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "al4Ro7wiU-Jh5ncAILFcEAAAAXQ"]
[Mon Jul 20 06:16:35.485553 2026] [security2:error] [pid 871012:tid 871203] [client 136.108.4.202:46970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4RorwiU-Jh5ncAILFb3QAAAUY"], referer: http://ivetstrategies.com/wp-json/batch/v1
[Mon Jul 20 06:16:35.584107 2026] [security2:error] [pid 871012:tid 871266] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/rest-api/"] [unique_id "al4Ro7wiU-Jh5ncAILFcOAAAAYU"]
[Mon Jul 20 06:16:35.586402 2026] [security2:error] [pid 871012:tid 871220] [client 57.141.18.70:27000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RnbwiU-Jh5ncAILFZYgABVyE"]
[Mon Jul 20 06:16:35.694969 2026] [security2:error] [pid 871012:tid 871206] [client 57.141.18.59:46250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RnbwiU-Jh5ncAILFZZgABSSs"]
[Mon Jul 20 06:16:35.772411 2026] [security2:error] [pid 871012:tid 871226] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ro7wiU-Jh5ncAILFcRAAAAV0"]
[Mon Jul 20 06:16:35.913011 2026] [security2:error] [pid 871012:tid 871259] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/sitemaps/"] [unique_id "al4Ro7wiU-Jh5ncAILFcWQAAAX4"]
[Mon Jul 20 06:16:36.065612 2026] [security2:error] [pid 871012:tid 871191] [client 14.225.17.146:50242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb8gAAATo"], referer: http://walkingandtalking.net/WordPress
[Mon Jul 20 06:16:36.130353 2026] [security2:error] [pid 871012:tid 871161] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpLwiU-Jh5ncAILFcZwAAARw"]
[Mon Jul 20 06:16:36.280408 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4RpLwiU-Jh5ncAILFceQAAAUA"]
[Mon Jul 20 06:16:36.444423 2026] [security2:error] [pid 871012:tid 871257] [client 45.116.69.230:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFcjQAAAXw"]
[Mon Jul 20 06:16:36.444539 2026] [security2:error] [pid 871012:tid 871257] [client 45.116.69.230:52866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFcjQAAAXw"]
[Mon Jul 20 06:16:36.462006 2026] [security2:error] [pid 871012:tid 871119] [remote 156.59.198.135:59556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/wp-content/uploads/2025/09/Aosta-Drinks-Menu.pdf"] [unique_id "al4RpLwiU-Jh5ncAILFckQABFmk"]
[Mon Jul 20 06:16:36.463365 2026] [security2:error] [pid 871012:tid 871175] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpLwiU-Jh5ncAILFciQAAASo"]
[Mon Jul 20 06:16:36.474255 2026] [security2:error] [pid 871012:tid 871217] [client 103.141.108.143:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFckAAAAVQ"]
[Mon Jul 20 06:16:36.474451 2026] [security2:error] [pid 871012:tid 871217] [client 103.141.108.143:55224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFckAAAAVQ"]
[Mon Jul 20 06:16:36.603606 2026] [security2:error] [pid 871012:tid 871240] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/style-engine/"] [unique_id "al4RpLwiU-Jh5ncAILFcngAAAWs"]
[Mon Jul 20 06:16:36.785469 2026] [security2:error] [pid 871012:tid 871160] [client 14.225.17.146:50179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb9gAAARs"], referer: http://lelandumc.org/WordPress
[Mon Jul 20 06:16:36.823656 2026] [security2:error] [pid 871012:tid 871223] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpLwiU-Jh5ncAILFcuwAAAVo"]
[Mon Jul 20 06:16:36.832284 2026] [security2:error] [pid 871012:tid 871161] [client 50.116.65.227:54448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4RpLwiU-Jh5ncAILFcwwAAARw"]
[Mon Jul 20 06:16:36.848701 2026] [security2:error] [pid 871012:tid 871236] [client 50.116.65.227:40284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4RpLwiU-Jh5ncAILFcxAAAAWc"]
[Mon Jul 20 06:16:36.913992 2026] [security2:error] [pid 871012:tid 871151] [client 119.18.1.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4RpLwiU-Jh5ncAILFcmQAAARI"], referer: https://aosta.nz/
[Mon Jul 20 06:16:36.937193 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:50278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4Ro7wiU-Jh5ncAILFcEgAAAWk"], referer: http://omrobuildingcenter.com/WordPress
[Mon Jul 20 06:16:36.978773 2026] [http2:info] [pid 874439:tid 874439] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:16:36.981170 2026] [security2:error] [pid 871012:tid 871170] [client 14.225.17.146:55694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4RpLwiU-Jh5ncAILFczwAAASU"], referer: https://walkingandtalking.net/WordPress
[Mon Jul 20 06:16:37.000206 2026] [security2:error] [pid 871012:tid 871153] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/theme-compat/"] [unique_id "al4RpLwiU-Jh5ncAILFc0gAAARQ"]
[Mon Jul 20 06:16:37.099363 2026] [security2:error] [pid 871012:tid 871052] [remote 216.73.216.55:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4RpbwiU-Jh5ncAILFc3AABKCY"]
[Mon Jul 20 06:16:37.227207 2026] [security2:error] [pid 871012:tid 871164] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpbwiU-Jh5ncAILFc5AAAAR8"]
[Mon Jul 20 06:16:37.391895 2026] [security2:error] [pid 871012:tid 871168] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/widgets/"] [unique_id "al4RpbwiU-Jh5ncAILFc7QAAASM"]
[Mon Jul 20 06:16:37.476925 2026] [security2:error] [pid 871012:tid 871147] [client 57.141.18.118:63280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFaHgABDmo"]
[Mon Jul 20 06:16:37.497859 2026] [security2:error] [pid 871012:tid 871087] [remote 115.74.105.156:38772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RpbwiU-Jh5ncAILFc8QABhkk"]
[Mon Jul 20 06:16:37.552571 2026] [security2:error] [pid 874439:tid 874441] [remote 8.217.108.67:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RpY6ZSrFvCrJJhtT5pwAAAQE"]
[Mon Jul 20 06:16:37.627340 2026] [security2:error] [pid 871012:tid 871188] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpbwiU-Jh5ncAILFc-QAAATc"]
[Mon Jul 20 06:16:37.787224 2026] [security2:error] [pid 871012:tid 871161] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "al4RpbwiU-Jh5ncAILFdAgAAARw"]
[Mon Jul 20 06:16:38.032586 2026] [security2:error] [pid 871012:tid 871159] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpbwiU-Jh5ncAILFdDAAAARo"]
[Mon Jul 20 06:16:38.038868 2026] [security2:error] [pid 871012:tid 871121] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RprwiU-Jh5ncAILFdDgABSWs"]
[Mon Jul 20 06:16:38.039090 2026] [security2:error] [pid 871012:tid 871206] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RprwiU-Jh5ncAILFdDgABSWs"]
[Mon Jul 20 06:16:38.184445 2026] [security2:error] [pid 871012:tid 871186] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/css/colors/"] [unique_id "al4RprwiU-Jh5ncAILFdGAAAATU"]
[Mon Jul 20 06:16:38.231140 2026] [security2:error] [pid 871012:tid 871225] [client 14.225.17.146:50671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4RpLwiU-Jh5ncAILFcpQAAAVw"], referer: http://kromosenergy.com/WordPress
[Mon Jul 20 06:16:38.388306 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RprwiU-Jh5ncAILFdIAAAAXQ"]
[Mon Jul 20 06:16:38.474102 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:55888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4RpbwiU-Jh5ncAILFc4wAAARE"], referer: http://elitetax-mi.com/WordPress
[Mon Jul 20 06:16:38.528849 2026] [security2:error] [pid 871012:tid 871266] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/images/slider/"] [unique_id "al4RprwiU-Jh5ncAILFdLAAAAYU"]
[Mon Jul 20 06:16:38.553636 2026] [security2:error] [pid 874439:tid 874446] [remote 8.217.108.67:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Rpo6ZSrFvCrJJhtT50QAAXQY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:16:38.566842 2026] [security2:error] [pid 871012:tid 871259] [client 103.217.239.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4RpbwiU-Jh5ncAILFc2AAAAX4"]
[Mon Jul 20 06:16:38.580459 2026] [security2:error] [pid 871012:tid 871178] [client 103.217.239.26:49680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/22518.php"] [unique_id "al4RpbwiU-Jh5ncAILFc0wABLRA"]
[Mon Jul 20 06:16:38.623861 2026] [security2:error] [pid 874439:tid 874652] [client 178.152.178.232:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rpo6ZSrFvCrJJhtT50gAAAFM"]
[Mon Jul 20 06:16:38.623978 2026] [security2:error] [pid 874439:tid 874652] [client 178.152.178.232:37856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rpo6ZSrFvCrJJhtT50gAAAFM"]
[Mon Jul 20 06:16:38.711282 2026] [security2:error] [pid 871012:tid 871228] [client 57.141.18.67:25620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rn7wiU-Jh5ncAILFasgABXzs"]
[Mon Jul 20 06:16:38.741428 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RprwiU-Jh5ncAILFdMwAAAUs"]
[Mon Jul 20 06:16:38.881002 2026] [security2:error] [pid 871012:tid 871164] [client 104.234.53.80:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RprwiU-Jh5ncAILFdPQAAAR8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:38.887313 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "al4RprwiU-Jh5ncAILFdPgAAAWk"]
[Mon Jul 20 06:16:39.129379 2026] [security2:error] [pid 871012:tid 871267] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rp7wiU-Jh5ncAILFdRgAAAYY"]
[Mon Jul 20 06:16:39.131057 2026] [security2:error] [pid 874439:tid 874689] [client 77.110.127.138:59061] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/baking/feed/"] [unique_id "al4Rp46ZSrFvCrJJhtT54AAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:39.316054 2026] [security2:error] [pid 871012:tid 871201] [client 185.132.186.90:47115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/wp-login.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUAAAAUQ"]
[Mon Jul 20 06:16:39.392514 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUwAAAYI"]
[Mon Jul 20 06:16:39.392801 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:65150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUwAAAYI"]
[Mon Jul 20 06:16:39.596544 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/sites/default/files/"] [unique_id "al4Rp7wiU-Jh5ncAILFdZQAAARk"]
[Mon Jul 20 06:16:39.706389 2026] [security2:error] [pid 871012:tid 871176] [client 14.251.3.155:61271] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Rp7wiU-Jh5ncAILFdcgAAASs"]
[Mon Jul 20 06:16:39.813770 2026] [security2:error] [pid 871012:tid 871261] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rp7wiU-Jh5ncAILFddQAAAYA"]
[Mon Jul 20 06:16:39.835289 2026] [security2:error] [pid 871012:tid 871084] [remote 38.242.157.30:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdeQABLkY"]
[Mon Jul 20 06:16:39.835442 2026] [security2:error] [pid 871012:tid 871179] [client 38.242.157.30:37278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdeQABLkY"]
[Mon Jul 20 06:16:39.975027 2026] [security2:error] [pid 871012:tid 871269] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/controller/extension/extension/"] [unique_id "al4Rp7wiU-Jh5ncAILFdfQAAAYg"]
[Mon Jul 20 06:16:40.153323 2026] [security2:error] [pid 871012:tid 871203] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqLwiU-Jh5ncAILFdhAAAAUY"]
[Mon Jul 20 06:16:40.174566 2026] [security2:error] [pid 871012:tid 871255] [client 57.141.18.91:48926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RobwiU-Jh5ncAILFbOgABemw"]
[Mon Jul 20 06:16:40.293930 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "al4RqLwiU-Jh5ncAILFdkAAAARk"]
[Mon Jul 20 06:16:40.462024 2026] [security2:error] [pid 874439:tid 874607] [client 104.234.53.61:42967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RqI6ZSrFvCrJJhtT5-AAAACY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:40.522426 2026] [security2:error] [pid 871012:tid 871239] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqLwiU-Jh5ncAILFdnAAAAWo"]
[Mon Jul 20 06:16:40.563604 2026] [security2:error] [pid 871012:tid 871270] [client 57.141.18.35:31616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RobwiU-Jh5ncAILFbXAABiQk"]
[Mon Jul 20 06:16:40.689002 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/components/"] [unique_id "al4RqLwiU-Jh5ncAILFdrgAAAVU"]
[Mon Jul 20 06:16:40.692620 2026] [security2:error] [pid 874439:tid 874642] [client 104.234.53.61:42967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RqI6ZSrFvCrJJhtT6AgAAAEk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:40.923333 2026] [security2:error] [pid 871012:tid 871144] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqLwiU-Jh5ncAILFduAAAAQs"]
[Mon Jul 20 06:16:41.092823 2026] [security2:error] [pid 871012:tid 871193] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/uploads/images/"] [unique_id "al4RqbwiU-Jh5ncAILFdwAAAATw"]
[Mon Jul 20 06:16:41.190640 2026] [security2:error] [pid 874439:tid 874667] [client 74.208.214.194:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6DwAAAGI"]
[Mon Jul 20 06:16:41.314254 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqbwiU-Jh5ncAILFdzgAAAT8"]
[Mon Jul 20 06:16:41.320999 2026] [security2:error] [pid 874439:tid 874688] [client 185.132.186.75:28435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/autoload_classmap.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6GAAAAHc"]
[Mon Jul 20 06:16:41.408881 2026] [security2:error] [pid 874439:tid 874646] [client 181.224.94.124:61626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6GgAAAE0"]
[Mon Jul 20 06:16:41.409055 2026] [security2:error] [pid 874439:tid 874646] [client 181.224.94.124:61626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6GgAAAE0"]
[Mon Jul 20 06:16:41.460090 2026] [security2:error] [pid 871012:tid 871215] [client 57.141.18.92:53102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RorwiU-Jh5ncAILFbtAABUgw"]
[Mon Jul 20 06:16:41.484464 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "al4RqbwiU-Jh5ncAILFd1gAAAXQ"]
[Mon Jul 20 06:16:41.706162 2026] [ssl:error] [pid 871012:tid 871192] [client 54.86.115.253:1955] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname webdisk.ithurtsuntilyoudie.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:16:41.711265 2026] [security2:error] [pid 871012:tid 871259] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqbwiU-Jh5ncAILFd4AAAAX4"]
[Mon Jul 20 06:16:41.889731 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/fonts/"] [unique_id "al4RqbwiU-Jh5ncAILFd7gAAAUk"]
[Mon Jul 20 06:16:41.925485 2026] [security2:error] [pid 871012:tid 871085] [remote 115.74.105.156:38772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RqbwiU-Jh5ncAILFd8wABZEc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:16:42.050450 2026] [security2:error] [pid 874439:tid 874464] [remote 20.173.88.122:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6MQAAGRg"]
[Mon Jul 20 06:16:42.077394 2026] [security2:error] [pid 871012:tid 871179] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqrwiU-Jh5ncAILFd-QAAAS4"]
[Mon Jul 20 06:16:42.219948 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "al4RqrwiU-Jh5ncAILFeBwAAAUs"]
[Mon Jul 20 06:16:42.401358 2026] [security2:error] [pid 874439:tid 874468] [remote 20.173.88.122:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6PQAAOBw"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 06:16:42.439432 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqrwiU-Jh5ncAILFeEAAAAR4"]
[Mon Jul 20 06:16:42.537727 2026] [security2:error] [pid 874439:tid 874642] [client 63.176.132.15:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6QwAAAEk"]
[Mon Jul 20 06:16:42.537886 2026] [security2:error] [pid 874439:tid 874642] [client 63.176.132.15:12890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6QwAAAEk"]
[Mon Jul 20 06:16:42.581619 2026] [security2:error] [pid 871012:tid 871229] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "al4RqrwiU-Jh5ncAILFeGgAAAWA"]
[Mon Jul 20 06:16:42.654048 2026] [security2:error] [pid 871012:tid 871212] [client 50.116.65.227:28062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4RqrwiU-Jh5ncAILFeJAAAAU8"]
[Mon Jul 20 06:16:42.664815 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:46752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4RqrwiU-Jh5ncAILFeJgAAAS0"]
[Mon Jul 20 06:16:42.671067 2026] [security2:error] [pid 871012:tid 871202] [client 190.44.20.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4RqrwiU-Jh5ncAILFeEwAAAUU"]
[Mon Jul 20 06:16:42.679441 2026] [security2:error] [pid 874439:tid 874640] [client 190.44.20.234:36140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/22518.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6QgAARx0"]
[Mon Jul 20 06:16:42.763484 2026] [security2:error] [pid 871012:tid 871159] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqrwiU-Jh5ncAILFeKgAAARo"]
[Mon Jul 20 06:16:42.912035 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wordpress/"] [unique_id "al4RqrwiU-Jh5ncAILFeNQAAAT8"]
[Mon Jul 20 06:16:43.130327 2026] [security2:error] [pid 871012:tid 871150] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rq7wiU-Jh5ncAILFeOAAAARE"]
[Mon Jul 20 06:16:43.290003 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/images/"] [unique_id "al4Rq7wiU-Jh5ncAILFeRAAAAWE"]
[Mon Jul 20 06:16:43.338967 2026] [security2:error] [pid 874439:tid 874690] [client 185.132.186.84:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-nav-widgets.php"] [unique_id "al4Rq46ZSrFvCrJJhtT6WAAAAHk"]
[Mon Jul 20 06:16:43.517097 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rq7wiU-Jh5ncAILFeTQAAAXs"]
[Mon Jul 20 06:16:43.682441 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "al4Rq7wiU-Jh5ncAILFeWgAAATI"]
[Mon Jul 20 06:16:43.920354 2026] [security2:error] [pid 871012:tid 871263] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rq7wiU-Jh5ncAILFeYgAAAYI"]
[Mon Jul 20 06:16:44.085895 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "al4RrLwiU-Jh5ncAILFeaAAAAXQ"]
[Mon Jul 20 06:16:44.157840 2026] [security2:error] [pid 874439:tid 874481] [remote 217.61.143.92:40114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RrI6ZSrFvCrJJhtT6cgAAVyk"]
[Mon Jul 20 06:16:44.158099 2026] [security2:error] [pid 874439:tid 874656] [client 217.61.143.92:40114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RrI6ZSrFvCrJJhtT6cgAAVyk"]
[Mon Jul 20 06:16:44.269380 2026] [security2:error] [pid 871012:tid 871162] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrLwiU-Jh5ncAILFecAAAAR0"]
[Mon Jul 20 06:16:44.399245 2026] [security2:error] [pid 874439:tid 874582] [client 57.141.18.61:43238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RpY6ZSrFvCrJJhtT5pgAADX8"]
[Mon Jul 20 06:16:44.409262 2026] [security2:error] [pid 871012:tid 871222] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/js/"] [unique_id "al4RrLwiU-Jh5ncAILFeegAAAVk"]
[Mon Jul 20 06:16:44.553368 2026] [security2:error] [pid 874439:tid 874687] [client 45.61.188.240:57953] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/"] [unique_id "al4RrI6ZSrFvCrJJhtT6gQAAAHY"]
[Mon Jul 20 06:16:44.623429 2026] [security2:error] [pid 871012:tid 871239] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrLwiU-Jh5ncAILFefwAAAWo"]
[Mon Jul 20 06:16:44.672981 2026] [security2:error] [pid 871012:tid 871198] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RrLwiU-Jh5ncAILFeeAABQVU"]
[Mon Jul 20 06:16:44.775207 2026] [security2:error] [pid 871012:tid 871168] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "al4RrLwiU-Jh5ncAILFehgAAASM"]
[Mon Jul 20 06:16:44.817254 2026] [security2:error] [pid 874439:tid 874638] [client 45.61.188.240:57991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/"] [unique_id "al4RrI6ZSrFvCrJJhtT6jwAAAEU"]
[Mon Jul 20 06:16:44.954430 2026] [security2:error] [pid 871012:tid 871265] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrLwiU-Jh5ncAILFekAAAAYQ"]
[Mon Jul 20 06:16:45.093457 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "al4RrbwiU-Jh5ncAILFelAAAAVU"]
[Mon Jul 20 06:16:45.313332 2026] [security2:error] [pid 871012:tid 871166] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrbwiU-Jh5ncAILFemgAAASE"]
[Mon Jul 20 06:16:45.351373 2026] [security2:error] [pid 871012:tid 871179] [client 185.132.186.101:64849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "al4RrbwiU-Jh5ncAILFenwAAAS4"]
[Mon Jul 20 06:16:45.385705 2026] [security2:error] [pid 874439:tid 874489] [remote 47.128.28.81:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "innovativecleaningsvs.com"] [uri "/robots.txt"] [unique_id "al4RrY6ZSrFvCrJJhtT6pQAASzE"]
[Mon Jul 20 06:16:45.446718 2026] [security2:error] [pid 874439:tid 874490] [remote 100.42.189.89:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6qAAAYjI"]
[Mon Jul 20 06:16:45.460150 2026] [security2:error] [pid 871012:tid 871208] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RrbwiU-Jh5ncAILFemQABS3o"]
[Mon Jul 20 06:16:45.483840 2026] [security2:error] [pid 871012:tid 871195] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/meta/"] [unique_id "al4RrbwiU-Jh5ncAILFeqAAAAT4"]
[Mon Jul 20 06:16:45.601936 2026] [security2:error] [pid 871012:tid 871152] [client 188.232.28.208:36424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4RrbwiU-Jh5ncAILFeqQAAARM"]
[Mon Jul 20 06:16:45.618093 2026] [security2:error] [pid 871012:tid 871068] [remote 154.66.198.148:18512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4RrbwiU-Jh5ncAILFetQABWjY"]
[Mon Jul 20 06:16:45.645717 2026] [security2:error] [pid 874439:tid 874491] [remote 100.42.189.89:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6rwAAGzM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:16:45.667973 2026] [security2:error] [pid 874439:tid 874624] [client 41.173.37.102:2195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6sAAAADc"]
[Mon Jul 20 06:16:45.668115 2026] [security2:error] [pid 874439:tid 874624] [client 41.173.37.102:2195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6sAAAADc"]
[Mon Jul 20 06:16:45.731240 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrbwiU-Jh5ncAILFeugAAAT8"]
[Mon Jul 20 06:16:45.850588 2026] [security2:error] [pid 874439:tid 874688] [client 170.0.244.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6uwAAAHc"]
[Mon Jul 20 06:16:45.894361 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/network/"] [unique_id "al4RrbwiU-Jh5ncAILFewAAAATQ"]
[Mon Jul 20 06:16:45.910848 2026] [security2:error] [pid 874439:tid 874594] [client 171.60.139.123:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6wwAAABk"]
[Mon Jul 20 06:16:45.911041 2026] [security2:error] [pid 874439:tid 874594] [client 171.60.139.123:62201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6wwAAABk"]
[Mon Jul 20 06:16:45.962325 2026] [security2:error] [pid 871012:tid 871151] [client 57.141.18.32:25640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUQABEjQ"]
[Mon Jul 20 06:16:46.116137 2026] [security2:error] [pid 871012:tid 871194] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrrwiU-Jh5ncAILFexgAAAT0"]
[Mon Jul 20 06:16:46.261684 2026] [security2:error] [pid 871012:tid 871033] [remote 154.66.198.148:18512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4RrrwiU-Jh5ncAILFe1wABhxM"], referer: https://sbinframx.com/wp-login.php
[Mon Jul 20 06:16:46.276022 2026] [security2:error] [pid 871012:tid 871166] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/user/"] [unique_id "al4RrrwiU-Jh5ncAILFe2AAAASE"]
[Mon Jul 20 06:16:46.466351 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrrwiU-Jh5ncAILFe4QAAAWE"]
[Mon Jul 20 06:16:46.605205 2026] [security2:error] [pid 871012:tid 871152] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/"] [unique_id "al4RrrwiU-Jh5ncAILFe5wAAARM"]
[Mon Jul 20 06:16:46.657391 2026] [security2:error] [pid 874439:tid 874597] [client 57.141.18.99:27224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rp46ZSrFvCrJJhtT57wAAHAk"]
[Mon Jul 20 06:16:46.822297 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrrwiU-Jh5ncAILFe8QAAAT8"]
[Mon Jul 20 06:16:46.856413 2026] [security2:error] [pid 874439:tid 874620] [client 104.234.53.72:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Rro6ZSrFvCrJJhtT64QAAADM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:46.987346 2026] [security2:error] [pid 871012:tid 871156] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/"] [unique_id "al4RrrwiU-Jh5ncAILFe-wAAARc"]
[Mon Jul 20 06:16:47.210365 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rr7wiU-Jh5ncAILFfAAAAAUk"]
[Mon Jul 20 06:16:47.229830 2026] [security2:error] [pid 871012:tid 871183] [client 103.141.108.143:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfAwAAATI"]
[Mon Jul 20 06:16:47.230095 2026] [security2:error] [pid 871012:tid 871183] [client 103.141.108.143:55713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfAwAAATI"]
[Mon Jul 20 06:16:47.253005 2026] [security2:error] [pid 871012:tid 871233] [client 45.116.69.230:53400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfBAAAAWQ"]
[Mon Jul 20 06:16:47.253175 2026] [security2:error] [pid 871012:tid 871233] [client 45.116.69.230:53400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfBAAAAWQ"]
[Mon Jul 20 06:16:47.349385 2026] [security2:error] [pid 874439:tid 874506] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4Rr46ZSrFvCrJJhtT69AAAe0I"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:47.353437 2026] [security2:error] [pid 874439:tid 874595] [client 185.132.186.98:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/install.php"] [unique_id "al4Rr46ZSrFvCrJJhtT69wAAABo"]
[Mon Jul 20 06:16:47.396429 2026] [security2:error] [pid 871012:tid 871201] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/themes/"] [unique_id "al4Rr7wiU-Jh5ncAILFfDAAAAUQ"]
[Mon Jul 20 06:16:47.401549 2026] [security2:error] [pid 874439:tid 874649] [client 57.141.18.96:44592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RqI6ZSrFvCrJJhtT6BQAAUA8"]
[Mon Jul 20 06:16:47.571936 2026] [security2:error] [pid 871012:tid 871097] [remote 20.153.140.50:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfGgABaVM"]
[Mon Jul 20 06:16:47.641433 2026] [security2:error] [pid 871012:tid 871267] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rr7wiU-Jh5ncAILFfGwAAAYY"]
[Mon Jul 20 06:16:47.678418 2026] [security2:error] [pid 874439:tid 874601] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rr46ZSrFvCrJJhtT6_wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:47.778619 2026] [security2:error] [pid 871012:tid 871175] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfDgABKhU"]
[Mon Jul 20 06:16:47.792210 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/includes/"] [unique_id "al4Rr7wiU-Jh5ncAILFfHwAAAR4"]
[Mon Jul 20 06:16:47.969501 2026] [security2:error] [pid 871012:tid 871088] [remote 20.153.140.50:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfLQABF0o"], referer: https://detroitcsc.com/wp-login.php
[Mon Jul 20 06:16:48.046343 2026] [security2:error] [pid 871012:tid 871151] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rr7wiU-Jh5ncAILFfLgAAARI"]
[Mon Jul 20 06:16:48.204066 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/"] [unique_id "al4RsLwiU-Jh5ncAILFfNwAAATI"]
[Mon Jul 20 06:16:48.425417 2026] [security2:error] [pid 871012:tid 871263] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RsLwiU-Jh5ncAILFfOQAAAYI"]
[Mon Jul 20 06:16:48.571573 2026] [security2:error] [pid 871012:tid 871149] [client 57.141.18.21:40508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RqbwiU-Jh5ncAILFd6QABEGo"]
[Mon Jul 20 06:16:48.576468 2026] [security2:error] [pid 871012:tid 871180] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/upgrade/"] [unique_id "al4RsLwiU-Jh5ncAILFfRQAAAS8"]
[Mon Jul 20 06:16:48.749445 2026] [security2:error] [pid 874439:tid 874517] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7MAAAW00"]
[Mon Jul 20 06:16:48.749689 2026] [security2:error] [pid 874439:tid 874660] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7MAAAW00"]
[Mon Jul 20 06:16:48.760631 2026] [security2:error] [pid 871012:tid 871261] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RsLwiU-Jh5ncAILFfTQAAAYA"]
[Mon Jul 20 06:16:48.785772 2026] [security2:error] [pid 874439:tid 874518] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7MgAAAE4"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:48.875590 2026] [security2:error] [pid 874439:tid 874622] [client 57.141.18.103:51976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6NwAANRk"]
[Mon Jul 20 06:16:49.032356 2026] [security2:error] [pid 871012:tid 871244] [client 104.234.53.75:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RsbwiU-Jh5ncAILFfVwAAAW8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:49.138584 2026] [security2:error] [pid 874439:tid 874522] [remote 160.187.68.132:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4RsY6ZSrFvCrJJhtT7QAAAMlI"]
[Mon Jul 20 06:16:49.364904 2026] [security2:error] [pid 871012:tid 871187] [client 185.132.186.101:44963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/install.php"] [unique_id "al4RsbwiU-Jh5ncAILFfYwAAATY"]
[Mon Jul 20 06:16:49.643181 2026] [security2:error] [pid 874439:tid 874525] [remote 160.187.68.132:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4RsY6ZSrFvCrJJhtT7UAAASVU"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:16:49.794052 2026] [security2:error] [pid 871012:tid 871249] [client 50.116.65.227:50348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4RsbwiU-Jh5ncAILFfgQAAAXQ"]
[Mon Jul 20 06:16:49.796113 2026] [security2:error] [pid 874439:tid 874528] [remote 217.61.143.92:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RsY6ZSrFvCrJJhtT7VQAAB1g"]
[Mon Jul 20 06:16:49.804022 2026] [security2:error] [pid 874439:tid 874639] [client 50.116.65.227:19118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4RsY6ZSrFvCrJJhtT7VwAAAEY"]
[Mon Jul 20 06:16:49.842649 2026] [security2:error] [pid 871012:tid 871186] [client 103.77.203.233:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RsbwiU-Jh5ncAILFfggAAATU"]
[Mon Jul 20 06:16:49.842786 2026] [security2:error] [pid 871012:tid 871186] [client 103.77.203.233:49324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RsbwiU-Jh5ncAILFfggAAATU"]
[Mon Jul 20 06:16:50.041696 2026] [security2:error] [pid 874439:tid 874533] [remote 217.61.143.92:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Rso6ZSrFvCrJJhtT7awAAGF0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:50.229457 2026] [security2:error] [pid 874439:tid 874534] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4Rso6ZSrFvCrJJhtT7cQAAZl4"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:50.253482 2026] [security2:error] [pid 874439:tid 874569] [client 104.234.53.81:65047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Rso6ZSrFvCrJJhtT7cgAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:50.434905 2026] [security2:error] [pid 871012:tid 871255] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RsrwiU-Jh5ncAILFftAABegA"]
[Mon Jul 20 06:16:50.516640 2026] [security2:error] [pid 874439:tid 874650] [client 57.141.18.15:64806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rq46ZSrFvCrJJhtT6awAAUSc"]
[Mon Jul 20 06:16:51.341709 2026] [security2:error] [pid 874439:tid 874640] [client 185.132.186.73:40681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/providers/doc.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7qAAAAEc"]
[Mon Jul 20 06:16:51.396490 2026] [security2:error] [pid 874439:tid 874549] [remote 100.42.189.89:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7rQAAP20"]
[Mon Jul 20 06:16:51.544886 2026] [security2:error] [pid 874439:tid 874570] [client 57.141.18.112:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RrI6ZSrFvCrJJhtT6hwAAAS0"]
[Mon Jul 20 06:16:51.612795 2026] [security2:error] [pid 874439:tid 874550] [remote 100.42.189.89:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7sgAAQ24"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:16:51.676165 2026] [security2:error] [pid 874439:tid 874552] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7tgAACHA"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:51.855217 2026] [security2:error] [pid 874439:tid 874553] [remote 195.26.244.42:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7uQAANnE"]
[Mon Jul 20 06:16:51.926460 2026] [security2:error] [pid 874439:tid 874580] [client 181.224.94.124:34638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7vAAAAAs"]
[Mon Jul 20 06:16:51.926650 2026] [security2:error] [pid 874439:tid 874580] [client 181.224.94.124:34638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7vAAAAAs"]
[Mon Jul 20 06:16:52.095795 2026] [security2:error] [pid 874439:tid 874556] [remote 72.167.132.114:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7xQAAZ3Q"]
[Mon Jul 20 06:16:52.145271 2026] [security2:error] [pid 874439:tid 874558] [remote 195.26.244.42:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7yAAAIHY"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 06:16:52.207076 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7zgAAADk"]
[Mon Jul 20 06:16:52.207256 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:37386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7zgAAADk"]
[Mon Jul 20 06:16:52.340629 2026] [security2:error] [pid 874439:tid 874561] [remote 72.167.132.114:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4RtI6ZSrFvCrJJhtT70wAALHk"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 06:16:52.905981 2026] [security2:error] [pid 871012:tid 871257] [client 104.234.53.51:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RtLwiU-Jh5ncAILFgGQAAAXw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:53.168196 2026] [security2:error] [pid 874439:tid 874625] [client 57.141.18.2:39444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rro6ZSrFvCrJJhtT6yQAAODk"]
[Mon Jul 20 06:16:53.287857 2026] [security2:error] [pid 871012:tid 871261] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RtLwiU-Jh5ncAILFgGgABgH8"]
[Mon Jul 20 06:16:53.343396 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.65:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ws.php"] [unique_id "al4RtbwiU-Jh5ncAILFgLAAAAXo"]
[Mon Jul 20 06:16:53.360862 2026] [security2:error] [pid 874439:tid 874629] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RtY6ZSrFvCrJJhtT78gAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:53.464225 2026] [security2:error] [pid 871012:tid 871107] [remote 202.51.202.242:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RtbwiU-Jh5ncAILFgLgABHF0"]
[Mon Jul 20 06:16:54.001482 2026] [security2:error] [pid 871012:tid 871084] [remote 202.51.202.242:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RtbwiU-Jh5ncAILFgRwABc0Y"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:54.353130 2026] [security2:error] [pid 874439:tid 874594] [client 57.141.18.122:53300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rr46ZSrFvCrJJhtT67QAAGUA"]
[Mon Jul 20 06:16:54.410401 2026] [security2:error] [pid 871012:tid 871171] [client 158.173.166.181:44213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RtrwiU-Jh5ncAILFgXAAAASY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:54.517783 2026] [core:error] [pid 871012:tid 871251] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.517809 2026] [core:error] [pid 871012:tid 871251] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.527108 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.527132 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.536210 2026] [core:error] [pid 871012:tid 871160] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.536232 2026] [core:error] [pid 871012:tid 871160] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.079952 2026] [core:error] [pid 874439:tid 874644] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.079974 2026] [core:error] [pid 874439:tid 874644] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.135055 2026] [core:error] [pid 871012:tid 871205] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.135079 2026] [core:error] [pid 871012:tid 871205] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.342870 2026] [security2:error] [pid 874439:tid 874599] [client 57.141.18.118:37706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rr46ZSrFvCrJJhtT7EAAAHkc"]
[Mon Jul 20 06:16:55.351202 2026] [security2:error] [pid 874439:tid 874607] [client 185.132.186.97:42107] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/1.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8ZAAAACY"]
[Mon Jul 20 06:16:55.368978 2026] [security2:error] [pid 871012:tid 871250] [client 104.234.53.80:34649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Rt7wiU-Jh5ncAILFgmAAAAXU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:55.389108 2026] [security2:error] [pid 874439:tid 874607] [client 185.132.186.97:42107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/1.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8ZAAAACY"]
[Mon Jul 20 06:16:55.591500 2026] [security2:error] [pid 871012:tid 871090] [remote 154.66.198.148:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Rt7wiU-Jh5ncAILFgoQABKUw"]
[Mon Jul 20 06:16:55.904765 2026] [security2:error] [pid 874439:tid 874604] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8dgAAIxo"]
[Mon Jul 20 06:16:56.210340 2026] [security2:error] [pid 871012:tid 871133] [remote 57.141.18.42:32868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5504138"] [unique_id "al4RuLwiU-Jh5ncAILFgsgABhnc"]
[Mon Jul 20 06:16:56.247948 2026] [security2:error] [pid 874439:tid 874672] [client 41.173.37.102:2633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8iQAAAGc"]
[Mon Jul 20 06:16:56.248056 2026] [security2:error] [pid 874439:tid 874672] [client 41.173.37.102:2633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8iQAAAGc"]
[Mon Jul 20 06:16:56.310449 2026] [security2:error] [pid 871012:tid 871194] [client 104.234.53.80:34649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RuLwiU-Jh5ncAILFguwAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:56.447968 2026] [security2:error] [pid 871012:tid 871080] [remote 154.66.198.148:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RuLwiU-Jh5ncAILFgwgABQkI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:56.455357 2026] [security2:error] [pid 874439:tid 874598] [client 171.60.139.123:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8jwAAAB0"]
[Mon Jul 20 06:16:56.455570 2026] [security2:error] [pid 874439:tid 874598] [client 171.60.139.123:62698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8jwAAAB0"]
[Mon Jul 20 06:16:56.472573 2026] [security2:error] [pid 871012:tid 871211] [client 14.225.17.146:59093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RuLwiU-Jh5ncAILFguAAAAU4"], referer: http://secretkeynumerology.com/wp
[Mon Jul 20 06:16:56.533460 2026] [security2:error] [pid 874439:tid 874588] [client 14.225.17.146:49397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8UAAAABM"], referer: http://dereckcastellon.com/wp
[Mon Jul 20 06:16:56.600303 2026] [security2:error] [pid 874439:tid 874645] [client 57.141.18.91:52844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7OQAATFE"]
[Mon Jul 20 06:16:56.842391 2026] [security2:error] [pid 874439:tid 874690] [client 14.225.17.146:50360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8VAAAAHk"], referer: http://superiorcopywriting.com/wp
[Mon Jul 20 06:16:57.391195 2026] [security2:error] [pid 874439:tid 874625] [client 185.132.186.66:53619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/fonts/class_api.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8sAAAADg"]
[Mon Jul 20 06:16:57.505311 2026] [security2:error] [pid 874439:tid 874648] [client 14.225.17.146:59237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8rQAAAE8"], referer: https://secretkeynumerology.com/wp
[Mon Jul 20 06:16:57.910815 2026] [security2:error] [pid 874439:tid 874645] [client 103.141.108.143:56193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8wwAAAEw"]
[Mon Jul 20 06:16:57.911243 2026] [security2:error] [pid 874439:tid 874645] [client 103.141.108.143:56193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8wwAAAEw"]
[Mon Jul 20 06:16:57.942337 2026] [security2:error] [pid 874439:tid 874677] [client 45.116.69.230:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8xAAAAGw"]
[Mon Jul 20 06:16:57.942473 2026] [security2:error] [pid 874439:tid 874677] [client 45.116.69.230:53936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8xAAAAGw"]
[Mon Jul 20 06:16:58.164293 2026] [security2:error] [pid 874439:tid 874481] [remote 173.249.4.11:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT8zAAAfik"]
[Mon Jul 20 06:16:58.164608 2026] [security2:error] [pid 874439:tid 874695] [client 173.249.4.11:50387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT8zAAAfik"]
[Mon Jul 20 06:16:58.209802 2026] [security2:error] [pid 871012:tid 871226] [client 14.225.17.146:62515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4RuLwiU-Jh5ncAILFgzQAAAV0"], referer: http://myspineworld.com/wp
[Mon Jul 20 06:16:58.232369 2026] [security2:error] [pid 874439:tid 874578] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT8xwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:58.232958 2026] [security2:error] [pid 874439:tid 874483] [remote 173.249.4.11:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturalsolutionsurbanforestry.com"] [uri "/wp-login.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT80wAAVCs"]
[Mon Jul 20 06:16:58.429276 2026] [security2:error] [pid 874439:tid 874676] [client 50.116.65.227:19308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Ruo6ZSrFvCrJJhtT82wAAAGs"]
[Mon Jul 20 06:16:58.438921 2026] [security2:error] [pid 874439:tid 874484] [remote 57.141.18.99:23640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5257534"] [unique_id "al4Ruo6ZSrFvCrJJhtT83AAACCw"]
[Mon Jul 20 06:16:58.439963 2026] [security2:error] [pid 874439:tid 874633] [client 50.116.65.227:19312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Ruo6ZSrFvCrJJhtT83QAAAEA"]
[Mon Jul 20 06:16:58.472833 2026] [security2:error] [pid 874439:tid 874486] [remote 173.249.4.11:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturalsolutionsurbanforestry.com"] [uri "/wp-login.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT83wAATS4"], referer: https://naturalsolutionsurbanforestry.com/wp-login.php
[Mon Jul 20 06:16:58.763991 2026] [security2:error] [pid 874439:tid 874663] [client 104.234.53.88:22725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT87gAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:58.985464 2026] [security2:error] [pid 874439:tid 874669] [client 50.116.65.227:44308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ruo6ZSrFvCrJJhtT8_AAAAGQ"]
[Mon Jul 20 06:16:58.999502 2026] [security2:error] [pid 874439:tid 874650] [client 50.116.65.227:39420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ruo6ZSrFvCrJJhtT8_gAAAFE"]
[Mon Jul 20 06:16:59.027317 2026] [security2:error] [pid 871012:tid 871222] [client 50.116.65.227:19330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RurwiU-Jh5ncAILFhLgAAAVk"]
[Mon Jul 20 06:16:59.194177 2026] [security2:error] [pid 871012:tid 871197] [client 14.225.17.146:55184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhNgAAAUA"], referer: https://myspineworld.com/wp
[Mon Jul 20 06:16:59.246662 2026] [security2:error] [pid 874439:tid 874578] [client 50.116.65.227:39426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Ru46ZSrFvCrJJhtT8_wAAAAk"]
[Mon Jul 20 06:16:59.308565 2026] [security2:error] [pid 871012:tid 871045] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhQwABTB8"]
[Mon Jul 20 06:16:59.308705 2026] [security2:error] [pid 871012:tid 871209] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhQwABTB8"]
[Mon Jul 20 06:16:59.409079 2026] [security2:error] [pid 871012:tid 871223] [client 185.132.186.78:46917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/shop.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhSQAAAVo"]
[Mon Jul 20 06:16:59.631759 2026] [security2:error] [pid 871012:tid 871236] [client 104.234.53.81:24683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhWAAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:59.938574 2026] [security2:error] [pid 871012:tid 871228] [client 14.225.17.146:61841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhXQAAAV8"], referer: http://whiteoutcb.com/wp
[Mon Jul 20 06:16:59.973785 2026] [security2:error] [pid 874439:tid 874629] [client 45.146.54.116:46727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marscafe.com"] [uri "/wp-login.php"] [unique_id "al4Ru46ZSrFvCrJJhtT9GgAAADw"]
[Mon Jul 20 06:17:00.017957 2026] [security2:error] [pid 874439:tid 874588] [client 178.152.178.232:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9HwAAABM"]
[Mon Jul 20 06:17:00.018119 2026] [security2:error] [pid 874439:tid 874588] [client 178.152.178.232:36278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9HwAAABM"]
[Mon Jul 20 06:17:00.300144 2026] [security2:error] [pid 874439:tid 874604] [client 15.237.142.234:19458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9JgAAACM"]
[Mon Jul 20 06:17:00.300286 2026] [security2:error] [pid 874439:tid 874604] [client 15.237.142.234:19458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9JgAAACM"]
[Mon Jul 20 06:17:00.449368 2026] [security2:error] [pid 874439:tid 874690] [client 103.77.203.233:49899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9MAAAAHk"]
[Mon Jul 20 06:17:00.449523 2026] [security2:error] [pid 874439:tid 874690] [client 103.77.203.233:49899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9MAAAAHk"]
[Mon Jul 20 06:17:00.587235 2026] [security2:error] [pid 874439:tid 874654] [client 104.234.53.90:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9MwAAAFU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:00.879354 2026] [security2:error] [pid 874439:tid 874659] [client 35.162.140.124:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT80gAAAFo"]
[Mon Jul 20 06:17:00.894847 2026] [security2:error] [pid 874439:tid 874655] [client 35.162.140.124:60291] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/"] [unique_id "al4Ruo6ZSrFvCrJJhtT8zgAAAFY"]
[Mon Jul 20 06:17:01.145517 2026] [cgid:error] [pid 871012:tid 871151] [client 37.27.55.110:21928] AH01265: stderr from /home1/jedalill/public_html/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 06:17:01.204670 2026] [security2:error] [pid 874439:tid 874591] [client 57.141.18.100:50186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RtY6ZSrFvCrJJhtT8DQAAFgM"]
[Mon Jul 20 06:17:01.229527 2026] [security2:error] [pid 871012:tid 871221] [client 14.225.17.146:65360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4RvbwiU-Jh5ncAILFhmgAAAVg"], referer: http://windowtx.com/wp
[Mon Jul 20 06:17:01.415214 2026] [security2:error] [pid 874439:tid 874690] [client 185.132.186.81:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd-1/dedi1.php"] [unique_id "al4RvY6ZSrFvCrJJhtT9VwAAAHk"]
[Mon Jul 20 06:17:01.494393 2026] [security2:error] [pid 874439:tid 874620] [client 14.225.17.146:63350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4RvY6ZSrFvCrJJhtT9UwAAADM"], referer: http://outlookturf.com/wp
[Mon Jul 20 06:17:01.554621 2026] [security2:error] [pid 871012:tid 871246] [client 98.159.234.160:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RvbwiU-Jh5ncAILFhsgAAAXE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:01.704939 2026] [security2:error] [pid 874439:tid 874638] [client 35.162.140.124:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9QQAAAEU"], referer: https://youpositive.co/?rnd=1784549818004
[Mon Jul 20 06:17:01.707502 2026] [security2:error] [pid 874439:tid 874648] [client 35.162.140.124:60291] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/ar/"] [unique_id "al4RvI6ZSrFvCrJJhtT9PgAAAE8"], referer: https://youpositive.co/?rnd=1784549818004
[Mon Jul 20 06:17:01.730819 2026] [security2:error] [pid 871012:tid 871076] [remote 115.79.143.180:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4RvbwiU-Jh5ncAILFhuAABYj4"]
[Mon Jul 20 06:17:01.844538 2026] [security2:error] [pid 871012:tid 871163] [client 45.157.112.60:58297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RvbwiU-Jh5ncAILFhuwAAAR4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:02.178948 2026] [security2:error] [pid 871012:tid 871024] [remote 115.79.143.180:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4RvrwiU-Jh5ncAILFhzQABRQo"], referer: https://slutilities.com/wp-login.php
[Mon Jul 20 06:17:02.402827 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:63874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9eQAAABc"], referer: http://idigress.group/wp
[Mon Jul 20 06:17:02.447010 2026] [security2:error] [pid 874439:tid 874660] [client 57.141.18.126:59984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rto6ZSrFvCrJJhtT8SAAAWxM"]
[Mon Jul 20 06:17:02.452356 2026] [security2:error] [pid 871012:tid 871195] [client 181.224.94.124:60210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RvrwiU-Jh5ncAILFh3QAAAT4"]
[Mon Jul 20 06:17:02.452486 2026] [security2:error] [pid 871012:tid 871195] [client 181.224.94.124:60210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RvrwiU-Jh5ncAILFh3QAAAT4"]
[Mon Jul 20 06:17:02.503932 2026] [security2:error] [pid 874439:tid 874689] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9gwAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:02.688301 2026] [security2:error] [pid 874439:tid 874512] [remote 57.141.18.21:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3802589"] [unique_id "al4Rvo6ZSrFvCrJJhtT9lgAAEUg"]
[Mon Jul 20 06:17:02.845501 2026] [security2:error] [pid 871012:tid 871053] [remote 192.241.143.148:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4RvrwiU-Jh5ncAILFh7wABdic"]
[Mon Jul 20 06:17:03.088138 2026] [security2:error] [pid 871012:tid 871063] [remote 192.241.143.148:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4Rv7wiU-Jh5ncAILFh-wABXjE"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:17:03.185344 2026] [security2:error] [pid 874439:tid 874634] [client 57.141.18.35:35826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8bAAAQRQ"]
[Mon Jul 20 06:17:03.409681 2026] [security2:error] [pid 874439:tid 874608] [client 185.132.186.67:24593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/setting.php"] [unique_id "al4Rv46ZSrFvCrJJhtT9rAAAACc"]
[Mon Jul 20 06:17:04.087689 2026] [security2:error] [pid 874439:tid 874645] [client 14.225.17.146:55038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9fQAAAEw"], referer: http://areitoproducciones.com/wp
[Mon Jul 20 06:17:04.710173 2026] [security2:error] [pid 871012:tid 871124] [remote 152.228.213.32:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4RwLwiU-Jh5ncAILFiWAABPG4"]
[Mon Jul 20 06:17:04.845075 2026] [security2:error] [pid 871012:tid 871179] [client 57.141.18.29:43188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RuLwiU-Jh5ncAILFg3AABLjc"]
[Mon Jul 20 06:17:04.927546 2026] [security2:error] [pid 871012:tid 871037] [remote 152.228.213.32:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4RwLwiU-Jh5ncAILFiZgABWxc"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:17:05.056593 2026] [security2:error] [pid 874439:tid 874608] [client 74.7.227.179:43710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RwI6ZSrFvCrJJhtT95QAAJ1U"], referer: https://tejasenvironmental.com/p=156629
[Mon Jul 20 06:17:05.182766 2026] [security2:error] [pid 871012:tid 871160] [client 14.225.17.146:65279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4RwLwiU-Jh5ncAILFiXwAAARs"], referer: http://carolinapressurewashers.com/wp
[Mon Jul 20 06:17:05.337735 2026] [security2:error] [pid 874439:tid 874655] [client 185.132.186.67:56195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/smilies/admin.php"] [unique_id "al4RwY6ZSrFvCrJJhtT98QAAAFY"]
[Mon Jul 20 06:17:05.433543 2026] [security2:error] [pid 871012:tid 871237] [client 57.141.18.106:37758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RubwiU-Jh5ncAILFg-wABaEM"]
[Mon Jul 20 06:17:05.791971 2026] [security2:error] [pid 871012:tid 871154] [client 14.225.17.146:65466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4RwbwiU-Jh5ncAILFiggAAARU"], referer: http://hilltopnurseryinc.com/wp
[Mon Jul 20 06:17:06.015553 2026] [security2:error] [pid 871012:tid 871187] [client 57.141.18.50:48048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RurwiU-Jh5ncAILFhFAABNjM"]
[Mon Jul 20 06:17:06.129233 2026] [security2:error] [pid 871012:tid 871234] [client 14.225.17.146:55630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4RwLwiU-Jh5ncAILFiSgAAAWU"], referer: http://vinovinhowine.com/wp
[Mon Jul 20 06:17:06.200486 2026] [security2:error] [pid 874439:tid 874653] [client 50.116.65.227:44316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Rwo6ZSrFvCrJJhtT-GgAAAFQ"]
[Mon Jul 20 06:17:06.213778 2026] [security2:error] [pid 871012:tid 871186] [client 50.116.65.227:39636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4RwrwiU-Jh5ncAILFiowAAASU"]
[Mon Jul 20 06:17:06.515562 2026] [security2:error] [pid 874439:tid 874655] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rwo6ZSrFvCrJJhtT-IgAAVmA"]
[Mon Jul 20 06:17:06.812023 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:65188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4RwrwiU-Jh5ncAILFiuAAAAWk"]
[Mon Jul 20 06:17:06.829758 2026] [security2:error] [pid 874439:tid 874539] [remote 57.141.18.97:26170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5276127"] [unique_id "al4Rwo6ZSrFvCrJJhtT-KwAAJGM"]
[Mon Jul 20 06:17:06.873321 2026] [security2:error] [pid 871012:tid 871198] [client 41.173.37.102:3060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RwrwiU-Jh5ncAILFiygAAAUE"]
[Mon Jul 20 06:17:06.873424 2026] [security2:error] [pid 871012:tid 871198] [client 41.173.37.102:3060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RwrwiU-Jh5ncAILFiygAAAUE"]
[Mon Jul 20 06:17:07.215143 2026] [security2:error] [pid 871012:tid 871197] [client 171.60.139.123:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi2QAAAUA"]
[Mon Jul 20 06:17:07.215288 2026] [security2:error] [pid 871012:tid 871197] [client 171.60.139.123:63203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi2QAAAUA"]
[Mon Jul 20 06:17:07.253641 2026] [security2:error] [pid 871012:tid 871180] [client 185.132.186.91:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/as.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi3AAAAS8"]
[Mon Jul 20 06:17:07.332487 2026] [security2:error] [pid 871012:tid 871255] [client 57.141.18.95:57904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhUgABegk"]
[Mon Jul 20 06:17:07.453744 2026] [security2:error] [pid 871012:tid 871162] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi2gAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:07.589452 2026] [security2:error] [pid 871012:tid 871083] [remote 173.249.4.11:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi7QABQ0U"]
[Mon Jul 20 06:17:07.965479 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:54885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Rw46ZSrFvCrJJhtT-UgAAABc"], referer: http://effingweirdmuseums.com/wp
[Mon Jul 20 06:17:08.122829 2026] [security2:error] [pid 871012:tid 871018] [remote 173.249.4.11:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4RxLwiU-Jh5ncAILFjAQABJwQ"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 06:17:08.307268 2026] [security2:error] [pid 871012:tid 871154] [client 14.225.17.146:65128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4RxLwiU-Jh5ncAILFjBQAAARU"], referer: http://techtradeinc.com/wp
[Mon Jul 20 06:17:08.628892 2026] [security2:error] [pid 871012:tid 871250] [client 14.225.17.146:55562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi7AAAAXU"], referer: http://ncsynchro.com/wp
[Mon Jul 20 06:17:08.680343 2026] [security2:error] [pid 871012:tid 871221] [client 104.210.140.133:61184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mtredistricting.gov"] [uri "/index.php"] [unique_id "al4RxLwiU-Jh5ncAILFjDAABWB8"]
[Mon Jul 20 06:17:08.715304 2026] [security2:error] [pid 871012:tid 871224] [client 114.119.135.84:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.theablesea.com"] [uri "/robots.txt"] [unique_id "al4RxLwiU-Jh5ncAILFjGQAAAVs"], referer: http://www.theablesea.com/robots.txt
[Mon Jul 20 06:17:08.719935 2026] [security2:error] [pid 871012:tid 871179] [client 45.116.69.230:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RxLwiU-Jh5ncAILFjGgAAAS4"]
[Mon Jul 20 06:17:08.720090 2026] [security2:error] [pid 871012:tid 871179] [client 45.116.69.230:54503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RxLwiU-Jh5ncAILFjGgAAAS4"]
[Mon Jul 20 06:17:08.731167 2026] [security2:error] [pid 874439:tid 874674] [client 103.141.108.143:56692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-egAAAGk"]
[Mon Jul 20 06:17:08.731291 2026] [security2:error] [pid 874439:tid 874674] [client 103.141.108.143:56692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-egAAAGk"]
[Mon Jul 20 06:17:08.784020 2026] [security2:error] [pid 874439:tid 874548] [remote 5.161.225.162:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-ewAAcmw"]
[Mon Jul 20 06:17:08.796409 2026] [security2:error] [pid 874439:tid 874654] [client 57.141.18.6:59580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RvY6ZSrFvCrJJhtT9XwAAVUI"]
[Mon Jul 20 06:17:08.890671 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:56314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-fAAAAA0"], referer: https://effingweirdmuseums.com/wp
[Mon Jul 20 06:17:08.892512 2026] [security2:error] [pid 871012:tid 871222] [client 45.61.188.240:61791] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.superiorcopywriting.com"] [uri "/"] [unique_id "al4RxLwiU-Jh5ncAILFjIAAAAVk"]
[Mon Jul 20 06:17:08.993244 2026] [security2:error] [pid 874439:tid 874553] [remote 5.161.225.162:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-iwAAOXE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:09.111061 2026] [security2:error] [pid 874439:tid 874585] [client 185.132.186.97:39733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/user/header.php"] [unique_id "al4RxY6ZSrFvCrJJhtT-kAAAABA"]
[Mon Jul 20 06:17:09.161574 2026] [security2:error] [pid 874439:tid 874644] [client 45.61.188.240:61830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.superiorcopywriting.com"] [uri "/"] [unique_id "al4RxY6ZSrFvCrJJhtT-kgAAAEs"]
[Mon Jul 20 06:17:09.340415 2026] [security2:error] [pid 871012:tid 871265] [client 57.141.18.59:33762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RvrwiU-Jh5ncAILFhyQABhDk"]
[Mon Jul 20 06:17:09.646108 2026] [security2:error] [pid 874439:tid 874581] [client 57.141.18.31:53292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9iwAADEQ"]
[Mon Jul 20 06:17:10.083706 2026] [security2:error] [pid 874439:tid 874560] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-uwAAXHg"]
[Mon Jul 20 06:17:10.083902 2026] [security2:error] [pid 874439:tid 874661] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-uwAAXHg"]
[Mon Jul 20 06:17:10.275437 2026] [security2:error] [pid 871012:tid 871236] [client 57.141.18.88:37014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rv7wiU-Jh5ncAILFh_AABZwU"]
[Mon Jul 20 06:17:10.363107 2026] [security2:error] [pid 871012:tid 871221] [client 216.38.230.126:50068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4RxrwiU-Jh5ncAILFjSwAAAVg"]
[Mon Jul 20 06:17:10.371420 2026] [security2:error] [pid 871012:tid 871218] [client 57.141.18.113:23770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rv7wiU-Jh5ncAILFiAQABVSs"]
[Mon Jul 20 06:17:10.706588 2026] [security2:error] [pid 874439:tid 874632] [client 14.225.17.146:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4RxY6ZSrFvCrJJhtT-oQAAAD8"], referer: http://hammadownenterprises.com/wp
[Mon Jul 20 06:17:10.912109 2026] [security2:error] [pid 874439:tid 874598] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-3QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:10.933912 2026] [security2:error] [pid 874439:tid 874671] [client 185.132.186.91:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/about.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-5wAAAGY"]
[Mon Jul 20 06:17:11.122825 2026] [security2:error] [pid 874439:tid 874679] [client 178.152.178.232:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9AAAAG4"]
[Mon Jul 20 06:17:11.122910 2026] [security2:error] [pid 874439:tid 874679] [client 178.152.178.232:36428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9AAAAG4"]
[Mon Jul 20 06:17:11.176702 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9QAAAGw"]
[Mon Jul 20 06:17:11.176839 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:50456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9QAAAGw"]
[Mon Jul 20 06:17:11.361413 2026] [security2:error] [pid 874439:tid 874453] [remote 72.167.132.114:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4Rx46ZSrFvCrJJhtT_AAAAeA0"]
[Mon Jul 20 06:17:11.425690 2026] [security2:error] [pid 874439:tid 874586] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rx46ZSrFvCrJJhtT--gAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:11.622857 2026] [security2:error] [pid 874439:tid 874454] [remote 72.167.132.114:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4Rx46ZSrFvCrJJhtT_EgAAJQ4"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 06:17:11.720583 2026] [security2:error] [pid 874439:tid 874683] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rx46ZSrFvCrJJhtT_DwAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:11.829306 2026] [security2:error] [pid 874439:tid 874607] [client 14.225.17.146:56255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-vgAAACY"], referer: http://according2plant.com/wp
[Mon Jul 20 06:17:12.258828 2026] [core:error] [pid 874439:tid 874629] [client 14.225.17.146:58029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:12.258853 2026] [core:error] [pid 874439:tid 874629] [client 14.225.17.146:58029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:12.270932 2026] [security2:error] [pid 871012:tid 871170] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rx7wiU-Jh5ncAILFjfQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:12.431167 2026] [security2:error] [pid 874439:tid 874659] [client 14.224.227.113:54321] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4RyI6ZSrFvCrJJhtT_QQAAAFo"]
[Mon Jul 20 06:17:12.674174 2026] [security2:error] [pid 874439:tid 874696] [client 57.141.18.53:22328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RwY6ZSrFvCrJJhtT9_wAAf1s"]
[Mon Jul 20 06:17:12.715601 2026] [security2:error] [pid 871012:tid 871181] [client 185.132.186.100:29327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-api.php"] [unique_id "al4RyLwiU-Jh5ncAILFjoQAAATA"]
[Mon Jul 20 06:17:12.749853 2026] [security2:error] [pid 874439:tid 874615] [client 114.119.133.35:49337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worbals.com"] [uri "/you-need-to-understand-the-role-of-a-legal-transcriptionist/"] [unique_id "al4RyI6ZSrFvCrJJhtT_TgAAAC4"], referer: https://worbals.com/one-of-the-amazing-wonders-of-the-digital-marketing-world-content-pyramid/
[Mon Jul 20 06:17:12.832873 2026] [security2:error] [pid 874439:tid 874472] [remote 95.217.78.234:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RyI6ZSrFvCrJJhtT_VQAAayA"]
[Mon Jul 20 06:17:12.839019 2026] [security2:error] [pid 871012:tid 871215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RyLwiU-Jh5ncAILFjlgAAAVI"]
[Mon Jul 20 06:17:12.979991 2026] [security2:error] [pid 871012:tid 871202] [client 181.224.94.124:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RyLwiU-Jh5ncAILFjsAAAAUU"]
[Mon Jul 20 06:17:12.980115 2026] [security2:error] [pid 871012:tid 871202] [client 181.224.94.124:36465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RyLwiU-Jh5ncAILFjsAAAAUU"]
[Mon Jul 20 06:17:12.995467 2026] [security2:error] [pid 871012:tid 871190] [client 14.225.17.146:56465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4RyLwiU-Jh5ncAILFjpQAAATk"], referer: http://omrobuildingcenter.com/wp
[Mon Jul 20 06:17:13.065717 2026] [security2:error] [pid 874439:tid 874521] [remote 95.217.78.234:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_XQAAcVE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:13.100359 2026] [security2:error] [pid 871012:tid 871268] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RyLwiU-Jh5ncAILFjrAAAAYc"]
[Mon Jul 20 06:17:13.244720 2026] [security2:error] [pid 871012:tid 871168] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RybwiU-Jh5ncAILFjtQAAASM"]
[Mon Jul 20 06:17:13.417977 2026] [security2:error] [pid 874439:tid 874573] [client 27.96.94.195:37358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_bgAAAAQ"]
[Mon Jul 20 06:17:13.418120 2026] [security2:error] [pid 874439:tid 874573] [client 27.96.94.195:37358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_bgAAAAQ"]
[Mon Jul 20 06:17:14.145455 2026] [security2:error] [pid 874439:tid 874541] [remote 152.228.213.32:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_lQAARmU"]
[Mon Jul 20 06:17:14.164224 2026] [security2:error] [pid 874439:tid 874695] [client 14.225.17.146:50768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4RyI6ZSrFvCrJJhtT_TQAAAH4"], referer: http://phillipbloch.com/wp
[Mon Jul 20 06:17:14.348648 2026] [security2:error] [pid 874439:tid 874567] [remote 152.228.213.32:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_oAAAJH8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:17:14.363246 2026] [security2:error] [pid 871012:tid 871160] [client 57.141.18.59:57546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi5wABGw8"]
[Mon Jul 20 06:17:14.492530 2026] [security2:error] [pid 874439:tid 874617] [client 44.245.170.32:14940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_sQAAADA"]
[Mon Jul 20 06:17:14.512994 2026] [security2:error] [pid 871012:tid 871236] [client 185.132.186.82:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/install.php"] [unique_id "al4RyrwiU-Jh5ncAILFj9AAAAWc"]
[Mon Jul 20 06:17:14.585558 2026] [security2:error] [pid 874439:tid 874696] [client 35.90.38.209:37912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_sgAAAH8"]
[Mon Jul 20 06:17:14.865510 2026] [security2:error] [pid 871012:tid 871184] [client 14.225.17.146:52893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4RybwiU-Jh5ncAILFjxwAAATM"], referer: http://goyalsatyam.com/wp
[Mon Jul 20 06:17:15.219469 2026] [security2:error] [pid 874439:tid 874573] [client 50.116.65.227:16666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Ry46ZSrFvCrJJhtT_ygAAAAQ"]
[Mon Jul 20 06:17:15.230618 2026] [security2:error] [pid 874439:tid 874619] [client 50.116.65.227:56844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Ry46ZSrFvCrJJhtT_ywAAACk"]
[Mon Jul 20 06:17:15.422865 2026] [security2:error] [pid 871012:tid 871156] [client 14.225.17.146:56538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4Ry7wiU-Jh5ncAILFkBgAAARc"], referer: http://www.justinagrayman.com/wp
[Mon Jul 20 06:17:15.855482 2026] [core:error] [pid 871012:tid 871236] [client 173.252.82.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:15.855508 2026] [core:error] [pid 871012:tid 871236] [client 173.252.82.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:16.192258 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.64:29356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RxY6ZSrFvCrJJhtT-owAATnY"]
[Mon Jul 20 06:17:16.315002 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.58:56735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css.php"] [unique_id "al4RzI6ZSrFvCrJJhtT_7gAAAFQ"]
[Mon Jul 20 06:17:16.564168 2026] [security2:error] [pid 874439:tid 874594] [client 82.102.18.116:42734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4RzI6ZSrFvCrJJhtQAAwAAABk"]
[Mon Jul 20 06:17:16.920482 2026] [security2:error] [pid 874439:tid 874633] [client 82.102.18.116:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RzI6ZSrFvCrJJhtQAGgAAAEA"]
[Mon Jul 20 06:17:17.119334 2026] [security2:error] [pid 874439:tid 874643] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RzI6ZSrFvCrJJhtQAHwAASks"]
[Mon Jul 20 06:17:17.231237 2026] [security2:error] [pid 874439:tid 874665] [client 82.102.18.116:42750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4RzY6ZSrFvCrJJhtQALAAAAGA"]
[Mon Jul 20 06:17:17.505937 2026] [security2:error] [pid 874439:tid 874692] [client 41.173.37.102:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAPAAAAHs"]
[Mon Jul 20 06:17:17.506046 2026] [security2:error] [pid 874439:tid 874692] [client 41.173.37.102:3495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAPAAAAHs"]
[Mon Jul 20 06:17:17.558154 2026] [security2:error] [pid 874439:tid 874671] [client 82.102.18.116:42756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4RzY6ZSrFvCrJJhtQAQAAAAGY"]
[Mon Jul 20 06:17:17.565490 2026] [security2:error] [pid 874439:tid 874661] [client 57.141.18.87:27036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-6AAAXEA"]
[Mon Jul 20 06:17:17.755026 2026] [security2:error] [pid 874439:tid 874527] [remote 45.90.123.233:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RzY6ZSrFvCrJJhtQATAAAJFc"]
[Mon Jul 20 06:17:17.887112 2026] [security2:error] [pid 874439:tid 874663] [client 82.102.18.116:42758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4RzY6ZSrFvCrJJhtQAVQAAAF4"]
[Mon Jul 20 06:17:17.949137 2026] [security2:error] [pid 874439:tid 874595] [client 171.60.139.123:63701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAWQAAABo"]
[Mon Jul 20 06:17:17.949251 2026] [security2:error] [pid 874439:tid 874595] [client 171.60.139.123:63701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAWQAAABo"]
[Mon Jul 20 06:17:18.112457 2026] [security2:error] [pid 874439:tid 874633] [client 158.173.89.95:64535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAZAAAAEA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:18.115993 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:54969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4Ry46ZSrFvCrJJhtT_2AAAAG0"], referer: http://drewsasburyparkbeachhouse.com/wp
[Mon Jul 20 06:17:18.117588 2026] [security2:error] [pid 874439:tid 874589] [client 185.132.186.93:47399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/db.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAZQAAABQ"]
[Mon Jul 20 06:17:18.180615 2026] [security2:error] [pid 874439:tid 874540] [remote 45.90.123.233:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAaAAATWQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:18.200857 2026] [security2:error] [pid 871012:tid 871254] [client 82.102.18.116:58128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4RzrwiU-Jh5ncAILFkhAAAAXk"]
[Mon Jul 20 06:17:18.416873 2026] [security2:error] [pid 871012:tid 871259] [client 113.160.97.242:50198] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4RzrwiU-Jh5ncAILFkiwAAAX4"]
[Mon Jul 20 06:17:18.530686 2026] [security2:error] [pid 874439:tid 874693] [client 82.102.18.116:58138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4Rzo6ZSrFvCrJJhtQAdwAAAHw"]
[Mon Jul 20 06:17:18.663574 2026] [security2:error] [pid 874439:tid 874656] [client 14.225.17.146:57155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAcwAAAFc"], referer: http://sesamegreenbeans.com/wp
[Mon Jul 20 06:17:18.810432 2026] [security2:error] [pid 874439:tid 874696] [client 14.167.202.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAZwAAAH8"]
[Mon Jul 20 06:17:18.854013 2026] [security2:error] [pid 874439:tid 874580] [client 82.102.18.116:58140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4Rzo6ZSrFvCrJJhtQAiQAAAAs"]
[Mon Jul 20 06:17:19.193683 2026] [security2:error] [pid 874439:tid 874629] [client 82.102.18.116:58148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Rz46ZSrFvCrJJhtQAnQAAADw"]
[Mon Jul 20 06:17:19.349962 2026] [security2:error] [pid 874439:tid 874634] [client 45.116.69.230:55031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz46ZSrFvCrJJhtQAnwAAAEE"]
[Mon Jul 20 06:17:19.350058 2026] [security2:error] [pid 874439:tid 874634] [client 45.116.69.230:55031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz46ZSrFvCrJJhtQAnwAAAEE"]
[Mon Jul 20 06:17:19.362243 2026] [security2:error] [pid 871012:tid 871212] [client 103.141.108.143:57181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkrQAAAU8"]
[Mon Jul 20 06:17:19.362560 2026] [security2:error] [pid 871012:tid 871212] [client 103.141.108.143:57181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkrQAAAU8"]
[Mon Jul 20 06:17:19.491969 2026] [security2:error] [pid 874439:tid 874575] [client 57.141.18.48:51844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_YQAABiE"]
[Mon Jul 20 06:17:19.515041 2026] [security2:error] [pid 871012:tid 871218] [client 82.102.18.116:58160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Rz7wiU-Jh5ncAILFkuQAAAVU"]
[Mon Jul 20 06:17:19.693939 2026] [security2:error] [pid 871012:tid 871164] [client 14.225.17.146:58277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Rz7wiU-Jh5ncAILFktwAAAR8"], referer: https://sesamegreenbeans.com/wp
[Mon Jul 20 06:17:19.838623 2026] [security2:error] [pid 871012:tid 871161] [client 82.102.18.116:62340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Rz7wiU-Jh5ncAILFkxgAAARw"]
[Mon Jul 20 06:17:19.858873 2026] [security2:error] [pid 871012:tid 871201] [client 104.234.53.48:53669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkyAAAAUQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:19.908958 2026] [security2:error] [pid 871012:tid 871171] [client 32.198.12.77:43486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkyQAAASY"]
[Mon Jul 20 06:17:19.918647 2026] [security2:error] [pid 871012:tid 871181] [client 185.132.186.58:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-customize-manager-interpreter.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkzAAAATA"]
[Mon Jul 20 06:17:20.108679 2026] [security2:error] [pid 871012:tid 871119] [remote 91.142.222.105:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4R0LwiU-Jh5ncAILFk1QABfWk"]
[Mon Jul 20 06:17:20.151814 2026] [security2:error] [pid 874439:tid 874669] [client 82.102.18.116:58172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4R0I6ZSrFvCrJJhtQAwgAAAGQ"]
[Mon Jul 20 06:17:20.242105 2026] [security2:error] [pid 874439:tid 874649] [client 13.221.132.12:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.132.221.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4R0I6ZSrFvCrJJhtQAxQAAAFA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:17:20.291286 2026] [security2:error] [pid 874439:tid 874598] [client 57.141.18.116:55204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_hwAAHWI"]
[Mon Jul 20 06:17:20.331905 2026] [security2:error] [pid 874439:tid 874557] [remote 124.55.178.99:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4R0I6ZSrFvCrJJhtQAyAAAT3U"]
[Mon Jul 20 06:17:20.346119 2026] [security2:error] [pid 871012:tid 871115] [remote 91.142.222.105:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4R0LwiU-Jh5ncAILFk3wABcWU"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:17:20.461864 2026] [security2:error] [pid 874439:tid 874634] [client 82.102.18.116:58174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4R0I6ZSrFvCrJJhtQAzgAAAEE"]
[Mon Jul 20 06:17:20.680975 2026] [security2:error] [pid 874439:tid 874444] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA2gAAegQ"]
[Mon Jul 20 06:17:20.681161 2026] [security2:error] [pid 874439:tid 874691] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA2gAAegQ"]
[Mon Jul 20 06:17:20.799266 2026] [security2:error] [pid 874439:tid 874659] [client 82.102.18.116:58182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4R0I6ZSrFvCrJJhtQA3gAAAFo"]
[Mon Jul 20 06:17:20.886333 2026] [security2:error] [pid 874439:tid 874446] [remote 124.55.178.99:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA3wAAVwY"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:17:21.120171 2026] [security2:error] [pid 874439:tid 874589] [client 82.102.18.116:58198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4R0Y6ZSrFvCrJJhtQA6wAAABQ"]
[Mon Jul 20 06:17:21.445757 2026] [security2:error] [pid 874439:tid 874613] [client 82.102.18.116:58214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4R0Y6ZSrFvCrJJhtQA_wAAACw"]
[Mon Jul 20 06:17:21.691653 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:51011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R0Y6ZSrFvCrJJhtQBCQAAACA"]
[Mon Jul 20 06:17:21.691801 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:51011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R0Y6ZSrFvCrJJhtQBCQAAACA"]
[Mon Jul 20 06:17:21.716457 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.83:30409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/bypass.php"] [unique_id "al4R0Y6ZSrFvCrJJhtQBDgAAAFQ"]
[Mon Jul 20 06:17:22.017804 2026] [security2:error] [pid 874439:tid 874617] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA0QAAADA"], referer: http://eduardsales.com/wp
[Mon Jul 20 06:17:22.189492 2026] [security2:error] [pid 874439:tid 874511] [remote 57.141.18.5:58778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4R0o6ZSrFvCrJJhtQBHwAAbEc"]
[Mon Jul 20 06:17:22.598193 2026] [security2:error] [pid 871012:tid 871267] [client 57.141.18.116:55222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ry7wiU-Jh5ncAILFkJQABhlE"]
[Mon Jul 20 06:17:22.672842 2026] [security2:error] [pid 874439:tid 874647] [client 50.116.65.227:60006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4R0o6ZSrFvCrJJhtQBMwAAAE4"]
[Mon Jul 20 06:17:22.683728 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:52356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4R0rwiU-Jh5ncAILFlOgAAAS0"]
[Mon Jul 20 06:17:22.913779 2026] [core:error] [pid 871012:tid 871206] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.913809 2026] [core:error] [pid 871012:tid 871206] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914275 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914289 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914578 2026] [core:error] [pid 871012:tid 871202] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914592 2026] [core:error] [pid 871012:tid 871202] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.937278 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.937297 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:23.236338 2026] [security2:error] [pid 871012:tid 871250] [client 57.141.18.73:63070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RzLwiU-Jh5ncAILFkPgABdUA"]
[Mon Jul 20 06:17:23.392411 2026] [security2:error] [pid 874439:tid 874472] [remote 156.67.31.167:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4R046ZSrFvCrJJhtQBUwAARiA"]
[Mon Jul 20 06:17:23.404801 2026] [security2:error] [pid 874439:tid 874470] [remote 154.66.198.148:11108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R046ZSrFvCrJJhtQBVAAAXx4"]
[Mon Jul 20 06:17:23.489388 2026] [security2:error] [pid 871012:tid 871252] [client 185.132.186.99:31279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/fm.php7"] [unique_id "al4R07wiU-Jh5ncAILFlYAAAAXc"]
[Mon Jul 20 06:17:23.503490 2026] [security2:error] [pid 874439:tid 874613] [client 181.224.94.124:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R046ZSrFvCrJJhtQBWwAAACw"]
[Mon Jul 20 06:17:23.503631 2026] [security2:error] [pid 874439:tid 874613] [client 181.224.94.124:21067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R046ZSrFvCrJJhtQBWwAAACw"]
[Mon Jul 20 06:17:23.677655 2026] [core:error] [pid 874439:tid 874690] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:23.677675 2026] [core:error] [pid 874439:tid 874690] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:23.826110 2026] [security2:error] [pid 874439:tid 874614] [client 104.234.53.67:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4R046ZSrFvCrJJhtQBcQAAAC0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:23.869159 2026] [security2:error] [pid 874439:tid 874475] [remote 156.67.31.167:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4R046ZSrFvCrJJhtQBdQAAJyM"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:17:24.021764 2026] [security2:error] [pid 871012:tid 871112] [remote 50.28.1.50:45458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R1LwiU-Jh5ncAILFleAABfWI"]
[Mon Jul 20 06:17:24.036795 2026] [security2:error] [pid 874439:tid 874655] [client 103.153.183.69:14660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4R1I6ZSrFvCrJJhtQBewAAAFY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:17:24.234208 2026] [security2:error] [pid 871012:tid 871114] [remote 50.28.1.50:45458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R1LwiU-Jh5ncAILFlgQABXmQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:17:24.285710 2026] [security2:error] [pid 874439:tid 874483] [remote 154.66.198.148:11096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4R1I6ZSrFvCrJJhtQBiAAAICs"]
[Mon Jul 20 06:17:24.538178 2026] [security2:error] [pid 874439:tid 874567] [remote 154.66.198.148:11108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R1I6ZSrFvCrJJhtQBlAAAS38"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:24.555446 2026] [security2:error] [pid 874439:tid 874576] [client 57.141.18.95:58244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAMQAABxk"]
[Mon Jul 20 06:17:24.653847 2026] [security2:error] [pid 871012:tid 871213] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R1LwiU-Jh5ncAILFlhwAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:24.803972 2026] [security2:error] [pid 874439:tid 874484] [remote 45.90.123.233:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1I6ZSrFvCrJJhtQBnQAAQCw"]
[Mon Jul 20 06:17:24.878889 2026] [security2:error] [pid 874439:tid 874656] [client 45.61.188.240:64600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "superiorcopywriting.com"] [uri "/"] [unique_id "al4R1I6ZSrFvCrJJhtQBogAAAFc"]
[Mon Jul 20 06:17:25.025941 2026] [security2:error] [pid 874439:tid 874564] [remote 45.90.123.233:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBsgAAfHw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:25.034873 2026] [security2:error] [pid 874439:tid 874493] [remote 20.153.140.50:55352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBsQAAHTU"]
[Mon Jul 20 06:17:25.131378 2026] [security2:error] [pid 874439:tid 874458] [remote 154.66.198.148:11096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBugAAIxI"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:17:25.160639 2026] [security2:error] [pid 874439:tid 874601] [client 45.61.188.240:64641] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "superiorcopywriting.com"] [uri "/"] [unique_id "al4R1Y6ZSrFvCrJJhtQBvAAAACA"]
[Mon Jul 20 06:17:25.293418 2026] [security2:error] [pid 874439:tid 874642] [client 14.225.17.146:57316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBvwAAAEk"], referer: http://ravmike.com/wp
[Mon Jul 20 06:17:25.317949 2026] [security2:error] [pid 874439:tid 874496] [remote 160.187.68.132:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBwwAAaDg"]
[Mon Jul 20 06:17:25.391352 2026] [security2:error] [pid 874439:tid 874672] [client 14.225.17.146:57322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBwgAAAGc"], referer: http://alrowad-hub.net/wp
[Mon Jul 20 06:17:25.424796 2026] [security2:error] [pid 874439:tid 874449] [remote 20.153.140.50:55352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBygAAawk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:25.806431 2026] [security2:error] [pid 874439:tid 874693] [client 103.153.183.69:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fhome/www-data/.ssh/id_rsa"] [unique_id "al4R1Y6ZSrFvCrJJhtQB5AAAAHw"], referer: https://duckduckgo.com/?q=fkezl
[Mon Jul 20 06:17:26.197402 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:57402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4R1rwiU-Jh5ncAILFl0wAAAWk"], referer: https://ravmike.com/wp
[Mon Jul 20 06:17:26.380730 2026] [security2:error] [pid 874439:tid 874630] [client 185.132.186.100:40299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/count.php"] [unique_id "al4R1o6ZSrFvCrJJhtQB_QAAAD0"]
[Mon Jul 20 06:17:26.385403 2026] [security2:error] [pid 874439:tid 874459] [remote 160.187.68.132:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4R1o6ZSrFvCrJJhtQB_AAAcxM"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 06:17:26.472288 2026] [security2:error] [pid 871012:tid 871244] [client 57.141.18.13:58672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rz7wiU-Jh5ncAILFksAABb2w"]
[Mon Jul 20 06:17:26.632960 2026] [core:error] [pid 874439:tid 874620] [client 14.225.17.146:56966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:26.632980 2026] [core:error] [pid 874439:tid 874620] [client 14.225.17.146:56966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:26.683803 2026] [security2:error] [pid 874439:tid 874667] [client 57.141.18.81:60458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rz46ZSrFvCrJJhtQAsAAAYlw"]
[Mon Jul 20 06:17:26.703507 2026] [security2:error] [pid 874439:tid 874581] [client 74.208.214.194:46278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4R1o6ZSrFvCrJJhtQCEgAAAAw"]
[Mon Jul 20 06:17:26.943146 2026] [security2:error] [pid 871012:tid 871214] [client 14.225.17.146:56897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4R1rwiU-Jh5ncAILFl7gAAAVE"], referer: http://kromosenergy.com/wp
[Mon Jul 20 06:17:27.265994 2026] [security2:error] [pid 874439:tid 874664] [client 14.225.17.146:60515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4R146ZSrFvCrJJhtQCMQAAAF8"], referer: http://39ishlife.com/wp
[Mon Jul 20 06:17:27.290816 2026] [security2:error] [pid 871012:tid 871178] [client 14.225.17.146:60509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFl-wAAAS0"], referer: http://savilerowtravel.com/wp
[Mon Jul 20 06:17:27.320979 2026] [security2:error] [pid 871012:tid 871223] [client 14.225.17.146:64490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFl_wAAAVo"], referer: http://mourgroup.com/wp
[Mon Jul 20 06:17:27.321652 2026] [security2:error] [pid 871012:tid 871224] [client 14.225.17.146:60519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFl_AAAAVs"], referer: http://qualitycoatingsinspection.com/wp
[Mon Jul 20 06:17:27.490042 2026] [security2:error] [pid 874439:tid 874539] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R146ZSrFvCrJJhtQCQQAAbWM"]
[Mon Jul 20 06:17:27.490250 2026] [security2:error] [pid 874439:tid 874678] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R146ZSrFvCrJJhtQCQQAAbWM"]
[Mon Jul 20 06:17:27.624173 2026] [security2:error] [pid 874439:tid 874635] [client 57.141.18.100:49440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA2wAAQgU"]
[Mon Jul 20 06:17:27.922492 2026] [security2:error] [pid 874439:tid 874692] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R146ZSrFvCrJJhtQCRwAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:28.102428 2026] [security2:error] [pid 874439:tid 874586] [client 41.173.37.102:3926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCaAAAABE"]
[Mon Jul 20 06:17:28.102537 2026] [security2:error] [pid 874439:tid 874586] [client 41.173.37.102:3926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCaAAAABE"]
[Mon Jul 20 06:17:28.178526 2026] [security2:error] [pid 874439:tid 874599] [client 185.132.186.53:36659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-error_log.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCawAAAB4"]
[Mon Jul 20 06:17:28.313944 2026] [security2:error] [pid 874439:tid 874621] [client 104.234.53.61:42487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCbgAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:28.316936 2026] [security2:error] [pid 874439:tid 874618] [client 14.225.17.146:64841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCbQAAADE"], referer: https://39ishlife.com/wp
[Mon Jul 20 06:17:28.360388 2026] [security2:error] [pid 874439:tid 874642] [client 14.225.17.146:64779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCbAAAAEk"], referer: https://qualitycoatingsinspection.com/wp
[Mon Jul 20 06:17:28.586257 2026] [security2:error] [pid 871012:tid 871247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmKQAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:28.635052 2026] [security2:error] [pid 871012:tid 871075] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/api/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmRgABCz0"]
[Mon Jul 20 06:17:28.638102 2026] [security2:error] [pid 871012:tid 871100] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/backend/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmSAABdVY"]
[Mon Jul 20 06:17:28.638960 2026] [security2:error] [pid 871012:tid 871101] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/.env.backup"] [unique_id "al4R2LwiU-Jh5ncAILFmSQABdVc"]
[Mon Jul 20 06:17:28.641967 2026] [security2:error] [pid 871012:tid 871023] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.env.bak"] [unique_id "al4R2LwiU-Jh5ncAILFmSgABdQk"]
[Mon Jul 20 06:17:28.642977 2026] [security2:error] [pid 871012:tid 871035] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/admin/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmSwABdRU"]
[Mon Jul 20 06:17:28.646631 2026] [security2:error] [pid 871012:tid 871060] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.env.old"] [unique_id "al4R2LwiU-Jh5ncAILFmTQABdS4"]
[Mon Jul 20 06:17:28.678362 2026] [security2:error] [pid 871012:tid 871030] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/config/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmUAABdRA"]
[Mon Jul 20 06:17:28.678551 2026] [security2:error] [pid 874439:tid 874688] [client 13.229.83.156:46304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCigAAAHc"]
[Mon Jul 20 06:17:28.678707 2026] [security2:error] [pid 874439:tid 874688] [client 13.229.83.156:46304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCigAAAHc"]
[Mon Jul 20 06:17:28.689879 2026] [security2:error] [pid 874439:tid 874670] [client 14.225.17.146:49231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCewAAAGU"], referer: https://savilerowtravel.com/wp
[Mon Jul 20 06:17:28.720779 2026] [security2:error] [pid 874439:tid 874609] [client 103.153.183.69:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fhome/git/.ssh/id_rsa"] [unique_id "al4R2I6ZSrFvCrJJhtQCjQAAACg"], referer: https://www.google.com/
[Mon Jul 20 06:17:28.764708 2026] [security2:error] [pid 874439:tid 874661] [client 171.60.139.123:64197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCkAAAAFw"]
[Mon Jul 20 06:17:28.764846 2026] [security2:error] [pid 874439:tid 874661] [client 171.60.139.123:64197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCkAAAAFw"]
[Mon Jul 20 06:17:28.798913 2026] [security2:error] [pid 871012:tid 871236] [client 13.223.141.79:59584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.verdunestate.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmQwAAAWc"]
[Mon Jul 20 06:17:28.854176 2026] [security2:error] [pid 871012:tid 871197] [client 14.225.17.146:49290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmRQAAAUA"], referer: http://ironcitywellness.com/wp
[Mon Jul 20 06:17:28.953655 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmTgABdWo"]
[Mon Jul 20 06:17:28.954271 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmTAABdRo"]
[Mon Jul 20 06:17:28.980216 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmUwABdTo"]
[Mon Jul 20 06:17:28.990542 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmUgABdSc"]
[Mon Jul 20 06:17:29.105942 2026] [security2:error] [pid 874439:tid 874689] [client 57.141.18.100:49456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R0o6ZSrFvCrJJhtQBFgAAeBU"]
[Mon Jul 20 06:17:29.518726 2026] [security2:error] [pid 874439:tid 874473] [remote 217.61.143.92:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCqQAAaCE"]
[Mon Jul 20 06:17:29.738915 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmbgABQmM"]
[Mon Jul 20 06:17:29.754543 2026] [security2:error] [pid 874439:tid 874635] [client 14.225.17.146:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4R146ZSrFvCrJJhtQCVwAAAEI"], referer: http://mobilesurvsolutions.com/wp
[Mon Jul 20 06:17:29.789816 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdQABQlw"]
[Mon Jul 20 06:17:29.790069 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdwABQg4"]
[Mon Jul 20 06:17:29.790224 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmcwABQnk"]
[Mon Jul 20 06:17:29.790484 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmeAABQh8"]
[Mon Jul 20 06:17:29.791649 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdAABQmg"]
[Mon Jul 20 06:17:29.791843 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdgABQkY"]
[Mon Jul 20 06:17:29.791997 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmcgABQgQ"]
[Mon Jul 20 06:17:29.817431 2026] [security2:error] [pid 874439:tid 874551] [remote 57.141.18.91:20892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5168046"] [unique_id "al4R2Y6ZSrFvCrJJhtQCsgAAc28"]
[Mon Jul 20 06:17:29.829540 2026] [security2:error] [pid 874439:tid 874556] [remote 217.61.143.92:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCtQAAIXQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:29.914442 2026] [security2:error] [pid 874439:tid 874649] [client 104.234.53.61:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCtgAAAFA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:29.980949 2026] [security2:error] [pid 871012:tid 871147] [client 103.141.108.143:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R2bwiU-Jh5ncAILFmlAAAAQ4"]
[Mon Jul 20 06:17:29.981979 2026] [security2:error] [pid 871012:tid 871147] [client 103.141.108.143:57660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R2bwiU-Jh5ncAILFmlAAAAQ4"]
[Mon Jul 20 06:17:29.983580 2026] [security2:error] [pid 871012:tid 871198] [client 185.132.186.65:60909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/class_update_plugins.php"] [unique_id "al4R2bwiU-Jh5ncAILFmlQAAAUE"]
[Mon Jul 20 06:17:30.011143 2026] [security2:error] [pid 871012:tid 871258] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmiwAAAX0"]
[Mon Jul 20 06:17:30.032514 2026] [security2:error] [pid 874439:tid 874614] [client 45.116.69.230:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R2o6ZSrFvCrJJhtQCvAAAAC0"]
[Mon Jul 20 06:17:30.032604 2026] [security2:error] [pid 874439:tid 874614] [client 45.116.69.230:55568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R2o6ZSrFvCrJJhtQCvAAAAC0"]
[Mon Jul 20 06:17:30.222828 2026] [security2:error] [pid 871012:tid 871269] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmigAAAYg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:30.544324 2026] [security2:error] [pid 874439:tid 874584] [client 50.116.65.227:19344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R2o6ZSrFvCrJJhtQC6AAAAA8"]
[Mon Jul 20 06:17:30.555577 2026] [security2:error] [pid 874439:tid 874664] [client 50.116.65.227:34104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R2o6ZSrFvCrJJhtQC6gAAAF8"]
[Mon Jul 20 06:17:30.560302 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQCzAAAWHc"], referer: https://guidehunting.com/.env.local
[Mon Jul 20 06:17:30.653695 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC1QAAWHU"], referer: https://guidehunting.com/.npmrc
[Mon Jul 20 06:17:30.656654 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC0QAAWHg"], referer: https://guidehunting.com/.docker/config.json
[Mon Jul 20 06:17:30.657014 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC1AAAWH4"], referer: https://guidehunting.com/firebase-adminsdk.json
[Mon Jul 20 06:17:30.657163 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC0gAAWHo"], referer: https://guidehunting.com/credentials.json
[Mon Jul 20 06:17:30.659307 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC0wAAWGI"], referer: https://guidehunting.com/secrets.yml
[Mon Jul 20 06:17:30.695006 2026] [security2:error] [pid 874439:tid 874673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC4AAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:30.867914 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC6wAAWAo"], referer: https://guidehunting.com/key.json
[Mon Jul 20 06:17:30.869804 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC7QAAWHc"], referer: https://guidehunting.com/serviceAccountKey.json
[Mon Jul 20 06:17:30.869954 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC7AAAWAI"], referer: https://guidehunting.com/service-account.json
[Mon Jul 20 06:17:30.981560 2026] [security2:error] [pid 874439:tid 874685] [client 82.102.18.116:53832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4R2o6ZSrFvCrJJhtQDCAAAAHQ"]
[Mon Jul 20 06:17:31.094576 2026] [security2:error] [pid 874439:tid 874596] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQDAAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:31.219976 2026] [security2:error] [pid 874439:tid 874572] [client 193.36.225.138:24945] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "newoffice.ca"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4R246ZSrFvCrJJhtQDEgAAAAM"]
[Mon Jul 20 06:17:31.328179 2026] [security2:error] [pid 874439:tid 874605] [client 82.102.18.116:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.ferrarimenezes.com"] [uri "/xmlrpc.php"] [unique_id "al4R246ZSrFvCrJJhtQDGwAAACQ"]
[Mon Jul 20 06:17:31.416528 2026] [security2:error] [pid 874439:tid 874479] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R246ZSrFvCrJJhtQDKQAAOic"]
[Mon Jul 20 06:17:31.416694 2026] [security2:error] [pid 874439:tid 874627] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R246ZSrFvCrJJhtQDKQAAOic"]
[Mon Jul 20 06:17:31.452402 2026] [security2:error] [pid 874439:tid 874584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDFwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:31.768948 2026] [security2:error] [pid 871012:tid 871090] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/.boto"] [unique_id "al4R27wiU-Jh5ncAILFmyAABP0w"]
[Mon Jul 20 06:17:31.769202 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/.boto"] [unique_id "al4R27wiU-Jh5ncAILFmyAABP0w"]
[Mon Jul 20 06:17:31.772023 2026] [security2:error] [pid 871012:tid 871014] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.ssh/id_rsa"] [unique_id "al4R27wiU-Jh5ncAILFmyQABPwA"]
[Mon Jul 20 06:17:31.772571 2026] [authz_core:error] [pid 871012:tid 871052] [remote 35.245.65.174:33432] AH01630: client denied by server configuration: /home4/guidehun/public_html/.htpasswd
[Mon Jul 20 06:17:31.789745 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.83:29689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/av.php"] [unique_id "al4R246ZSrFvCrJJhtQDQgAAAFQ"]
[Mon Jul 20 06:17:31.814096 2026] [security2:error] [pid 871012:tid 871215] [client 82.102.18.116:62336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4R27wiU-Jh5ncAILFm0AAAAVI"]
[Mon Jul 20 06:17:31.841875 2026] [security2:error] [pid 871012:tid 871239] [client 57.141.18.27:51696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R1LwiU-Jh5ncAILFlngABaiQ"]
[Mon Jul 20 06:17:31.915300 2026] [security2:error] [pid 874439:tid 874665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDOAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:32.033043 2026] [security2:error] [pid 874439:tid 874637] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDOQAARCs"], referer: https://guidehunting.com/rclone.conf
[Mon Jul 20 06:17:32.060615 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmxQABPy0"]
[Mon Jul 20 06:17:32.063008 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmxgABPzA"]
[Mon Jul 20 06:17:32.070777 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmzQABP18"]
[Mon Jul 20 06:17:32.073146 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmygABP3E"]
[Mon Jul 20 06:17:32.086583 2026] [security2:error] [pid 874439:tid 874672] [client 178.152.178.232:37686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDUwAAAGc"]
[Mon Jul 20 06:17:32.086665 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmzAABP0E"]
[Mon Jul 20 06:17:32.086822 2026] [security2:error] [pid 874439:tid 874672] [client 178.152.178.232:37686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDUwAAAGc"]
[Mon Jul 20 06:17:32.088543 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmywABP3o"]
[Mon Jul 20 06:17:32.098209 2026] [security2:error] [pid 874439:tid 874637] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDPwAARCg"], referer: https://guidehunting.com/z9x8c7v6b5-debug-trigger-guidehunting.com
[Mon Jul 20 06:17:32.098864 2026] [security2:error] [pid 874439:tid 874637] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDPgAARH8"], referer: https://guidehunting.com/secrets.json
[Mon Jul 20 06:17:32.138419 2026] [security2:error] [pid 874439:tid 874603] [client 82.102.18.116:53856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4R3I6ZSrFvCrJJhtQDWAAAACI"]
[Mon Jul 20 06:17:32.148221 2026] [security2:error] [pid 874439:tid 874689] [client 74.208.214.194:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDWgAAAHg"]
[Mon Jul 20 06:17:32.186960 2026] [security2:error] [pid 874439:tid 874663] [client 103.77.203.233:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDXQAAAF4"]
[Mon Jul 20 06:17:32.189148 2026] [security2:error] [pid 874439:tid 874663] [client 103.77.203.233:51569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDXQAAAF4"]
[Mon Jul 20 06:17:32.250262 2026] [security2:error] [pid 874439:tid 874492] [remote 72.167.132.114:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDYgAABjQ"]
[Mon Jul 20 06:17:32.261651 2026] [security2:error] [pid 874439:tid 874631] [client 57.141.18.58:48078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBtgAAPjs"]
[Mon Jul 20 06:17:32.381761 2026] [security2:error] [pid 871012:tid 871133] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.ssh/id_dsa"] [unique_id "al4R3LwiU-Jh5ncAILFm2AABNXc"]
[Mon Jul 20 06:17:32.473351 2026] [security2:error] [pid 874439:tid 874509] [remote 72.167.132.114:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDeQAAVEU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:32.479819 2026] [security2:error] [pid 874439:tid 874648] [client 82.102.18.116:53870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4R3I6ZSrFvCrJJhtQDegAAAE8"]
[Mon Jul 20 06:17:32.510778 2026] [security2:error] [pid 874439:tid 874681] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDaQAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:32.618545 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:54656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDCwAAAE4"], referer: http://headachescarpaltunnelfibromyalgia.com/wp
[Mon Jul 20 06:17:32.640074 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDbgAAHTc"], referer: https://guidehunting.com/.s3cfg
[Mon Jul 20 06:17:32.644311 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcAAAHT0"], referer: https://guidehunting.com/.ssh/id_ed25519
[Mon Jul 20 06:17:32.644471 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcwAAHT4"], referer: https://guidehunting.com/.vscode/launch.json
[Mon Jul 20 06:17:32.644711 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDbwAAHXY"], referer: https://guidehunting.com/.svn/entries
[Mon Jul 20 06:17:32.644864 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcQAAHTo"], referer: https://guidehunting.com/terraform.tfstate
[Mon Jul 20 06:17:32.645971 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcgAAHQw"], referer: https://guidehunting.com/docker-compose.yaml
[Mon Jul 20 06:17:32.683491 2026] [security2:error] [pid 871012:tid 871186] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R3LwiU-Jh5ncAILFm2QABNUc"]
[Mon Jul 20 06:17:32.790360 2026] [security2:error] [pid 874439:tid 874589] [client 82.102.18.116:53874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4R3I6ZSrFvCrJJhtQDjQAAABQ"]
[Mon Jul 20 06:17:33.024461 2026] [security2:error] [pid 874439:tid 874584] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDhwAAD00"]
[Mon Jul 20 06:17:33.128073 2026] [security2:error] [pid 871012:tid 871182] [client 82.102.18.116:53876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4R3bwiU-Jh5ncAILFm6AAAATE"]
[Mon Jul 20 06:17:33.261145 2026] [security2:error] [pid 871012:tid 871174] [client 46.110.96.34:61718] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4R3bwiU-Jh5ncAILFm7AAAASk"]
[Mon Jul 20 06:17:33.261163 2026] [security2:error] [pid 874439:tid 874592] [client 46.110.96.34:36182] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4R3Y6ZSrFvCrJJhtQDpQAAABc"]
[Mon Jul 20 06:17:33.366233 2026] [security2:error] [pid 874439:tid 874635] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDnwAAQgE"], referer: https://guidehunting.com/.ssh/id_ecdsa
[Mon Jul 20 06:17:33.367646 2026] [security2:error] [pid 871012:tid 871153] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R3bwiU-Jh5ncAILFm5gABFHw"]
[Mon Jul 20 06:17:33.407529 2026] [security2:error] [pid 871012:tid 871221] [client 129.151.80.191:38564] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "perrysnopeep.com"] [uri "/index.html"] [unique_id "al4R3bwiU-Jh5ncAILFm-AAAAVg"]
[Mon Jul 20 06:17:33.447931 2026] [security2:error] [pid 874439:tid 874690] [client 82.102.18.116:36075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4R3Y6ZSrFvCrJJhtQDsAAAAHk"]
[Mon Jul 20 06:17:33.543547 2026] [security2:error] [pid 871012:tid 871153] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R3bwiU-Jh5ncAILFm7QABFA0"]
[Mon Jul 20 06:17:33.597306 2026] [security2:error] [pid 874439:tid 874615] [client 185.132.186.95:32877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/templates/beez5/error.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDtwAAAC4"]
[Mon Jul 20 06:17:33.702729 2026] [security2:error] [pid 874439:tid 874463] [remote 152.228.213.32:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDvQAARBc"]
[Mon Jul 20 06:17:33.762848 2026] [security2:error] [pid 871012:tid 871161] [client 82.102.18.116:38537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4R3bwiU-Jh5ncAILFnBAAAARw"]
[Mon Jul 20 06:17:33.905245 2026] [security2:error] [pid 874439:tid 874529] [remote 152.228.213.32:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDwQAAB1k"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:17:34.055460 2026] [security2:error] [pid 874439:tid 874589] [client 181.224.94.124:6549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R3o6ZSrFvCrJJhtQDygAAABQ"]
[Mon Jul 20 06:17:34.055561 2026] [security2:error] [pid 874439:tid 874589] [client 181.224.94.124:6549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R3o6ZSrFvCrJJhtQDygAAABQ"]
[Mon Jul 20 06:17:34.109885 2026] [security2:error] [pid 874439:tid 874596] [client 82.102.18.116:53900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4R3o6ZSrFvCrJJhtQD0gAAABs"]
[Mon Jul 20 06:17:34.434206 2026] [security2:error] [pid 871012:tid 871263] [client 82.102.18.116:53906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4R3rwiU-Jh5ncAILFnGwAAAYI"]
[Mon Jul 20 06:17:34.560026 2026] [security2:error] [pid 874439:tid 874630] [client 14.225.17.146:64476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4R3o6ZSrFvCrJJhtQD0wAAAD0"], referer: http://adastra.love/wp
[Mon Jul 20 06:17:34.585332 2026] [security2:error] [pid 871012:tid 871155] [client 104.234.53.89:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4R3rwiU-Jh5ncAILFnIQAAARY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:34.746568 2026] [security2:error] [pid 874439:tid 874611] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3o6ZSrFvCrJJhtQD2AAAKko"], referer: https://guidehunting.com/.ssh/config
[Mon Jul 20 06:17:34.748561 2026] [security2:error] [pid 874439:tid 874611] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3o6ZSrFvCrJJhtQD2QAAKkI"], referer: https://guidehunting.com/.ssh/authorized_keys
[Mon Jul 20 06:17:34.750528 2026] [security2:error] [pid 871012:tid 871261] [client 82.102.18.116:53920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4R3rwiU-Jh5ncAILFnJQAAAYA"]
[Mon Jul 20 06:17:34.864258 2026] [security2:error] [pid 871012:tid 871225] [client 14.225.17.146:58664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4R3bwiU-Jh5ncAILFm5wAAAVw"], referer: http://bigwormfishing.com/wp
[Mon Jul 20 06:17:34.984938 2026] [security2:error] [pid 871012:tid 871170] [client 57.141.18.67:63220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFmIgABJRI"]
[Mon Jul 20 06:17:35.099913 2026] [security2:error] [pid 874439:tid 874575] [client 82.102.18.116:53926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4R346ZSrFvCrJJhtQEBAAAAAY"]
[Mon Jul 20 06:17:35.397126 2026] [security2:error] [pid 874439:tid 874599] [client 185.132.186.103:42175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/admin-footer.php"] [unique_id "al4R346ZSrFvCrJJhtQEJgAAAB4"]
[Mon Jul 20 06:17:35.429905 2026] [security2:error] [pid 874439:tid 874604] [client 57.141.18.30:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCcgAAI18"]
[Mon Jul 20 06:17:35.445186 2026] [security2:error] [pid 874439:tid 874660] [client 14.225.17.146:49762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDuQAAAFs"], referer: http://ccsdifference.com/wp
[Mon Jul 20 06:17:35.455344 2026] [security2:error] [pid 874439:tid 874648] [client 82.102.18.116:53938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4R346ZSrFvCrJJhtQEKwAAAE8"]
[Mon Jul 20 06:17:35.775432 2026] [security2:error] [pid 871012:tid 871214] [client 82.102.18.116:15653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4R37wiU-Jh5ncAILFnPwAAAVE"]
[Mon Jul 20 06:17:35.877098 2026] [security2:error] [pid 871012:tid 871167] [client 57.141.18.10:54542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmXAABIn8"]
[Mon Jul 20 06:17:35.925351 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:52886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4R346ZSrFvCrJJhtQEPQAAAEM"], referer: https://bigwormfishing.com/wp
[Mon Jul 20 06:17:36.090562 2026] [security2:error] [pid 871012:tid 871254] [client 82.102.18.116:53942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4R4LwiU-Jh5ncAILFnRQAAAXk"]
[Mon Jul 20 06:17:36.201558 2026] [security2:error] [pid 874439:tid 874592] [client 77.110.127.138:59396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4R4I6ZSrFvCrJJhtQEYwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:36.244453 2026] [security2:error] [pid 871012:tid 871083] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/key.pem"] [unique_id "al4R4LwiU-Jh5ncAILFnSAABc0U"]
[Mon Jul 20 06:17:36.244621 2026] [security2:error] [pid 871012:tid 871248] [client 35.245.65.174:33432] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/key.pem"] [unique_id "al4R4LwiU-Jh5ncAILFnSAABc0U"]
[Mon Jul 20 06:17:36.263426 2026] [security2:error] [pid 871012:tid 871105] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/privatekey.key"] [unique_id "al4R4LwiU-Jh5ncAILFnSQABdls"]
[Mon Jul 20 06:17:36.299620 2026] [security2:error] [pid 871012:tid 871096] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/id_rsa"] [unique_id "al4R4LwiU-Jh5ncAILFnSwABGFI"]
[Mon Jul 20 06:17:36.299789 2026] [security2:error] [pid 871012:tid 871048] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/id_dsa"] [unique_id "al4R4LwiU-Jh5ncAILFnSgABGCI"]
[Mon Jul 20 06:17:36.400356 2026] [security2:error] [pid 874439:tid 874596] [client 82.102.18.116:53954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4R4I6ZSrFvCrJJhtQEhQAAABs"]
[Mon Jul 20 06:17:36.604203 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTAABGDE"]
[Mon Jul 20 06:17:36.604374 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTwABGHQ"]
[Mon Jul 20 06:17:36.604632 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnUAABGAY"]
[Mon Jul 20 06:17:36.604734 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTQABGGQ"]
[Mon Jul 20 06:17:36.604908 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTgABGCk"]
[Mon Jul 20 06:17:36.625413 2026] [security2:error] [pid 874439:tid 874692] [client 57.141.18.75:36682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCqgAAe2w"]
[Mon Jul 20 06:17:36.666576 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:53273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4R4I6ZSrFvCrJJhtQEhwAAAE4"], referer: https://ccsdifference.com/wp
[Mon Jul 20 06:17:37.202166 2026] [security2:error] [pid 874439:tid 874587] [client 185.132.186.86:49509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/firewall.php7"] [unique_id "al4R4Y6ZSrFvCrJJhtQEsQAAABI"]
[Mon Jul 20 06:17:37.472847 2026] [security2:error] [pid 871012:tid 871152] [client 57.141.18.8:58030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2rwiU-Jh5ncAILFmpAABExc"]
[Mon Jul 20 06:17:37.542644 2026] [security2:error] [pid 874439:tid 874536] [remote 47.86.33.52:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQEygAAMmA"]
[Mon Jul 20 06:17:37.906031 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQE4QAAAE8"]
[Mon Jul 20 06:17:37.906172 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQE4QAAAE8"]
[Mon Jul 20 06:17:38.031073 2026] [security2:error] [pid 874439:tid 874684] [client 44.240.37.43:60258] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQE2AAAAEU"]
[Mon Jul 20 06:17:38.043069 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE6AAAAFw"]
[Mon Jul 20 06:17:38.043175 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE6AAAAFw"]
[Mon Jul 20 06:17:38.112980 2026] [security2:error] [pid 871012:tid 871110] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFnfgABZWA"]
[Mon Jul 20 06:17:38.113787 2026] [security2:error] [pid 871012:tid 871234] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFnfgABZWA"]
[Mon Jul 20 06:17:38.227599 2026] [security2:error] [pid 874439:tid 874654] [client 50.116.65.227:19360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4R4o6ZSrFvCrJJhtQE8wAAAFU"]
[Mon Jul 20 06:17:38.241368 2026] [security2:error] [pid 874439:tid 874599] [client 50.116.65.227:34304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4R4o6ZSrFvCrJJhtQE9AAAAB4"]
[Mon Jul 20 06:17:38.286340 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:6582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sql.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE9gAAAHc"]
[Mon Jul 20 06:17:38.286437 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:6582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sql.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE9gAAAHc"]
[Mon Jul 20 06:17:38.519433 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFBwAAACw"]
[Mon Jul 20 06:17:38.519560 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFBwAAACw"]
[Mon Jul 20 06:17:38.639687 2026] [security2:error] [pid 874439:tid 874623] [client 20.63.63.128:7023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reop1.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFDAAAADY"]
[Mon Jul 20 06:17:38.639866 2026] [security2:error] [pid 874439:tid 874623] [client 20.63.63.128:7023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reop1.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFDAAAADY"]
[Mon Jul 20 06:17:38.681013 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:55411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQErgAAAHY"], referer: http://tntcatholic.com/wp
[Mon Jul 20 06:17:38.756419 2026] [security2:error] [pid 871012:tid 871249] [client 41.173.37.102:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFniwAAAXQ"]
[Mon Jul 20 06:17:38.756528 2026] [security2:error] [pid 871012:tid 871249] [client 41.173.37.102:4367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFniwAAAXQ"]
[Mon Jul 20 06:17:38.787185 2026] [security2:error] [pid 874439:tid 874685] [client 104.234.53.84:48487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFGQAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:38.809827 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:7022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj18.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFGgAAAGI"]
[Mon Jul 20 06:17:38.809951 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:7022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj18.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFGgAAAGI"]
[Mon Jul 20 06:17:38.813461 2026] [security2:error] [pid 874439:tid 874601] [client 34.211.13.134:48226] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFDwAAACA"]
[Mon Jul 20 06:17:38.967643 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj15.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFJAAAAE0"]
[Mon Jul 20 06:17:38.967743 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj15.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFJAAAAE0"]
[Mon Jul 20 06:17:38.998636 2026] [security2:error] [pid 874439:tid 874688] [client 185.132.186.92:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFKQAAAHc"]
[Mon Jul 20 06:17:39.072095 2026] [security2:error] [pid 874439:tid 874475] [remote 47.86.33.52:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R446ZSrFvCrJJhtQFLgAAayM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:39.109029 2026] [security2:error] [pid 874439:tid 874664] [client 20.63.63.128:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/rft8.php"] [unique_id "al4R446ZSrFvCrJJhtQFMwAAAF8"]
[Mon Jul 20 06:17:39.109123 2026] [security2:error] [pid 874439:tid 874664] [client 20.63.63.128:6584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/rft8.php"] [unique_id "al4R446ZSrFvCrJJhtQFMwAAAF8"]
[Mon Jul 20 06:17:39.230689 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ai.php"] [unique_id "al4R47wiU-Jh5ncAILFnlAAAAXc"]
[Mon Jul 20 06:17:39.230796 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ai.php"] [unique_id "al4R47wiU-Jh5ncAILFnlAAAAXc"]
[Mon Jul 20 06:17:39.350394 2026] [security2:error] [pid 874439:tid 874662] [client 57.141.18.51:50456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDbQAAXQk"]
[Mon Jul 20 06:17:39.406577 2026] [security2:error] [pid 871012:tid 871193] [client 20.63.63.128:6557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-rdf.php"] [unique_id "al4R47wiU-Jh5ncAILFnmAAAATw"]
[Mon Jul 20 06:17:39.406732 2026] [security2:error] [pid 871012:tid 871193] [client 20.63.63.128:6557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-rdf.php"] [unique_id "al4R47wiU-Jh5ncAILFnmAAAATw"]
[Mon Jul 20 06:17:39.566263 2026] [security2:error] [pid 871012:tid 871229] [client 20.63.63.128:6581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fx.php"] [unique_id "al4R47wiU-Jh5ncAILFnngAAAWA"]
[Mon Jul 20 06:17:39.566379 2026] [security2:error] [pid 871012:tid 871229] [client 20.63.63.128:6581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fx.php"] [unique_id "al4R47wiU-Jh5ncAILFnngAAAWA"]
[Mon Jul 20 06:17:39.693429 2026] [security2:error] [pid 874439:tid 874578] [client 171.60.139.123:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R446ZSrFvCrJJhtQFUgAAAAk"]
[Mon Jul 20 06:17:39.693565 2026] [security2:error] [pid 874439:tid 874578] [client 171.60.139.123:64704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R446ZSrFvCrJJhtQFUgAAAAk"]
[Mon Jul 20 06:17:39.728732 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R446ZSrFvCrJJhtQFVwAAAD0"]
[Mon Jul 20 06:17:39.728841 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R446ZSrFvCrJJhtQFVwAAAD0"]
[Mon Jul 20 06:17:39.901224 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:7002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dropdown.php"] [unique_id "al4R47wiU-Jh5ncAILFnpQAAAUg"]
[Mon Jul 20 06:17:39.901331 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:7002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dropdown.php"] [unique_id "al4R47wiU-Jh5ncAILFnpQAAAUg"]
[Mon Jul 20 06:17:39.905743 2026] [security2:error] [pid 874439:tid 874563] [remote 152.228.213.32:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4R446ZSrFvCrJJhtQFYgAAYXs"]
[Mon Jul 20 06:17:40.096787 2026] [security2:error] [pid 874439:tid 874493] [remote 152.228.213.32:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFagAAMzU"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:17:40.115487 2026] [security2:error] [pid 874439:tid 874632] [client 20.63.63.128:6990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file11.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFbgAAAD8"]
[Mon Jul 20 06:17:40.115570 2026] [security2:error] [pid 874439:tid 874632] [client 20.63.63.128:6990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file11.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFbgAAAD8"]
[Mon Jul 20 06:17:40.173656 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:55537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFFAAAAG0"], referer: http://inspirespublishing.com/wp
[Mon Jul 20 06:17:40.245255 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:7000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/png.php"] [unique_id "al4R5LwiU-Jh5ncAILFnqwAAAT0"]
[Mon Jul 20 06:17:40.245368 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:7000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/png.php"] [unique_id "al4R5LwiU-Jh5ncAILFnqwAAAT0"]
[Mon Jul 20 06:17:40.274879 2026] [security2:error] [pid 871012:tid 871180] [client 35.236.255.199:60503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.255.236.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "redneckrising.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnrQAAAS8"]
[Mon Jul 20 06:17:40.275027 2026] [security2:error] [pid 871012:tid 871180] [client 35.236.255.199:60503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "redneckrising.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnrQAAAS8"]
[Mon Jul 20 06:17:40.399010 2026] [security2:error] [pid 871012:tid 871122] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/graphql"] [unique_id "al4R5LwiU-Jh5ncAILFntAABTmw"]
[Mon Jul 20 06:17:40.421893 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-slss.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFggAAAD0"]
[Mon Jul 20 06:17:40.422015 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-slss.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFggAAAD0"]
[Mon Jul 20 06:17:40.452165 2026] [security2:error] [pid 874439:tid 874674] [client 57.141.18.87:42386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDpgAAaUE"]
[Mon Jul 20 06:17:40.467177 2026] [security2:error] [pid 871012:tid 871129] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/.openclaw/openclaw.json"] [unique_id "al4R5LwiU-Jh5ncAILFnvAABNnM"]
[Mon Jul 20 06:17:40.467346 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33432] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/.openclaw/openclaw.json"] [unique_id "al4R5LwiU-Jh5ncAILFnvAABNnM"]
[Mon Jul 20 06:17:40.468695 2026] [security2:error] [pid 871012:tid 871031] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.openclaw/.env"] [unique_id "al4R5LwiU-Jh5ncAILFnvQABNhE"]
[Mon Jul 20 06:17:40.605293 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ah25.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFkgAAAF4"]
[Mon Jul 20 06:17:40.605453 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:6984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ah25.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFkgAAAF4"]
[Mon Jul 20 06:17:40.695407 2026] [security2:error] [pid 871012:tid 871167] [client 45.116.69.230:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnyAAAASI"]
[Mon Jul 20 06:17:40.695561 2026] [security2:error] [pid 871012:tid 871167] [client 45.116.69.230:56100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnyAAAASI"]
[Mon Jul 20 06:17:40.734607 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ccou.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFmwAAAEI"]
[Mon Jul 20 06:17:40.734775 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:6546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ccou.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFmwAAAEI"]
[Mon Jul 20 06:17:40.742050 2026] [security2:error] [pid 871012:tid 871057] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFntwABNis"]
[Mon Jul 20 06:17:40.787104 2026] [security2:error] [pid 871012:tid 871186] [client 103.141.108.143:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnygAAATU"]
[Mon Jul 20 06:17:40.787201 2026] [security2:error] [pid 871012:tid 871186] [client 103.141.108.143:58372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnygAAATU"]
[Mon Jul 20 06:17:40.799245 2026] [security2:error] [pid 874439:tid 874620] [client 185.132.186.76:64513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/about.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFnQAAADM"]
[Mon Jul 20 06:17:40.857613 2026] [security2:error] [pid 871012:tid 871224] [client 20.63.63.128:7011] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1.php"] [unique_id "al4R5LwiU-Jh5ncAILFnzwAAAVs"]
[Mon Jul 20 06:17:40.857785 2026] [security2:error] [pid 871012:tid 871224] [client 20.63.63.128:7011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1.php"] [unique_id "al4R5LwiU-Jh5ncAILFnzwAAAVs"]
[Mon Jul 20 06:17:40.857920 2026] [security2:error] [pid 871012:tid 871224] [client 20.63.63.128:7011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1.php"] [unique_id "al4R5LwiU-Jh5ncAILFnzwAAAVs"]
[Mon Jul 20 06:17:40.877395 2026] [security2:error] [pid 874439:tid 874648] [client 14.225.17.146:60130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4R446ZSrFvCrJJhtQFTQAAAE8"], referer: http://cloudspacesgroup.com/wp
[Mon Jul 20 06:17:41.064630 2026] [security2:error] [pid 871012:tid 871173] [client 20.63.63.128:7003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/900.php"] [unique_id "al4R5bwiU-Jh5ncAILFn1AAAASg"]
[Mon Jul 20 06:17:41.064741 2026] [security2:error] [pid 871012:tid 871173] [client 20.63.63.128:7003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/900.php"] [unique_id "al4R5bwiU-Jh5ncAILFn1AAAASg"]
[Mon Jul 20 06:17:41.124824 2026] [security2:error] [pid 871012:tid 871066] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnuAABNjQ"]
[Mon Jul 20 06:17:41.126308 2026] [security2:error] [pid 871012:tid 871117] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnuQABNmc"]
[Mon Jul 20 06:17:41.171015 2026] [security2:error] [pid 871012:tid 871081] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnvgABNkM"]
[Mon Jul 20 06:17:41.173087 2026] [security2:error] [pid 874439:tid 874495] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhgAADjc"], referer: https://guidehunting.com/.ssh/known_hosts
[Mon Jul 20 06:17:41.177365 2026] [security2:error] [pid 874439:tid 874532] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhQAADlw"], referer: https://guidehunting.com/private-key
[Mon Jul 20 06:17:41.177409 2026] [security2:error] [pid 874439:tid 874458] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhAAADhI"], referer: https://guidehunting.com/server.key
[Mon Jul 20 06:17:41.177864 2026] [security2:error] [pid 874439:tid 874549] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFgwAADm0"], referer: https://guidehunting.com/id_ed25519
[Mon Jul 20 06:17:41.186454 2026] [security2:error] [pid 871012:tid 871042] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnuwABNhw"]
[Mon Jul 20 06:17:41.188429 2026] [security2:error] [pid 874439:tid 874503] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhwAADj8"], referer: https://guidehunting.com/id_ecdsa
[Mon Jul 20 06:17:41.198153 2026] [security2:error] [pid 874439:tid 874624] [client 20.63.63.128:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file59.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFsQAAADc"]
[Mon Jul 20 06:17:41.198255 2026] [security2:error] [pid 874439:tid 874624] [client 20.63.63.128:60994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file59.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFsQAAADc"]
[Mon Jul 20 06:17:41.302108 2026] [security2:error] [pid 871012:tid 871052] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnxAABKSY"]
[Mon Jul 20 06:17:41.302149 2026] [security2:error] [pid 871012:tid 871054] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnxgABKSg"]
[Mon Jul 20 06:17:41.302242 2026] [security2:error] [pid 871012:tid 871050] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnxQABKSQ"]
[Mon Jul 20 06:17:41.420491 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amxloxxr.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFtgAAAHI"]
[Mon Jul 20 06:17:41.420613 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amxloxxr.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFtgAAAHI"]
[Mon Jul 20 06:17:41.560095 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:7012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aboutc.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFwAAAAEI"]
[Mon Jul 20 06:17:41.560211 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:7012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aboutc.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFwAAAAEI"]
[Mon Jul 20 06:17:41.727181 2026] [security2:error] [pid 874439:tid 874593] [client 104.234.53.87:56257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFwgAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:41.758949 2026] [security2:error] [pid 871012:tid 871158] [client 168.144.100.227:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.100.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/xmlrpc.php"] [unique_id "al4R5bwiU-Jh5ncAILFn6QAAARk"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:41.794221 2026] [security2:error] [pid 874439:tid 874638] [client 20.63.63.128:6580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless18.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFywAAAEU"]
[Mon Jul 20 06:17:41.794323 2026] [security2:error] [pid 874439:tid 874638] [client 20.63.63.128:6580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless18.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFywAAAEU"]
[Mon Jul 20 06:17:41.911388 2026] [security2:error] [pid 874439:tid 874602] [client 158.173.166.181:28055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQF1AAAACE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:41.951358 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5AABGnA"]
[Mon Jul 20 06:17:41.954621 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn4wABGjg"]
[Mon Jul 20 06:17:41.970467 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5QABGkc"]
[Mon Jul 20 06:17:41.990231 2026] [security2:error] [pid 871012:tid 871144] [client 20.63.63.128:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/crgio.php"] [unique_id "al4R5bwiU-Jh5ncAILFn8wAAAQs"]
[Mon Jul 20 06:17:41.990331 2026] [security2:error] [pid 871012:tid 871144] [client 20.63.63.128:6544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/crgio.php"] [unique_id "al4R5bwiU-Jh5ncAILFn8wAAAQs"]
[Mon Jul 20 06:17:41.996363 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5gABGjM"]
[Mon Jul 20 06:17:41.996698 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5wABGmE"]
[Mon Jul 20 06:17:42.039445 2026] [security2:error] [pid 871012:tid 871080] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFn9gABQUI"]
[Mon Jul 20 06:17:42.039582 2026] [security2:error] [pid 871012:tid 871198] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFn9gABQUI"]
[Mon Jul 20 06:17:42.052489 2026] [security2:error] [pid 871012:tid 871088] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/api/graphql"] [unique_id "al4R5rwiU-Jh5ncAILFn9wABQEo"]
[Mon Jul 20 06:17:42.108511 2026] [security2:error] [pid 874439:tid 874576] [client 104.234.53.87:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF2gAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:42.138122 2026] [security2:error] [pid 871012:tid 871248] [client 20.63.63.128:7036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-act.php"] [unique_id "al4R5rwiU-Jh5ncAILFn-wAAAXM"]
[Mon Jul 20 06:17:42.138238 2026] [security2:error] [pid 871012:tid 871248] [client 20.63.63.128:7036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-act.php"] [unique_id "al4R5rwiU-Jh5ncAILFn-wAAAXM"]
[Mon Jul 20 06:17:42.254787 2026] [security2:error] [pid 874439:tid 874595] [client 103.203.57.3:58758] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.65.228"] [uri "/index.cgi"] [unique_id "al4R5o6ZSrFvCrJJhtQF6QAAABo"]
[Mon Jul 20 06:17:42.312972 2026] [security2:error] [pid 871012:tid 871211] [client 65.1.132.125:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoAQAAAU4"]
[Mon Jul 20 06:17:42.313104 2026] [security2:error] [pid 871012:tid 871211] [client 65.1.132.125:33976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoAQAAAU4"]
[Mon Jul 20 06:17:42.399170 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new4.php"] [unique_id "al4R5rwiU-Jh5ncAILFoDQAAAR8"]
[Mon Jul 20 06:17:42.399293 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new4.php"] [unique_id "al4R5rwiU-Jh5ncAILFoDQAAAR8"]
[Mon Jul 20 06:17:42.478410 2026] [security2:error] [pid 874439:tid 874665] [client 178.152.178.232:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF8QAAAGA"]
[Mon Jul 20 06:17:42.478542 2026] [security2:error] [pid 874439:tid 874665] [client 178.152.178.232:36711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF8QAAAGA"]
[Mon Jul 20 06:17:42.502382 2026] [security2:error] [pid 874439:tid 874643] [client 57.141.18.101:21984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R346ZSrFvCrJJhtQECgAASn4"]
[Mon Jul 20 06:17:42.594243 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-the.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF9AAAAE8"]
[Mon Jul 20 06:17:42.594359 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-the.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF9AAAAE8"]
[Mon Jul 20 06:17:42.597578 2026] [security2:error] [pid 871012:tid 871155] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5rwiU-Jh5ncAILFoAwABFn0"]
[Mon Jul 20 06:17:42.611998 2026] [security2:error] [pid 871012:tid 871152] [client 185.132.186.104:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/file/incpb.php"] [unique_id "al4R5rwiU-Jh5ncAILFoEQAAARM"]
[Mon Jul 20 06:17:42.658011 2026] [security2:error] [pid 871012:tid 871016] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/v1/graphql"] [unique_id "al4R5rwiU-Jh5ncAILFoFQABOQI"]
[Mon Jul 20 06:17:42.736348 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atkno.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGAgAAAB0"]
[Mon Jul 20 06:17:42.736450 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atkno.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGAgAAAB0"]
[Mon Jul 20 06:17:42.762140 2026] [security2:error] [pid 871012:tid 871169] [client 103.77.203.233:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoGgAAASQ"]
[Mon Jul 20 06:17:42.762268 2026] [security2:error] [pid 871012:tid 871169] [client 103.77.203.233:52127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoGgAAASQ"]
[Mon Jul 20 06:17:42.821995 2026] [security2:error] [pid 874439:tid 874614] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF7AAALUQ"], referer: http://ardhalwafaa.com/wp
[Mon Jul 20 06:17:42.882827 2026] [security2:error] [pid 871012:tid 871178] [client 57.141.18.70:20798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R37wiU-Jh5ncAILFnPAABLWo"]
[Mon Jul 20 06:17:42.893527 2026] [security2:error] [pid 874439:tid 874578] [client 20.63.63.128:6530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mass.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDAAAAAk"]
[Mon Jul 20 06:17:42.893661 2026] [security2:error] [pid 874439:tid 874578] [client 20.63.63.128:6530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mass.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDAAAAAk"]
[Mon Jul 20 06:17:42.896132 2026] [security2:error] [pid 871012:tid 871086] [remote 57.141.18.57:27214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4R5rwiU-Jh5ncAILFoHwABRkg"]
[Mon Jul 20 06:17:42.939862 2026] [security2:error] [pid 874439:tid 874561] [remote 192.241.143.148:49192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDwAASHk"]
[Mon Jul 20 06:17:42.940046 2026] [security2:error] [pid 874439:tid 874641] [client 192.241.143.148:49192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDwAASHk"]
[Mon Jul 20 06:17:42.950767 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF-gAAVWo"], referer: https://guidehunting.com/webpack-stats.json
[Mon Jul 20 06:17:42.950968 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF-wAAVW4"], referer: https://guidehunting.com/_next/static/buildManifest.js
[Mon Jul 20 06:17:42.952230 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF-QAAVXQ"], referer: https://guidehunting.com/asset-manifest.json
[Mon Jul 20 06:17:42.969187 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF_gAAVQc"], referer: https://guidehunting.com/manifest.json
[Mon Jul 20 06:17:42.973574 2026] [security2:error] [pid 874439:tid 874577] [client 57.141.18.0:31142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R346ZSrFvCrJJhtQENgAACGE"]
[Mon Jul 20 06:17:42.984370 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF_QAAVUo"], referer: https://guidehunting.com/build-manifest.json
[Mon Jul 20 06:17:43.097307 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wefile.php"] [unique_id "al4R546ZSrFvCrJJhtQGFAAAAEY"]
[Mon Jul 20 06:17:43.097423 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wefile.php"] [unique_id "al4R546ZSrFvCrJJhtQGFAAAAEY"]
[Mon Jul 20 06:17:43.228918 2026] [security2:error] [pid 874439:tid 874582] [client 20.63.63.128:6574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/min.php"] [unique_id "al4R546ZSrFvCrJJhtQGGAAAAA0"]
[Mon Jul 20 06:17:43.229028 2026] [security2:error] [pid 874439:tid 874582] [client 20.63.63.128:6574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/min.php"] [unique_id "al4R546ZSrFvCrJJhtQGGAAAAA0"]
[Mon Jul 20 06:17:43.389069 2026] [security2:error] [pid 874439:tid 874586] [client 20.63.63.128:6550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sid3.php"] [unique_id "al4R546ZSrFvCrJJhtQGIQAAABE"]
[Mon Jul 20 06:17:43.389154 2026] [security2:error] [pid 874439:tid 874586] [client 20.63.63.128:6550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sid3.php"] [unique_id "al4R546ZSrFvCrJJhtQGIQAAABE"]
[Mon Jul 20 06:17:43.523357 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fileas.php"] [unique_id "al4R546ZSrFvCrJJhtQGJgAAACw"]
[Mon Jul 20 06:17:43.523465 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fileas.php"] [unique_id "al4R546ZSrFvCrJJhtQGJgAAACw"]
[Mon Jul 20 06:17:43.660905 2026] [security2:error] [pid 874439:tid 874657] [client 20.63.63.128:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless24.php"] [unique_id "al4R546ZSrFvCrJJhtQGLAAAAFg"]
[Mon Jul 20 06:17:43.661007 2026] [security2:error] [pid 874439:tid 874657] [client 20.63.63.128:7016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless24.php"] [unique_id "al4R546ZSrFvCrJJhtQGLAAAAFg"]
[Mon Jul 20 06:17:43.864274 2026] [security2:error] [pid 874439:tid 874629] [client 20.63.63.128:7018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fun.php"] [unique_id "al4R546ZSrFvCrJJhtQGOQAAADw"]
[Mon Jul 20 06:17:43.864390 2026] [security2:error] [pid 874439:tid 874629] [client 20.63.63.128:7018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fun.php"] [unique_id "al4R546ZSrFvCrJJhtQGOQAAADw"]
[Mon Jul 20 06:17:44.002009 2026] [security2:error] [pid 871012:tid 871208] [client 104.234.53.49:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4R6LwiU-Jh5ncAILFoOQAAAUs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:44.021579 2026] [security2:error] [pid 874439:tid 874628] [client 57.141.18.22:47002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R4I6ZSrFvCrJJhtQEowAAO1o"]
[Mon Jul 20 06:17:44.026730 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/drykl.php"] [unique_id "al4R6LwiU-Jh5ncAILFoOwAAAXc"]
[Mon Jul 20 06:17:44.026871 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/drykl.php"] [unique_id "al4R6LwiU-Jh5ncAILFoOwAAAXc"]
[Mon Jul 20 06:17:44.106099 2026] [security2:error] [pid 874439:tid 874677] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R546ZSrFvCrJJhtQGMwAAbEM"], referer: https://guidehunting.com/_next/build-manifest.json
[Mon Jul 20 06:17:44.161439 2026] [security2:error] [pid 874439:tid 874603] [client 20.63.63.128:6539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGSwAAACI"]
[Mon Jul 20 06:17:44.161528 2026] [security2:error] [pid 874439:tid 874603] [client 20.63.63.128:6539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGSwAAACI"]
[Mon Jul 20 06:17:44.341323 2026] [security2:error] [pid 871012:tid 871172] [client 20.63.63.128:6233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mifta.php"] [unique_id "al4R6LwiU-Jh5ncAILFoRAAAASc"]
[Mon Jul 20 06:17:44.341440 2026] [security2:error] [pid 871012:tid 871172] [client 20.63.63.128:6233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mifta.php"] [unique_id "al4R6LwiU-Jh5ncAILFoRAAAASc"]
[Mon Jul 20 06:17:44.383195 2026] [security2:error] [pid 871012:tid 871267] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R6LwiU-Jh5ncAILFoPwABhmI"]
[Mon Jul 20 06:17:44.409892 2026] [security2:error] [pid 874439:tid 874616] [client 185.132.186.71:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/stories/themes.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGUwAAAC8"]
[Mon Jul 20 06:17:44.542540 2026] [security2:error] [pid 871012:tid 871257] [client 20.63.63.128:7017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/class-t.api.php"] [unique_id "al4R6LwiU-Jh5ncAILFoSgAAAXw"]
[Mon Jul 20 06:17:44.542644 2026] [security2:error] [pid 871012:tid 871257] [client 20.63.63.128:7017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/class-t.api.php"] [unique_id "al4R6LwiU-Jh5ncAILFoSgAAAXw"]
[Mon Jul 20 06:17:44.613986 2026] [security2:error] [pid 874439:tid 874621] [client 181.224.94.124:9333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGXAAAADQ"]
[Mon Jul 20 06:17:44.614179 2026] [security2:error] [pid 874439:tid 874621] [client 181.224.94.124:9333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGXAAAADQ"]
[Mon Jul 20 06:17:44.678561 2026] [security2:error] [pid 874439:tid 874579] [client 20.63.63.128:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vgtyu.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGYQAAAAo"]
[Mon Jul 20 06:17:44.678705 2026] [security2:error] [pid 874439:tid 874579] [client 20.63.63.128:7021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vgtyu.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGYQAAAAo"]
[Mon Jul 20 06:17:44.702257 2026] [security2:error] [pid 871012:tid 871175] [client 57.141.18.99:46816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R4bwiU-Jh5ncAILFndwABKgQ"]
[Mon Jul 20 06:17:44.935647 2026] [security2:error] [pid 871012:tid 871163] [client 20.63.63.128:6209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atomlib.php"] [unique_id "al4R6LwiU-Jh5ncAILFoVwAAAR4"]
[Mon Jul 20 06:17:44.935778 2026] [security2:error] [pid 871012:tid 871163] [client 20.63.63.128:6209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atomlib.php"] [unique_id "al4R6LwiU-Jh5ncAILFoVwAAAR4"]
[Mon Jul 20 06:17:45.018717 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:63651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGWgAAABc"], referer: http://uritems.net/wp
[Mon Jul 20 06:17:45.054931 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.055012 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.9:61204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.055659 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.055690 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.9:61204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.060421 2026] [security2:error] [pid 874439:tid 874593] [client 20.63.63.128:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-access.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGdQAAABg"]
[Mon Jul 20 06:17:45.060532 2026] [security2:error] [pid 874439:tid 874593] [client 20.63.63.128:6590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-access.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGdQAAABg"]
[Mon Jul 20 06:17:45.069237 2026] [proxy:error] [pid 874439:tid 874600] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.069282 2026] [proxy_http:error] [pid 874439:tid 874600] [client 205.210.31.9:61220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.069811 2026] [proxy:error] [pid 874439:tid 874600] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.069835 2026] [proxy_http:error] [pid 874439:tid 874600] [client 205.210.31.9:61220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.235432 2026] [security2:error] [pid 874439:tid 874665] [client 20.63.63.128:6573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-update.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGhAAAAGA"]
[Mon Jul 20 06:17:45.235530 2026] [security2:error] [pid 874439:tid 874665] [client 20.63.63.128:6573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-update.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGhAAAAGA"]
[Mon Jul 20 06:17:45.239970 2026] [core:error] [pid 874439:tid 874651] [client 14.225.17.146:63738] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:45.239984 2026] [core:error] [pid 874439:tid 874651] [client 14.225.17.146:63738] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:45.315741 2026] [security2:error] [pid 874439:tid 874599] [client 77.110.127.138:59448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4R6Y6ZSrFvCrJJhtQGiwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:45.419170 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/erty.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGjgAAAEY"]
[Mon Jul 20 06:17:45.419264 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/erty.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGjgAAAEY"]
[Mon Jul 20 06:17:45.602382 2026] [security2:error] [pid 871012:tid 871150] [client 20.63.63.128:6222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R6bwiU-Jh5ncAILFoagAAARE"]
[Mon Jul 20 06:17:45.602524 2026] [security2:error] [pid 871012:tid 871150] [client 20.63.63.128:6222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R6bwiU-Jh5ncAILFoagAAARE"]
[Mon Jul 20 06:17:45.688108 2026] [security2:error] [pid 874439:tid 874573] [client 14.225.17.146:63746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGnQAAAAQ"], referer: http://xp-design.co/wp
[Mon Jul 20 06:17:45.690067 2026] [security2:error] [pid 874439:tid 874629] [client 14.225.17.146:56744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGpgAAADw"], referer: http://walkingandtalking.net/wp
[Mon Jul 20 06:17:45.722572 2026] [security2:error] [pid 871012:tid 871248] [client 14.225.17.146:56801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4R6bwiU-Jh5ncAILFoaAAAAXM"], referer: http://slutilities.com/wp
[Mon Jul 20 06:17:45.760635 2026] [security2:error] [pid 874439:tid 874694] [client 20.63.63.128:6997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGsgAAAH0"]
[Mon Jul 20 06:17:45.760740 2026] [security2:error] [pid 874439:tid 874694] [client 20.63.63.128:6997] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGsgAAAH0"]
[Mon Jul 20 06:17:45.805658 2026] [security2:error] [pid 874439:tid 874660] [client 57.141.18.22:47014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R446ZSrFvCrJJhtQFKwAAW1E"]
[Mon Jul 20 06:17:45.982440 2026] [security2:error] [pid 871012:tid 871217] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4R6LwiU-Jh5ncAILFoSQAAAVQ"]
[Mon Jul 20 06:17:45.993675 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless5.php"] [unique_id "al4R6bwiU-Jh5ncAILFocQAAAR8"]
[Mon Jul 20 06:17:45.993843 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless5.php"] [unique_id "al4R6bwiU-Jh5ncAILFocQAAAR8"]
[Mon Jul 20 06:17:46.008908 2026] [security2:error] [pid 874439:tid 874608] [client 57.141.18.6:25192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R446ZSrFvCrJJhtQFOwAAJyY"]
[Mon Jul 20 06:17:46.166606 2026] [security2:error] [pid 874439:tid 874625] [client 20.63.63.128:6578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/t.php"] [unique_id "al4R6o6ZSrFvCrJJhtQGygAAADg"]
[Mon Jul 20 06:17:46.166723 2026] [security2:error] [pid 874439:tid 874625] [client 20.63.63.128:6578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/t.php"] [unique_id "al4R6o6ZSrFvCrJJhtQGygAAADg"]
[Mon Jul 20 06:17:46.200061 2026] [security2:error] [pid 874439:tid 874656] [client 185.132.186.72:42381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/theme-compat/footer-embed-function.php"] [unique_id "al4R6o6ZSrFvCrJJhtQGzQAAAFc"]
[Mon Jul 20 06:17:46.301104 2026] [security2:error] [pid 874439:tid 874525] [remote 81.173.115.7:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG0QAAB1U"]
[Mon Jul 20 06:17:46.361834 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:7009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xoot.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG0gAAAFw"]
[Mon Jul 20 06:17:46.361972 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:7009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xoot.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG0gAAAFw"]
[Mon Jul 20 06:17:46.522375 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:6260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xqq.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG3QAAABw"]
[Mon Jul 20 06:17:46.522514 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:6260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xqq.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG3QAAABw"]
[Mon Jul 20 06:17:46.558068 2026] [security2:error] [pid 871012:tid 871157] [client 14.225.17.146:56727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4R6rwiU-Jh5ncAILFofgAAARg"], referer: https://walkingandtalking.net/wp
[Mon Jul 20 06:17:46.590291 2026] [security2:error] [pid 874439:tid 874495] [remote 81.173.115.7:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG3wAADDc"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:17:46.686722 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-load.php"] [unique_id "al4R6rwiU-Jh5ncAILFohgAAAT4"]
[Mon Jul 20 06:17:46.686836 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-load.php"] [unique_id "al4R6rwiU-Jh5ncAILFohgAAAT4"]
[Mon Jul 20 06:17:46.690787 2026] [security2:error] [pid 871012:tid 871218] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R5rwiU-Jh5ncAILFoHgAAAVU"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:46.829813 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG7wAAAFc"]
[Mon Jul 20 06:17:46.829920 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:61018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG7wAAAFc"]
[Mon Jul 20 06:17:46.850537 2026] [security2:error] [pid 874439:tid 874645] [client 49.13.134.145:57758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG6AAAAEw"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:17:46.914121 2026] [security2:error] [pid 874439:tid 874594] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG4AAAGVw"], referer: https://guidehunting.com/ssilko3
[Mon Jul 20 06:17:46.985346 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/i.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG9QAAADM"]
[Mon Jul 20 06:17:46.985431 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:6554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/i.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG9QAAADM"]
[Mon Jul 20 06:17:47.129921 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:6534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms-edit.php"] [unique_id "al4R646ZSrFvCrJJhtQG_QAAAGo"]
[Mon Jul 20 06:17:47.130041 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:6534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms-edit.php"] [unique_id "al4R646ZSrFvCrJJhtQG_QAAAGo"]
[Mon Jul 20 06:17:47.264320 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/v2.php"] [unique_id "al4R646ZSrFvCrJJhtQHBwAAABI"]
[Mon Jul 20 06:17:47.264454 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/v2.php"] [unique_id "al4R646ZSrFvCrJJhtQHBwAAABI"]
[Mon Jul 20 06:17:47.330899 2026] [security2:error] [pid 874439:tid 874612] [client 57.141.18.35:28860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFpgAAKzA"]
[Mon Jul 20 06:17:47.397076 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new.php"] [unique_id "al4R646ZSrFvCrJJhtQHEQAAAGg"]
[Mon Jul 20 06:17:47.397174 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:6535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new.php"] [unique_id "al4R646ZSrFvCrJJhtQHEQAAAGg"]
[Mon Jul 20 06:17:47.428075 2026] [security2:error] [pid 871012:tid 871197] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R6rwiU-Jh5ncAILFokAAAAUA"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:47.483434 2026] [security2:error] [pid 874439:tid 874642] [client 50.116.65.227:20844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R646ZSrFvCrJJhtQHFQAAAEk"]
[Mon Jul 20 06:17:47.488307 2026] [security2:error] [pid 874439:tid 874687] [client 27.96.94.195:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R646ZSrFvCrJJhtQHFAAAAHY"]
[Mon Jul 20 06:17:47.488466 2026] [security2:error] [pid 874439:tid 874687] [client 27.96.94.195:37027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R646ZSrFvCrJJhtQHFAAAAHY"]
[Mon Jul 20 06:17:47.494974 2026] [security2:error] [pid 874439:tid 874595] [client 50.116.65.227:33054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R646ZSrFvCrJJhtQHFwAAABo"]
[Mon Jul 20 06:17:47.533818 2026] [security2:error] [pid 874439:tid 874684] [client 20.63.63.128:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/network/edit.php"] [unique_id "al4R646ZSrFvCrJJhtQHGgAAAHM"]
[Mon Jul 20 06:17:47.533947 2026] [security2:error] [pid 874439:tid 874684] [client 20.63.63.128:6558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/network/edit.php"] [unique_id "al4R646ZSrFvCrJJhtQHGgAAAHM"]
[Mon Jul 20 06:17:47.691662 2026] [security2:error] [pid 871012:tid 871247] [client 20.63.63.128:6562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pouhg.php"] [unique_id "al4R67wiU-Jh5ncAILFopQAAAXI"]
[Mon Jul 20 06:17:47.691785 2026] [security2:error] [pid 871012:tid 871247] [client 20.63.63.128:6562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pouhg.php"] [unique_id "al4R67wiU-Jh5ncAILFopQAAAXI"]
[Mon Jul 20 06:17:47.886300 2026] [security2:error] [pid 871012:tid 871216] [client 20.63.63.128:6537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/cilus.php"] [unique_id "al4R67wiU-Jh5ncAILFoqAAAAVM"]
[Mon Jul 20 06:17:47.886401 2026] [security2:error] [pid 871012:tid 871216] [client 20.63.63.128:6537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/cilus.php"] [unique_id "al4R67wiU-Jh5ncAILFoqAAAAVM"]
[Mon Jul 20 06:17:48.004535 2026] [security2:error] [pid 874439:tid 874676] [client 185.132.186.74:29587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/firewall.php7"] [unique_id "al4R7I6ZSrFvCrJJhtQHRAAAAGs"]
[Mon Jul 20 06:17:48.038348 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file4.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSAAAAB0"]
[Mon Jul 20 06:17:48.038437 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file4.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSAAAAB0"]
[Mon Jul 20 06:17:48.172877 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:7035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/samll.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSgAAAAs"]
[Mon Jul 20 06:17:48.172957 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:7035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/samll.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSgAAAAs"]
[Mon Jul 20 06:17:48.208694 2026] [security2:error] [pid 871012:tid 871164] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R67wiU-Jh5ncAILFopgAAAR8"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:48.225120 2026] [security2:error] [pid 871012:tid 871152] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R67wiU-Jh5ncAILFoqQABE0Q"]
[Mon Jul 20 06:17:48.322945 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/Okxob.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHTwAAAFU"]
[Mon Jul 20 06:17:48.323032 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/Okxob.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHTwAAAFU"]
[Mon Jul 20 06:17:48.392374 2026] [security2:error] [pid 871012:tid 871227] [client 34.85.238.37:53274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.238.85.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fjy.yvs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R7LwiU-Jh5ncAILFouwAAAV4"]
[Mon Jul 20 06:17:48.465800 2026] [security2:error] [pid 874439:tid 874609] [client 20.63.63.128:60993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ok.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHWAAAACg"]
[Mon Jul 20 06:17:48.465902 2026] [security2:error] [pid 874439:tid 874609] [client 20.63.63.128:60993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ok.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHWAAAACg"]
[Mon Jul 20 06:17:48.568075 2026] [security2:error] [pid 874439:tid 874603] [client 46.110.96.34:9303] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7I6ZSrFvCrJJhtQHWwAAACI"]
[Mon Jul 20 06:17:48.568937 2026] [security2:error] [pid 871012:tid 871195] [client 46.110.96.34:23648] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7LwiU-Jh5ncAILFovwAAAT4"]
[Mon Jul 20 06:17:48.568979 2026] [security2:error] [pid 874439:tid 874649] [client 46.110.96.34:42077] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7I6ZSrFvCrJJhtQHXAAAAFA"]
[Mon Jul 20 06:17:48.598872 2026] [security2:error] [pid 871012:tid 871241] [client 20.63.63.128:6231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wuasr.php"] [unique_id "al4R7LwiU-Jh5ncAILFowQAAAWw"]
[Mon Jul 20 06:17:48.598970 2026] [security2:error] [pid 871012:tid 871241] [client 20.63.63.128:6231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wuasr.php"] [unique_id "al4R7LwiU-Jh5ncAILFowQAAAWw"]
[Mon Jul 20 06:17:48.698000 2026] [security2:error] [pid 874439:tid 874556] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHZgAAQXQ"]
[Mon Jul 20 06:17:48.698163 2026] [security2:error] [pid 874439:tid 874634] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHZgAAQXQ"]
[Mon Jul 20 06:17:48.708700 2026] [security2:error] [pid 874439:tid 874608] [client 34.85.238.37:52096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4R7I6ZSrFvCrJJhtQHZwAAACc"]
[Mon Jul 20 06:17:48.780535 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:7014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless11.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHbgAAAAE"]
[Mon Jul 20 06:17:48.780633 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:7014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless11.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHbgAAAAE"]
[Mon Jul 20 06:17:48.845499 2026] [security2:error] [pid 871012:tid 871268] [client 104.234.53.63:41739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4R7LwiU-Jh5ncAILFoxAAAAYc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:48.962451 2026] [security2:error] [pid 874439:tid 874680] [client 34.85.238.37:60360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4R7I6ZSrFvCrJJhtQHewAAAG8"]
[Mon Jul 20 06:17:48.990371 2026] [security2:error] [pid 874439:tid 874616] [client 20.63.63.128:7020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-block.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHfgAAAC8"]
[Mon Jul 20 06:17:48.990528 2026] [security2:error] [pid 874439:tid 874616] [client 20.63.63.128:7020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-block.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHfgAAAC8"]
[Mon Jul 20 06:17:48.999989 2026] [security2:error] [pid 871012:tid 871237] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R7LwiU-Jh5ncAILFovQAAAWg"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:49.135254 2026] [security2:error] [pid 871012:tid 871207] [client 104.234.53.63:41739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R7bwiU-Jh5ncAILFozAAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:49.148150 2026] [security2:error] [pid 871012:tid 871228] [client 20.63.63.128:7032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aevly.php"] [unique_id "al4R7bwiU-Jh5ncAILFozgAAAV8"]
[Mon Jul 20 06:17:49.148259 2026] [security2:error] [pid 871012:tid 871228] [client 20.63.63.128:7032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aevly.php"] [unique_id "al4R7bwiU-Jh5ncAILFozgAAAV8"]
[Mon Jul 20 06:17:49.193695 2026] [security2:error] [pid 874439:tid 874604] [client 187.190.23.31:4610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHigAAI3g"]
[Mon Jul 20 06:17:49.201035 2026] [core:error] [pid 874439:tid 874596] [client 103.153.183.69:44022] AH10244: invalid URI path (/%2e./%2e./etc/passwd?_=oyuc8fnu&v=93r2e), referer: https://news.ycombinator.com/
[Mon Jul 20 06:17:49.202872 2026] [security2:error] [pid 874439:tid 874582] [client 127.0.0.1:44954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4R7Y6ZSrFvCrJJhtQHkQAAAA0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:17:49.281329 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hello.php"] [unique_id "al4R7bwiU-Jh5ncAILFo1QAAAT8"]
[Mon Jul 20 06:17:49.281436 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:6552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hello.php"] [unique_id "al4R7bwiU-Jh5ncAILFo1QAAAT8"]
[Mon Jul 20 06:17:49.346765 2026] [security2:error] [pid 874439:tid 874645] [client 41.173.37.102:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHnAAAAEw"]
[Mon Jul 20 06:17:49.346960 2026] [security2:error] [pid 874439:tid 874645] [client 41.173.37.102:4800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHnAAAAEw"]
[Mon Jul 20 06:17:49.374052 2026] [security2:error] [pid 874439:tid 874664] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHggAAXxs"], referer: https://guidehunting.com/ssilko4
[Mon Jul 20 06:17:49.412455 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-links-opml.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHogAAACk"]
[Mon Jul 20 06:17:49.412539 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:7015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-links-opml.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHogAAACk"]
[Mon Jul 20 06:17:49.415620 2026] [security2:error] [pid 871012:tid 871186] [client 34.85.238.37:64845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4R7bwiU-Jh5ncAILFo2gAAATU"]
[Mon Jul 20 06:17:49.418801 2026] [security2:error] [pid 874439:tid 874612] [client 46.110.96.34:63883] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7Y6ZSrFvCrJJhtQHpAAAACs"]
[Mon Jul 20 06:17:49.457126 2026] [security2:error] [pid 874439:tid 874647] [client 46.110.96.34:51113] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7Y6ZSrFvCrJJhtQHqQAAAE4"]
[Mon Jul 20 06:17:49.568696 2026] [security2:error] [pid 874439:tid 874677] [client 46.110.96.34:61756] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7Y6ZSrFvCrJJhtQHsAAAAGw"]
[Mon Jul 20 06:17:49.603294 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/forbidals.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHsQAAAFU"]
[Mon Jul 20 06:17:49.603391 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/forbidals.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHsQAAAFU"]
[Mon Jul 20 06:17:49.715145 2026] [security2:error] [pid 874439:tid 874595] [client 34.85.238.37:64307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4R7Y6ZSrFvCrJJhtQHuwAAABo"]
[Mon Jul 20 06:17:49.807153 2026] [security2:error] [pid 874439:tid 874655] [client 185.132.186.102:21201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/home/O-Simple.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHwgAAAFY"]
[Mon Jul 20 06:17:49.807156 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file30.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHwwAAADA"]
[Mon Jul 20 06:17:49.807247 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file30.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHwwAAADA"]
[Mon Jul 20 06:17:49.831285 2026] [security2:error] [pid 874439:tid 874531] [remote 5.161.225.162:57268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHxwAASFs"]
[Mon Jul 20 06:17:49.831421 2026] [security2:error] [pid 874439:tid 874641] [client 5.161.225.162:57268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHxwAASFs"]
[Mon Jul 20 06:17:49.965331 2026] [security2:error] [pid 874439:tid 874606] [client 20.63.63.128:6239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xda.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHzAAAACU"]
[Mon Jul 20 06:17:49.965463 2026] [security2:error] [pid 874439:tid 874606] [client 20.63.63.128:6239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xda.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHzAAAACU"]
[Mon Jul 20 06:17:50.051439 2026] [security2:error] [pid 874439:tid 874645] [client 34.85.238.37:56467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4R7o6ZSrFvCrJJhtQH2AAAAEw"]
[Mon Jul 20 06:17:50.081546 2026] [security2:error] [pid 874439:tid 874640] [client 14.225.17.146:64269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHdAAAAEc"], referer: http://keywayconstructionclt.com/wp
[Mon Jul 20 06:17:50.106510 2026] [security2:error] [pid 874439:tid 874671] [client 20.63.63.128:6566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/z.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH3AAAAGY"]
[Mon Jul 20 06:17:50.106646 2026] [security2:error] [pid 874439:tid 874671] [client 20.63.63.128:6566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/z.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH3AAAAGY"]
[Mon Jul 20 06:17:50.190912 2026] [security2:error] [pid 874439:tid 874609] [client 14.182.134.81:46311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH4AAAKCA"]
[Mon Jul 20 06:17:50.260705 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/b.php"] [unique_id "al4R7rwiU-Jh5ncAILFo7gAAAR8"]
[Mon Jul 20 06:17:50.260879 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/b.php"] [unique_id "al4R7rwiU-Jh5ncAILFo7gAAAR8"]
[Mon Jul 20 06:17:50.295809 2026] [security2:error] [pid 874439:tid 874624] [client 113.172.54.19:60553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH6QAANyU"]
[Mon Jul 20 06:17:50.388414 2026] [security2:error] [pid 874439:tid 874649] [client 20.63.63.128:6532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9QAAAFA"]
[Mon Jul 20 06:17:50.388584 2026] [security2:error] [pid 874439:tid 874649] [client 20.63.63.128:6532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9QAAAFA"]
[Mon Jul 20 06:17:50.443024 2026] [security2:error] [pid 874439:tid 874694] [client 171.60.139.123:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9wAAAH0"]
[Mon Jul 20 06:17:50.443199 2026] [security2:error] [pid 874439:tid 874694] [client 171.60.139.123:65204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9wAAAH0"]
[Mon Jul 20 06:17:50.488466 2026] [security2:error] [pid 874439:tid 874578] [client 41.237.101.92:55684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH-AAACXI"]
[Mon Jul 20 06:17:50.493566 2026] [security2:error] [pid 874439:tid 874643] [client 57.141.18.76:43230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGTwAASic"]
[Mon Jul 20 06:17:50.522705 2026] [security2:error] [pid 871012:tid 871148] [client 34.85.238.37:61348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4R7rwiU-Jh5ncAILFo9wAAAQ8"]
[Mon Jul 20 06:17:50.525994 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:60965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/app.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH_QAAACk"]
[Mon Jul 20 06:17:50.526098 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:60965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/app.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH_QAAACk"]
[Mon Jul 20 06:17:50.593042 2026] [security2:error] [pid 874439:tid 874647] [client 77.110.127.138:59488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4R7o6ZSrFvCrJJhtQIBgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:50.687869 2026] [security2:error] [pid 874439:tid 874637] [client 14.225.17.146:53161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIAwAAAEQ"], referer: http://momheadquarters.com/wp
[Mon Jul 20 06:17:50.773485 2026] [security2:error] [pid 874439:tid 874595] [client 20.63.63.128:6227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-png.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIEgAAABo"]
[Mon Jul 20 06:17:50.773632 2026] [security2:error] [pid 874439:tid 874595] [client 20.63.63.128:6227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-png.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIEgAAABo"]
[Mon Jul 20 06:17:50.781491 2026] [security2:error] [pid 874439:tid 874597] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH8AAAABw"]
[Mon Jul 20 06:17:50.837245 2026] [security2:error] [pid 871012:tid 871149] [client 14.225.17.146:56665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4R7bwiU-Jh5ncAILFo4QAAARA"]
[Mon Jul 20 06:17:50.861675 2026] [security2:error] [pid 874439:tid 874614] [client 34.85.238.37:59715] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4R7o6ZSrFvCrJJhtQIHAAAAC0"]
[Mon Jul 20 06:17:50.879796 2026] [security2:error] [pid 874439:tid 874576] [client 45.157.112.60:43293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIHQAAAAc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:50.925266 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lib.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIIAAAAG0"]
[Mon Jul 20 06:17:50.925376 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lib.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIIAAAAG0"]
[Mon Jul 20 06:17:51.085866 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sys.php"] [unique_id "al4R746ZSrFvCrJJhtQIJwAAAHI"]
[Mon Jul 20 06:17:51.086020 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sys.php"] [unique_id "al4R746ZSrFvCrJJhtQIJwAAAHI"]
[Mon Jul 20 06:17:51.187197 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:65047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIKgAAAHY"], referer: https://keywayconstructionclt.com/wp
[Mon Jul 20 06:17:51.264707 2026] [security2:error] [pid 874439:tid 874669] [client 34.85.238.37:49765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4R746ZSrFvCrJJhtQINwAAAGQ"]
[Mon Jul 20 06:17:51.284915 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:6555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/la.php"] [unique_id "al4R746ZSrFvCrJJhtQIOAAAAHA"]
[Mon Jul 20 06:17:51.285024 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:6555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/la.php"] [unique_id "al4R746ZSrFvCrJJhtQIOAAAAHA"]
[Mon Jul 20 06:17:51.374336 2026] [security2:error] [pid 874439:tid 874598] [client 45.116.69.230:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIQAAAAB0"]
[Mon Jul 20 06:17:51.374441 2026] [security2:error] [pid 874439:tid 874598] [client 45.116.69.230:56685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIQAAAAB0"]
[Mon Jul 20 06:17:51.375326 2026] [security2:error] [pid 874439:tid 874693] [client 84.233.195.150:49466] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R746ZSrFvCrJJhtQIQQAAAHw"]
[Mon Jul 20 06:17:51.409618 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/tires.php"] [unique_id "al4R746ZSrFvCrJJhtQISAAAAC0"]
[Mon Jul 20 06:17:51.409723 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:61002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/tires.php"] [unique_id "al4R746ZSrFvCrJJhtQISAAAAC0"]
[Mon Jul 20 06:17:51.464905 2026] [security2:error] [pid 874439:tid 874597] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIPQAAABw"]
[Mon Jul 20 06:17:51.554744 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lv.php"] [unique_id "al4R746ZSrFvCrJJhtQIUgAAACc"]
[Mon Jul 20 06:17:51.554924 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lv.php"] [unique_id "al4R746ZSrFvCrJJhtQIUgAAACc"]
[Mon Jul 20 06:17:51.607655 2026] [security2:error] [pid 871012:tid 871233] [client 185.132.186.72:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/class-wp-translation-file-mo-event.php"] [unique_id "al4R77wiU-Jh5ncAILFpEgAAAWQ"]
[Mon Jul 20 06:17:51.645067 2026] [security2:error] [pid 871012:tid 871243] [client 34.85.238.37:65317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4R77wiU-Jh5ncAILFpFQAAAW4"]
[Mon Jul 20 06:17:51.661273 2026] [security2:error] [pid 874439:tid 874655] [client 103.141.108.143:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIXAAAAFY"]
[Mon Jul 20 06:17:51.661441 2026] [security2:error] [pid 874439:tid 874655] [client 103.141.108.143:59045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIXAAAAFY"]
[Mon Jul 20 06:17:51.735128 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:7001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/myfile.php"] [unique_id "al4R746ZSrFvCrJJhtQIYAAAAE8"]
[Mon Jul 20 06:17:51.735268 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:7001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/myfile.php"] [unique_id "al4R746ZSrFvCrJJhtQIYAAAAE8"]
[Mon Jul 20 06:17:51.862255 2026] [security2:error] [pid 874439:tid 874669] [client 84.233.195.157:64532] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R746ZSrFvCrJJhtQIaAAAAGQ"]
[Mon Jul 20 06:17:51.866200 2026] [security2:error] [pid 871012:tid 871202] [client 20.63.63.128:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/06.php"] [unique_id "al4R77wiU-Jh5ncAILFpIAAAAUU"]
[Mon Jul 20 06:17:51.866307 2026] [security2:error] [pid 871012:tid 871202] [client 20.63.63.128:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/06.php"] [unique_id "al4R77wiU-Jh5ncAILFpIAAAAUU"]
[Mon Jul 20 06:17:51.955386 2026] [security2:error] [pid 874439:tid 874629] [client 34.85.238.37:65063] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4R746ZSrFvCrJJhtQIbgAAADw"]
[Mon Jul 20 06:17:51.996040 2026] [security2:error] [pid 874439:tid 874643] [client 20.63.63.128:7033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fs.php"] [unique_id "al4R746ZSrFvCrJJhtQIcQAAAEo"]
[Mon Jul 20 06:17:51.996182 2026] [security2:error] [pid 874439:tid 874643] [client 20.63.63.128:7033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fs.php"] [unique_id "al4R746ZSrFvCrJJhtQIcQAAAEo"]
[Mon Jul 20 06:17:52.102064 2026] [security2:error] [pid 871012:tid 871208] [client 14.225.17.146:56807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4R7bwiU-Jh5ncAILFo5gAAAUs"], referer: http://webgardensbypaula.com/wp
[Mon Jul 20 06:17:52.129589 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:6228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/asasx.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIegAAAAE"]
[Mon Jul 20 06:17:52.129742 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:6228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/asasx.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIegAAAAE"]
[Mon Jul 20 06:17:52.260588 2026] [security2:error] [pid 874439:tid 874652] [client 34.85.238.37:58008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4R8I6ZSrFvCrJJhtQIfwAAAFM"]
[Mon Jul 20 06:17:52.290951 2026] [security2:error] [pid 874439:tid 874621] [client 57.141.18.87:29082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGswAANEU"]
[Mon Jul 20 06:17:52.304198 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIgAAAAF4"]
[Mon Jul 20 06:17:52.304354 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:60952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIgAAAAF4"]
[Mon Jul 20 06:17:52.328479 2026] [security2:error] [pid 874439:tid 874584] [client 84.233.195.153:59585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R8I6ZSrFvCrJJhtQIgwAAAA8"]
[Mon Jul 20 06:17:52.410487 2026] [security2:error] [pid 874439:tid 874580] [client 103.70.86.152:30136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIhgAAC2M"]
[Mon Jul 20 06:17:52.417228 2026] [security2:error] [pid 874439:tid 874488] [remote 192.241.143.148:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIjQAATjA"]
[Mon Jul 20 06:17:52.441306 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-good.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIjwAAAB4"]
[Mon Jul 20 06:17:52.441401 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-good.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIjwAAAB4"]
[Mon Jul 20 06:17:52.443595 2026] [security2:error] [pid 874439:tid 874534] [remote 57.141.18.24:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6432167"] [unique_id "al4R8I6ZSrFvCrJJhtQIkAAAAF4"]
[Mon Jul 20 06:17:52.458013 2026] [security2:error] [pid 874439:tid 874622] [client 57.141.18.10:44792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGugAANTo"]
[Mon Jul 20 06:17:52.583848 2026] [security2:error] [pid 874439:tid 874604] [client 20.63.63.128:6216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/scxy.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIngAAACM"]
[Mon Jul 20 06:17:52.583954 2026] [security2:error] [pid 874439:tid 874604] [client 20.63.63.128:6216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/scxy.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIngAAACM"]
[Mon Jul 20 06:17:52.602786 2026] [security2:error] [pid 874439:tid 874555] [remote 192.241.143.148:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8I6ZSrFvCrJJhtQInwAAWHM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:52.678397 2026] [security2:error] [pid 874439:tid 874684] [client 14.225.17.146:52995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIFQAAAHM"], referer: http://nurturemarple.co.uk/wp
[Mon Jul 20 06:17:52.687107 2026] [security2:error] [pid 871012:tid 871017] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R8LwiU-Jh5ncAILFpNwABZQM"]
[Mon Jul 20 06:17:52.687265 2026] [security2:error] [pid 871012:tid 871234] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R8LwiU-Jh5ncAILFpNwABZQM"]
[Mon Jul 20 06:17:52.769014 2026] [security2:error] [pid 871012:tid 871201] [client 20.63.63.128:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wmore1.php"] [unique_id "al4R8LwiU-Jh5ncAILFpOwAAAUQ"]
[Mon Jul 20 06:17:52.769162 2026] [security2:error] [pid 871012:tid 871201] [client 20.63.63.128:61045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wmore1.php"] [unique_id "al4R8LwiU-Jh5ncAILFpOwAAAUQ"]
[Mon Jul 20 06:17:52.823334 2026] [security2:error] [pid 874439:tid 874683] [client 84.233.195.152:65082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R8I6ZSrFvCrJJhtQIsQAAAHI"]
[Mon Jul 20 06:17:52.930608 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:6264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R8I6ZSrFvCrJJhtQItgAAAAs"]
[Mon Jul 20 06:17:52.930713 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:6264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R8I6ZSrFvCrJJhtQItgAAAAs"]
[Mon Jul 20 06:17:53.005706 2026] [security2:error] [pid 874439:tid 874665] [client 98.159.234.160:49157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQIwgAAAGA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:53.062579 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQIxAAAAHc"]
[Mon Jul 20 06:17:53.062661 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:60964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQIxAAAAHc"]
[Mon Jul 20 06:17:53.128773 2026] [security2:error] [pid 871012:tid 871159] [client 178.152.178.232:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpRQAAARo"]
[Mon Jul 20 06:17:53.128894 2026] [security2:error] [pid 871012:tid 871159] [client 178.152.178.232:37885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpRQAAARo"]
[Mon Jul 20 06:17:53.155357 2026] [security2:error] [pid 871012:tid 871218] [client 50.116.65.227:26008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R8LwiU-Jh5ncAILFpPQAAAVU"]
[Mon Jul 20 06:17:53.213545 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:6979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xa.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI0AAAABs"]
[Mon Jul 20 06:17:53.213681 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:6979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xa.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI0AAAABs"]
[Mon Jul 20 06:17:53.294965 2026] [security2:error] [pid 871012:tid 871198] [client 103.77.203.233:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpSgAAAUE"]
[Mon Jul 20 06:17:53.295134 2026] [security2:error] [pid 871012:tid 871198] [client 103.77.203.233:52688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpSgAAAUE"]
[Mon Jul 20 06:17:53.362443 2026] [security2:error] [pid 874439:tid 874696] [client 20.63.63.128:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kolda.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI2gAAAH8"]
[Mon Jul 20 06:17:53.362599 2026] [security2:error] [pid 874439:tid 874696] [client 20.63.63.128:6559] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kolda.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI2gAAAH8"]
[Mon Jul 20 06:17:53.368047 2026] [security2:error] [pid 871012:tid 871150] [client 50.116.65.227:26024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R8bwiU-Jh5ncAILFpSAAAARE"]
[Mon Jul 20 06:17:53.390946 2026] [security2:error] [pid 871012:tid 871016] [remote 57.141.18.34:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6432167"] [unique_id "al4R8bwiU-Jh5ncAILFpTgABcgI"]
[Mon Jul 20 06:17:53.469792 2026] [security2:error] [pid 874439:tid 874572] [client 57.141.18.22:63550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG7gAAAz8"]
[Mon Jul 20 06:17:53.478333 2026] [security2:error] [pid 871012:tid 871249] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R8bwiU-Jh5ncAILFpRwABdH0"]
[Mon Jul 20 06:17:53.495207 2026] [security2:error] [pid 874439:tid 874641] [client 20.63.63.128:6585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-aothait.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI5gAAAEg"]
[Mon Jul 20 06:17:53.495321 2026] [security2:error] [pid 874439:tid 874641] [client 20.63.63.128:6585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-aothait.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI5gAAAEg"]
[Mon Jul 20 06:17:53.518918 2026] [security2:error] [pid 874439:tid 874553] [remote 162.19.86.63:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI6QAAK3E"]
[Mon Jul 20 06:17:53.625720 2026] [security2:error] [pid 871012:tid 871121] [remote 5.161.225.162:57274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpVgABMWs"]
[Mon Jul 20 06:17:53.626038 2026] [security2:error] [pid 871012:tid 871182] [client 5.161.225.162:57274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpVgABMWs"]
[Mon Jul 20 06:17:53.650461 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ftde.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI9wAAAB4"]
[Mon Jul 20 06:17:53.650569 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ftde.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI9wAAAB4"]
[Mon Jul 20 06:17:53.728122 2026] [security2:error] [pid 874439:tid 874538] [remote 162.19.86.63:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI_AAACWI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:17:53.782542 2026] [security2:error] [pid 874439:tid 874644] [client 20.63.63.128:6560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vx.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJAwAAAEs"]
[Mon Jul 20 06:17:53.782649 2026] [security2:error] [pid 874439:tid 874644] [client 20.63.63.128:6560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vx.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJAwAAAEs"]
[Mon Jul 20 06:17:53.875093 2026] [security2:error] [pid 874439:tid 874641] [client 185.132.186.81:37639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/vars-soap.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJDgAAAEg"]
[Mon Jul 20 06:17:53.979667 2026] [security2:error] [pid 871012:tid 871186] [client 20.63.63.128:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/a5.php"] [unique_id "al4R8bwiU-Jh5ncAILFpXQAAATU"]
[Mon Jul 20 06:17:53.979773 2026] [security2:error] [pid 871012:tid 871186] [client 20.63.63.128:6551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/a5.php"] [unique_id "al4R8bwiU-Jh5ncAILFpXQAAATU"]
[Mon Jul 20 06:17:54.124568 2026] [security2:error] [pid 874439:tid 874466] [remote 65.109.34.160:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.34.109.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJGAAAVRo"]
[Mon Jul 20 06:17:54.161804 2026] [security2:error] [pid 871012:tid 871240] [client 20.63.63.128:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-sing.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZQAAAWs"]
[Mon Jul 20 06:17:54.161944 2026] [security2:error] [pid 871012:tid 871240] [client 20.63.63.128:60936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-sing.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZQAAAWs"]
[Mon Jul 20 06:17:54.200720 2026] [security2:error] [pid 871012:tid 871263] [client 14.225.17.146:50995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4R8LwiU-Jh5ncAILFpNAAAAYI"], referer: http://grecruit.online/wp
[Mon Jul 20 06:17:54.289087 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/database.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZgAAAU4"]
[Mon Jul 20 06:17:54.289198 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:61029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/database.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZgAAAU4"]
[Mon Jul 20 06:17:54.365362 2026] [security2:error] [pid 874439:tid 874627] [client 14.225.17.146:59572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJGgAAADo"], referer: https://nurturemarple.co.uk/wp
[Mon Jul 20 06:17:54.375861 2026] [security2:error] [pid 874439:tid 874552] [remote 65.109.34.160:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.34.109.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJIQAAWXA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:54.420896 2026] [security2:error] [pid 874439:tid 874456] [remote 57.141.18.8:37802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4R8o6ZSrFvCrJJhtQJJAAAARA"]
[Mon Jul 20 06:17:54.445305 2026] [security2:error] [pid 874439:tid 874690] [client 14.225.17.146:65013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIsgAAAHk"], referer: http://amalia-capital.com/wp
[Mon Jul 20 06:17:54.455958 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/explorer/index_.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJKQAAAC0"]
[Mon Jul 20 06:17:54.456054 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/explorer/index_.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJKQAAAC0"]
[Mon Jul 20 06:17:54.536007 2026] [security2:error] [pid 874439:tid 874472] [remote 20.153.140.50:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJKwAAVCA"]
[Mon Jul 20 06:17:54.584891 2026] [security2:error] [pid 874439:tid 874636] [client 57.141.18.40:27358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R646ZSrFvCrJJhtQHLQAAQ2k"]
[Mon Jul 20 06:17:54.591357 2026] [security2:error] [pid 871012:tid 871160] [client 20.63.63.128:6250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-at.php"] [unique_id "al4R8rwiU-Jh5ncAILFpcQAAARs"]
[Mon Jul 20 06:17:54.591441 2026] [security2:error] [pid 871012:tid 871160] [client 20.63.63.128:6250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-at.php"] [unique_id "al4R8rwiU-Jh5ncAILFpcQAAARs"]
[Mon Jul 20 06:17:54.669283 2026] [security2:error] [pid 874439:tid 874573] [client 14.225.17.146:53413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJIAAAAAQ"], referer: http://aljosour-alarabia.com/wp
[Mon Jul 20 06:17:54.786165 2026] [security2:error] [pid 871012:tid 871220] [client 20.63.63.128:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-wz.php"] [unique_id "al4R8rwiU-Jh5ncAILFpewAAAVc"]
[Mon Jul 20 06:17:54.786306 2026] [security2:error] [pid 871012:tid 871220] [client 20.63.63.128:7004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-wz.php"] [unique_id "al4R8rwiU-Jh5ncAILFpewAAAVc"]
[Mon Jul 20 06:17:54.880144 2026] [security2:error] [pid 874439:tid 874581] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJLgAADCU"], referer: https://guidehunting.com/ssilko5
[Mon Jul 20 06:17:54.988982 2026] [security2:error] [pid 874439:tid 874476] [remote 20.153.140.50:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJQQAAIiQ"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:17:54.993459 2026] [security2:error] [pid 874439:tid 874654] [client 50.116.65.227:56810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4R8o6ZSrFvCrJJhtQJQwAAAFU"]
[Mon Jul 20 06:17:54.999831 2026] [security2:error] [pid 871012:tid 871198] [client 20.63.63.128:7039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-ver.php"] [unique_id "al4R8rwiU-Jh5ncAILFphAAAAUE"]
[Mon Jul 20 06:17:54.999928 2026] [security2:error] [pid 871012:tid 871198] [client 20.63.63.128:7039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-ver.php"] [unique_id "al4R8rwiU-Jh5ncAILFphAAAAUE"]
[Mon Jul 20 06:17:55.006142 2026] [security2:error] [pid 871012:tid 871200] [client 50.116.65.227:26096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4R87wiU-Jh5ncAILFphQAAARE"]
[Mon Jul 20 06:17:55.047274 2026] [security2:error] [pid 874439:tid 874631] [client 123.21.68.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIrQAAAD4"]
[Mon Jul 20 06:17:55.128022 2026] [security2:error] [pid 874439:tid 874576] [client 181.224.94.124:6360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJSgAAAAc"]
[Mon Jul 20 06:17:55.128273 2026] [security2:error] [pid 874439:tid 874576] [client 181.224.94.124:6360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJSgAAAAc"]
[Mon Jul 20 06:17:55.182045 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp5.php"] [unique_id "al4R87wiU-Jh5ncAILFpkAAAAR8"]
[Mon Jul 20 06:17:55.182177 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp5.php"] [unique_id "al4R87wiU-Jh5ncAILFpkAAAAR8"]
[Mon Jul 20 06:17:55.186378 2026] [security2:error] [pid 871012:tid 871190] [client 50.116.65.227:26114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4R87wiU-Jh5ncAILFpkQAAATk"]
[Mon Jul 20 06:17:55.198269 2026] [security2:error] [pid 871012:tid 871265] [client 50.116.65.227:26122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4R87wiU-Jh5ncAILFpkgAAAYQ"]
[Mon Jul 20 06:17:55.205046 2026] [security2:error] [pid 871012:tid 871084] [remote 100.42.189.89:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFpkwABYkY"]
[Mon Jul 20 06:17:55.228532 2026] [security2:error] [pid 874439:tid 874567] [remote 8.217.108.67:59208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJTgAAHX8"]
[Mon Jul 20 06:17:55.228756 2026] [security2:error] [pid 874439:tid 874598] [client 8.217.108.67:59208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJTgAAHX8"]
[Mon Jul 20 06:17:55.252180 2026] [security2:error] [pid 871012:tid 871215] [client 57.141.18.22:63560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R7LwiU-Jh5ncAILFotwABUh0"]
[Mon Jul 20 06:17:55.268993 2026] [security2:error] [pid 874439:tid 874665] [client 14.225.17.146:65060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJCQAAAGA"], referer: http://chestermonty.com/wp
[Mon Jul 20 06:17:55.309798 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-pp.php"] [unique_id "al4R846ZSrFvCrJJhtQJVQAAACc"]
[Mon Jul 20 06:17:55.309921 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-pp.php"] [unique_id "al4R846ZSrFvCrJJhtQJVQAAACc"]
[Mon Jul 20 06:17:55.436884 2026] [security2:error] [pid 871012:tid 871107] [remote 100.42.189.89:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFpmAABS10"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:17:55.437021 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/w3lls.php"] [unique_id "al4R87wiU-Jh5ncAILFplwAAAT4"]
[Mon Jul 20 06:17:55.437128 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/w3lls.php"] [unique_id "al4R87wiU-Jh5ncAILFplwAAAT4"]
[Mon Jul 20 06:17:55.559701 2026] [security2:error] [pid 871012:tid 871035] [remote 57.141.18.87:42036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4R87wiU-Jh5ncAILFpngABIhU"]
[Mon Jul 20 06:17:55.584793 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sbhu.php"] [unique_id "al4R87wiU-Jh5ncAILFpoAAAAT0"]
[Mon Jul 20 06:17:55.584881 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:6547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sbhu.php"] [unique_id "al4R87wiU-Jh5ncAILFpoAAAAT0"]
[Mon Jul 20 06:17:55.654262 2026] [security2:error] [pid 874439:tid 874684] [client 185.132.186.78:54579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/av.php"] [unique_id "al4R846ZSrFvCrJJhtQJaQAAAHM"]
[Mon Jul 20 06:17:55.673476 2026] [security2:error] [pid 871012:tid 871128] [remote 72.167.132.114:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFppgABa3I"]
[Mon Jul 20 06:17:55.695517 2026] [security2:error] [pid 874439:tid 874638] [client 103.153.183.69:60012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/passwd"] [unique_id "al4R846ZSrFvCrJJhtQJbAAAAEU"], referer: https://www.reddit.com/
[Mon Jul 20 06:17:55.717623 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4R846ZSrFvCrJJhtQJbgAAAE0"]
[Mon Jul 20 06:17:55.717765 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4R846ZSrFvCrJJhtQJbgAAAE0"]
[Mon Jul 20 06:17:55.774289 2026] [security2:error] [pid 874439:tid 874558] [remote 124.55.178.99:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJcAAAQ3Y"]
[Mon Jul 20 06:17:55.774474 2026] [security2:error] [pid 874439:tid 874636] [client 124.55.178.99:57838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJcAAAQ3Y"]
[Mon Jul 20 06:17:55.780418 2026] [security2:error] [pid 874439:tid 874571] [client 104.234.53.82:42547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4R846ZSrFvCrJJhtQJcgAAAAI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:55.793497 2026] [security2:error] [pid 874439:tid 874583] [client 57.141.18.48:42004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHaQAADgc"]
[Mon Jul 20 06:17:55.888683 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/favicon.php"] [unique_id "al4R87wiU-Jh5ncAILFprwAAARo"]
[Mon Jul 20 06:17:55.888805 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/favicon.php"] [unique_id "al4R87wiU-Jh5ncAILFprwAAARo"]
[Mon Jul 20 06:17:55.939264 2026] [security2:error] [pid 871012:tid 871063] [remote 72.167.132.114:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFpsAABWDE"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:17:56.060652 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/txets.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJgwAAAE4"]
[Mon Jul 20 06:17:56.060774 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:6579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/txets.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJgwAAAE4"]
[Mon Jul 20 06:17:56.160595 2026] [security2:error] [pid 874439:tid 874610] [client 14.225.17.146:51790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJMwAAACk"], referer: http://709fx.com/wp
[Mon Jul 20 06:17:56.228203 2026] [security2:error] [pid 874439:tid 874589] [client 20.63.63.128:6531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-su.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJjQAAABQ"]
[Mon Jul 20 06:17:56.228301 2026] [security2:error] [pid 874439:tid 874589] [client 20.63.63.128:6531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-su.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJjQAAABQ"]
[Mon Jul 20 06:17:56.314661 2026] [security2:error] [pid 874439:tid 874634] [client 14.225.17.146:54153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJjgAAAEE"], referer: https://chestermonty.com/wp
[Mon Jul 20 06:17:56.324197 2026] [security2:error] [pid 874439:tid 874644] [client 14.225.17.146:53729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJNwAAAEs"], referer: http://adirondackengineering.com/wp
[Mon Jul 20 06:17:56.358090 2026] [core:error] [pid 874439:tid 874569] [client 14.225.17.146:59352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/wp
[Mon Jul 20 06:17:56.358126 2026] [core:error] [pid 874439:tid 874569] [client 14.225.17.146:59352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/wp
[Mon Jul 20 06:17:56.367127 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff.php"] [unique_id "al4R9LwiU-Jh5ncAILFptwAAAXc"]
[Mon Jul 20 06:17:56.367215 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:61007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff.php"] [unique_id "al4R9LwiU-Jh5ncAILFptwAAAXc"]
[Mon Jul 20 06:17:56.506388 2026] [security2:error] [pid 874439:tid 874575] [client 20.63.63.128:6565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reze.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJoAAAAAY"]
[Mon Jul 20 06:17:56.506494 2026] [security2:error] [pid 874439:tid 874575] [client 20.63.63.128:6565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reze.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJoAAAAAY"]
[Mon Jul 20 06:17:56.647555 2026] [security2:error] [pid 871012:tid 871267] [client 20.63.63.128:61043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/666.php"] [unique_id "al4R9LwiU-Jh5ncAILFpvwAAAYY"]
[Mon Jul 20 06:17:56.647677 2026] [security2:error] [pid 871012:tid 871267] [client 20.63.63.128:61043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/666.php"] [unique_id "al4R9LwiU-Jh5ncAILFpvwAAAYY"]
[Mon Jul 20 06:17:56.787150 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:6978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wehrman.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJsgAAADI"]
[Mon Jul 20 06:17:56.787258 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:6978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wehrman.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJsgAAADI"]
[Mon Jul 20 06:17:56.880159 2026] [security2:error] [pid 874439:tid 874660] [client 103.153.183.69:60012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/shadow"] [unique_id "al4R9I6ZSrFvCrJJhtQJvAAAAFs"], referer: https://www.bing.com/search?q=wud1ut
[Mon Jul 20 06:17:56.886696 2026] [security2:error] [pid 871012:tid 871028] [remote 57.141.18.7:38292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4R9LwiU-Jh5ncAILFpyAABKA4"]
[Mon Jul 20 06:17:56.949498 2026] [security2:error] [pid 874439:tid 874583] [client 20.63.63.128:6263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-conflg.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJvgAAAA4"]
[Mon Jul 20 06:17:56.949573 2026] [security2:error] [pid 874439:tid 874583] [client 20.63.63.128:6263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-conflg.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJvgAAAA4"]
[Mon Jul 20 06:17:57.084183 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:6243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff1.php"] [unique_id "al4R9bwiU-Jh5ncAILFp1QAAAUg"]
[Mon Jul 20 06:17:57.084282 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:6243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff1.php"] [unique_id "al4R9bwiU-Jh5ncAILFp1QAAAUg"]
[Mon Jul 20 06:17:57.180026 2026] [security2:error] [pid 874439:tid 874596] [client 114.119.153.158:28593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/tours/golf-in-the-algarve/"] [unique_id "al4R9Y6ZSrFvCrJJhtQJyAAAABs"], referer: https://www.savilerowtravel.com/destinations/portugal
[Mon Jul 20 06:17:57.195815 2026] [security2:error] [pid 871012:tid 871244] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R9LwiU-Jh5ncAILFpygABbzU"]
[Mon Jul 20 06:17:57.243156 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fff.php"] [unique_id "al4R9bwiU-Jh5ncAILFp4AAAARM"]
[Mon Jul 20 06:17:57.243316 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:61021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fff.php"] [unique_id "al4R9bwiU-Jh5ncAILFp4AAAARM"]
[Mon Jul 20 06:17:57.318034 2026] [security2:error] [pid 874439:tid 874670] [client 57.141.18.72:60050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH8gAAZSI"]
[Mon Jul 20 06:17:57.383312 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amax.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ2QAAAEY"]
[Mon Jul 20 06:17:57.383427 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amax.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ2QAAAEY"]
[Mon Jul 20 06:17:57.448607 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ3AAAADM"]
[Mon Jul 20 06:17:57.448732 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ3AAAADM"]
[Mon Jul 20 06:17:57.461451 2026] [security2:error] [pid 871012:tid 871154] [client 185.132.186.63:34753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/style.php%20"] [unique_id "al4R9bwiU-Jh5ncAILFp4gAAARU"]
[Mon Jul 20 06:17:57.524455 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:61026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-firewall.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ4wAAAH4"]
[Mon Jul 20 06:17:57.524539 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:61026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-firewall.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ4wAAAH4"]
[Mon Jul 20 06:17:57.526199 2026] [security2:error] [pid 874439:tid 874445] [remote 45.90.123.233:56734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ5AAATwU"]
[Mon Jul 20 06:17:57.526344 2026] [security2:error] [pid 874439:tid 874648] [client 45.90.123.233:56734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ5AAATwU"]
[Mon Jul 20 06:17:57.573719 2026] [security2:error] [pid 874439:tid 874643] [client 46.110.96.34:10165] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ5wAAAEo"]
[Mon Jul 20 06:17:57.591726 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R9bwiU-Jh5ncAILFp5gAAAU4"]
[Mon Jul 20 06:17:57.591875 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:63945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R9bwiU-Jh5ncAILFp5gAAAU4"]
[Mon Jul 20 06:17:57.604349 2026] [security2:error] [pid 874439:tid 874692] [client 46.110.96.34:48608] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ6gAAAHs"]
[Mon Jul 20 06:17:57.636923 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:51768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJhgAAAFQ"], referer: http://cephasnext.com/wp
[Mon Jul 20 06:17:57.656767 2026] [security2:error] [pid 871012:tid 871233] [client 20.63.63.128:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/appt.php"] [unique_id "al4R9bwiU-Jh5ncAILFp6gAAAWQ"]
[Mon Jul 20 06:17:57.656865 2026] [security2:error] [pid 871012:tid 871233] [client 20.63.63.128:6577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/appt.php"] [unique_id "al4R9bwiU-Jh5ncAILFp6gAAAWQ"]
[Mon Jul 20 06:17:57.719792 2026] [security2:error] [pid 874439:tid 874672] [client 46.110.96.34:60293] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ8wAAAGc"]
[Mon Jul 20 06:17:57.788446 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:6232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-thi.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-AAAAG8"]
[Mon Jul 20 06:17:57.788536 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:6232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-thi.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-AAAAG8"]
[Mon Jul 20 06:17:57.792664 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/sql.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-gAAABs"]
[Mon Jul 20 06:17:57.792729 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:64028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/sql.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-gAAABs"]
[Mon Jul 20 06:17:57.942418 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/jj.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKBgAAAG0"]
[Mon Jul 20 06:17:57.942514 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/jj.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKBgAAAG0"]
[Mon Jul 20 06:17:57.997492 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/1index.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKCQAAACs"]
[Mon Jul 20 06:17:57.997612 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:64014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/1index.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKCQAAACs"]
[Mon Jul 20 06:17:58.100438 2026] [security2:error] [pid 874439:tid 874622] [client 20.63.63.128:6218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/333.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKDwAAADU"]
[Mon Jul 20 06:17:58.100548 2026] [security2:error] [pid 874439:tid 874622] [client 20.63.63.128:6218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/333.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKDwAAADU"]
[Mon Jul 20 06:17:58.247301 2026] [security2:error] [pid 874439:tid 874668] [client 20.63.63.128:6536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/albin.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKHwAAAGM"]
[Mon Jul 20 06:17:58.247388 2026] [security2:error] [pid 874439:tid 874668] [client 20.63.63.128:6536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/albin.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKHwAAAGM"]
[Mon Jul 20 06:17:58.281900 2026] [security2:error] [pid 874439:tid 874569] [client 173.252.87.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKGgAAAAA"]
[Mon Jul 20 06:17:58.307643 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/reop1.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJAAAAE4"]
[Mon Jul 20 06:17:58.307733 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:63994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/reop1.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJAAAAE4"]
[Mon Jul 20 06:17:58.342823 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.87:29092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIWQAAaEk"]
[Mon Jul 20 06:17:58.358065 2026] [security2:error] [pid 874439:tid 874610] [client 104.234.53.84:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJgAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:58.396844 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/66.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJwAAAEE"]
[Mon Jul 20 06:17:58.396953 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/66.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJwAAAEE"]
[Mon Jul 20 06:17:58.443421 2026] [security2:error] [pid 874439:tid 874618] [client 57.141.18.106:43218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIWgAAMRg"]
[Mon Jul 20 06:17:58.467969 2026] [security2:error] [pid 874439:tid 874589] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKFwAAFG8"], referer: https://guidehunting.com/ssilko6
[Mon Jul 20 06:17:58.523462 2026] [security2:error] [pid 874439:tid 874669] [client 20.63.63.128:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/motu.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKLwAAAGQ"]
[Mon Jul 20 06:17:58.523569 2026] [security2:error] [pid 874439:tid 874669] [client 20.63.63.128:6257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/motu.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKLwAAAGQ"]
[Mon Jul 20 06:17:58.649475 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/trusj18.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKOAAAADI"]
[Mon Jul 20 06:17:58.649618 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:63939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/trusj18.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKOAAAADI"]
[Mon Jul 20 06:17:58.704253 2026] [security2:error] [pid 874439:tid 874503] [remote 41.186.86.12:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKOwAAJD8"]
[Mon Jul 20 06:17:58.739205 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kj.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKPgAAABI"]
[Mon Jul 20 06:17:58.739285 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6543] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kj.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKPgAAABI"]
[Mon Jul 20 06:17:58.806573 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/trusj15.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRAAAAGU"]
[Mon Jul 20 06:17:58.806685 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/trusj15.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRAAAAGU"]
[Mon Jul 20 06:17:58.827072 2026] [security2:error] [pid 874439:tid 874657] [client 27.96.94.195:38202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRwAAAFg"]
[Mon Jul 20 06:17:58.827842 2026] [security2:error] [pid 874439:tid 874657] [client 27.96.94.195:38202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRwAAAFg"]
[Mon Jul 20 06:17:58.871127 2026] [security2:error] [pid 874439:tid 874653] [client 20.63.63.128:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp4.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKSQAAAFQ"]
[Mon Jul 20 06:17:58.871225 2026] [security2:error] [pid 874439:tid 874653] [client 20.63.63.128:6992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp4.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKSQAAAFQ"]
[Mon Jul 20 06:17:58.940740 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/rft8.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKTwAAADQ"]
[Mon Jul 20 06:17:58.940866 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:64041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/rft8.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKTwAAADQ"]
[Mon Jul 20 06:17:59.015860 2026] [security2:error] [pid 874439:tid 874577] [client 57.141.18.2:20246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIeQAACFw"]
[Mon Jul 20 06:17:59.057370 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:6211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file61.php"] [unique_id "al4R946ZSrFvCrJJhtQKVAAAACs"]
[Mon Jul 20 06:17:59.057512 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:6211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file61.php"] [unique_id "al4R946ZSrFvCrJJhtQKVAAAACs"]
[Mon Jul 20 06:17:59.087234 2026] [security2:error] [pid 871012:tid 871182] [client 20.63.63.128:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/ai.php"] [unique_id "al4R97wiU-Jh5ncAILFp_wAAATE"]
[Mon Jul 20 06:17:59.087377 2026] [security2:error] [pid 871012:tid 871182] [client 20.63.63.128:63959] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/ai.php"] [unique_id "al4R97wiU-Jh5ncAILFp_wAAATE"]
[Mon Jul 20 06:17:59.098360 2026] [security2:error] [pid 874439:tid 874661] [client 112.208.70.94:45642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4R946ZSrFvCrJJhtQKVgAAAFw"]
[Mon Jul 20 06:17:59.098498 2026] [security2:error] [pid 874439:tid 874661] [client 112.208.70.94:45642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4R946ZSrFvCrJJhtQKVgAAAFw"]
[Mon Jul 20 06:17:59.118219 2026] [security2:error] [pid 874439:tid 874684] [client 41.83.32.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRgAAcyE"]
[Mon Jul 20 06:17:59.191894 2026] [security2:error] [pid 874439:tid 874537] [remote 41.186.86.12:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4R946ZSrFvCrJJhtQKXAAAcmE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:17:59.268727 2026] [security2:error] [pid 874439:tid 874677] [client 20.63.63.128:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp.php"] [unique_id "al4R946ZSrFvCrJJhtQKYAAAAGw"]
[Mon Jul 20 06:17:59.268865 2026] [security2:error] [pid 874439:tid 874677] [client 20.63.63.128:6244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp.php"] [unique_id "al4R946ZSrFvCrJJhtQKYAAAAGw"]
[Mon Jul 20 06:17:59.328402 2026] [security2:error] [pid 871012:tid 871061] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqEwABNy8"]
[Mon Jul 20 06:17:59.328594 2026] [security2:error] [pid 871012:tid 871188] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqEwABNy8"]
[Mon Jul 20 06:17:59.346245 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-rdf.php"] [unique_id "al4R946ZSrFvCrJJhtQKZgAAAB0"]
[Mon Jul 20 06:17:59.346397 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:64015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-rdf.php"] [unique_id "al4R946ZSrFvCrJJhtQKZgAAAB0"]
[Mon Jul 20 06:17:59.392901 2026] [security2:error] [pid 871012:tid 871234] [client 20.63.63.128:61001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-trackback.php"] [unique_id "al4R97wiU-Jh5ncAILFqFAAAAWU"]
[Mon Jul 20 06:17:59.393017 2026] [security2:error] [pid 871012:tid 871234] [client 20.63.63.128:61001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-trackback.php"] [unique_id "al4R97wiU-Jh5ncAILFqFAAAAWU"]
[Mon Jul 20 06:17:59.427730 2026] [security2:error] [pid 874439:tid 874442] [remote 47.86.33.52:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R946ZSrFvCrJJhtQKaAAANwI"]
[Mon Jul 20 06:17:59.496809 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/fx.php"] [unique_id "al4R97wiU-Jh5ncAILFqFQAAARM"]
[Mon Jul 20 06:17:59.497198 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:63941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/fx.php"] [unique_id "al4R97wiU-Jh5ncAILFqFQAAARM"]
[Mon Jul 20 06:17:59.515920 2026] [security2:error] [pid 874439:tid 874591] [client 20.63.63.128:6246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/db.php"] [unique_id "al4R946ZSrFvCrJJhtQKagAAABY"]
[Mon Jul 20 06:17:59.516060 2026] [security2:error] [pid 874439:tid 874591] [client 20.63.63.128:6246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/db.php"] [unique_id "al4R946ZSrFvCrJJhtQKagAAABY"]
[Mon Jul 20 06:17:59.677622 2026] [security2:error] [pid 871012:tid 871161] [client 20.63.63.128:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/NewFile.php"] [unique_id "al4R97wiU-Jh5ncAILFqGgAAARw"]
[Mon Jul 20 06:17:59.677707 2026] [security2:error] [pid 871012:tid 871161] [client 20.63.63.128:60974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/NewFile.php"] [unique_id "al4R97wiU-Jh5ncAILFqGgAAARw"]
[Mon Jul 20 06:17:59.744122 2026] [security2:error] [pid 874439:tid 874574] [client 20.63.63.128:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKdgAAAAU"]
[Mon Jul 20 06:17:59.744199 2026] [security2:error] [pid 874439:tid 874574] [client 20.63.63.128:64048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKdgAAAAU"]
[Mon Jul 20 06:17:59.831579 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKfAAAADA"]
[Mon Jul 20 06:17:59.831658 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKfAAAADA"]
[Mon Jul 20 06:17:59.846657 2026] [security2:error] [pid 874439:tid 874466] [remote 47.86.33.52:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R946ZSrFvCrJJhtQKfQAAbho"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:59.920761 2026] [security2:error] [pid 871012:tid 871238] [client 41.173.37.102:5236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqIQAAAWk"]
[Mon Jul 20 06:17:59.920864 2026] [security2:error] [pid 871012:tid 871238] [client 41.173.37.102:5236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqIQAAAWk"]
[Mon Jul 20 06:17:59.964994 2026] [security2:error] [pid 874439:tid 874682] [client 20.63.63.128:61042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms.php"] [unique_id "al4R946ZSrFvCrJJhtQKhAAAAHE"]
[Mon Jul 20 06:17:59.965096 2026] [security2:error] [pid 874439:tid 874682] [client 20.63.63.128:61042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms.php"] [unique_id "al4R946ZSrFvCrJJhtQKhAAAAHE"]
[Mon Jul 20 06:18:00.143161 2026] [security2:error] [pid 871012:tid 871214] [client 20.63.63.128:6238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mini.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJgAAAVE"]
[Mon Jul 20 06:18:00.143299 2026] [security2:error] [pid 871012:tid 871214] [client 20.63.63.128:6238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mini.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJgAAAVE"]
[Mon Jul 20 06:18:00.146813 2026] [security2:error] [pid 871012:tid 871166] [client 20.63.63.128:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/dropdown.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJwAAASE"]
[Mon Jul 20 06:18:00.146896 2026] [security2:error] [pid 871012:tid 871166] [client 20.63.63.128:64016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/dropdown.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJwAAASE"]
[Mon Jul 20 06:18:00.287889 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:6563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/first.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKkAAAAEA"]
[Mon Jul 20 06:18:00.288023 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:6563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/first.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKkAAAAEA"]
[Mon Jul 20 06:18:00.293032 2026] [security2:error] [pid 871012:tid 871147] [client 185.132.186.76:38591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/files.php"] [unique_id "al4R-LwiU-Jh5ncAILFqMAAAAQ4"]
[Mon Jul 20 06:18:00.361963 2026] [security2:error] [pid 871012:tid 871220] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJAABVxA"]
[Mon Jul 20 06:18:00.396460 2026] [security2:error] [pid 874439:tid 874602] [client 57.141.18.77:64328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI3gAAIXk"]
[Mon Jul 20 06:18:00.497652 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/0okj.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKngAAAD4"]
[Mon Jul 20 06:18:00.497777 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:61014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/0okj.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKngAAAD4"]
[Mon Jul 20 06:18:00.506584 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/file11.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKnwAAAHc"]
[Mon Jul 20 06:18:00.506725 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/file11.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKnwAAAHc"]
[Mon Jul 20 06:18:00.516943 2026] [security2:error] [pid 871012:tid 871252] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqMQAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:00.586523 2026] [security2:error] [pid 874439:tid 874476] [remote 72.167.132.114:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKpwAANiQ"]
[Mon Jul 20 06:18:00.604147 2026] [security2:error] [pid 871012:tid 871202] [client 104.234.53.91:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqNQAAAUU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:00.683368 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/grsiuk.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKrAAAAFU"]
[Mon Jul 20 06:18:00.683491 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:57820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/grsiuk.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKrAAAAFU"]
[Mon Jul 20 06:18:00.711304 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/png.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKsAAAABw"]
[Mon Jul 20 06:18:00.711427 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:63938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/png.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKsAAAABw"]
[Mon Jul 20 06:18:00.765781 2026] [security2:error] [pid 874439:tid 874486] [remote 188.138.102.156:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKtAAASS4"]
[Mon Jul 20 06:18:00.812094 2026] [security2:error] [pid 871012:tid 871189] [client 20.63.63.128:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/shell20211028.php"] [unique_id "al4R-LwiU-Jh5ncAILFqPQAAATg"]
[Mon Jul 20 06:18:00.812212 2026] [security2:error] [pid 871012:tid 871189] [client 20.63.63.128:60934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/shell20211028.php"] [unique_id "al4R-LwiU-Jh5ncAILFqPQAAATg"]
[Mon Jul 20 06:18:00.904592 2026] [security2:error] [pid 874439:tid 874691] [client 57.141.18.3:38574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJDwAAehE"]
[Mon Jul 20 06:18:00.905125 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-slss.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKvQAAAEA"]
[Mon Jul 20 06:18:00.905216 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:63970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-slss.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKvQAAAEA"]
[Mon Jul 20 06:18:00.967008 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/revealability.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKwwAAAGI"]
[Mon Jul 20 06:18:00.967138 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:6568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/revealability.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKwwAAAGI"]
[Mon Jul 20 06:18:00.976959 2026] [security2:error] [pid 874439:tid 874480] [remote 188.138.102.156:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKxgAALSg"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:18:00.987450 2026] [security2:error] [pid 874439:tid 874470] [remote 72.167.132.114:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKxQAAFB4"], referer: https://mrbambooplus.com/wp-login.php
[Mon Jul 20 06:18:01.090319 2026] [security2:error] [pid 874439:tid 874601] [client 20.63.63.128:61009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/btx25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzAAAACA"]
[Mon Jul 20 06:18:01.090420 2026] [security2:error] [pid 874439:tid 874601] [client 20.63.63.128:61009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/btx25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzAAAACA"]
[Mon Jul 20 06:18:01.124641 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/ah25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzwAAAD4"]
[Mon Jul 20 06:18:01.124736 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:64026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/ah25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzwAAAD4"]
[Mon Jul 20 06:18:01.178019 2026] [security2:error] [pid 871012:tid 871224] [client 171.60.139.123:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R-bwiU-Jh5ncAILFqQgAAAVs"]
[Mon Jul 20 06:18:01.178146 2026] [security2:error] [pid 871012:tid 871224] [client 171.60.139.123:49334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R-bwiU-Jh5ncAILFqQgAAAVs"]
[Mon Jul 20 06:18:01.221214 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bthil.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK3AAAAFw"]
[Mon Jul 20 06:18:01.221297 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bthil.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK3AAAAFw"]
[Mon Jul 20 06:18:01.337185 2026] [security2:error] [pid 874439:tid 874655] [client 104.234.53.90:32807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK5AAAAFY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:01.379895 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/ccou.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6AAAADM"]
[Mon Jul 20 06:18:01.379984 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/ccou.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6AAAADM"]
[Mon Jul 20 06:18:01.391437 2026] [security2:error] [pid 874439:tid 874576] [client 20.63.63.128:6981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hplfuns.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6gAAAAc"]
[Mon Jul 20 06:18:01.391562 2026] [security2:error] [pid 874439:tid 874576] [client 20.63.63.128:6981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hplfuns.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6gAAAAc"]
[Mon Jul 20 06:18:01.490559 2026] [security2:error] [pid 874439:tid 874584] [client 57.141.18.114:27928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJLQAADzE"]
[Mon Jul 20 06:18:01.520369 2026] [security2:error] [pid 874439:tid 874660] [client 20.63.63.128:57547] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.theablesea.com"] [uri "/1.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK7wAAAFs"]
[Mon Jul 20 06:18:01.520481 2026] [security2:error] [pid 874439:tid 874660] [client 20.63.63.128:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/1.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK7wAAAFs"]
[Mon Jul 20 06:18:01.520580 2026] [security2:error] [pid 874439:tid 874660] [client 20.63.63.128:57547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/1.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK7wAAAFs"]
[Mon Jul 20 06:18:01.538287 2026] [security2:error] [pid 871012:tid 871208] [client 20.63.63.128:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/error.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTQAAAUs"]
[Mon Jul 20 06:18:01.538391 2026] [security2:error] [pid 871012:tid 871208] [client 20.63.63.128:57814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/error.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTQAAAUs"]
[Mon Jul 20 06:18:01.545535 2026] [security2:error] [pid 874439:tid 874581] [client 14.225.17.146:59333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK4wAAAAw"]
[Mon Jul 20 06:18:01.655915 2026] [security2:error] [pid 871012:tid 871222] [client 20.63.63.128:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/900.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTgAAAVk"]
[Mon Jul 20 06:18:01.656034 2026] [security2:error] [pid 871012:tid 871222] [client 20.63.63.128:57581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/900.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTgAAAVk"]
[Mon Jul 20 06:18:01.670550 2026] [security2:error] [pid 874439:tid 874645] [client 20.63.63.128:6254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK9gAAAEw"]
[Mon Jul 20 06:18:01.670629 2026] [security2:error] [pid 874439:tid 874645] [client 20.63.63.128:6254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK9gAAAEw"]
[Mon Jul 20 06:18:01.800326 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/file59.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLAgAAAAA"]
[Mon Jul 20 06:18:01.801164 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:57557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/file59.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLAgAAAAA"]
[Mon Jul 20 06:18:01.827395 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pass4.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLBQAAAFw"]
[Mon Jul 20 06:18:01.827496 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:60958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pass4.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLBQAAAFw"]
[Mon Jul 20 06:18:01.889821 2026] [security2:error] [pid 874439:tid 874624] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK8wAAN08"], referer: https://guidehunting.com/ssilko7
[Mon Jul 20 06:18:01.941543 2026] [security2:error] [pid 874439:tid 874627] [client 20.63.63.128:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/amxloxxr.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLDQAAADo"]
[Mon Jul 20 06:18:01.941713 2026] [security2:error] [pid 874439:tid 874627] [client 20.63.63.128:64051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/amxloxxr.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLDQAAADo"]
[Mon Jul 20 06:18:01.957217 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sadcut1.php"] [unique_id "al4R-bwiU-Jh5ncAILFqWQAAARo"]
[Mon Jul 20 06:18:01.957327 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sadcut1.php"] [unique_id "al4R-bwiU-Jh5ncAILFqWQAAARo"]
[Mon Jul 20 06:18:02.070635 2026] [security2:error] [pid 874439:tid 874625] [client 45.116.69.230:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEQAAADg"]
[Mon Jul 20 06:18:02.070890 2026] [security2:error] [pid 874439:tid 874625] [client 45.116.69.230:57207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEQAAADg"]
[Mon Jul 20 06:18:02.094710 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:6267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bgymj.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEwAAAEY"]
[Mon Jul 20 06:18:02.094744 2026] [security2:error] [pid 874439:tid 874695] [client 185.132.186.53:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/av.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEgAAAH4"]
[Mon Jul 20 06:18:02.094861 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:6267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bgymj.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEwAAAEY"]
[Mon Jul 20 06:18:02.112674 2026] [security2:error] [pid 874439:tid 874572] [client 20.63.63.128:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/aboutc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLFQAAAAM"]
[Mon Jul 20 06:18:02.112788 2026] [security2:error] [pid 874439:tid 874572] [client 20.63.63.128:64027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/aboutc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLFQAAAAM"]
[Mon Jul 20 06:18:02.162569 2026] [security2:error] [pid 874439:tid 874613] [client 3.109.4.218:16572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLGAAAACw"]
[Mon Jul 20 06:18:02.250781 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yas.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLIgAAAC0"]
[Mon Jul 20 06:18:02.250880 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yas.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLIgAAAC0"]
[Mon Jul 20 06:18:02.290878 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/bless18.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLJQAAAGg"]
[Mon Jul 20 06:18:02.291092 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:64058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/bless18.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLJQAAAGg"]
[Mon Jul 20 06:18:02.328724 2026] [security2:error] [pid 874439:tid 874608] [client 50.116.65.227:55346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R-o6ZSrFvCrJJhtQLJwAAACc"]
[Mon Jul 20 06:18:02.342745 2026] [security2:error] [pid 874439:tid 874583] [client 50.116.65.227:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R-o6ZSrFvCrJJhtQLKAAAAHE"]
[Mon Jul 20 06:18:02.380158 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:7000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dx.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLLQAAADQ"]
[Mon Jul 20 06:18:02.380249 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:7000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dx.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLLQAAADQ"]
[Mon Jul 20 06:18:02.462058 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/crgio.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLMwAAAGU"]
[Mon Jul 20 06:18:02.462157 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/crgio.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLMwAAAGU"]
[Mon Jul 20 06:18:02.528500 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:7034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yellow.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLOQAAAHI"]
[Mon Jul 20 06:18:02.528603 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:7034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yellow.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLOQAAAHI"]
[Mon Jul 20 06:18:02.624786 2026] [security2:error] [pid 871012:tid 871235] [client 20.63.63.128:63940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-act.php"] [unique_id "al4R-rwiU-Jh5ncAILFqZwAAAWY"]
[Mon Jul 20 06:18:02.624925 2026] [security2:error] [pid 871012:tid 871235] [client 20.63.63.128:63940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-act.php"] [unique_id "al4R-rwiU-Jh5ncAILFqZwAAAWY"]
[Mon Jul 20 06:18:02.653944 2026] [security2:error] [pid 874439:tid 874671] [client 103.141.108.143:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLQAAAAGY"]
[Mon Jul 20 06:18:02.654086 2026] [security2:error] [pid 874439:tid 874671] [client 103.141.108.143:59548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLQAAAAGY"]
[Mon Jul 20 06:18:02.678312 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-der.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLRAAAAEE"]
[Mon Jul 20 06:18:02.678456 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-der.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLRAAAAEE"]
[Mon Jul 20 06:18:02.745072 2026] [security2:error] [pid 871012:tid 871174] [client 57.141.18.99:23678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R87wiU-Jh5ncAILFpqQABKVk"]
[Mon Jul 20 06:18:02.809554 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/new4.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLUgAAAFc"]
[Mon Jul 20 06:18:02.809672 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:63943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/new4.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLUgAAAFc"]
[Mon Jul 20 06:18:02.840552 2026] [security2:error] [pid 874439:tid 874607] [client 20.63.63.128:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lala.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLVAAAACY"]
[Mon Jul 20 06:18:02.840644 2026] [security2:error] [pid 874439:tid 874607] [client 20.63.63.128:60961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lala.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLVAAAACY"]
[Mon Jul 20 06:18:02.953894 2026] [security2:error] [pid 874439:tid 874691] [client 20.63.63.128:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-the.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLWgAAAHo"]
[Mon Jul 20 06:18:02.953984 2026] [security2:error] [pid 874439:tid 874691] [client 20.63.63.128:63993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-the.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLWgAAAHo"]
[Mon Jul 20 06:18:02.976656 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:59690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6wAAAA0"], referer: http://ghivs.com/wp
[Mon Jul 20 06:18:02.995996 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aa.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLXgAAAGo"]
[Mon Jul 20 06:18:02.996092 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:61032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aa.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLXgAAAGo"]
[Mon Jul 20 06:18:03.017429 2026] [security2:error] [pid 874439:tid 874620] [client 14.225.17.146:53718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLVgAAADM"], referer: http://scott-assist.com/wp
[Mon Jul 20 06:18:03.088279 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/atkno.php"] [unique_id "al4R-46ZSrFvCrJJhtQLZwAAAHc"]
[Mon Jul 20 06:18:03.088364 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/atkno.php"] [unique_id "al4R-46ZSrFvCrJJhtQLZwAAAHc"]
[Mon Jul 20 06:18:03.213328 2026] [security2:error] [pid 874439:tid 874678] [client 3.109.4.218:16582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4R-46ZSrFvCrJJhtQLcQAAAG0"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:18:03.285494 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/mass.php"] [unique_id "al4R-46ZSrFvCrJJhtQLdAAAABk"]
[Mon Jul 20 06:18:03.285598 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:63999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/mass.php"] [unique_id "al4R-46ZSrFvCrJJhtQLdAAAABk"]
[Mon Jul 20 06:18:03.339064 2026] [security2:error] [pid 874439:tid 874614] [client 47.128.99.8:24204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.muamoicosmetics.com"] [uri "/robots.txt"] [unique_id "al4R-46ZSrFvCrJJhtQLdgAAAC0"]
[Mon Jul 20 06:18:03.366062 2026] [security2:error] [pid 874439:tid 874566] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLeAAAMX4"]
[Mon Jul 20 06:18:03.366187 2026] [security2:error] [pid 874439:tid 874618] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLeAAAMX4"]
[Mon Jul 20 06:18:03.417034 2026] [security2:error] [pid 874439:tid 874584] [client 20.63.63.128:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wefile.php"] [unique_id "al4R-46ZSrFvCrJJhtQLegAAAA8"]
[Mon Jul 20 06:18:03.417142 2026] [security2:error] [pid 874439:tid 874584] [client 20.63.63.128:63975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wefile.php"] [unique_id "al4R-46ZSrFvCrJJhtQLegAAAA8"]
[Mon Jul 20 06:18:03.551629 2026] [security2:error] [pid 874439:tid 874659] [client 20.63.63.128:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/min.php"] [unique_id "al4R-46ZSrFvCrJJhtQLhgAAAFo"]
[Mon Jul 20 06:18:03.551801 2026] [security2:error] [pid 874439:tid 874659] [client 20.63.63.128:64004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/min.php"] [unique_id "al4R-46ZSrFvCrJJhtQLhgAAAFo"]
[Mon Jul 20 06:18:03.689329 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/sid3.php"] [unique_id "al4R-46ZSrFvCrJJhtQLigAAAFw"]
[Mon Jul 20 06:18:03.689435 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:63950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/sid3.php"] [unique_id "al4R-46ZSrFvCrJJhtQLigAAAFw"]
[Mon Jul 20 06:18:03.734989 2026] [security2:error] [pid 871012:tid 871206] [client 57.141.18.105:58868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9LwiU-Jh5ncAILFpxQABSWM"]
[Mon Jul 20 06:18:03.747245 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:53252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkAAAACA"]
[Mon Jul 20 06:18:03.747368 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:53252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkAAAACA"]
[Mon Jul 20 06:18:03.797882 2026] [security2:error] [pid 874439:tid 874581] [client 178.152.178.232:36239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkgAAAAw"]
[Mon Jul 20 06:18:03.797980 2026] [security2:error] [pid 874439:tid 874581] [client 178.152.178.232:36239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkgAAAAw"]
[Mon Jul 20 06:18:03.853944 2026] [security2:error] [pid 871012:tid 871192] [client 20.63.63.128:57537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/fileas.php"] [unique_id "al4R-7wiU-Jh5ncAILFqgQAAATs"]
[Mon Jul 20 06:18:03.854052 2026] [security2:error] [pid 871012:tid 871192] [client 20.63.63.128:57537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/fileas.php"] [unique_id "al4R-7wiU-Jh5ncAILFqgQAAATs"]
[Mon Jul 20 06:18:03.897166 2026] [security2:error] [pid 874439:tid 874626] [client 185.132.186.93:21273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/about.php"] [unique_id "al4R-46ZSrFvCrJJhtQLlQAAADk"]
[Mon Jul 20 06:18:04.015569 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/bless24.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLoAAAABk"]
[Mon Jul 20 06:18:04.015715 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:64061] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/bless24.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLoAAAABk"]
[Mon Jul 20 06:18:04.077959 2026] [security2:error] [pid 874439:tid 874608] [client 54.204.130.104:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLgQAAACc"]
[Mon Jul 20 06:18:04.079603 2026] [security2:error] [pid 874439:tid 874651] [client 54.204.130.104:26474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/category/food/holiday-recipes"] [unique_id "al4R-46ZSrFvCrJJhtQLfgAAAFI"]
[Mon Jul 20 06:18:04.167540 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/fun.php"] [unique_id "al4R_LwiU-Jh5ncAILFqkgAAAT8"]
[Mon Jul 20 06:18:04.167666 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:63980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/fun.php"] [unique_id "al4R_LwiU-Jh5ncAILFqkgAAAT8"]
[Mon Jul 20 06:18:04.320849 2026] [security2:error] [pid 871012:tid 871238] [client 20.63.63.128:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/drykl.php"] [unique_id "al4R_LwiU-Jh5ncAILFqmgAAAWk"]
[Mon Jul 20 06:18:04.320981 2026] [security2:error] [pid 871012:tid 871238] [client 20.63.63.128:63988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/drykl.php"] [unique_id "al4R_LwiU-Jh5ncAILFqmgAAAWk"]
[Mon Jul 20 06:18:04.408151 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqiAABIng"]
[Mon Jul 20 06:18:04.408356 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqiwABIkA"]
[Mon Jul 20 06:18:04.408468 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqigABIlA"]
[Mon Jul 20 06:18:04.409597 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqjQABIlY"]
[Mon Jul 20 06:18:04.410461 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqiQABIj0"]
[Mon Jul 20 06:18:04.523590 2026] [security2:error] [pid 871012:tid 871212] [client 20.63.63.128:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R_LwiU-Jh5ncAILFqowAAAU8"]
[Mon Jul 20 06:18:04.523710 2026] [security2:error] [pid 871012:tid 871212] [client 20.63.63.128:64003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R_LwiU-Jh5ncAILFqowAAAU8"]
[Mon Jul 20 06:18:04.654671 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.7:60278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKAQAAAk0"]
[Mon Jul 20 06:18:04.686206 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/mifta.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLxQAAAH4"]
[Mon Jul 20 06:18:04.686314 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:63936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/mifta.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLxQAAAH4"]
[Mon Jul 20 06:18:04.837486 2026] [security2:error] [pid 874439:tid 874651] [client 20.63.63.128:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/class-t.api.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL0AAAAFI"]
[Mon Jul 20 06:18:04.837624 2026] [security2:error] [pid 874439:tid 874651] [client 20.63.63.128:64003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/class-t.api.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL0AAAAFI"]
[Mon Jul 20 06:18:04.970888 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/vgtyu.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL1gAAAGo"]
[Mon Jul 20 06:18:04.971016 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:63960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/vgtyu.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL1gAAAGo"]
[Mon Jul 20 06:18:05.051303 2026] [security2:error] [pid 871012:tid 871178] [client 34.207.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqlwAAAS0"]
[Mon Jul 20 06:18:05.089678 2026] [security2:error] [pid 874439:tid 874646] [client 57.141.18.13:28344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKIgAATUI"]
[Mon Jul 20 06:18:05.103238 2026] [security2:error] [pid 874439:tid 874637] [client 34.207.130.29:30424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/category/food/holiday-recipes/"] [unique_id "al4R_I6ZSrFvCrJJhtQLsAAAAEQ"]
[Mon Jul 20 06:18:05.138923 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/atomlib.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL3QAAAHA"]
[Mon Jul 20 06:18:05.139069 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:64059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/atomlib.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL3QAAAHA"]
[Mon Jul 20 06:18:05.292669 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-access.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL4gAAAAA"]
[Mon Jul 20 06:18:05.292791 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:63978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-access.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL4gAAAAA"]
[Mon Jul 20 06:18:05.422019 2026] [security2:error] [pid 871012:tid 871148] [client 20.63.63.128:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-update.php"] [unique_id "al4R_bwiU-Jh5ncAILFqxQAAAQ8"]
[Mon Jul 20 06:18:05.422138 2026] [security2:error] [pid 871012:tid 871148] [client 20.63.63.128:64049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-update.php"] [unique_id "al4R_bwiU-Jh5ncAILFqxQAAAQ8"]
[Mon Jul 20 06:18:05.530209 2026] [security2:error] [pid 871012:tid 871268] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFqvgAAAYc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:05.578459 2026] [security2:error] [pid 871012:tid 871169] [client 20.63.63.128:63954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/erty.php"] [unique_id "al4R_bwiU-Jh5ncAILFqzQAAASQ"]
[Mon Jul 20 06:18:05.578564 2026] [security2:error] [pid 871012:tid 871169] [client 20.63.63.128:63954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/erty.php"] [unique_id "al4R_bwiU-Jh5ncAILFqzQAAASQ"]
[Mon Jul 20 06:18:05.607273 2026] [security2:error] [pid 874439:tid 874592] [client 57.141.18.7:60288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKQQAAF0o"]
[Mon Jul 20 06:18:05.626421 2026] [security2:error] [pid 871012:tid 871255] [client 14.225.17.146:52402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4R-7wiU-Jh5ncAILFqbgAAAXo"], referer: http://bruceledewitz.com/wp
[Mon Jul 20 06:18:05.641282 2026] [security2:error] [pid 871012:tid 871214] [client 216.73.217.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFqygABURU"]
[Mon Jul 20 06:18:05.663319 2026] [security2:error] [pid 871012:tid 871234] [client 181.224.94.124:38529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R_bwiU-Jh5ncAILFq0gAAAWU"]
[Mon Jul 20 06:18:05.663465 2026] [security2:error] [pid 871012:tid 871234] [client 181.224.94.124:38529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R_bwiU-Jh5ncAILFq0gAAAWU"]
[Mon Jul 20 06:18:05.672799 2026] [lsapi:warn] [pid 874439:tid 874508] [remote 86.24.97.244:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:18:05.709256 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:57577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R_bwiU-Jh5ncAILFq1QAAAT4"]
[Mon Jul 20 06:18:05.709345 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:57577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R_bwiU-Jh5ncAILFq1QAAAT4"]
[Mon Jul 20 06:18:05.839296 2026] [security2:error] [pid 871012:tid 871243] [client 20.63.63.128:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/like.php"] [unique_id "al4R_bwiU-Jh5ncAILFq2gAAAW4"]
[Mon Jul 20 06:18:05.839437 2026] [security2:error] [pid 871012:tid 871243] [client 20.63.63.128:64039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/like.php"] [unique_id "al4R_bwiU-Jh5ncAILFq2gAAAW4"]
[Mon Jul 20 06:18:05.849168 2026] [security2:error] [pid 874439:tid 874461] [remote 8.217.108.67:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL-gAAGBU"]
[Mon Jul 20 06:18:05.950385 2026] [security2:error] [pid 874439:tid 874644] [client 14.225.17.146:59917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLeQAAAEs"], referer: http://gearwaterproof.com/wp
[Mon Jul 20 06:18:05.957442 2026] [security2:error] [pid 874439:tid 874651] [client 216.73.217.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL-QAAUkc"]
[Mon Jul 20 06:18:05.983297 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/bless5.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQMBAAAAFU"]
[Mon Jul 20 06:18:05.983394 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:64022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/bless5.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQMBAAAAFU"]
[Mon Jul 20 06:18:06.047198 2026] [security2:error] [pid 871012:tid 871265] [client 104.234.53.50:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4R_rwiU-Jh5ncAILFq5AAAAYQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:06.158006 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/t.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMDQAAAG8"]
[Mon Jul 20 06:18:06.158106 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:64047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/t.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMDQAAAG8"]
[Mon Jul 20 06:18:06.285851 2026] [security2:error] [pid 871012:tid 871157] [client 20.63.63.128:57561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/xoot.php"] [unique_id "al4R_rwiU-Jh5ncAILFq7gAAARg"]
[Mon Jul 20 06:18:06.285990 2026] [security2:error] [pid 871012:tid 871157] [client 20.63.63.128:57561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/xoot.php"] [unique_id "al4R_rwiU-Jh5ncAILFq7gAAARg"]
[Mon Jul 20 06:18:06.398308 2026] [security2:error] [pid 871012:tid 871147] [client 14.225.17.146:50984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4R_rwiU-Jh5ncAILFq5QAAAQ4"], referer: http://itdynamix.com/wp
[Mon Jul 20 06:18:06.531529 2026] [security2:error] [pid 874439:tid 874608] [client 14.225.17.146:52558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMEAAAACc"], referer: http://fineartsfactory.net/wp
[Mon Jul 20 06:18:06.669996 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.76:43725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/id3/wp-work.php"] [unique_id "al4R_rwiU-Jh5ncAILFq_QAAAXo"]
[Mon Jul 20 06:18:06.991361 2026] [security2:error] [pid 871012:tid 871233] [client 158.173.89.95:20815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R_rwiU-Jh5ncAILFrDgAAAWQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:07.038793 2026] [security2:error] [pid 871012:tid 871207] [client 57.141.18.20:58208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJQABSjA"]
[Mon Jul 20 06:18:07.047781 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMHgAAAD8"]
[Mon Jul 20 06:18:07.254554 2026] [security2:error] [pid 874439:tid 874574] [client 128.1.120.248:51490] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "video/x-msvideo"] [severity "WARNING"] [hostname "cira.org"] [uri "/"] [unique_id "al4R_46ZSrFvCrJJhtQMMgAAAAU"]
[Mon Jul 20 06:18:07.254675 2026] [security2:error] [pid 874439:tid 874574] [client 128.1.120.248:51490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cira.org"] [uri "/"] [unique_id "al4R_46ZSrFvCrJJhtQMMgAAAAU"]
[Mon Jul 20 06:18:07.277860 2026] [security2:error] [pid 871012:tid 871231] [client 14.225.17.146:64970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4R_rwiU-Jh5ncAILFq4gAAAWI"], referer: http://betterbonddogtraining.com/wp
[Mon Jul 20 06:18:07.298071 2026] [security2:error] [pid 874439:tid 874521] [remote 8.217.108.67:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4R_46ZSrFvCrJJhtQMNgAAa1E"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:18:07.435952 2026] [security2:error] [pid 871012:tid 871256] [client 14.225.17.146:59857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrEwAAAXs"], referer: https://itdynamix.com/wp
[Mon Jul 20 06:18:07.706324 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQAAAIjs"], referer: https://guidehunting.com/login
[Mon Jul 20 06:18:07.706501 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQQAAIkw"], referer: https://guidehunting.com/dashboard
[Mon Jul 20 06:18:07.726495 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMRAAAInY"], referer: https://guidehunting.com/settings
[Mon Jul 20 06:18:07.726660 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQgAAIg8"], referer: https://guidehunting.com/app
[Mon Jul 20 06:18:07.727981 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQwAAIms"], referer: https://guidehunting.com/console
[Mon Jul 20 06:18:07.764728 2026] [security2:error] [pid 871012:tid 871185] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrGwABNB8"]
[Mon Jul 20 06:18:07.829141 2026] [security2:error] [pid 871012:tid 871171] [client 14.225.17.146:52643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4R_rwiU-Jh5ncAILFrDAAAASY"], referer: http://idigress.agency/wp
[Mon Jul 20 06:18:08.260459 2026] [security2:error] [pid 871012:tid 871160] [client 57.141.18.88:63922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-bwiU-Jh5ncAILFqRgABGyg"]
[Mon Jul 20 06:18:08.468401 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.87:32207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/WordPressCore/gecko.php"] [unique_id "al4SALwiU-Jh5ncAILFrNAAAAXo"]
[Mon Jul 20 06:18:08.534217 2026] [security2:error] [pid 874439:tid 874685] [client 104.234.53.79:54887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMgwAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:08.575851 2026] [security2:error] [pid 874439:tid 874620] [client 27.96.94.195:37803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMkAAAADM"]
[Mon Jul 20 06:18:08.576066 2026] [security2:error] [pid 874439:tid 874620] [client 27.96.94.195:37803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMkAAAADM"]
[Mon Jul 20 06:18:08.682675 2026] [security2:error] [pid 871012:tid 871115] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SALwiU-Jh5ncAILFrOQABMWU"]
[Mon Jul 20 06:18:08.778569 2026] [security2:error] [pid 874439:tid 874662] [client 57.141.18.51:35168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLCQAAXSY"]
[Mon Jul 20 06:18:08.886119 2026] [security2:error] [pid 874439:tid 874632] [client 104.234.53.79:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMmgAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:08.894367 2026] [security2:error] [pid 871012:tid 871242] [client 14.225.17.146:61894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrIgAAAW0"], referer: http://sarahholyfield.com/wp
[Mon Jul 20 06:18:09.060526 2026] [security2:error] [pid 874439:tid 874488] [remote 35.245.65.174:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.65.245.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMpAAALzA"], referer: https://www.guidehunting.com/login
[Mon Jul 20 06:18:09.100059 2026] [security2:error] [pid 871012:tid 871218] [client 74.7.227.179:56412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrRwABVW4"], referer: https://tejasenvironmental.com/p=905261
[Mon Jul 20 06:18:09.171838 2026] [security2:error] [pid 874439:tid 874594] [client 14.225.17.146:52663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMpgAAABk"], referer: http://transparentservices.online/wp
[Mon Jul 20 06:18:09.235062 2026] [security2:error] [pid 871012:tid 871031] [remote 162.19.86.63:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SAbwiU-Jh5ncAILFrUwABNxE"]
[Mon Jul 20 06:18:09.329289 2026] [security2:error] [pid 874439:tid 874616] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMqAAAL14"], referer: https://guidehunting.com/admin
[Mon Jul 20 06:18:09.416694 2026] [security2:error] [pid 871012:tid 871132] [remote 47.86.33.52:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SAbwiU-Jh5ncAILFrVwABRHY"]
[Mon Jul 20 06:18:09.446306 2026] [security2:error] [pid 871012:tid 871057] [remote 162.19.86.63:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SAbwiU-Jh5ncAILFrWQABGCs"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:18:09.451726 2026] [security2:error] [pid 874439:tid 874569] [client 14.225.17.146:54027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMXAAAAAA"], referer: http://swafforddetailing.com/wp
[Mon Jul 20 06:18:09.520987 2026] [proxy:error] [pid 871012:tid 871224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:18:09.521066 2026] [proxy_http:error] [pid 871012:tid 871224] [client 23.180.120.147:40246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:18:09.521784 2026] [proxy:error] [pid 871012:tid 871224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:18:09.521828 2026] [proxy_http:error] [pid 871012:tid 871224] [client 23.180.120.147:40246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:18:09.743400 2026] [security2:error] [pid 871012:tid 871158] [client 66.249.70.130:50816] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.umatha.art"] [uri "/robots.txt"] [unique_id "al4SAbwiU-Jh5ncAILFrZgAAARk"]
[Mon Jul 20 06:18:09.948120 2026] [security2:error] [pid 874439:tid 874497] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SAY6ZSrFvCrJJhtQM0wAAPDk"]
[Mon Jul 20 06:18:09.948302 2026] [security2:error] [pid 874439:tid 874629] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SAY6ZSrFvCrJJhtQM0wAAPDk"]
[Mon Jul 20 06:18:10.039822 2026] [security2:error] [pid 874439:tid 874692] [client 57.141.18.11:60458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLcgAAe3M"]
[Mon Jul 20 06:18:10.097191 2026] [security2:error] [pid 874439:tid 874624] [client 57.141.18.10:38224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLbwAAN2Q"]
[Mon Jul 20 06:18:10.116094 2026] [security2:error] [pid 871012:tid 871259] [client 50.116.65.227:57452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SArwiU-Jh5ncAILFrawAAAX4"]
[Mon Jul 20 06:18:10.129170 2026] [security2:error] [pid 871012:tid 871255] [client 50.116.65.227:28106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SArwiU-Jh5ncAILFrbAAAAXo"]
[Mon Jul 20 06:18:10.273607 2026] [security2:error] [pid 874439:tid 874613] [client 185.132.186.88:35551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/baxa1.php7"] [unique_id "al4SAo6ZSrFvCrJJhtQM6gAAACw"]
[Mon Jul 20 06:18:10.556529 2026] [security2:error] [pid 871012:tid 871189] [client 104.222.171.226:30774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrRAABOAc"]
[Mon Jul 20 06:18:10.719813 2026] [security2:error] [pid 871012:tid 871050] [remote 47.86.33.52:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SArwiU-Jh5ncAILFrfQABfCQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:18:11.036493 2026] [security2:error] [pid 874439:tid 874608] [client 14.225.17.146:61799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMyQAAACc"]
[Mon Jul 20 06:18:11.037386 2026] [security2:error] [pid 871012:tid 871193] [client 14.225.17.146:52632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4SAbwiU-Jh5ncAILFrUQAAATw"], referer: http://aandarealtygroup.com/wp
[Mon Jul 20 06:18:11.201455 2026] [security2:error] [pid 871012:tid 871093] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SA7wiU-Jh5ncAILFrjAABck8"]
[Mon Jul 20 06:18:11.368242 2026] [security2:error] [pid 874439:tid 874514] [remote 35.245.65.174:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.65.245.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4SA46ZSrFvCrJJhtQNKwAAL0o"], referer: https://www.guidehunting.com/wp-admin/
[Mon Jul 20 06:18:11.570097 2026] [security2:error] [pid 874439:tid 874681] [client 14.225.17.146:52429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMwAAAAHA"], referer: http://narv.co/wp
[Mon Jul 20 06:18:11.902374 2026] [security2:error] [pid 874439:tid 874596] [client 171.60.139.123:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SA46ZSrFvCrJJhtQNTAAAABs"]
[Mon Jul 20 06:18:11.902520 2026] [security2:error] [pid 874439:tid 874596] [client 171.60.139.123:49853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SA46ZSrFvCrJJhtQNTAAAABs"]
[Mon Jul 20 06:18:11.954015 2026] [security2:error] [pid 871012:tid 871160] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SA7wiU-Jh5ncAILFrkwAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:12.070864 2026] [security2:error] [pid 874439:tid 874595] [client 185.132.186.89:38119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-taxonomy.editor.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNVQAAABo"]
[Mon Jul 20 06:18:12.112142 2026] [security2:error] [pid 871012:tid 871222] [client 112.208.70.94:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SBLwiU-Jh5ncAILFrowAAAVk"]
[Mon Jul 20 06:18:12.112269 2026] [security2:error] [pid 871012:tid 871222] [client 112.208.70.94:45838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SBLwiU-Jh5ncAILFrowAAAVk"]
[Mon Jul 20 06:18:12.131717 2026] [security2:error] [pid 874439:tid 874545] [remote 35.245.65.174:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.65.245.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNVgAADmk"], referer: https://www.guidehunting.com/wp-admin/
[Mon Jul 20 06:18:12.250552 2026] [security2:error] [pid 874439:tid 874535] [remote 45.90.123.233:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNZAAAcl8"]
[Mon Jul 20 06:18:12.337047 2026] [security2:error] [pid 874439:tid 874658] [client 63.176.132.15:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SA46ZSrFvCrJJhtQNOgAAAFk"]
[Mon Jul 20 06:18:12.391634 2026] [security2:error] [pid 874439:tid 874636] [client 63.176.132.15:12278] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/ensalada-de-coditos-puerto-rican-macaroni-salad/"] [unique_id "al4SA46ZSrFvCrJJhtQNNgAAAEM"]
[Mon Jul 20 06:18:12.535744 2026] [security2:error] [pid 871012:tid 871159] [client 57.141.18.70:47766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFq0QABGjo"]
[Mon Jul 20 06:18:12.626050 2026] [security2:error] [pid 874439:tid 874629] [client 14.225.17.146:51562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNcQAAADw"], referer: https://narv.co/wp
[Mon Jul 20 06:18:12.650370 2026] [security2:error] [pid 874439:tid 874580] [client 57.141.18.7:60294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL_wAAC3A"]
[Mon Jul 20 06:18:12.692738 2026] [autoindex:error] [pid 874439:tid 874646] [client 43.165.125.66:59536] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:18:12.704695 2026] [security2:error] [pid 874439:tid 874659] [client 45.116.69.230:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNfQAAAFo"]
[Mon Jul 20 06:18:12.704842 2026] [security2:error] [pid 874439:tid 874659] [client 45.116.69.230:57958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNfQAAAFo"]
[Mon Jul 20 06:18:12.725801 2026] [security2:error] [pid 871012:tid 871173] [client 57.141.18.78:34394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFq4QABKAY"]
[Mon Jul 20 06:18:13.093012 2026] [security2:error] [pid 874439:tid 874644] [client 103.141.108.143:60032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNjgAAAEs"]
[Mon Jul 20 06:18:13.093738 2026] [security2:error] [pid 874439:tid 874644] [client 103.141.108.143:60032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNjgAAAEs"]
[Mon Jul 20 06:18:13.434121 2026] [security2:error] [pid 871012:tid 871078] [remote 45.90.123.233:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr0AABE0A"]
[Mon Jul 20 06:18:13.434263 2026] [security2:error] [pid 871012:tid 871152] [client 45.90.123.233:55064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr0AABE0A"]
[Mon Jul 20 06:18:13.444922 2026] [security2:error] [pid 871012:tid 871250] [client 173.239.224.43:46993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4SBbwiU-Jh5ncAILFrzgAAAXU"]
[Mon Jul 20 06:18:13.869715 2026] [security2:error] [pid 874439:tid 874621] [client 185.132.186.100:22431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/dedi1.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNsQAAADQ"]
[Mon Jul 20 06:18:13.920730 2026] [security2:error] [pid 871012:tid 871023] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr3AABLgk"]
[Mon Jul 20 06:18:13.920890 2026] [security2:error] [pid 871012:tid 871179] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr3AABLgk"]
[Mon Jul 20 06:18:14.274815 2026] [security2:error] [pid 871012:tid 871186] [client 57.141.18.96:64664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrHwABNTU"]
[Mon Jul 20 06:18:14.365075 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:53809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SBo6ZSrFvCrJJhtQN3AAAAGw"]
[Mon Jul 20 06:18:14.365195 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:53809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SBo6ZSrFvCrJJhtQN3AAAAGw"]
[Mon Jul 20 06:18:14.378734 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:51829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4SBo6ZSrFvCrJJhtQNzQAAAFQ"], referer: http://taskidsvirginia.com/wp
[Mon Jul 20 06:18:14.741206 2026] [security2:error] [pid 874439:tid 874656] [client 14.225.17.146:51665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNjwAAAFc"], referer: http://laceycaraccident.com/wp
[Mon Jul 20 06:18:14.882072 2026] [security2:error] [pid 871012:tid 871144] [client 57.141.18.46:53510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrKQABCyE"]
[Mon Jul 20 06:18:15.147920 2026] [security2:error] [pid 871012:tid 871214] [client 57.141.18.119:30790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrNwABUSw"]
[Mon Jul 20 06:18:15.500885 2026] [security2:error] [pid 871012:tid 871191] [client 57.141.18.72:44020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SAbwiU-Jh5ncAILFrSwABOgU"]
[Mon Jul 20 06:18:15.657588 2026] [security2:error] [pid 874439:tid 874678] [client 185.132.186.104:21257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/wp-conflg.php"] [unique_id "al4SB46ZSrFvCrJJhtQOGAAAAG0"]
[Mon Jul 20 06:18:16.194321 2026] [security2:error] [pid 871012:tid 871258] [client 181.224.94.124:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SCLwiU-Jh5ncAILFsEAAAAX0"]
[Mon Jul 20 06:18:16.194434 2026] [security2:error] [pid 871012:tid 871258] [client 181.224.94.124:20910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SCLwiU-Jh5ncAILFsEAAAAX0"]
[Mon Jul 20 06:18:16.220891 2026] [security2:error] [pid 871012:tid 871218] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SCLwiU-Jh5ncAILFsCwAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:16.642387 2026] [security2:error] [pid 874439:tid 874612] [client 57.141.18.125:58548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SAo6ZSrFvCrJJhtQM-wAAK00"]
[Mon Jul 20 06:18:16.654138 2026] [security2:error] [pid 874439:tid 874599] [client 180.153.197.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SCI6ZSrFvCrJJhtQOSgAAHnE"], referer: https://www.aleishapenny.ca/listing/page/564?paged=1&view=grid&posts_per_page=48
[Mon Jul 20 06:18:17.406094 2026] [security2:error] [pid 874439:tid 874691] [client 66.249.65.168:53263] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "colliersgroup.com"] [uri "/robots.txt"] [unique_id "al4SCY6ZSrFvCrJJhtQOdAAAAHo"]
[Mon Jul 20 06:18:17.450907 2026] [security2:error] [pid 871012:tid 871182] [client 185.132.186.104:30437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/blog.php"] [unique_id "al4SCbwiU-Jh5ncAILFsNwAAATE"]
[Mon Jul 20 06:18:17.494460 2026] [security2:error] [pid 871012:tid 871145] [client 57.141.18.115:21310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SA7wiU-Jh5ncAILFrlAABDEI"]
[Mon Jul 20 06:18:17.637716 2026] [security2:error] [pid 874439:tid 874472] [remote 20.153.140.50:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SCY6ZSrFvCrJJhtQOewAAbCA"]
[Mon Jul 20 06:18:17.764690 2026] [security2:error] [pid 871012:tid 871135] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SCbwiU-Jh5ncAILFsOQABank"]
[Mon Jul 20 06:18:17.838792 2026] [security2:error] [pid 874439:tid 874635] [client 50.116.65.227:57484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SCY6ZSrFvCrJJhtQOiAAAAEI"]
[Mon Jul 20 06:18:17.849428 2026] [security2:error] [pid 874439:tid 874671] [client 50.116.65.227:28226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SCY6ZSrFvCrJJhtQOigAAAGY"]
[Mon Jul 20 06:18:18.019624 2026] [security2:error] [pid 874439:tid 874454] [remote 45.90.123.233:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOkgAAGQ4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:18.031772 2026] [security2:error] [pid 874439:tid 874492] [remote 20.153.140.50:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOlAAALjQ"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:18:18.103356 2026] [security2:error] [pid 871012:tid 871152] [client 216.73.217.138:43142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SCrwiU-Jh5ncAILFsQAABE2g"]
[Mon Jul 20 06:18:18.125584 2026] [security2:error] [pid 874439:tid 874449] [remote 45.90.123.233:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOmwAAOgk"]
[Mon Jul 20 06:18:18.184862 2026] [security2:error] [pid 874439:tid 874644] [client 14.225.17.146:61430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4SCY6ZSrFvCrJJhtQOhAAAAEs"], referer: http://idigress.studio/wp
[Mon Jul 20 06:18:18.243531 2026] [security2:error] [pid 871012:tid 871038] [remote 103.255.134.61:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SCrwiU-Jh5ncAILFsSAABQhg"]
[Mon Jul 20 06:18:18.362328 2026] [security2:error] [pid 874439:tid 874470] [remote 45.90.123.233:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOrwAAWR4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:18.750808 2026] [security2:error] [pid 874439:tid 874628] [client 104.234.53.65:29957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOvgAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:19.135717 2026] [security2:error] [pid 874439:tid 874488] [remote 68.178.160.25:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4SC46ZSrFvCrJJhtQO6AAAPDA"]
[Mon Jul 20 06:18:19.247685 2026] [security2:error] [pid 874439:tid 874606] [client 185.132.186.97:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/about/install.php"] [unique_id "al4SC46ZSrFvCrJJhtQO7AAAACU"]
[Mon Jul 20 06:18:19.520768 2026] [security2:error] [pid 874439:tid 874501] [remote 68.178.160.25:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4SC46ZSrFvCrJJhtQO-wAAOz0"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:18:19.697238 2026] [security2:error] [pid 874439:tid 874658] [client 27.96.94.195:37104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SC46ZSrFvCrJJhtQPBQAAAFk"]
[Mon Jul 20 06:18:19.697428 2026] [security2:error] [pid 874439:tid 874658] [client 27.96.94.195:37104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SC46ZSrFvCrJJhtQPBQAAAFk"]
[Mon Jul 20 06:18:20.052201 2026] [security2:error] [pid 874439:tid 874598] [client 14.225.17.146:51930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4SCY6ZSrFvCrJJhtQOjQAAAB0"], referer: http://cheesewithjam.com/wp
[Mon Jul 20 06:18:20.063034 2026] [security2:error] [pid 874439:tid 874596] [client 57.141.18.24:27950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNowAAGw8"]
[Mon Jul 20 06:18:20.273346 2026] [security2:error] [pid 871012:tid 871109] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4SDLwiU-Jh5ncAILFsfAABhl8"]
[Mon Jul 20 06:18:20.300741 2026] [security2:error] [pid 874439:tid 874623] [client 14.225.17.146:63089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPLgAAADY"], referer: http://careysheatingandcooling.com/wp
[Mon Jul 20 06:18:20.362738 2026] [security2:error] [pid 871012:tid 871030] [remote 103.255.134.61:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SDLwiU-Jh5ncAILFsfwABKBA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:18:20.538122 2026] [security2:error] [pid 871012:tid 871081] [remote 182.77.62.24:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SDLwiU-Jh5ncAILFshQABU0M"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:18:20.541541 2026] [security2:error] [pid 874439:tid 874527] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPSAAAYlc"]
[Mon Jul 20 06:18:20.541712 2026] [security2:error] [pid 874439:tid 874667] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPSAAAYlc"]
[Mon Jul 20 06:18:21.052920 2026] [security2:error] [pid 874439:tid 874691] [client 185.132.186.98:44211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/bypass.php"] [unique_id "al4SDY6ZSrFvCrJJhtQPYAAAAHo"]
[Mon Jul 20 06:18:21.069835 2026] [security2:error] [pid 874439:tid 874672] [client 114.119.155.126:46785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cloudspacesgroup.com"] [uri "/robots.txt"] [unique_id "al4SDY6ZSrFvCrJJhtQPYwAAAGc"], referer: http://cloudspacesgroup.com/robots.txt
[Mon Jul 20 06:18:21.864625 2026] [security2:error] [pid 871012:tid 871222] [client 104.234.53.78:28103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SDbwiU-Jh5ncAILFsoQAAAVk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:22.076946 2026] [security2:error] [pid 874439:tid 874475] [remote 124.55.178.99:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SDo6ZSrFvCrJJhtQPoAAADSM"]
[Mon Jul 20 06:18:22.165873 2026] [security2:error] [pid 874439:tid 874608] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SDY6ZSrFvCrJJhtQPmgAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:22.278602 2026] [security2:error] [pid 871012:tid 871111] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SDrwiU-Jh5ncAILFspwABJGE"]
[Mon Jul 20 06:18:22.284436 2026] [security2:error] [pid 874439:tid 874476] [remote 57.141.18.91:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4SDo6ZSrFvCrJJhtQPrQAACyQ"]
[Mon Jul 20 06:18:22.504531 2026] [security2:error] [pid 871012:tid 871167] [client 171.60.139.123:50362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SDrwiU-Jh5ncAILFsrQAAASI"]
[Mon Jul 20 06:18:22.504725 2026] [security2:error] [pid 871012:tid 871167] [client 171.60.139.123:50362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SDrwiU-Jh5ncAILFsrQAAASI"]
[Mon Jul 20 06:18:22.517308 2026] [security2:error] [pid 874439:tid 874492] [remote 124.55.178.99:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SDo6ZSrFvCrJJhtQPwgAALDQ"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:18:22.589802 2026] [security2:error] [pid 874439:tid 874620] [client 57.141.18.58:49988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCI6ZSrFvCrJJhtQOSQAAM2o"]
[Mon Jul 20 06:18:22.811158 2026] [security2:error] [pid 871012:tid 871164] [client 57.141.18.47:40692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCLwiU-Jh5ncAILFsIwABHzA"]
[Mon Jul 20 06:18:22.971373 2026] [security2:error] [pid 874439:tid 874595] [client 104.234.53.72:43815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SDo6ZSrFvCrJJhtQP4QAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:23.046226 2026] [security2:error] [pid 871012:tid 871076] [remote 182.77.62.24:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SD7wiU-Jh5ncAILFsvAABLj4"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:18:23.441346 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:58657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SD46ZSrFvCrJJhtQP9AAAACU"]
[Mon Jul 20 06:18:23.441439 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:58657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SD46ZSrFvCrJJhtQP9AAAACU"]
[Mon Jul 20 06:18:23.706695 2026] [security2:error] [pid 874439:tid 874661] [client 14.225.17.146:61559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4SD46ZSrFvCrJJhtQP-AAAAFw"], referer: http://elitetax-mi.com/wp
[Mon Jul 20 06:18:23.805053 2026] [security2:error] [pid 871012:tid 871246] [client 51.15.140.81:56698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4SD7wiU-Jh5ncAILFs1wAAAXE"]
[Mon Jul 20 06:18:23.866950 2026] [security2:error] [pid 874439:tid 874587] [client 57.141.18.22:32930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOmAAAEnw"]
[Mon Jul 20 06:18:23.912165 2026] [security2:error] [pid 874439:tid 874687] [client 185.132.186.96:46393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/chosen.php"] [unique_id "al4SD46ZSrFvCrJJhtQQDAAAAHY"]
[Mon Jul 20 06:18:23.935981 2026] [security2:error] [pid 871012:tid 871134] [remote 194.164.192.228:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SD7wiU-Jh5ncAILFs2AABJ3g"]
[Mon Jul 20 06:18:24.118968 2026] [security2:error] [pid 874439:tid 874612] [client 13.201.64.214:63170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQGQAAACs"]
[Mon Jul 20 06:18:24.119106 2026] [security2:error] [pid 874439:tid 874612] [client 13.201.64.214:63170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQGQAAACs"]
[Mon Jul 20 06:18:24.145291 2026] [security2:error] [pid 871012:tid 871075] [remote 194.164.192.228:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SELwiU-Jh5ncAILFs3gABVz0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:18:24.250157 2026] [security2:error] [pid 874439:tid 874591] [client 103.141.108.143:60507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQJgAAABY"]
[Mon Jul 20 06:18:24.250281 2026] [security2:error] [pid 874439:tid 874591] [client 103.141.108.143:60507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQJgAAABY"]
[Mon Jul 20 06:18:24.448245 2026] [security2:error] [pid 871012:tid 871201] [client 57.141.18.97:59060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCrwiU-Jh5ncAILFsVQABRFU"]
[Mon Jul 20 06:18:24.550149 2026] [security2:error] [pid 871012:tid 871044] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SELwiU-Jh5ncAILFs6AABhh4"]
[Mon Jul 20 06:18:24.550443 2026] [security2:error] [pid 871012:tid 871267] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SELwiU-Jh5ncAILFs6AABhh4"]
[Mon Jul 20 06:18:24.764276 2026] [security2:error] [pid 874439:tid 874685] [client 57.141.18.22:32940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOzQAAdDc"]
[Mon Jul 20 06:18:24.852058 2026] [security2:error] [pid 874439:tid 874633] [client 103.77.203.233:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQSAAAAEA"]
[Mon Jul 20 06:18:24.852192 2026] [security2:error] [pid 874439:tid 874633] [client 103.77.203.233:54351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQSAAAAEA"]
[Mon Jul 20 06:18:24.978404 2026] [security2:error] [pid 874439:tid 874609] [client 178.152.178.232:35842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQVQAAACg"]
[Mon Jul 20 06:18:24.985269 2026] [security2:error] [pid 874439:tid 874609] [client 178.152.178.232:35842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQVQAAACg"]
[Mon Jul 20 06:18:25.052533 2026] [security2:error] [pid 871012:tid 871174] [client 77.110.127.138:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SELwiU-Jh5ncAILFs8AAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.104408 2026] [security2:error] [pid 871012:tid 871186] [client 77.110.127.138:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/charity/6b4akeh9ddzd.php"] [unique_id "al4SEbwiU-Jh5ncAILFs-gAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.106694 2026] [security2:error] [pid 871012:tid 871166] [client 77.110.127.138:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4SEbwiU-Jh5ncAILFs-wAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.302051 2026] [security2:error] [pid 871012:tid 871157] [client 14.225.17.146:63063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtAgAAARg"], referer: http://alaraycreative.com/wp
[Mon Jul 20 06:18:25.339801 2026] [security2:error] [pid 871012:tid 871141] [remote 100.42.189.89:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SEbwiU-Jh5ncAILFtBgABYn8"]
[Mon Jul 20 06:18:25.347362 2026] [security2:error] [pid 871012:tid 871215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFs-AAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.441420 2026] [security2:error] [pid 874439:tid 874653] [client 77.110.127.138:59623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQbgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.443408 2026] [security2:error] [pid 871012:tid 871198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtAwAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.472448 2026] [security2:error] [pid 874439:tid 874614] [client 112.208.70.94:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQggAAAC0"]
[Mon Jul 20 06:18:25.472578 2026] [security2:error] [pid 874439:tid 874614] [client 112.208.70.94:42049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQggAAAC0"]
[Mon Jul 20 06:18:25.487225 2026] [security2:error] [pid 874439:tid 874678] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQdQAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.550526 2026] [security2:error] [pid 871012:tid 871058] [remote 100.42.189.89:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SEbwiU-Jh5ncAILFtDQABcyw"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:18:25.760889 2026] [security2:error] [pid 874439:tid 874662] [client 185.132.186.104:29467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/av.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQjAAAAF0"]
[Mon Jul 20 06:18:25.897579 2026] [security2:error] [pid 874439:tid 874644] [client 57.141.18.106:25802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPMwAAS28"]
[Mon Jul 20 06:18:26.021642 2026] [security2:error] [pid 874439:tid 874594] [client 14.225.17.146:49951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQTQAAABk"], referer: http://massagelacey.com/wp
[Mon Jul 20 06:18:26.218445 2026] [security2:error] [pid 874439:tid 874667] [client 14.225.17.146:52066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQIgAAAGI"], referer: http://mollycahill.com/wp
[Mon Jul 20 06:18:26.241440 2026] [security2:error] [pid 874439:tid 874540] [remote 192.241.143.148:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQqgAAPmQ"]
[Mon Jul 20 06:18:26.275126 2026] [security2:error] [pid 871012:tid 871176] [client 57.141.18.102:51366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDLwiU-Jh5ncAILFsiQABKwc"]
[Mon Jul 20 06:18:26.278479 2026] [security2:error] [pid 874439:tid 874691] [client 14.225.17.146:52075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQOAAAAHo"], referer: http://margaretspeckogawa.com/wp
[Mon Jul 20 06:18:26.343330 2026] [security2:error] [pid 874439:tid 874643] [client 77.110.127.138:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/cowl/dyh555y8ulcg.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQtQAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:26.419361 2026] [security2:error] [pid 874439:tid 874644] [client 50.116.65.227:21954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SEo6ZSrFvCrJJhtQQwwAAAEs"]
[Mon Jul 20 06:18:26.433461 2026] [security2:error] [pid 874439:tid 874582] [client 50.116.65.227:48584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SEo6ZSrFvCrJJhtQQyAAAAA0"]
[Mon Jul 20 06:18:26.452436 2026] [security2:error] [pid 874439:tid 874464] [remote 192.241.143.148:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQzgAAOhg"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:18:26.901243 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:49914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQ4gAAAEM"], referer: http://oldracelimited.com/wp
[Mon Jul 20 06:18:26.964288 2026] [security2:error] [pid 874439:tid 874651] [client 57.141.18.50:31092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDY6ZSrFvCrJJhtQPgwAAUno"]
[Mon Jul 20 06:18:27.106384 2026] [security2:error] [pid 874439:tid 874662] [client 181.224.94.124:34307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SE46ZSrFvCrJJhtQQ9QAAAF0"]
[Mon Jul 20 06:18:27.106519 2026] [security2:error] [pid 874439:tid 874662] [client 181.224.94.124:34307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SE46ZSrFvCrJJhtQQ9QAAAF0"]
[Mon Jul 20 06:18:27.409761 2026] [security2:error] [pid 871012:tid 871194] [client 172.59.220.76:1305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtIQABPUU"]
[Mon Jul 20 06:18:27.438065 2026] [security2:error] [pid 874439:tid 874654] [client 57.141.18.70:64962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDo6ZSrFvCrJJhtQPpAAAVSA"]
[Mon Jul 20 06:18:27.445342 2026] [security2:error] [pid 871012:tid 871194] [client 172.59.220.76:1305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtIAABPQw"]
[Mon Jul 20 06:18:27.454078 2026] [security2:error] [pid 874439:tid 874629] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQuAAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.586250 2026] [security2:error] [pid 874439:tid 874677] [client 77.110.127.138:59624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQvgAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.713951 2026] [security2:error] [pid 874439:tid 874638] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQzAAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.735258 2026] [security2:error] [pid 874439:tid 874669] [client 185.132.186.73:44885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/interactivity-api/interactivity-api-xml.php"] [unique_id "al4SE46ZSrFvCrJJhtQRHgAAAGQ"]
[Mon Jul 20 06:18:27.745421 2026] [security2:error] [pid 871012:tid 871145] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SErwiU-Jh5ncAILFtOwAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.756426 2026] [security2:error] [pid 874439:tid 874475] [remote 152.228.213.32:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SE46ZSrFvCrJJhtQRHwAALCM"]
[Mon Jul 20 06:18:27.946490 2026] [security2:error] [pid 874439:tid 874454] [remote 152.228.213.32:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SE46ZSrFvCrJJhtQRLwAADQ4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:28.254302 2026] [security2:error] [pid 871012:tid 871155] [client 57.141.18.23:21746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SD7wiU-Jh5ncAILFsvQABFgY"]
[Mon Jul 20 06:18:28.413491 2026] [security2:error] [pid 871012:tid 871234] [client 57.141.18.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtbgAAAWU"]
[Mon Jul 20 06:18:28.483946 2026] [security2:error] [pid 874439:tid 874602] [client 104.234.53.70:33723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRXgAAACE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:28.580645 2026] [security2:error] [pid 871012:tid 871203] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtZAAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:28.758900 2026] [security2:error] [pid 874439:tid 874625] [client 114.119.139.107:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/robots.txt"] [unique_id "al4SFI6ZSrFvCrJJhtQRcAAAADg"], referer: http://lakelopezonline.com/robots.txt
[Mon Jul 20 06:18:28.884699 2026] [security2:error] [pid 874439:tid 874582] [client 77.110.127.138:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/img_4196-2/mme2a5ginrc1.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRgAAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.098077 2026] [security2:error] [pid 871012:tid 871086] [remote 154.66.198.148:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SFbwiU-Jh5ncAILFtggABZEg"]
[Mon Jul 20 06:18:29.188950 2026] [security2:error] [pid 871012:tid 871199] [client 77.110.127.138:59681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtegAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.191709 2026] [security2:error] [pid 874439:tid 874693] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRigAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.193784 2026] [security2:error] [pid 871012:tid 871242] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtfQAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.223891 2026] [security2:error] [pid 874439:tid 874645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRlgAAAEw"]
[Mon Jul 20 06:18:29.230067 2026] [security2:error] [pid 874439:tid 874576] [client 14.225.17.146:54365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRRAAAAAc"], referer: http://intelligentengineeringsolutions.com/wp
[Mon Jul 20 06:18:29.266893 2026] [security2:error] [pid 874439:tid 874610] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFY6ZSrFvCrJJhtQRmAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.278989 2026] [security2:error] [pid 874439:tid 874604] [client 216.73.216.78:10513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/index.php"] [unique_id "al4SE46ZSrFvCrJJhtQRLAAAIyg"]
[Mon Jul 20 06:18:29.534746 2026] [ssl:error] [pid 874439:tid 874691] [client 104.48.69.105:60302] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:29.539888 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.53:25127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/colour.php"] [unique_id "al4SFY6ZSrFvCrJJhtQRxAAAAFQ"]
[Mon Jul 20 06:18:29.635010 2026] [security2:error] [pid 874439:tid 874570] [client 14.225.17.146:62355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4SFY6ZSrFvCrJJhtQRvQAAAAE"]
[Mon Jul 20 06:18:29.980518 2026] [security2:error] [pid 871012:tid 871223] [client 66.249.93.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4SFbwiU-Jh5ncAILFtjwAAAVo"]
[Mon Jul 20 06:18:29.997820 2026] [security2:error] [pid 871012:tid 871144] [client 104.234.53.55:20659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SFbwiU-Jh5ncAILFtmQAAAQs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:30.052941 2026] [security2:error] [pid 874439:tid 874628] [client 14.225.17.146:62673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4SFY6ZSrFvCrJJhtQR1gAAADs"], referer: http://ksands.co.uk/wp
[Mon Jul 20 06:18:30.117809 2026] [security2:error] [pid 871012:tid 871156] [client 68.235.52.68:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SFrwiU-Jh5ncAILFtnwAAARc"]
[Mon Jul 20 06:18:30.117920 2026] [security2:error] [pid 871012:tid 871156] [client 68.235.52.68:56126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SFrwiU-Jh5ncAILFtnwAAARc"]
[Mon Jul 20 06:18:30.231267 2026] [security2:error] [pid 874439:tid 874672] [client 158.173.166.181:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SFo6ZSrFvCrJJhtQR6AAAAGc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:30.251642 2026] [security2:error] [pid 874439:tid 874605] [client 57.141.18.76:30520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQQgAAJCI"]
[Mon Jul 20 06:18:30.323060 2026] [security2:error] [pid 874439:tid 874676] [client 57.141.18.107:61696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQRQAAazA"]
[Mon Jul 20 06:18:30.389623 2026] [security2:error] [pid 874439:tid 874685] [client 14.225.17.146:61986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRjQAAAHQ"], referer: http://detroitcsc.com/wp
[Mon Jul 20 06:18:30.394550 2026] [security2:error] [pid 871012:tid 871090] [remote 154.66.198.148:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SFrwiU-Jh5ncAILFtrQABXkw"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:18:30.607896 2026] [security2:error] [pid 871012:tid 871167] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFrwiU-Jh5ncAILFtrAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:30.930503 2026] [security2:error] [pid 874439:tid 874537] [remote 20.153.140.50:35638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SFo6ZSrFvCrJJhtQSEwAAL2E"]
[Mon Jul 20 06:18:31.127018 2026] [security2:error] [pid 874439:tid 874532] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSHQAABVw"]
[Mon Jul 20 06:18:31.127202 2026] [security2:error] [pid 874439:tid 874574] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSHQAABVw"]
[Mon Jul 20 06:18:31.357798 2026] [security2:error] [pid 874439:tid 874692] [client 185.132.186.66:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/elp.php"] [unique_id "al4SF46ZSrFvCrJJhtQSLAAAAHs"]
[Mon Jul 20 06:18:31.366055 2026] [security2:error] [pid 874439:tid 874466] [remote 20.153.140.50:35638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SF46ZSrFvCrJJhtQSLQAAABo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:31.421663 2026] [security2:error] [pid 874439:tid 874461] [remote 45.90.123.233:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SF46ZSrFvCrJJhtQSMwAAIBU"]
[Mon Jul 20 06:18:31.467104 2026] [security2:error] [pid 874439:tid 874612] [client 54.81.157.232:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SFo6ZSrFvCrJJhtQSDQAAACs"]
[Mon Jul 20 06:18:31.497203 2026] [security2:error] [pid 874439:tid 874598] [client 54.81.157.232:15810] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pegao-puerto-rican-crispy-rice/"] [unique_id "al4SFo6ZSrFvCrJJhtQSCAAAAB0"]
[Mon Jul 20 06:18:31.638301 2026] [security2:error] [pid 874439:tid 874469] [remote 45.90.123.233:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SF46ZSrFvCrJJhtQSPAAAMx0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:31.783402 2026] [security2:error] [pid 874439:tid 874604] [client 27.96.94.195:37688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSQQAAACM"]
[Mon Jul 20 06:18:31.783586 2026] [security2:error] [pid 874439:tid 874604] [client 27.96.94.195:37688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSQQAAACM"]
[Mon Jul 20 06:18:31.830261 2026] [security2:error] [pid 871012:tid 871034] [remote 47.86.33.52:41156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SF7wiU-Jh5ncAILFtzwABMhQ"]
[Mon Jul 20 06:18:32.020441 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.95:38012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQwgAATn0"]
[Mon Jul 20 06:18:32.177223 2026] [security2:error] [pid 871012:tid 871148] [client 145.223.130.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt3AABD0c"]
[Mon Jul 20 06:18:32.552134 2026] [security2:error] [pid 871012:tid 871210] [client 77.110.127.138:59663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt5AAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:32.589395 2026] [security2:error] [pid 871012:tid 871221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt6AAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:32.811449 2026] [security2:error] [pid 871012:tid 871161] [client 114.119.146.145:57631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "massagelacey.com"] [uri "/robots.txt"] [unique_id "al4SGLwiU-Jh5ncAILFt8gAAARw"], referer: https://massagelacey.com/robots.txt
[Mon Jul 20 06:18:32.861961 2026] [security2:error] [pid 871012:tid 871239] [client 54.158.124.211:45766] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt3wAAAWo"]
[Mon Jul 20 06:18:32.884874 2026] [security2:error] [pid 871012:tid 871103] [remote 5.161.225.162:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4SGLwiU-Jh5ncAILFt9AABglk"]
[Mon Jul 20 06:18:32.973160 2026] [security2:error] [pid 871012:tid 871159] [client 57.141.18.38:61634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SE7wiU-Jh5ncAILFtRgABGnU"]
[Mon Jul 20 06:18:33.042578 2026] [core:error] [pid 874439:tid 874679] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.042601 2026] [core:error] [pid 874439:tid 874679] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.079485 2026] [security2:error] [pid 874439:tid 874627] [client 171.60.139.123:51060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSgwAAADo"]
[Mon Jul 20 06:18:33.079645 2026] [security2:error] [pid 874439:tid 874627] [client 171.60.139.123:51060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSgwAAADo"]
[Mon Jul 20 06:18:33.141251 2026] [security2:error] [pid 871012:tid 871049] [remote 5.161.225.162:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4SGbwiU-Jh5ncAILFuBAABKiM"], referer: https://karimnawfal.com/wp-login.php
[Mon Jul 20 06:18:33.182262 2026] [security2:error] [pid 874439:tid 874594] [client 185.132.186.96:40595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-background-position-control-variable.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSiwAAABk"]
[Mon Jul 20 06:18:33.204065 2026] [core:error] [pid 874439:tid 874639] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.204096 2026] [core:error] [pid 874439:tid 874639] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.227773 2026] [security2:error] [pid 874439:tid 874651] [client 14.224.227.113:55629] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SGY6ZSrFvCrJJhtQSkwAAAFI"]
[Mon Jul 20 06:18:33.229460 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.229479 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.229569 2026] [core:error] [pid 874439:tid 874643] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.229589 2026] [core:error] [pid 874439:tid 874643] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.239858 2026] [security2:error] [pid 874439:tid 874610] [client 14.224.227.113:55631] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SGY6ZSrFvCrJJhtQSlgAAACk"]
[Mon Jul 20 06:18:33.285823 2026] [security2:error] [pid 871012:tid 871172] [client 14.224.227.113:55633] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SGbwiU-Jh5ncAILFuCAAAASc"]
[Mon Jul 20 06:18:33.338176 2026] [security2:error] [pid 874439:tid 874581] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4SGI6ZSrFvCrJJhtQScwAADH8"], referer: http://ali-alghanim.net/wp
[Mon Jul 20 06:18:33.411345 2026] [security2:error] [pid 874439:tid 874676] [client 37.59.204.159:44386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "innspace.ca"] [uri "/robots.txt"] [unique_id "al4SGY6ZSrFvCrJJhtQSpAAAAGs"]
[Mon Jul 20 06:18:33.411489 2026] [security2:error] [pid 874439:tid 874676] [client 37.59.204.159:44386] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "innspace.ca"] [uri "/robots.txt"] [unique_id "al4SGY6ZSrFvCrJJhtQSpAAAAGs"]
[Mon Jul 20 06:18:33.759940 2026] [security2:error] [pid 871012:tid 871224] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGbwiU-Jh5ncAILFuFAAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:33.763962 2026] [security2:error] [pid 871012:tid 871254] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGbwiU-Jh5ncAILFuFQAAAXk"], referer: https://mezzacraft.com/about-mezzacraft-crochet/
[Mon Jul 20 06:18:33.802387 2026] [security2:error] [pid 874439:tid 874638] [client 77.110.127.138:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/contact-me/feed/0uk8ftfxb98i.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSwwAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:33.830106 2026] [core:error] [pid 874439:tid 874672] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.830128 2026] [core:error] [pid 874439:tid 874672] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.910229 2026] [security2:error] [pid 871012:tid 871240] [client 57.141.18.37:25930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtaQABaxs"]
[Mon Jul 20 06:18:33.983554 2026] [autoindex:error] [pid 874439:tid 874633] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:18:34.096634 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS1gAAACU"]
[Mon Jul 20 06:18:34.096799 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:59200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS1gAAACU"]
[Mon Jul 20 06:18:34.116854 2026] [security2:error] [pid 871012:tid 871144] [client 50.116.65.227:59868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuKAAAAQs"]
[Mon Jul 20 06:18:34.122301 2026] [security2:error] [pid 874439:tid 874653] [client 14.224.227.113:58376] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4SGo6ZSrFvCrJJhtQS1wAAAFQ"]
[Mon Jul 20 06:18:34.127733 2026] [security2:error] [pid 871012:tid 871147] [client 50.116.65.227:35124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuKQAAAQ4"]
[Mon Jul 20 06:18:34.264849 2026] [security2:error] [pid 874439:tid 874548] [remote 216.73.216.55:34545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SGo6ZSrFvCrJJhtQS3AAAWGw"]
[Mon Jul 20 06:18:34.338021 2026] [security2:error] [pid 871012:tid 871251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGbwiU-Jh5ncAILFuJAAAAXY"]
[Mon Jul 20 06:18:34.452774 2026] [security2:error] [pid 871012:tid 871171] [client 103.141.108.143:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SGrwiU-Jh5ncAILFuMAAAASY"]
[Mon Jul 20 06:18:34.452893 2026] [security2:error] [pid 871012:tid 871171] [client 103.141.108.143:60982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SGrwiU-Jh5ncAILFuMAAAASY"]
[Mon Jul 20 06:18:34.526699 2026] [security2:error] [pid 874439:tid 874603] [client 14.225.17.146:51396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS3gAAACI"], referer: http://tacticaltreeoperations.com/wp
[Mon Jul 20 06:18:34.656951 2026] [security2:error] [pid 874439:tid 874522] [remote 57.141.18.86:64558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2898939"] [unique_id "al4SGo6ZSrFvCrJJhtQS7wAADVI"]
[Mon Jul 20 06:18:34.749516 2026] [security2:error] [pid 871012:tid 871203] [client 15.235.98.122:22774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "innspace.ca"] [uri "/"] [unique_id "al4SGrwiU-Jh5ncAILFuPgAAAUY"]
[Mon Jul 20 06:18:34.749626 2026] [security2:error] [pid 871012:tid 871203] [client 15.235.98.122:22774] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "innspace.ca"] [uri "/"] [unique_id "al4SGrwiU-Jh5ncAILFuPgAAAUY"]
[Mon Jul 20 06:18:34.791792 2026] [security2:error] [pid 871012:tid 871231] [client 57.141.18.72:21698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFbwiU-Jh5ncAILFtgQABYlo"]
[Mon Jul 20 06:18:34.923105 2026] [security2:error] [pid 871012:tid 871215] [client 74.208.214.194:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SGrwiU-Jh5ncAILFuQwAAAVI"]
[Mon Jul 20 06:18:34.924952 2026] [security2:error] [pid 871012:tid 871152] [client 50.116.65.227:59872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuRAAAARM"]
[Mon Jul 20 06:18:34.935723 2026] [security2:error] [pid 871012:tid 871224] [client 50.116.65.227:35164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuRgAAAQ8"]
[Mon Jul 20 06:18:35.107640 2026] [security2:error] [pid 871012:tid 871067] [remote 5.252.52.249:37852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4SG7wiU-Jh5ncAILFuTgABDDU"]
[Mon Jul 20 06:18:35.125511 2026] [security2:error] [pid 874439:tid 874612] [client 185.132.186.83:23647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/include.php"] [unique_id "al4SG46ZSrFvCrJJhtQTAwAAACs"]
[Mon Jul 20 06:18:35.146256 2026] [security2:error] [pid 871012:tid 871060] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuTwABMC4"]
[Mon Jul 20 06:18:35.146470 2026] [security2:error] [pid 871012:tid 871181] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuTwABMC4"]
[Mon Jul 20 06:18:35.515321 2026] [security2:error] [pid 874439:tid 874647] [client 103.77.203.233:54885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SG46ZSrFvCrJJhtQTHgAAAE4"]
[Mon Jul 20 06:18:35.515432 2026] [security2:error] [pid 874439:tid 874647] [client 103.77.203.233:54885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SG46ZSrFvCrJJhtQTHgAAAE4"]
[Mon Jul 20 06:18:35.610319 2026] [security2:error] [pid 871012:tid 871216] [client 178.152.178.232:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuWgAAAVM"]
[Mon Jul 20 06:18:35.610427 2026] [security2:error] [pid 871012:tid 871216] [client 178.152.178.232:37524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuWgAAAVM"]
[Mon Jul 20 06:18:35.897007 2026] [security2:error] [pid 871012:tid 871154] [client 57.141.18.74:22710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFrwiU-Jh5ncAILFtogABFVE"]
[Mon Jul 20 06:18:36.290126 2026] [security2:error] [pid 874439:tid 874628] [client 57.141.18.122:39116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFo6ZSrFvCrJJhtQSCQAAOxg"]
[Mon Jul 20 06:18:36.370307 2026] [security2:error] [pid 871012:tid 871258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SG7wiU-Jh5ncAILFuXwAAAX0"]
[Mon Jul 20 06:18:36.678962 2026] [core:error] [pid 874439:tid 874641] [client 14.225.17.146:50610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wp
[Mon Jul 20 06:18:36.678984 2026] [core:error] [pid 874439:tid 874641] [client 14.225.17.146:50610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wp
[Mon Jul 20 06:18:36.813483 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.24:58428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SF46ZSrFvCrJJhtQSJgAAP1o"]
[Mon Jul 20 06:18:36.931411 2026] [security2:error] [pid 874439:tid 874634] [client 185.132.186.75:42789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/av.php.php"] [unique_id "al4SHI6ZSrFvCrJJhtQTWAAAAEE"]
[Mon Jul 20 06:18:36.942546 2026] [security2:error] [pid 874439:tid 874532] [remote 57.141.18.56:32544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3042932"] [unique_id "al4SHI6ZSrFvCrJJhtQTWQAAHVw"]
[Mon Jul 20 06:18:37.009425 2026] [security2:error] [pid 871012:tid 871035] [remote 5.252.52.249:37852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4SHbwiU-Jh5ncAILFueAABcxU"], referer: https://stepupstepmom.com/wp-login.php
[Mon Jul 20 06:18:37.014193 2026] [security2:error] [pid 871012:tid 871155] [client 57.141.18.35:48772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SF7wiU-Jh5ncAILFtyQABFjY"]
[Mon Jul 20 06:18:37.147800 2026] [security2:error] [pid 874439:tid 874645] [client 18.140.64.130:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTZQAAAEw"]
[Mon Jul 20 06:18:37.210533 2026] [ssl:error] [pid 874439:tid 874628] [client 104.48.69.105:60312] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:37.300128 2026] [security2:error] [pid 874439:tid 874609] [client 181.224.94.124:42960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTcAAAACg"]
[Mon Jul 20 06:18:37.300306 2026] [security2:error] [pid 874439:tid 874609] [client 181.224.94.124:42960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTcAAAACg"]
[Mon Jul 20 06:18:37.384692 2026] [security2:error] [pid 871012:tid 871021] [remote 154.66.198.148:16064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SHbwiU-Jh5ncAILFugAABLQc"]
[Mon Jul 20 06:18:37.524569 2026] [security2:error] [pid 871012:tid 871169] [client 57.141.18.29:57908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SF7wiU-Jh5ncAILFt2AABJHs"]
[Mon Jul 20 06:18:38.097645 2026] [security2:error] [pid 871012:tid 871106] [remote 81.173.115.7:44814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SHrwiU-Jh5ncAILFukAABOlw"]
[Mon Jul 20 06:18:38.097804 2026] [security2:error] [pid 871012:tid 871191] [client 81.173.115.7:44814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SHrwiU-Jh5ncAILFukAABOlw"]
[Mon Jul 20 06:18:38.114843 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.107:57764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SGI6ZSrFvCrJJhtQSbAAAaDE"]
[Mon Jul 20 06:18:38.181823 2026] [security2:error] [pid 874439:tid 874608] [client 18.140.64.130:11508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SHo6ZSrFvCrJJhtQTnAAAACc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:18:38.202439 2026] [core:error] [pid 874439:tid 874626] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:38.202458 2026] [core:error] [pid 874439:tid 874626] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:38.216669 2026] [autoindex:error] [pid 874439:tid 874618] [client 188.166.209.66:49970] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:18:38.243416 2026] [security2:error] [pid 871012:tid 871026] [remote 154.66.198.148:16064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SHrwiU-Jh5ncAILFulAABbgw"], referer: https://amalia-capital.com/wp-login.php
[Mon Jul 20 06:18:38.286570 2026] [ssl:error] [pid 874439:tid 874591] [client 104.48.69.105:39900] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:38.380151 2026] [security2:error] [pid 871012:tid 871256] [client 57.141.18.73:27496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt9QABe0o"]
[Mon Jul 20 06:18:38.703028 2026] [security2:error] [pid 874439:tid 874626] [client 185.132.186.94:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd-1/install.php"] [unique_id "al4SHo6ZSrFvCrJJhtQTuwAAADk"]
[Mon Jul 20 06:18:39.117779 2026] [security2:error] [pid 874439:tid 874623] [client 104.234.53.78:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SH46ZSrFvCrJJhtQT0QAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:39.167973 2026] [security2:error] [pid 871012:tid 871038] [remote 18.61.192.253:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4SH7wiU-Jh5ncAILFupwABcBg"]
[Mon Jul 20 06:18:39.168229 2026] [security2:error] [pid 871012:tid 871245] [client 18.61.192.253:53138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4SH7wiU-Jh5ncAILFupwABcBg"]
[Mon Jul 20 06:18:39.259893 2026] [security2:error] [pid 874439:tid 874643] [client 14.225.17.146:55708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTiwAAAEo"], referer: http://iagdevelopments.com/wp
[Mon Jul 20 06:18:39.624070 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:42406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SH46ZSrFvCrJJhtQT6gAAAHY"]
[Mon Jul 20 06:18:39.624198 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:42406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SH46ZSrFvCrJJhtQT6gAAAHY"]
[Mon Jul 20 06:18:39.664322 2026] [core:error] [pid 871012:tid 871165] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:39.664345 2026] [core:error] [pid 871012:tid 871165] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:39.967339 2026] [security2:error] [pid 871012:tid 871086] [remote 103.82.22.235:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SH7wiU-Jh5ncAILFuxAABfEg"]
[Mon Jul 20 06:18:40.161084 2026] [security2:error] [pid 874439:tid 874691] [client 14.225.17.146:60552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4SHo6ZSrFvCrJJhtQTswAAAHo"], referer: http://olearyplumbingllc.com/wp
[Mon Jul 20 06:18:40.221838 2026] [security2:error] [pid 874439:tid 874604] [client 14.225.17.146:64137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4SII6ZSrFvCrJJhtQUBQAAACM"], referer: https://iagdevelopments.com/wp
[Mon Jul 20 06:18:40.544340 2026] [security2:error] [pid 871012:tid 871268] [client 14.175.181.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4SHrwiU-Jh5ncAILFuoQAAAYc"]
[Mon Jul 20 06:18:40.563200 2026] [security2:error] [pid 874439:tid 874647] [client 185.132.186.69:40525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/imgareaselect/wp-login.php"] [unique_id "al4SII6ZSrFvCrJJhtQUHgAAAE4"]
[Mon Jul 20 06:18:40.595769 2026] [security2:error] [pid 871012:tid 871031] [remote 103.82.22.235:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SILwiU-Jh5ncAILFu0QABWhE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:18:40.680889 2026] [security2:error] [pid 871012:tid 871061] [remote 115.74.105.156:60870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SILwiU-Jh5ncAILFu1AABHS8"]
[Mon Jul 20 06:18:40.686567 2026] [security2:error] [pid 874439:tid 874526] [remote 194.164.192.228:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SII6ZSrFvCrJJhtQUMgAAb1Y"]
[Mon Jul 20 06:18:40.686758 2026] [security2:error] [pid 874439:tid 874680] [client 194.164.192.228:37154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SII6ZSrFvCrJJhtQUMgAAb1Y"]
[Mon Jul 20 06:18:40.814608 2026] [security2:error] [pid 871012:tid 871132] [remote 173.212.252.15:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SILwiU-Jh5ncAILFu2QABdnY"]
[Mon Jul 20 06:18:40.892953 2026] [security2:error] [pid 874439:tid 874693] [client 57.141.18.13:38806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS-gAAfDc"]
[Mon Jul 20 06:18:41.113526 2026] [security2:error] [pid 874439:tid 874509] [remote 20.153.140.50:49700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUTAAAWkU"]
[Mon Jul 20 06:18:41.138879 2026] [security2:error] [pid 874439:tid 874452] [remote 100.42.189.89:41710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUTQAANgw"]
[Mon Jul 20 06:18:41.159306 2026] [security2:error] [pid 871012:tid 871030] [remote 173.212.252.15:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SIbwiU-Jh5ncAILFu5AABTxA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:18:41.342026 2026] [security2:error] [pid 874439:tid 874683] [client 45.157.112.60:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUUgAAAHI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:41.360104 2026] [security2:error] [pid 874439:tid 874534] [remote 100.42.189.89:41710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUVAAAMl4"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 06:18:41.499822 2026] [security2:error] [pid 874439:tid 874473] [remote 5.161.225.162:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUYAAAOSE"]
[Mon Jul 20 06:18:41.592234 2026] [security2:error] [pid 874439:tid 874640] [client 50.116.65.227:33616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SIY6ZSrFvCrJJhtQUZgAAAEc"]
[Mon Jul 20 06:18:41.606782 2026] [security2:error] [pid 874439:tid 874644] [client 50.116.65.227:33622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SIY6ZSrFvCrJJhtQUZwAAAEs"]
[Mon Jul 20 06:18:41.652859 2026] [security2:error] [pid 874439:tid 874605] [client 57.141.18.57:47692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SG46ZSrFvCrJJhtQTKwAAJDk"]
[Mon Jul 20 06:18:41.677290 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:50116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4SII6ZSrFvCrJJhtQUPQAAAHY"]
[Mon Jul 20 06:18:41.710135 2026] [security2:error] [pid 871012:tid 871240] [client 14.251.3.155:55656] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SIbwiU-Jh5ncAILFu7wAAAWs"]
[Mon Jul 20 06:18:41.717292 2026] [security2:error] [pid 871012:tid 871178] [client 14.224.227.113:55655] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SIbwiU-Jh5ncAILFu8AAAAS0"]
[Mon Jul 20 06:18:41.718499 2026] [security2:error] [pid 874439:tid 874501] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUbAAAOj0"]
[Mon Jul 20 06:18:41.718698 2026] [security2:error] [pid 874439:tid 874627] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUbAAAOj0"]
[Mon Jul 20 06:18:41.747136 2026] [security2:error] [pid 874439:tid 874539] [remote 5.161.225.162:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUbgAAemM"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 06:18:41.753111 2026] [security2:error] [pid 874439:tid 874574] [client 14.224.227.113:55657] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SIY6ZSrFvCrJJhtQUbwAAAAU"]
[Mon Jul 20 06:18:42.497646 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SIo6ZSrFvCrJJhtQUjQAAAAI"]
[Mon Jul 20 06:18:42.745632 2026] [security2:error] [pid 871012:tid 871222] [client 50.116.65.227:44272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SIrwiU-Jh5ncAILFvAQAAAVk"]
[Mon Jul 20 06:18:42.757910 2026] [security2:error] [pid 874439:tid 874615] [client 50.116.65.227:33668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SIo6ZSrFvCrJJhtQUpAAAAC4"]
[Mon Jul 20 06:18:42.982687 2026] [security2:error] [pid 871012:tid 871160] [client 104.234.53.58:39379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SIrwiU-Jh5ncAILFvCgAAARs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:43.055012 2026] [security2:error] [pid 871012:tid 871236] [client 216.73.217.138:33816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SIrwiU-Jh5ncAILFvBwABZ08"]
[Mon Jul 20 06:18:43.240664 2026] [security2:error] [pid 874439:tid 874586] [client 50.116.65.227:33660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4SIo6ZSrFvCrJJhtQUmgAAABE"]
[Mon Jul 20 06:18:43.374945 2026] [security2:error] [pid 874439:tid 874678] [client 185.132.186.57:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/upload/bilder/cong.php"] [unique_id "al4SI46ZSrFvCrJJhtQUwwAAAG0"]
[Mon Jul 20 06:18:43.609696 2026] [security2:error] [pid 874439:tid 874622] [client 57.141.18.114:43226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SHY6ZSrFvCrJJhtQThQAANR8"]
[Mon Jul 20 06:18:43.721722 2026] [security2:error] [pid 874439:tid 874679] [client 171.60.139.123:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SI46ZSrFvCrJJhtQU0gAAAG4"]
[Mon Jul 20 06:18:43.721907 2026] [security2:error] [pid 874439:tid 874679] [client 171.60.139.123:51774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SI46ZSrFvCrJJhtQU0gAAAG4"]
[Mon Jul 20 06:18:43.784730 2026] [security2:error] [pid 874439:tid 874587] [client 14.225.17.146:56156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUyQAAABI"], referer: http://nwcarvingacademy.com/wp
[Mon Jul 20 06:18:43.844499 2026] [security2:error] [pid 874439:tid 874631] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUzQAAPmE"], referer: http://aleishapenny.ca/wp
[Mon Jul 20 06:18:43.856894 2026] [security2:error] [pid 874439:tid 874603] [client 57.141.18.20:52040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTjQAAInU"]
[Mon Jul 20 06:18:43.961816 2026] [security2:error] [pid 874439:tid 874573] [client 98.159.234.160:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SI46ZSrFvCrJJhtQU3QAAAAQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:44.015676 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:50644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4SI7wiU-Jh5ncAILFvLQAAAWk"], referer: http://dasmarque.com/wp
[Mon Jul 20 06:18:44.034568 2026] [security2:error] [pid 874439:tid 874673] [client 50.116.65.227:33684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUvAAAAGg"]
[Mon Jul 20 06:18:44.471833 2026] [security2:error] [pid 874439:tid 874508] [remote 57.141.18.56:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2898939"] [unique_id "al4SJI6ZSrFvCrJJhtQU-gAANUQ"]
[Mon Jul 20 06:18:44.660764 2026] [security2:error] [pid 874439:tid 874674] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVAAAAaX4"], referer: https://aleishapenny.ca/wp
[Mon Jul 20 06:18:44.738127 2026] [security2:error] [pid 874439:tid 874489] [remote 45.90.123.233:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVDgAADTE"]
[Mon Jul 20 06:18:44.755335 2026] [security2:error] [pid 874439:tid 874583] [client 45.116.69.230:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVEQAAAA4"]
[Mon Jul 20 06:18:44.757158 2026] [security2:error] [pid 874439:tid 874583] [client 45.116.69.230:59739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVEQAAAA4"]
[Mon Jul 20 06:18:44.929362 2026] [security2:error] [pid 871012:tid 871113] [remote 160.187.68.132:36474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJLwiU-Jh5ncAILFvRwABfGM"]
[Mon Jul 20 06:18:44.943042 2026] [security2:error] [pid 874439:tid 874481] [remote 45.90.123.233:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVGwAAQSk"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 06:18:45.086600 2026] [security2:error] [pid 874439:tid 874610] [client 14.225.17.146:62016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVFgAAACk"], referer: https://nwcarvingacademy.com/wp
[Mon Jul 20 06:18:45.100208 2026] [security2:error] [pid 871012:tid 871185] [client 103.141.108.143:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SJbwiU-Jh5ncAILFvUQAAATQ"]
[Mon Jul 20 06:18:45.100893 2026] [security2:error] [pid 871012:tid 871185] [client 103.141.108.143:61454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SJbwiU-Jh5ncAILFvUQAAATQ"]
[Mon Jul 20 06:18:45.156308 2026] [security2:error] [pid 874439:tid 874627] [client 14.225.17.146:55684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVHgAAADo"]
[Mon Jul 20 06:18:45.335688 2026] [security2:error] [pid 874439:tid 874586] [client 14.225.17.146:60666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVKQAAABE"], referer: http://nextlvlmarketingco.com/wp
[Mon Jul 20 06:18:45.447881 2026] [security2:error] [pid 874439:tid 874670] [client 14.225.17.146:60574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVHwAAAGU"], referer: http://backandneckpainrelieflaceychiropractor.com/wp
[Mon Jul 20 06:18:45.458699 2026] [security2:error] [pid 871012:tid 871087] [remote 160.187.68.132:36474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJbwiU-Jh5ncAILFvVgABLUk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:45.463022 2026] [security2:error] [pid 874439:tid 874591] [client 57.141.18.31:21596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SH46ZSrFvCrJJhtQT5wAAFhA"]
[Mon Jul 20 06:18:45.530673 2026] [security2:error] [pid 874439:tid 874598] [client 27.96.94.195:37136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVOgAAAB0"]
[Mon Jul 20 06:18:45.530809 2026] [security2:error] [pid 874439:tid 874598] [client 27.96.94.195:37136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVOgAAAB0"]
[Mon Jul 20 06:18:45.552258 2026] [security2:error] [pid 874439:tid 874440] [remote 167.233.114.32:42036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVQAAAdgA"]
[Mon Jul 20 06:18:45.579134 2026] [security2:error] [pid 874439:tid 874621] [client 14.225.17.146:50680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU4gAAADQ"], referer: http://blaizeaccountingservices.com/wp
[Mon Jul 20 06:18:45.806186 2026] [security2:error] [pid 874439:tid 874450] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVRwAAfAo"]
[Mon Jul 20 06:18:45.806318 2026] [security2:error] [pid 874439:tid 874693] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVRwAAfAo"]
[Mon Jul 20 06:18:45.887863 2026] [security2:error] [pid 874439:tid 874567] [remote 167.233.114.32:42036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVSgAAe38"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:45.969409 2026] [security2:error] [pid 874439:tid 874623] [client 14.225.17.146:61969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU9AAAADY"]
[Mon Jul 20 06:18:45.977543 2026] [security2:error] [pid 874439:tid 874669] [client 103.77.203.233:55465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVUQAAAGQ"]
[Mon Jul 20 06:18:45.977743 2026] [security2:error] [pid 874439:tid 874669] [client 103.77.203.233:55465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVUQAAAGQ"]
[Mon Jul 20 06:18:46.030926 2026] [security2:error] [pid 874439:tid 874688] [client 57.141.18.2:42632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SII6ZSrFvCrJJhtQUDwAAd0E"]
[Mon Jul 20 06:18:46.209282 2026] [security2:error] [pid 871012:tid 871172] [client 185.132.186.98:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/pass.php"] [unique_id "al4SJrwiU-Jh5ncAILFvawAAASc"]
[Mon Jul 20 06:18:46.223966 2026] [security2:error] [pid 874439:tid 874564] [remote 20.153.140.50:58650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVWwAAQnw"]
[Mon Jul 20 06:18:46.254859 2026] [security2:error] [pid 871012:tid 871235] [client 74.208.214.194:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SJrwiU-Jh5ncAILFvbwAAAWY"]
[Mon Jul 20 06:18:46.318154 2026] [security2:error] [pid 874439:tid 874574] [client 178.152.178.232:36097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVYAAAAAU"]
[Mon Jul 20 06:18:46.318311 2026] [security2:error] [pid 874439:tid 874574] [client 178.152.178.232:36097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVYAAAAAU"]
[Mon Jul 20 06:18:46.569130 2026] [core:error] [pid 874439:tid 874690] [client 14.225.17.146:55824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:46.569152 2026] [core:error] [pid 874439:tid 874690] [client 14.225.17.146:55824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:46.703699 2026] [security2:error] [pid 874439:tid 874504] [remote 20.153.140.50:58650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVbQAAEkA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:46.761357 2026] [security2:error] [pid 871012:tid 871162] [client 104.234.53.78:55125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SJrwiU-Jh5ncAILFvewAAAR0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:46.787590 2026] [security2:error] [pid 871012:tid 871258] [client 57.141.18.104:47654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SIbwiU-Jh5ncAILFu4QABfT8"]
[Mon Jul 20 06:18:47.038966 2026] [security2:error] [pid 871012:tid 871183] [client 14.225.17.146:55700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4SJbwiU-Jh5ncAILFvVQAAATI"], referer: http://maplerespiteservices.com/wp
[Mon Jul 20 06:18:47.146844 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:55932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVaAAAAA0"], referer: http://waterproofgoods.com/wp
[Mon Jul 20 06:18:47.826780 2026] [security2:error] [pid 871012:tid 871169] [client 181.224.94.124:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvnQAAASQ"]
[Mon Jul 20 06:18:47.826893 2026] [security2:error] [pid 871012:tid 871169] [client 181.224.94.124:7695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvnQAAASQ"]
[Mon Jul 20 06:18:47.981837 2026] [security2:error] [pid 871012:tid 871204] [client 185.132.186.77:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/class-wp-translations-interface.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvoAAAAUc"]
[Mon Jul 20 06:18:48.026780 2026] [security2:error] [pid 871012:tid 871176] [client 57.141.18.120:47658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SIrwiU-Jh5ncAILFu9wABK2U"]
[Mon Jul 20 06:18:48.343285 2026] [security2:error] [pid 871012:tid 871035] [remote 81.173.115.7:45210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SKLwiU-Jh5ncAILFvpwABRRU"]
[Mon Jul 20 06:18:48.349685 2026] [security2:error] [pid 871012:tid 871163] [client 14.225.17.146:56202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvjwAAAR4"], referer: http://retzkolonglogistics.com/wp
[Mon Jul 20 06:18:48.786817 2026] [security2:error] [pid 871012:tid 871063] [remote 81.173.115.7:45210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SKLwiU-Jh5ncAILFvtQABeDE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:18:49.201356 2026] [autoindex:error] [pid 874439:tid 874668] [client 146.112.163.57:27143] AH01276: Cannot serve directory /home2/yfqjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:18:49.254074 2026] [security2:error] [pid 874439:tid 874694] [client 57.141.18.41:55698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUxQAAfTY"]
[Mon Jul 20 06:18:49.298193 2026] [ssl:error] [pid 874439:tid 874619] [client 54.86.115.253:27203] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.skiboutiques.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:49.593968 2026] [security2:error] [pid 871012:tid 871029] [remote 173.212.252.15:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4SKbwiU-Jh5ncAILFvxQABPQ8"]
[Mon Jul 20 06:18:49.770463 2026] [security2:error] [pid 874439:tid 874571] [client 185.132.186.74:48017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/about5.php"] [unique_id "al4SKY6ZSrFvCrJJhtQWAgAAAAI"]
[Mon Jul 20 06:18:49.774727 2026] [security2:error] [pid 871012:tid 871196] [client 57.141.18.78:65494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SI7wiU-Jh5ncAILFvKAABPzA"]
[Mon Jul 20 06:18:49.977795 2026] [security2:error] [pid 871012:tid 871098] [remote 173.212.252.15:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4SKbwiU-Jh5ncAILFv0QABG1Q"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:18:50.039934 2026] [security2:error] [pid 874439:tid 874653] [client 57.141.18.84:41874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU3wAAVA0"]
[Mon Jul 20 06:18:50.354042 2026] [security2:error] [pid 874439:tid 874586] [client 50.116.65.227:55168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SKo6ZSrFvCrJJhtQWHAAAABE"]
[Mon Jul 20 06:18:50.368979 2026] [security2:error] [pid 874439:tid 874659] [client 50.116.65.227:29192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SKo6ZSrFvCrJJhtQWHQAAAFo"]
[Mon Jul 20 06:18:50.422137 2026] [security2:error] [pid 874439:tid 874651] [client 57.141.18.20:29938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU8gAAUno"]
[Mon Jul 20 06:18:50.437342 2026] [security2:error] [pid 871012:tid 871222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SKrwiU-Jh5ncAILFv1QAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:50.684837 2026] [security2:error] [pid 874439:tid 874640] [client 57.141.18.77:50334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVCgAARx0"]
[Mon Jul 20 06:18:51.012918 2026] [security2:error] [pid 874439:tid 874574] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SKo6ZSrFvCrJJhtQWMAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:51.028124 2026] [security2:error] [pid 874439:tid 874598] [client 124.243.178.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4SKI6ZSrFvCrJJhtQVsgAAHW0"]
[Mon Jul 20 06:18:51.046264 2026] [security2:error] [pid 874439:tid 874670] [client 114.119.144.132:56851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lutheranphilosopher.com"] [uri "/apps/members/membersList%3Bjsessionid=FE2B321CE0CEF378F3DBE62DAD1F077C"] [unique_id "al4SK46ZSrFvCrJJhtQWQgAAAGU"], referer: https://www.lutheranphilosopher.com/apps/members/membersList%3Bjsessionid=822B28D6867DCAC2CFBA9C8AF108AD91?offset=1&q&sort=DISPLAY_NAME&view=list
[Mon Jul 20 06:18:51.416393 2026] [security2:error] [pid 874439:tid 874524] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/price-table.js"] [unique_id "al4SK46ZSrFvCrJJhtQWUwAAZFQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.440040 2026] [security2:error] [pid 871012:tid 871071] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/jquery-migrate.js"] [unique_id "al4SK7wiU-Jh5ncAILFv-gABDDk"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.440879 2026] [security2:error] [pid 874439:tid 874456] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/owl.carousel.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWVQAAABA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.442626 2026] [security2:error] [pid 871012:tid 871064] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.js"] [unique_id "al4SK7wiU-Jh5ncAILFv-wABaTI"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.443323 2026] [security2:error] [pid 871012:tid 871120] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/jquery.js"] [unique_id "al4SK7wiU-Jh5ncAILFv_AABP2o"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.444280 2026] [security2:error] [pid 871012:tid 871082] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/allscripts.js"] [unique_id "al4SK7wiU-Jh5ncAILFv_QABcUQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.454852 2026] [security2:error] [pid 874439:tid 874521] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/wp-social/assets/js/front-main.js"] [unique_id "al4SK46ZSrFvCrJJhtQWWAAAaVE"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.455693 2026] [security2:error] [pid 874439:tid 874440] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/wp-social/assets/js/social-front.js"] [unique_id "al4SK46ZSrFvCrJJhtQWWQAAaQA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.459970 2026] [security2:error] [pid 871012:tid 871033] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.js"] [unique_id "al4SK7wiU-Jh5ncAILFv_wABShM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.461550 2026] [security2:error] [pid 871012:tid 871119] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAAABG2k"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.476536 2026] [security2:error] [pid 874439:tid 874554] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/jquery.easing.1.3.js"] [unique_id "al4SK46ZSrFvCrJJhtQWWwAAJXI"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.477504 2026] [security2:error] [pid 871012:tid 871086] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/wp-util.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAQABR0g"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.477862 2026] [security2:error] [pid 871012:tid 871065] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAgABdDM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.480661 2026] [security2:error] [pid 871012:tid 871102] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/themes/hello-elementor/assets/js/hello-frontend.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAwABR1g"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483225 2026] [security2:error] [pid 871012:tid 871124] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/hooks.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBQABR24"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483226 2026] [security2:error] [pid 874439:tid 874486] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/i18n.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXAAAey4"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483483 2026] [security2:error] [pid 871012:tid 871025] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/underscore.min.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBAABRws"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483816 2026] [security2:error] [pid 874439:tid 874484] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/frontend.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXQAANCw"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.485885 2026] [security2:error] [pid 874439:tid 874470] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/jquery.superslides.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXwAAex4"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.486112 2026] [security2:error] [pid 874439:tid 874484] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-consent-mode-86cb52dcb9f2b27ed244.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYAAANCw"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.486896 2026] [security2:error] [pid 874439:tid 874492] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/cookiez/assets/build/banner.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXgAAezQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.488187 2026] [security2:error] [pid 871012:tid 871122] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/webpack.runtime.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBgABGGw"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.489729 2026] [security2:error] [pid 874439:tid 874450] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/ui/autocomplete.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYgAANAo"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.490056 2026] [security2:error] [pid 874439:tid 874499] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/lib/swiper/v8/swiper.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYQAANDs"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.491677 2026] [security2:error] [pid 874439:tid 874490] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/a11y.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYwAANDI"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.492455 2026] [security2:error] [pid 871012:tid 871031] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/js/tourfic-scripts.min.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBwABCxE"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.492716 2026] [security2:error] [pid 874439:tid 874567] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widgets/nav-menu.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZAAAGX8"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.493136 2026] [security2:error] [pid 871012:tid 871061] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widgets/core.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCAABCy8"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.496282 2026] [security2:error] [pid 874439:tid 874479] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/frontend-modules.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZQAAGSc"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.496888 2026] [security2:error] [pid 871012:tid 871132] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/js/elements-handlers.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCQABMXY"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.500050 2026] [security2:error] [pid 871012:tid 871015] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/metform/public/assets/lib/cute-alert/cute-alert.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCgABKwE"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.500773 2026] [security2:error] [pid 874439:tid 874487] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZgAASy8"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.503085 2026] [security2:error] [pid 874439:tid 874477] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/wp-whatsapp-chat/build/frontend/js/index.js"] [unique_id "al4SK46ZSrFvCrJJhtQWagAAOSU"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.503147 2026] [security2:error] [pid 871012:tid 871057] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/flatpickr/flatpickr.min.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCwABKys"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.503147 2026] [security2:error] [pid 874439:tid 874547] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/sourcebuster/sourcebuster.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZwAAS2s"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.504306 2026] [security2:error] [pid 874439:tid 874496] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/slick/slick.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWaQAAOTg"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.506493 2026] [security2:error] [pid 871012:tid 871129] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/ui/menu.js"] [unique_id "al4SK7wiU-Jh5ncAILFwDAABOHM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.507199 2026] [security2:error] [pid 874439:tid 874459] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/leaflet/leaflet.js"] [unique_id "al4SK46ZSrFvCrJJhtQWawAAfxM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.508851 2026] [security2:error] [pid 874439:tid 874564] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/js/frontend.js"] [unique_id "al4SK46ZSrFvCrJJhtQWbAAAf3w"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.509032 2026] [security2:error] [pid 871012:tid 871030] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.js"] [unique_id "al4SK7wiU-Jh5ncAILFwDQABaBA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.509168 2026] [security2:error] [pid 874439:tid 874694] [client 104.234.53.76:45053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SK46ZSrFvCrJJhtQWbQAAAH0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:51.514025 2026] [security2:error] [pid 874439:tid 874516] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/range-slider/al-range-slider.js"] [unique_id "al4SK46ZSrFvCrJJhtQWbgAAY0w"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.515977 2026] [security2:error] [pid 874439:tid 874510] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/fancybox/jquery.fancybox.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWbwAAaEY"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.567638 2026] [security2:error] [pid 871012:tid 871257] [client 185.132.186.62:52067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/lint-branch.php"] [unique_id "al4SK7wiU-Jh5ncAILFwDwAAAXw"]
[Mon Jul 20 06:18:51.735555 2026] [security2:error] [pid 874439:tid 874531] [remote 81.173.115.7:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4SK46ZSrFvCrJJhtQWdQAAdFs"]
[Mon Jul 20 06:18:51.843599 2026] [security2:error] [pid 871012:tid 871108] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.js"] [unique_id "al4SK7wiU-Jh5ncAILFwEgABHV4"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.890358 2026] [security2:error] [pid 874439:tid 874504] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/dom-ready.js"] [unique_id "al4SK46ZSrFvCrJJhtQWfgAAAUA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.897540 2026] [security2:error] [pid 874439:tid 874515] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/notyf/notyf.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWfwAALUs"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.921456 2026] [security2:error] [pid 871012:tid 871081] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/ui/core.js"] [unique_id "al4SK7wiU-Jh5ncAILFwFgABKUM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.929643 2026] [security2:error] [pid 874439:tid 874526] [remote 81.173.115.7:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4SK46ZSrFvCrJJhtQWggAAYlY"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:18:52.082109 2026] [security2:error] [pid 871012:tid 871161] [client 57.141.18.59:53262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJrwiU-Jh5ncAILFvZgABHD0"]
[Mon Jul 20 06:18:52.086172 2026] [security2:error] [pid 874439:tid 874671] [client 14.225.17.146:56543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWQwAAAGY"], referer: http://ancestralidadytrance.space/wp
[Mon Jul 20 06:18:52.336464 2026] [security2:error] [pid 874439:tid 874493] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-454120fdf8df4537b59f.js"] [unique_id "al4SLI6ZSrFvCrJJhtQWlwAAGzU"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:52.343710 2026] [security2:error] [pid 871012:tid 871066] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/woocommerce-analytics/build/woocommerce-analytics-client.js"] [unique_id "al4SLLwiU-Jh5ncAILFwHQABhzQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:52.352344 2026] [security2:error] [pid 874439:tid 874463] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWmAAAORc"]
[Mon Jul 20 06:18:52.352547 2026] [security2:error] [pid 874439:tid 874626] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWmAAAORc"]
[Mon Jul 20 06:18:52.406946 2026] [security2:error] [pid 874439:tid 874605] [client 104.234.53.92:20285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWlAAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:52.461698 2026] [security2:error] [pid 874439:tid 874522] [remote 173.249.4.11:14695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWoAAAT1I"]
[Mon Jul 20 06:18:52.467367 2026] [security2:error] [pid 874439:tid 874591] [client 14.225.17.146:56428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4SKo6ZSrFvCrJJhtQWLAAAABY"], referer: http://soloceos.com/wp
[Mon Jul 20 06:18:52.618823 2026] [security2:error] [pid 871012:tid 871166] [client 50.116.65.227:29248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SLLwiU-Jh5ncAILFwIgAAASE"]
[Mon Jul 20 06:18:52.632719 2026] [security2:error] [pid 871012:tid 871220] [client 50.116.65.227:29262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SLLwiU-Jh5ncAILFwIwAAAVc"]
[Mon Jul 20 06:18:52.806835 2026] [security2:error] [pid 871012:tid 871059] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/wp-emoji.js"] [unique_id "al4SLLwiU-Jh5ncAILFwJgABSy0"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:52.823487 2026] [security2:error] [pid 874439:tid 874606] [client 27.96.94.195:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWrwAAACU"]
[Mon Jul 20 06:18:52.823584 2026] [security2:error] [pid 874439:tid 874606] [client 27.96.94.195:37948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWrwAAACU"]
[Mon Jul 20 06:18:52.862072 2026] [security2:error] [pid 874439:tid 874696] [client 112.208.70.94:42823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWsQAAAH8"]
[Mon Jul 20 06:18:52.862216 2026] [security2:error] [pid 874439:tid 874696] [client 112.208.70.94:42823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWsQAAAH8"]
[Mon Jul 20 06:18:52.958226 2026] [security2:error] [pid 874439:tid 874610] [client 14.225.17.146:56632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWSQAAACk"], referer: http://nomorewetsheets.net/wp
[Mon Jul 20 06:18:52.980581 2026] [security2:error] [pid 874439:tid 874659] [client 14.225.17.146:61480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWTgAAAFo"], referer: http://aberballet.co.uk/wp
[Mon Jul 20 06:18:53.162069 2026] [security2:error] [pid 874439:tid 874482] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/twemoji.js"] [unique_id "al4SLY6ZSrFvCrJJhtQWyAAAFyo"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:53.280849 2026] [security2:error] [pid 874439:tid 874627] [client 57.141.18.14:37870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJ46ZSrFvCrJJhtQVkAAAOhE"]
[Mon Jul 20 06:18:53.295119 2026] [security2:error] [pid 871012:tid 871149] [client 57.141.18.99:39862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJ7wiU-Jh5ncAILFviwABECE"]
[Mon Jul 20 06:18:53.374726 2026] [security2:error] [pid 874439:tid 874674] [client 104.234.53.92:20285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SLY6ZSrFvCrJJhtQWywAAAGk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:53.381760 2026] [security2:error] [pid 874439:tid 874631] [client 185.132.186.87:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/cong.php"] [unique_id "al4SLY6ZSrFvCrJJhtQWzgAAAD4"]
[Mon Jul 20 06:18:53.678034 2026] [security2:error] [pid 874439:tid 874679] [client 14.225.17.146:61851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQW2gAAAG4"], referer: http://fkconstructionfunding.com/wp
[Mon Jul 20 06:18:54.104065 2026] [security2:error] [pid 871012:tid 871190] [client 57.141.18.60:21490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKLwiU-Jh5ncAILFvrgABOSI"]
[Mon Jul 20 06:18:54.393417 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXAQAAAAI"]
[Mon Jul 20 06:18:54.393529 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:52296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXAQAAAAI"]
[Mon Jul 20 06:18:54.527650 2026] [security2:error] [pid 874439:tid 874635] [client 43.161.234.148:40804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4SLo6ZSrFvCrJJhtQXCwAAAEI"]
[Mon Jul 20 06:18:54.644799 2026] [security2:error] [pid 874439:tid 874514] [remote 100.42.189.89:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXFwAATko"]
[Mon Jul 20 06:18:54.654491 2026] [security2:error] [pid 874439:tid 874572] [client 57.141.18.84:41890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKY6ZSrFvCrJJhtQV1gAAA24"]
[Mon Jul 20 06:18:54.701267 2026] [security2:error] [pid 874439:tid 874654] [client 14.225.17.146:64847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXEAAAAFU"], referer: https://fkconstructionfunding.com/wp
[Mon Jul 20 06:18:54.718291 2026] [security2:error] [pid 874439:tid 874537] [remote 57.141.18.34:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5107369"] [unique_id "al4SLo6ZSrFvCrJJhtQXHgAAHWE"]
[Mon Jul 20 06:18:54.844203 2026] [security2:error] [pid 874439:tid 874562] [remote 100.42.189.89:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXIgAAVHo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:54.873278 2026] [security2:error] [pid 871012:tid 871261] [client 57.141.18.31:23636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKbwiU-Jh5ncAILFvwQABgH4"]
[Mon Jul 20 06:18:55.145500 2026] [security2:error] [pid 874439:tid 874577] [client 14.225.17.146:62568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXGwAAAAg"], referer: http://overloadcomedy.com/wp
[Mon Jul 20 06:18:55.181615 2026] [security2:error] [pid 874439:tid 874572] [client 185.132.186.96:37489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/db.php"] [unique_id "al4SL46ZSrFvCrJJhtQXNwAAAAM"]
[Mon Jul 20 06:18:55.339614 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:64017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4SL46ZSrFvCrJJhtQXPAAAAG0"], referer: http://thefriendlyspreadsheet.com/wp
[Mon Jul 20 06:18:55.393963 2026] [security2:error] [pid 874439:tid 874669] [client 45.116.69.230:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXRQAAAGQ"]
[Mon Jul 20 06:18:55.394077 2026] [security2:error] [pid 874439:tid 874669] [client 45.116.69.230:60274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXRQAAAGQ"]
[Mon Jul 20 06:18:55.509318 2026] [security2:error] [pid 871012:tid 871224] [client 57.141.18.62:55952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKbwiU-Jh5ncAILFv0AABWxk"]
[Mon Jul 20 06:18:55.631403 2026] [security2:error] [pid 874439:tid 874695] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4SL46ZSrFvCrJJhtQXWQAAAH4"]
[Mon Jul 20 06:18:55.664506 2026] [security2:error] [pid 874439:tid 874587] [client 14.225.17.146:62016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQW5wAAABI"], referer: http://fluidtemple.org/wp
[Mon Jul 20 06:18:55.833631 2026] [security2:error] [pid 874439:tid 874696] [client 103.141.108.143:61927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXZgAAAH8"]
[Mon Jul 20 06:18:55.833742 2026] [security2:error] [pid 874439:tid 874696] [client 103.141.108.143:61927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXZgAAAH8"]
[Mon Jul 20 06:18:56.160386 2026] [security2:error] [pid 874439:tid 874586] [client 103.153.183.69:30384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../.env"] [unique_id "al4SMI6ZSrFvCrJJhtQXggAAABE"], referer: https://duckduckgo.com/?q=hyeps
[Mon Jul 20 06:18:56.169442 2026] [security2:error] [pid 874439:tid 874598] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SMI6ZSrFvCrJJhtQXhAAAAB0"]
[Mon Jul 20 06:18:56.220554 2026] [security2:error] [pid 874439:tid 874492] [remote 159.65.81.207:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXhgAAUzQ"]
[Mon Jul 20 06:18:56.284266 2026] [security2:error] [pid 871012:tid 871094] [remote 152.228.213.32:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tumbletyn.com"] [uri "/wp-login.php"] [unique_id "al4SMLwiU-Jh5ncAILFwbQABP1A"]
[Mon Jul 20 06:18:56.370896 2026] [security2:error] [pid 874439:tid 874631] [client 158.173.89.95:35039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXjAAAAD4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:56.413927 2026] [security2:error] [pid 874439:tid 874477] [remote 159.65.81.207:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXkgAAGCU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:56.420028 2026] [security2:error] [pid 874439:tid 874637] [client 103.77.203.233:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXlAAAAEQ"]
[Mon Jul 20 06:18:56.420160 2026] [security2:error] [pid 874439:tid 874637] [client 103.77.203.233:56027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXlAAAAEQ"]
[Mon Jul 20 06:18:56.467887 2026] [security2:error] [pid 871012:tid 871037] [remote 152.228.213.32:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tumbletyn.com"] [uri "/wp-login.php"] [unique_id "al4SMLwiU-Jh5ncAILFwbgABVRc"], referer: https://tumbletyn.com/wp-login.php
[Mon Jul 20 06:18:56.468642 2026] [security2:error] [pid 874439:tid 874496] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXmQAAWjg"]
[Mon Jul 20 06:18:56.468775 2026] [security2:error] [pid 874439:tid 874659] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXmQAAWjg"]
[Mon Jul 20 06:18:56.484654 2026] [security2:error] [pid 874439:tid 874677] [client 14.225.17.146:61954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQW5AAAAGw"], referer: http://talknutritionwithlesley.com/wp
[Mon Jul 20 06:18:56.514335 2026] [security2:error] [pid 874439:tid 874638] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SMI6ZSrFvCrJJhtQXnAAAAEU"]
[Mon Jul 20 06:18:56.670267 2026] [security2:error] [pid 874439:tid 874682] [client 57.141.18.103:39880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWRgAAcWY"]
[Mon Jul 20 06:18:56.856859 2026] [security2:error] [pid 874439:tid 874578] [client 14.225.17.146:54870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXrAAAAAk"], referer: http://katsklar.com/wp
[Mon Jul 20 06:18:56.859935 2026] [security2:error] [pid 874439:tid 874614] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4SMI6ZSrFvCrJJhtQXsQAAAC0"]
[Mon Jul 20 06:18:56.986724 2026] [security2:error] [pid 874439:tid 874575] [client 185.132.186.58:41453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/buy.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXvAAAAAY"]
[Mon Jul 20 06:18:57.210652 2026] [security2:error] [pid 874439:tid 874671] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SMY6ZSrFvCrJJhtQX0gAAAGY"]
[Mon Jul 20 06:18:57.233175 2026] [security2:error] [pid 874439:tid 874687] [client 57.141.18.107:55692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWeAAAdmg"]
[Mon Jul 20 06:18:57.344622 2026] [security2:error] [pid 871012:tid 871204] [client 177.42.58.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4SMbwiU-Jh5ncAILFweAAAAUc"]
[Mon Jul 20 06:18:57.462808 2026] [security2:error] [pid 871012:tid 871200] [client 178.152.178.232:37449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwggAAAUM"]
[Mon Jul 20 06:18:57.462978 2026] [security2:error] [pid 871012:tid 871200] [client 178.152.178.232:37449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwggAAAUM"]
[Mon Jul 20 06:18:57.550129 2026] [security2:error] [pid 874439:tid 874650] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4SMY6ZSrFvCrJJhtQX-wAAAFE"]
[Mon Jul 20 06:18:57.754863 2026] [security2:error] [pid 874439:tid 874655] [client 14.225.17.146:64075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4SMY6ZSrFvCrJJhtQYAAAAAFY"], referer: http://daseighty.net/wp
[Mon Jul 20 06:18:57.755988 2026] [security2:error] [pid 874439:tid 874688] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMY6ZSrFvCrJJhtQX1AAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:57.758515 2026] [security2:error] [pid 871012:tid 871183] [client 68.235.52.68:50928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwjQAAATI"]
[Mon Jul 20 06:18:57.758592 2026] [security2:error] [pid 871012:tid 871183] [client 68.235.52.68:50928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwjQAAATI"]
[Mon Jul 20 06:18:57.801940 2026] [security2:error] [pid 874439:tid 874641] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMY6ZSrFvCrJJhtQX1wAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:57.896665 2026] [security2:error] [pid 874439:tid 874657] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4SMY6ZSrFvCrJJhtQYDgAAAFg"]
[Mon Jul 20 06:18:57.961039 2026] [security2:error] [pid 874439:tid 874634] [client 50.116.65.227:55176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SMY6ZSrFvCrJJhtQYEgAAAEE"]
[Mon Jul 20 06:18:57.972467 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:29406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SMbwiU-Jh5ncAILFwkAAAARk"]
[Mon Jul 20 06:18:58.141182 2026] [security2:error] [pid 874439:tid 874670] [client 57.141.18.112:35844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWqQAAZRQ"]
[Mon Jul 20 06:18:58.270861 2026] [security2:error] [pid 871012:tid 871234] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SMrwiU-Jh5ncAILFwngAAAWU"]
[Mon Jul 20 06:18:58.355673 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:7738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYIwAAAEw"]
[Mon Jul 20 06:18:58.355819 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:7738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYIwAAAEw"]
[Mon Jul 20 06:18:58.383194 2026] [security2:error] [pid 874439:tid 874621] [client 104.234.53.69:47289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYJAAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:58.385073 2026] [security2:error] [pid 871012:tid 871253] [client 57.141.18.63:38374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLLwiU-Jh5ncAILFwJwABeCc"]
[Mon Jul 20 06:18:58.610302 2026] [security2:error] [pid 874439:tid 874574] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SMo6ZSrFvCrJJhtQYMQAAAAU"]
[Mon Jul 20 06:18:58.770577 2026] [security2:error] [pid 874439:tid 874631] [client 185.132.186.64:61785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/db.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYQgAAAD4"]
[Mon Jul 20 06:18:58.866849 2026] [security2:error] [pid 874439:tid 874693] [client 57.141.18.2:65234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQWzAAAfA8"]
[Mon Jul 20 06:18:58.909706 2026] [security2:error] [pid 871012:tid 871137] [remote 97.74.87.194:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4SMrwiU-Jh5ncAILFwrAABK3s"]
[Mon Jul 20 06:18:58.938456 2026] [security2:error] [pid 874439:tid 874597] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SMo6ZSrFvCrJJhtQYVQAAABw"]
[Mon Jul 20 06:18:59.012612 2026] [security2:error] [pid 871012:tid 871227] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMrwiU-Jh5ncAILFwqwAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:59.130055 2026] [security2:error] [pid 874439:tid 874453] [remote 20.173.88.122:56506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SM46ZSrFvCrJJhtQYXwAASw0"]
[Mon Jul 20 06:18:59.159027 2026] [security2:error] [pid 874439:tid 874655] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYVgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:59.261870 2026] [security2:error] [pid 874439:tid 874603] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4SM46ZSrFvCrJJhtQYaAAAACI"]
[Mon Jul 20 06:18:59.467181 2026] [security2:error] [pid 874439:tid 874536] [remote 20.173.88.122:56506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SM46ZSrFvCrJJhtQYeAAAAmA"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:18:59.481700 2026] [security2:error] [pid 871012:tid 871029] [remote 97.74.87.194:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4SM7wiU-Jh5ncAILFwuQABhA8"], referer: https://justinagrayman.com/wp-login.php
[Mon Jul 20 06:18:59.595814 2026] [security2:error] [pid 874439:tid 874638] [client 57.141.18.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SM46ZSrFvCrJJhtQYdwAAAEU"]
[Mon Jul 20 06:18:59.596356 2026] [security2:error] [pid 874439:tid 874667] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4SM46ZSrFvCrJJhtQYhAAAAGI"]
[Mon Jul 20 06:18:59.621976 2026] [security2:error] [pid 871012:tid 871231] [client 14.225.17.146:64021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4SMrwiU-Jh5ncAILFwqgAAAWI"], referer: http://processorstudio.com/wp
[Mon Jul 20 06:18:59.797817 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.22:30836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQW-gAAP2Q"]
[Mon Jul 20 06:18:59.927925 2026] [security2:error] [pid 871012:tid 871167] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SM7wiU-Jh5ncAILFwwgAAASI"]
[Mon Jul 20 06:19:00.117845 2026] [security2:error] [pid 874439:tid 874612] [client 57.141.18.22:30850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXEgAAK3E"]
[Mon Jul 20 06:19:00.124801 2026] [security2:error] [pid 871012:tid 871224] [client 114.119.147.74:58501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hammadownenterprises.com"] [uri "/projects-item/construction-of-clark-meadow-lane"] [unique_id "al4SNLwiU-Jh5ncAILFwyQAAAVs"], referer: https://hammadownenterprises.com/projects-item/construction-of-clark-meadow-lane
[Mon Jul 20 06:19:00.197926 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.105:55954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXGQAAaBw"]
[Mon Jul 20 06:19:00.276113 2026] [security2:error] [pid 871012:tid 871270] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SNLwiU-Jh5ncAILFwzwAAAYk"]
[Mon Jul 20 06:19:00.561847 2026] [security2:error] [pid 874439:tid 874675] [client 185.132.186.101:45193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/function/install.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYtwAAAGo"]
[Mon Jul 20 06:19:00.563971 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:59205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYtQAAAEM"], referer: https://processorstudio.com/wp
[Mon Jul 20 06:19:00.611892 2026] [security2:error] [pid 874439:tid 874650] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4SNI6ZSrFvCrJJhtQYugAAAFE"]
[Mon Jul 20 06:19:00.925646 2026] [security2:error] [pid 874439:tid 874450] [remote 216.73.216.55:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4SNI6ZSrFvCrJJhtQY0wAAVAo"]
[Mon Jul 20 06:19:00.950288 2026] [security2:error] [pid 874439:tid 874619] [client 57.141.18.19:47220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SL46ZSrFvCrJJhtQXSQAAMmk"]
[Mon Jul 20 06:19:00.967118 2026] [security2:error] [pid 874439:tid 874499] [remote 154.0.166.254:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4SNI6ZSrFvCrJJhtQY1QAAWjs"]
[Mon Jul 20 06:19:01.091021 2026] [security2:error] [pid 874439:tid 874609] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYvwAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:01.364003 2026] [security2:error] [pid 874439:tid 874615] [client 93.177.118.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "wesmclucas.com"] [uri "/xmlrpc.php"] [unique_id "al4SMY6ZSrFvCrJJhtQXwAAALlY"]
[Mon Jul 20 06:19:01.464896 2026] [security2:error] [pid 871012:tid 871213] [client 57.141.18.52:34696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SL7wiU-Jh5ncAILFwZQABUEk"]
[Mon Jul 20 06:19:01.468550 2026] [security2:error] [pid 874439:tid 874672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYxQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:01.475404 2026] [security2:error] [pid 874439:tid 874567] [remote 154.0.166.254:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4SNY6ZSrFvCrJJhtQY9QAADn8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:19:01.755261 2026] [security2:error] [pid 874439:tid 874520] [remote 167.233.114.32:57706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4SNY6ZSrFvCrJJhtQZBQAAKFA"]
[Mon Jul 20 06:19:01.848463 2026] [security2:error] [pid 871012:tid 871209] [client 158.173.241.141:26689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4SNbwiU-Jh5ncAILFw9wAAAUw"], referer: http://sesamegreenbeans.com/tag/south-africa/
[Mon Jul 20 06:19:01.960182 2026] [security2:error] [pid 874439:tid 874451] [remote 167.233.114.32:57706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4SNY6ZSrFvCrJJhtQZDQAAQws"], referer: https://colinkeyphotography.com/wp-login.php
[Mon Jul 20 06:19:02.107003 2026] [security2:error] [pid 871012:tid 871152] [client 158.173.241.141:56551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4SNbwiU-Jh5ncAILFxAwAAARM"], referer: http://sesamegreenbeans.com/nine-days-south-africa-ix/
[Mon Jul 20 06:19:02.297416 2026] [security2:error] [pid 874439:tid 874671] [client 50.116.65.227:39064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SNo6ZSrFvCrJJhtQZLQAAAGY"]
[Mon Jul 20 06:19:02.307417 2026] [security2:error] [pid 874439:tid 874583] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZEQAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:02.310376 2026] [security2:error] [pid 874439:tid 874573] [client 50.116.65.227:39068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SNo6ZSrFvCrJJhtQZLwAAAAQ"]
[Mon Jul 20 06:19:02.364218 2026] [security2:error] [pid 874439:tid 874628] [client 185.132.186.104:50809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/tflow/av.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZNAAAADs"]
[Mon Jul 20 06:19:02.441440 2026] [security2:error] [pid 874439:tid 874668] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZJAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:02.586420 2026] [security2:error] [pid 874439:tid 874571] [client 50.116.65.227:14786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNo6ZSrFvCrJJhtQZQQAAAAI"]
[Mon Jul 20 06:19:02.600097 2026] [security2:error] [pid 874439:tid 874653] [client 50.116.65.227:39106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNo6ZSrFvCrJJhtQZQgAAAFQ"]
[Mon Jul 20 06:19:02.701308 2026] [security2:error] [pid 874439:tid 874587] [client 104.234.53.80:45255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZQwAAABI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:02.795824 2026] [security2:error] [pid 871012:tid 871252] [client 14.225.17.146:55182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4SNLwiU-Jh5ncAILFw2AAAAXc"], referer: http://floorsourcestock.com/wp
[Mon Jul 20 06:19:02.818574 2026] [security2:error] [pid 871012:tid 871172] [client 50.116.65.227:14794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNrwiU-Jh5ncAILFxGAAAASc"]
[Mon Jul 20 06:19:02.830552 2026] [security2:error] [pid 874439:tid 874682] [client 50.116.65.227:39138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNo6ZSrFvCrJJhtQZSQAAAHE"]
[Mon Jul 20 06:19:02.901521 2026] [security2:error] [pid 871012:tid 871267] [client 50.116.65.227:39122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SNrwiU-Jh5ncAILFxFwAAAYY"]
[Mon Jul 20 06:19:02.919871 2026] [security2:error] [pid 874439:tid 874687] [client 104.234.53.80:45255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZUQAAAHY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:02.974508 2026] [security2:error] [pid 871012:tid 871129] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SNrwiU-Jh5ncAILFxHwABQnM"]
[Mon Jul 20 06:19:02.974708 2026] [security2:error] [pid 871012:tid 871199] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SNrwiU-Jh5ncAILFxHwABQnM"]
[Mon Jul 20 06:19:03.051427 2026] [security2:error] [pid 874439:tid 874641] [client 14.225.17.146:63804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYuQAAAEg"], referer: http://mrbambooplus.com/wp
[Mon Jul 20 06:19:03.134140 2026] [security2:error] [pid 874439:tid 874638] [client 50.116.65.227:39156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZUwAAAEU"]
[Mon Jul 20 06:19:03.614778 2026] [security2:error] [pid 874439:tid 874693] [client 113.160.142.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4SN46ZSrFvCrJJhtQZdgAAAHw"]
[Mon Jul 20 06:19:03.614969 2026] [security2:error] [pid 874439:tid 874693] [client 113.160.142.119:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4SN46ZSrFvCrJJhtQZdgAAAHw"]
[Mon Jul 20 06:19:03.674725 2026] [security2:error] [pid 871012:tid 871228] [client 57.141.18.86:49994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SMrwiU-Jh5ncAILFwmAABXzY"]
[Mon Jul 20 06:19:03.907200 2026] [security2:error] [pid 874439:tid 874644] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SN46ZSrFvCrJJhtQZcgAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:03.969594 2026] [security2:error] [pid 874439:tid 874605] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SN46ZSrFvCrJJhtQZfwAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:04.171543 2026] [security2:error] [pid 871012:tid 871212] [client 185.132.186.98:58253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/dist/bypass.php"] [unique_id "al4SOLwiU-Jh5ncAILFxRQAAAU8"]
[Mon Jul 20 06:19:04.268360 2026] [security2:error] [pid 871012:tid 871168] [client 14.225.17.146:65257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4SN7wiU-Jh5ncAILFxJQAAASM"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/wp
[Mon Jul 20 06:19:04.403558 2026] [security2:error] [pid 874439:tid 874608] [client 57.141.18.96:24592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SM46ZSrFvCrJJhtQYXAAAJ3g"]
[Mon Jul 20 06:19:04.416216 2026] [security2:error] [pid 871012:tid 871154] [client 185.223.152.44:50729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "giftsurprizo.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4SOLwiU-Jh5ncAILFxSAAAARU"]
[Mon Jul 20 06:19:04.782127 2026] [security2:error] [pid 874439:tid 874587] [client 103.153.183.69:15676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../var/www/html/.env"] [unique_id "al4SOI6ZSrFvCrJJhtQZuwAAABI"], referer: https://www.reddit.com/
[Mon Jul 20 06:19:04.790134 2026] [security2:error] [pid 874439:tid 874622] [client 14.225.17.146:63468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZsgAAADU"], referer: https://north-woods-engineering.com/wp
[Mon Jul 20 06:19:04.809839 2026] [security2:error] [pid 874439:tid 874678] [client 103.153.183.69:15676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../var/www/.env"] [unique_id "al4SOI6ZSrFvCrJJhtQZvQAAAG0"], referer: https://www.google.com/search?q=uudfzk
[Mon Jul 20 06:19:04.834718 2026] [security2:error] [pid 874439:tid 874614] [client 103.153.183.69:15676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//var/www/html/wp-config.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZvgAAAC0"], referer: https://www.facebook.com/
[Mon Jul 20 06:19:04.884266 2026] [security2:error] [pid 871012:tid 871204] [client 104.234.53.67:28001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SOLwiU-Jh5ncAILFxYAAAAUc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:04.977210 2026] [security2:error] [pid 874439:tid 874603] [client 27.96.94.195:37043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZyQAAACI"]
[Mon Jul 20 06:19:04.977392 2026] [security2:error] [pid 874439:tid 874603] [client 27.96.94.195:37043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZyQAAACI"]
[Mon Jul 20 06:19:05.055418 2026] [security2:error] [pid 874439:tid 874578] [client 50.116.65.227:14798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SOY6ZSrFvCrJJhtQZzwAAAAk"]
[Mon Jul 20 06:19:05.063814 2026] [security2:error] [pid 874439:tid 874540] [remote 192.241.143.148:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ0gAAGmQ"]
[Mon Jul 20 06:19:05.066060 2026] [security2:error] [pid 871012:tid 871240] [client 50.116.65.227:39244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SObwiU-Jh5ncAILFxZAAAAWs"]
[Mon Jul 20 06:19:05.105671 2026] [security2:error] [pid 871012:tid 871198] [client 171.60.139.123:52801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SObwiU-Jh5ncAILFxZgAAAUE"]
[Mon Jul 20 06:19:05.105800 2026] [security2:error] [pid 871012:tid 871198] [client 171.60.139.123:52801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SObwiU-Jh5ncAILFxZgAAAUE"]
[Mon Jul 20 06:19:05.184726 2026] [security2:error] [pid 871012:tid 871244] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SOLwiU-Jh5ncAILFxYgAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:05.226652 2026] [security2:error] [pid 874439:tid 874549] [remote 192.241.143.148:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ4wAAKW0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:19:05.240511 2026] [security2:error] [pid 874439:tid 874696] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "waltzingdogsllc.com"] [uri "/.well-known/about.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ5QAAAH8"]
[Mon Jul 20 06:19:05.240690 2026] [security2:error] [pid 874439:tid 874696] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "waltzingdogsllc.com"] [uri "/.well-known/about.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ5QAAAH8"]
[Mon Jul 20 06:19:05.376706 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ2QAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:05.392628 2026] [security2:error] [pid 871012:tid 871220] [client 57.141.18.69:41414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNLwiU-Jh5ncAILFwzAABV0U"]
[Mon Jul 20 06:19:05.516527 2026] [security2:error] [pid 874439:tid 874677] [client 34.147.16.58:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.eloisetate.com"] [uri "/"] [unique_id "al4SOY6ZSrFvCrJJhtQZ9gAAAGw"]
[Mon Jul 20 06:19:05.516620 2026] [security2:error] [pid 874439:tid 874677] [client 34.147.16.58:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.eloisetate.com"] [uri "/"] [unique_id "al4SOY6ZSrFvCrJJhtQZ9gAAAGw"]
[Mon Jul 20 06:19:05.673195 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.125:32564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYsgAAPwA"]
[Mon Jul 20 06:19:05.866011 2026] [security2:error] [pid 871012:tid 871016] [remote 152.228.213.32:47982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SObwiU-Jh5ncAILFxiAABPQI"]
[Mon Jul 20 06:19:05.993193 2026] [security2:error] [pid 874439:tid 874659] [client 185.132.186.53:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/testt.php"] [unique_id "al4SOY6ZSrFvCrJJhtQaFAAAAFo"]
[Mon Jul 20 06:19:06.117177 2026] [security2:error] [pid 871012:tid 871072] [remote 152.228.213.32:47982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SOrwiU-Jh5ncAILFxjgABNjo"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:19:06.275193 2026] [security2:error] [pid 874439:tid 874638] [client 45.116.69.230:60817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaKQAAAEU"]
[Mon Jul 20 06:19:06.275315 2026] [security2:error] [pid 874439:tid 874638] [client 45.116.69.230:60817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaKQAAAEU"]
[Mon Jul 20 06:19:06.354689 2026] [security2:error] [pid 874439:tid 874593] [client 57.141.18.30:46408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNY6ZSrFvCrJJhtQY4AAAGBM"]
[Mon Jul 20 06:19:06.395507 2026] [security2:error] [pid 874439:tid 874591] [client 14.225.17.146:50928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ8gAAABY"], referer: http://dnsplumbing.com/wp
[Mon Jul 20 06:19:06.557849 2026] [security2:error] [pid 871012:tid 871240] [client 103.141.108.143:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SOrwiU-Jh5ncAILFxkgAAAWs"]
[Mon Jul 20 06:19:06.557988 2026] [security2:error] [pid 871012:tid 871240] [client 103.141.108.143:62406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SOrwiU-Jh5ncAILFxkgAAAWs"]
[Mon Jul 20 06:19:06.639088 2026] [security2:error] [pid 874439:tid 874670] [client 57.141.18.18:52344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNY6ZSrFvCrJJhtQZAAAAZVs"]
[Mon Jul 20 06:19:06.639984 2026] [security2:error] [pid 874439:tid 874608] [client 112.208.70.94:43248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaRAAAACc"]
[Mon Jul 20 06:19:06.640107 2026] [security2:error] [pid 874439:tid 874608] [client 112.208.70.94:43248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaRAAAACc"]
[Mon Jul 20 06:19:06.916486 2026] [security2:error] [pid 874439:tid 874600] [client 103.77.203.233:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaTgAAAB8"]
[Mon Jul 20 06:19:06.916719 2026] [security2:error] [pid 874439:tid 874600] [client 103.77.203.233:56597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaTgAAAB8"]
[Mon Jul 20 06:19:07.175846 2026] [security2:error] [pid 874439:tid 874502] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SO46ZSrFvCrJJhtQaZgAAKT4"]
[Mon Jul 20 06:19:07.176038 2026] [security2:error] [pid 874439:tid 874610] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SO46ZSrFvCrJJhtQaZgAAKT4"]
[Mon Jul 20 06:19:07.451276 2026] [security2:error] [pid 871012:tid 871255] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SO7wiU-Jh5ncAILFxogAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:07.477699 2026] [security2:error] [pid 874439:tid 874645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SO46ZSrFvCrJJhtQaagAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:07.637419 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:57832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaOAAAAHY"], referer: http://adultdaycarereno.com/wp
[Mon Jul 20 06:19:07.794017 2026] [security2:error] [pid 874439:tid 874633] [client 185.132.186.61:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/goods.php"] [unique_id "al4SO46ZSrFvCrJJhtQajQAAAEA"]
[Mon Jul 20 06:19:08.050609 2026] [security2:error] [pid 871012:tid 871206] [client 14.225.17.146:63472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4SObwiU-Jh5ncAILFxiQAAAUk"], referer: http://jvcmotorsports.com/wp
[Mon Jul 20 06:19:08.150340 2026] [security2:error] [pid 874439:tid 874577] [client 178.152.178.232:36977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQaoQAAAAg"]
[Mon Jul 20 06:19:08.150496 2026] [security2:error] [pid 874439:tid 874577] [client 178.152.178.232:36977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQaoQAAAAg"]
[Mon Jul 20 06:19:08.223698 2026] [security2:error] [pid 874439:tid 874601] [client 57.141.18.0:30440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SN46ZSrFvCrJJhtQZZgAAIBs"]
[Mon Jul 20 06:19:08.542244 2026] [security2:error] [pid 874439:tid 874646] [client 14.225.17.146:54855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4SPI6ZSrFvCrJJhtQatAAAAE0"], referer: https://adultdaycarereno.com/wp
[Mon Jul 20 06:19:08.887997 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa0gAAAEw"]
[Mon Jul 20 06:19:08.888136 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:56182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa0gAAAEw"]
[Mon Jul 20 06:19:09.093969 2026] [security2:error] [pid 874439:tid 874690] [client 104.234.53.63:53455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa2QAAAHk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:09.437911 2026] [lsapi:warn] [pid 871012:tid 871173] [client 14.225.17.146:55479] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wp
[Mon Jul 20 06:19:09.437931 2026] [lsapi:warn] [pid 871012:tid 871173] [client 14.225.17.146:55479] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wp
[Mon Jul 20 06:19:09.513419 2026] [security2:error] [pid 874439:tid 874692] [client 104.234.53.63:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SPY6ZSrFvCrJJhtQbAQAAAHs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:09.578874 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.66:55611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/sad.php"] [unique_id "al4SPbwiU-Jh5ncAILFx1wAAAVQ"]
[Mon Jul 20 06:19:09.873857 2026] [security2:error] [pid 871012:tid 871235] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SPbwiU-Jh5ncAILFx2gAAAWY"]
[Mon Jul 20 06:19:09.944674 2026] [lsapi:warn] [pid 874439:tid 874678] [client 50.116.65.227:38236] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:19:09.944715 2026] [lsapi:warn] [pid 874439:tid 874678] [client 50.116.65.227:38236] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:19:09.960223 2026] [security2:error] [pid 871012:tid 871173] [client 14.225.17.146:55479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4SPLwiU-Jh5ncAILFxvwAAASg"], referer: http://oswegooperatheater.com/wp
[Mon Jul 20 06:19:09.998966 2026] [security2:error] [pid 874439:tid 874666] [client 14.225.17.146:55449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa1gAAAGE"], referer: http://musichaven.info/wp
[Mon Jul 20 06:19:10.134394 2026] [security2:error] [pid 874439:tid 874670] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SPY6ZSrFvCrJJhtQbEwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:10.203193 2026] [security2:error] [pid 874439:tid 874601] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SPY6ZSrFvCrJJhtQbGgAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:10.516897 2026] [security2:error] [pid 871012:tid 871223] [client 34.34.17.27:57344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.almadisplay.ca"] [uri "/"] [unique_id "al4SPrwiU-Jh5ncAILFx6QAAAVo"]
[Mon Jul 20 06:19:10.516973 2026] [security2:error] [pid 871012:tid 871223] [client 34.34.17.27:57344] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.almadisplay.ca"] [uri "/"] [unique_id "al4SPrwiU-Jh5ncAILFx6QAAAVo"]
[Mon Jul 20 06:19:10.861685 2026] [lsapi:warn] [pid 874439:tid 874649] [client 14.225.17.146:65435] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wp
[Mon Jul 20 06:19:10.861702 2026] [lsapi:warn] [pid 874439:tid 874649] [client 14.225.17.146:65435] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wp
[Mon Jul 20 06:19:10.906561 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:65434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4SPo6ZSrFvCrJJhtQbVAAAAEM"], referer: https://musichaven.info/wp
[Mon Jul 20 06:19:10.913689 2026] [security2:error] [pid 874439:tid 874649] [client 14.225.17.146:65435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4SPo6ZSrFvCrJJhtQbVQAAAFA"], referer: https://oswegooperatheater.com/wp
[Mon Jul 20 06:19:11.014390 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.82:25568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SOY6ZSrFvCrJJhtQaDQAATi4"]
[Mon Jul 20 06:19:11.130829 2026] [security2:error] [pid 874439:tid 874676] [client 52.59.238.198:48558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbZAAAAGs"]
[Mon Jul 20 06:19:11.360656 2026] [security2:error] [pid 874439:tid 874484] [remote 162.19.86.63:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbdgAAcCw"]
[Mon Jul 20 06:19:11.374352 2026] [security2:error] [pid 874439:tid 874650] [client 185.132.186.62:40251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/wp-conflg.php"] [unique_id "al4SP46ZSrFvCrJJhtQbeAAAAFE"]
[Mon Jul 20 06:19:11.545565 2026] [security2:error] [pid 874439:tid 874545] [remote 162.19.86.63:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbgwAAfWk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:11.706667 2026] [security2:error] [pid 874439:tid 874646] [client 63.176.132.15:31468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbigAAAE0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:19:11.800297 2026] [security2:error] [pid 871012:tid 871199] [client 50.116.65.227:38294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SP7wiU-Jh5ncAILFx_QAAAUI"]
[Mon Jul 20 06:19:11.810956 2026] [security2:error] [pid 874439:tid 874695] [client 50.116.65.227:38308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SP46ZSrFvCrJJhtQbkgAAAH4"]
[Mon Jul 20 06:19:11.905341 2026] [security2:error] [pid 874439:tid 874592] [client 104.234.53.62:49711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbmgAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:12.107334 2026] [security2:error] [pid 874439:tid 874609] [client 34.74.185.202:55723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SQI6ZSrFvCrJJhtQbsQAAACg"]
[Mon Jul 20 06:19:12.204832 2026] [security2:error] [pid 874439:tid 874635] [client 57.141.18.76:52934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SO46ZSrFvCrJJhtQaVQAAQkw"]
[Mon Jul 20 06:19:12.219440 2026] [security2:error] [pid 874439:tid 874502] [remote 20.153.140.50:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4SQI6ZSrFvCrJJhtQbuQAADj4"]
[Mon Jul 20 06:19:12.443689 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.34:40340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SO46ZSrFvCrJJhtQacwAAaDI"]
[Mon Jul 20 06:19:12.650588 2026] [security2:error] [pid 874439:tid 874452] [remote 20.153.140.50:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4SQI6ZSrFvCrJJhtQb2gAAUgw"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:19:12.819136 2026] [security2:error] [pid 874439:tid 874607] [client 50.116.65.227:37594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SQI6ZSrFvCrJJhtQb4AAAACY"]
[Mon Jul 20 06:19:12.830306 2026] [security2:error] [pid 874439:tid 874652] [client 50.116.65.227:38324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SQI6ZSrFvCrJJhtQb4QAAAFM"]
[Mon Jul 20 06:19:12.915907 2026] [security2:error] [pid 874439:tid 874632] [client 104.158.101.130:54744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4SQI6ZSrFvCrJJhtQb6AAAAD8"]
[Mon Jul 20 06:19:13.026368 2026] [security2:error] [pid 874439:tid 874586] [client 74.7.227.179:33392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SQI6ZSrFvCrJJhtQb5wAAEWw"], referer: https://tejasenvironmental.com/p=920849
[Mon Jul 20 06:19:13.037441 2026] [security2:error] [pid 874439:tid 874629] [client 34.74.185.202:50598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SQY6ZSrFvCrJJhtQb8wAAADw"]
[Mon Jul 20 06:19:13.181869 2026] [security2:error] [pid 874439:tid 874614] [client 185.132.186.79:46117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/wp-includes/assets/script-loader-packages.php"] [unique_id "al4SQY6ZSrFvCrJJhtQb_QAAAC0"]
[Mon Jul 20 06:19:13.603761 2026] [security2:error] [pid 874439:tid 874539] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SQY6ZSrFvCrJJhtQcGwAAMmM"]
[Mon Jul 20 06:19:13.603959 2026] [security2:error] [pid 874439:tid 874619] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SQY6ZSrFvCrJJhtQcGwAAMmM"]
[Mon Jul 20 06:19:13.683067 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.44:35842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPI6ZSrFvCrJJhtQauwAAAio"]
[Mon Jul 20 06:19:13.746625 2026] [security2:error] [pid 871012:tid 871160] [client 14.251.3.155:55669] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SQbwiU-Jh5ncAILFyKAAAARs"]
[Mon Jul 20 06:19:13.814195 2026] [security2:error] [pid 871012:tid 871246] [client 34.74.185.202:61102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SQbwiU-Jh5ncAILFyKQAAAXE"]
[Mon Jul 20 06:19:14.059796 2026] [security2:error] [pid 874439:tid 874661] [client 74.208.214.194:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SQo6ZSrFvCrJJhtQcNAAAAFw"]
[Mon Jul 20 06:19:14.097059 2026] [security2:error] [pid 871012:tid 871161] [client 14.225.17.146:65272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4SQbwiU-Jh5ncAILFyEwAAARw"], referer: http://entuvy.com/wp
[Mon Jul 20 06:19:14.171053 2026] [security2:error] [pid 874439:tid 874682] [client 57.141.18.8:56858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPY6ZSrFvCrJJhtQa3gAAcQY"]
[Mon Jul 20 06:19:14.226074 2026] [security2:error] [pid 871012:tid 871222] [client 158.173.166.181:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SQrwiU-Jh5ncAILFyOQAAAVk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:14.330310 2026] [security2:error] [pid 871012:tid 871268] [client 57.141.18.10:55498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPbwiU-Jh5ncAILFxxQABhyc"]
[Mon Jul 20 06:19:14.332570 2026] [security2:error] [pid 871012:tid 871233] [client 57.141.18.31:50824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPbwiU-Jh5ncAILFxxwABZCY"]
[Mon Jul 20 06:19:14.450359 2026] [security2:error] [pid 871012:tid 871237] [client 34.74.185.202:55613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SQrwiU-Jh5ncAILFyPQAAAWg"]
[Mon Jul 20 06:19:14.694107 2026] [security2:error] [pid 874439:tid 874641] [client 50.116.65.227:37604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SQo6ZSrFvCrJJhtQcXAAAAEg"]
[Mon Jul 20 06:19:14.705146 2026] [security2:error] [pid 871012:tid 871170] [client 50.116.65.227:38366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SQrwiU-Jh5ncAILFyRQAAASo"]
[Mon Jul 20 06:19:14.800440 2026] [security2:error] [pid 871012:tid 871254] [client 14.225.17.146:55192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4SQbwiU-Jh5ncAILFyJgAAAXk"], referer: http://travelbyfire.com/wp
[Mon Jul 20 06:19:14.802000 2026] [security2:error] [pid 874439:tid 874582] [client 77.110.127.138:59964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4SQo6ZSrFvCrJJhtQcZwAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:14.950674 2026] [security2:error] [pid 874439:tid 874611] [client 77.110.127.138:59967] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/cake-recipe/feed/"] [unique_id "al4SQo6ZSrFvCrJJhtQccAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:14.985685 2026] [security2:error] [pid 874439:tid 874609] [client 90.254.155.226:53000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4SQo6ZSrFvCrJJhtQccwAAACg"]
[Mon Jul 20 06:19:14.987219 2026] [security2:error] [pid 874439:tid 874687] [client 185.132.186.80:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/login.php"] [unique_id "al4SQo6ZSrFvCrJJhtQcdAAAAHY"]
[Mon Jul 20 06:19:15.002286 2026] [security2:error] [pid 874439:tid 874648] [client 87.18.141.108:42414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4SQo6ZSrFvCrJJhtQcdwAAAE8"]
[Mon Jul 20 06:19:15.079230 2026] [security2:error] [pid 874439:tid 874673] [client 213.196.104.179:53807] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4SQ46ZSrFvCrJJhtQcgAAAAGg"]
[Mon Jul 20 06:19:15.101239 2026] [security2:error] [pid 871012:tid 871251] [client 14.187.227.208:41036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyUQAAAXY"]
[Mon Jul 20 06:19:15.156666 2026] [security2:error] [pid 874439:tid 874536] [remote 176.56.118.182:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SQ46ZSrFvCrJJhtQchgAAG2A"]
[Mon Jul 20 06:19:15.215319 2026] [security2:error] [pid 871012:tid 871150] [client 57.141.18.105:49620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPrwiU-Jh5ncAILFx4gABESA"]
[Mon Jul 20 06:19:15.264853 2026] [security2:error] [pid 874439:tid 874607] [client 176.102.194.224:41014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQcjgAAACY"]
[Mon Jul 20 06:19:15.265275 2026] [security2:error] [pid 874439:tid 874639] [client 24.141.218.37:38808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQcjQAAAEY"]
[Mon Jul 20 06:19:15.327148 2026] [security2:error] [pid 874439:tid 874575] [client 94.134.181.70:24253] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4SQ46ZSrFvCrJJhtQckAAAAAY"]
[Mon Jul 20 06:19:15.354782 2026] [security2:error] [pid 874439:tid 874696] [client 87.10.98.33:57244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQclAAAAH8"]
[Mon Jul 20 06:19:15.393272 2026] [security2:error] [pid 871012:tid 871249] [client 89.115.22.45:41482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4SQ7wiU-Jh5ncAILFyWwAAAXQ"]
[Mon Jul 20 06:19:15.393831 2026] [security2:error] [pid 874439:tid 874540] [remote 176.56.118.182:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SQ46ZSrFvCrJJhtQclwAAcWQ"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:15.423951 2026] [security2:error] [pid 871012:tid 871207] [client 86.146.184.240:60226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyXQAAAUo"]
[Mon Jul 20 06:19:15.430847 2026] [security2:error] [pid 871012:tid 871224] [client 216.244.66.243:52896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/auth/login"] [unique_id "al4SQ7wiU-Jh5ncAILFyXgAAAVs"]
[Mon Jul 20 06:19:15.430934 2026] [security2:error] [pid 871012:tid 871224] [client 216.244.66.243:52896] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/auth/login"] [unique_id "al4SQ7wiU-Jh5ncAILFyXgAAAVs"]
[Mon Jul 20 06:19:15.442278 2026] [security2:error] [pid 874439:tid 874649] [client 45.45.237.8:50462] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.git/HEAD"] [unique_id "al4SQ46ZSrFvCrJJhtQcmgAAAFA"]
[Mon Jul 20 06:19:15.463515 2026] [security2:error] [pid 871012:tid 871201] [client 190.69.45.223:54326] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyXwAAAUQ"]
[Mon Jul 20 06:19:15.489591 2026] [security2:error] [pid 874439:tid 874648] [client 34.74.185.202:52294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SQ46ZSrFvCrJJhtQcnwAAAE8"]
[Mon Jul 20 06:19:15.549087 2026] [security2:error] [pid 874439:tid 874681] [client 190.89.84.189:6051] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQcpgAAAHA"]
[Mon Jul 20 06:19:15.662983 2026] [security2:error] [pid 871012:tid 871173] [client 81.213.218.124:39482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4SQ7wiU-Jh5ncAILFyZQAAASg"]
[Mon Jul 20 06:19:15.727869 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:58078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4SQ46ZSrFvCrJJhtQctAAAAG0"], referer: https://travelbyfire.com/wp
[Mon Jul 20 06:19:15.766891 2026] [security2:error] [pid 871012:tid 871194] [client 93.38.25.239:33284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4SQ7wiU-Jh5ncAILFyZwAAAT0"]
[Mon Jul 20 06:19:15.782425 2026] [security2:error] [pid 874439:tid 874606] [client 171.60.139.123:53325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcwAAAACU"]
[Mon Jul 20 06:19:15.782538 2026] [security2:error] [pid 874439:tid 874606] [client 171.60.139.123:53325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcwAAAACU"]
[Mon Jul 20 06:19:15.809268 2026] [security2:error] [pid 871012:tid 871212] [client 37.202.11.102:46394] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamawcubgee.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyaAAAAU8"]
[Mon Jul 20 06:19:15.869726 2026] [security2:error] [pid 874439:tid 874607] [client 65.1.132.125:27410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcywAAACY"]
[Mon Jul 20 06:19:15.869865 2026] [security2:error] [pid 874439:tid 874607] [client 65.1.132.125:27410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcywAAACY"]
[Mon Jul 20 06:19:15.878785 2026] [security2:error] [pid 874439:tid 874650] [client 87.216.97.139:34216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4SQ46ZSrFvCrJJhtQczAAAAFE"]
[Mon Jul 20 06:19:15.887944 2026] [security2:error] [pid 874439:tid 874592] [client 103.99.162.124:10121] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4SQ46ZSrFvCrJJhtQczQAAABc"]
[Mon Jul 20 06:19:15.895916 2026] [security2:error] [pid 871012:tid 871042] [remote 220.181.108.90:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/index.php/store-share/"] [unique_id "al4SQ7wiU-Jh5ncAILFyagABXhw"]
[Mon Jul 20 06:19:16.020877 2026] [security2:error] [pid 874439:tid 874605] [client 45.45.237.8:50448] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.well-known/security.txt"] [unique_id "al4SRI6ZSrFvCrJJhtQc0gAAACQ"]
[Mon Jul 20 06:19:16.026554 2026] [security2:error] [pid 874439:tid 874521] [remote 81.173.115.7:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc2AAAR1E"]
[Mon Jul 20 06:19:16.039562 2026] [security2:error] [pid 874439:tid 874629] [client 89.242.146.38:55936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4SRI6ZSrFvCrJJhtQc2QAAADw"]
[Mon Jul 20 06:19:16.076311 2026] [security2:error] [pid 874439:tid 874609] [client 45.45.237.8:50462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/.env"] [unique_id "al4SRI6ZSrFvCrJJhtQc3wAAACg"]
[Mon Jul 20 06:19:16.096483 2026] [security2:error] [pid 874439:tid 874694] [client 82.37.76.155:60280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4SRI6ZSrFvCrJJhtQc4AAAAH0"]
[Mon Jul 20 06:19:16.121407 2026] [security2:error] [pid 874439:tid 874664] [client 57.141.18.88:24618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SP46ZSrFvCrJJhtQbbQAAXwE"]
[Mon Jul 20 06:19:16.144112 2026] [security2:error] [pid 871012:tid 871149] [client 5.49.120.104:37810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4SRLwiU-Jh5ncAILFycwAAARA"]
[Mon Jul 20 06:19:16.221077 2026] [security2:error] [pid 874439:tid 874658] [client 90.14.145.153:33254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQc7gAAAFk"]
[Mon Jul 20 06:19:16.239309 2026] [security2:error] [pid 874439:tid 874688] [client 81.173.161.212:46356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4SRI6ZSrFvCrJJhtQc8AAAAHc"]
[Mon Jul 20 06:19:16.239672 2026] [security2:error] [pid 874439:tid 874481] [remote 81.173.115.7:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc8QAAJik"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:19:16.253665 2026] [security2:error] [pid 871012:tid 871265] [client 80.244.47.31:44706] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4SRLwiU-Jh5ncAILFydgAAAYQ"]
[Mon Jul 20 06:19:16.264089 2026] [security2:error] [pid 874439:tid 874675] [client 86.172.60.13:41772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQc9AAAAGo"]
[Mon Jul 20 06:19:16.293374 2026] [security2:error] [pid 874439:tid 874661] [client 86.147.30.54:38206] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQc9wAAAFw"]
[Mon Jul 20 06:19:16.369134 2026] [security2:error] [pid 874439:tid 874645] [client 34.74.185.202:64137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SRI6ZSrFvCrJJhtQc_AAAAEw"]
[Mon Jul 20 06:19:16.373936 2026] [security2:error] [pid 874439:tid 874593] [client 27.96.94.195:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc_QAAABg"]
[Mon Jul 20 06:19:16.374029 2026] [security2:error] [pid 874439:tid 874593] [client 27.96.94.195:37826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc_QAAABg"]
[Mon Jul 20 06:19:16.751572 2026] [security2:error] [pid 874439:tid 874581] [client 45.116.69.230:61348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQdDgAAAAw"]
[Mon Jul 20 06:19:16.751677 2026] [security2:error] [pid 874439:tid 874581] [client 45.116.69.230:61348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQdDgAAAAw"]
[Mon Jul 20 06:19:16.777857 2026] [security2:error] [pid 874439:tid 874600] [client 177.130.118.6:42550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdFQAAAB8"]
[Mon Jul 20 06:19:16.777935 2026] [security2:error] [pid 874439:tid 874695] [client 95.251.203.116:57010] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdFAAAAH4"]
[Mon Jul 20 06:19:16.795421 2026] [security2:error] [pid 871012:tid 871213] [client 185.132.186.99:47567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/network.php"] [unique_id "al4SRLwiU-Jh5ncAILFyfQAAAVA"]
[Mon Jul 20 06:19:16.824931 2026] [security2:error] [pid 874439:tid 874666] [client 37.66.146.207:9746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdFwAAAGE"]
[Mon Jul 20 06:19:16.848378 2026] [security2:error] [pid 874439:tid 874614] [client 95.25.142.145:19514] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdGQAAAC0"]
[Mon Jul 20 06:19:16.881869 2026] [security2:error] [pid 874439:tid 874672] [client 95.214.186.53:37146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4SRI6ZSrFvCrJJhtQdGwAAAGc"]
[Mon Jul 20 06:19:17.158732 2026] [security2:error] [pid 874439:tid 874660] [client 2.121.236.140:39868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4SRY6ZSrFvCrJJhtQdKwAAAFs"]
[Mon Jul 20 06:19:17.166311 2026] [security2:error] [pid 874439:tid 874650] [client 45.45.237.8:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/.env.bak"] [unique_id "al4SRY6ZSrFvCrJJhtQdLAAAAFE"]
[Mon Jul 20 06:19:17.167154 2026] [security2:error] [pid 874439:tid 874619] [client 84.82.70.57:35810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdLQAAADI"]
[Mon Jul 20 06:19:17.189323 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:50462] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.env.development"] [unique_id "al4SRY6ZSrFvCrJJhtQdMAAAADc"]
[Mon Jul 20 06:19:17.262999 2026] [security2:error] [pid 871012:tid 871221] [client 57.141.18.102:44720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQLwiU-Jh5ncAILFyAgABWA4"]
[Mon Jul 20 06:19:17.278996 2026] [security2:error] [pid 874439:tid 874605] [client 190.71.186.101:51770] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdNgAAACQ"]
[Mon Jul 20 06:19:17.326310 2026] [security2:error] [pid 871012:tid 871254] [client 81.47.145.211:44984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbnka.woff2"] [unique_id "al4SRbwiU-Jh5ncAILFyhQAAAXk"]
[Mon Jul 20 06:19:17.375635 2026] [security2:error] [pid 874439:tid 874636] [client 103.141.108.143:62886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdPgAAAEM"]
[Mon Jul 20 06:19:17.375928 2026] [security2:error] [pid 874439:tid 874636] [client 103.141.108.143:62886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdPgAAAEM"]
[Mon Jul 20 06:19:17.385792 2026] [security2:error] [pid 874439:tid 874653] [client 90.167.51.8:19828] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4SRY6ZSrFvCrJJhtQdPwAAAFQ"]
[Mon Jul 20 06:19:17.398303 2026] [security2:error] [pid 874439:tid 874681] [client 109.252.8.177:1315] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdQgAAAHA"]
[Mon Jul 20 06:19:17.506821 2026] [security2:error] [pid 874439:tid 874664] [client 103.77.203.233:57214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdSAAAAF8"]
[Mon Jul 20 06:19:17.506975 2026] [security2:error] [pid 874439:tid 874664] [client 103.77.203.233:57214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdSAAAAF8"]
[Mon Jul 20 06:19:17.509596 2026] [security2:error] [pid 871012:tid 871252] [client 34.74.185.202:63221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SRbwiU-Jh5ncAILFyigAAAXc"]
[Mon Jul 20 06:19:17.557604 2026] [security2:error] [pid 871012:tid 871195] [client 95.19.188.2:47148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4SRbwiU-Jh5ncAILFyjAAAAT4"]
[Mon Jul 20 06:19:17.618823 2026] [security2:error] [pid 874439:tid 874581] [client 45.45.237.8:50476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/.env.backup"] [unique_id "al4SRY6ZSrFvCrJJhtQdTgAAAAw"]
[Mon Jul 20 06:19:17.659851 2026] [security2:error] [pid 874439:tid 874668] [client 86.74.35.50:39244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdVAAAAGM"]
[Mon Jul 20 06:19:17.713335 2026] [security2:error] [pid 874439:tid 874655] [client 105.157.215.226:59236] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdVwAAAFY"]
[Mon Jul 20 06:19:17.780546 2026] [security2:error] [pid 871012:tid 871103] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SRbwiU-Jh5ncAILFylgABFlk"]
[Mon Jul 20 06:19:17.780718 2026] [security2:error] [pid 871012:tid 871155] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SRbwiU-Jh5ncAILFylgABFlk"]
[Mon Jul 20 06:19:17.793118 2026] [security2:error] [pid 871012:tid 871160] [client 78.192.199.101:57550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4SRbwiU-Jh5ncAILFymAAAARs"]
[Mon Jul 20 06:19:17.923096 2026] [security2:error] [pid 871012:tid 871269] [client 45.45.237.8:50780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/keys.json"] [unique_id "al4SRbwiU-Jh5ncAILFynQAAAYg"]
[Mon Jul 20 06:19:17.923218 2026] [security2:error] [pid 871012:tid 871269] [client 45.45.237.8:50780] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/keys.json"] [unique_id "al4SRbwiU-Jh5ncAILFynQAAAYg"]
[Mon Jul 20 06:19:17.924572 2026] [security2:error] [pid 871012:tid 871241] [client 45.45.237.8:50734] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/serviceAccountKey.json"] [unique_id "al4SRbwiU-Jh5ncAILFymwAAAWw"]
[Mon Jul 20 06:19:17.924718 2026] [security2:error] [pid 874439:tid 874586] [client 45.45.237.8:50642] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/config.yml"] [unique_id "al4SRY6ZSrFvCrJJhtQdYwAAABE"]
[Mon Jul 20 06:19:17.924816 2026] [security2:error] [pid 871012:tid 871224] [client 45.45.237.8:50766] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/key.json"] [unique_id "al4SRbwiU-Jh5ncAILFyngAAAVs"]
[Mon Jul 20 06:19:17.924915 2026] [security2:error] [pid 871012:tid 871201] [client 45.45.237.8:50726] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/service_account.json"] [unique_id "al4SRbwiU-Jh5ncAILFyoAAAAUQ"]
[Mon Jul 20 06:19:17.924915 2026] [security2:error] [pid 871012:tid 871261] [client 45.45.237.8:50802] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4SRbwiU-Jh5ncAILFyoQAAAYA"]
[Mon Jul 20 06:19:17.925069 2026] [security2:error] [pid 874439:tid 874669] [client 45.45.237.8:50838] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/actuator/env"] [unique_id "al4SRY6ZSrFvCrJJhtQdawAAAGQ"]
[Mon Jul 20 06:19:17.943051 2026] [security2:error] [pid 871012:tid 871246] [client 79.117.198.39:59526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4SRbwiU-Jh5ncAILFypAAAAXE"]
[Mon Jul 20 06:19:18.015169 2026] [security2:error] [pid 871012:tid 871165] [client 79.117.162.242:46722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4SRrwiU-Jh5ncAILFypQAAASA"]
[Mon Jul 20 06:19:18.025144 2026] [security2:error] [pid 874439:tid 874691] [client 45.45.237.8:50582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/public/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQdegAAAHo"]
[Mon Jul 20 06:19:18.025520 2026] [security2:error] [pid 874439:tid 874607] [client 45.45.237.8:50564] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.env.test"] [unique_id "al4SRo6ZSrFvCrJJhtQddgAAACY"]
[Mon Jul 20 06:19:18.025656 2026] [security2:error] [pid 874439:tid 874657] [client 45.45.237.8:50568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/backend/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQdeQAAAFg"]
[Mon Jul 20 06:19:18.025715 2026] [security2:error] [pid 874439:tid 874602] [client 45.45.237.8:50598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/laravel/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQdewAAACE"]
[Mon Jul 20 06:19:18.025737 2026] [security2:error] [pid 874439:tid 874582] [client 45.45.237.8:50580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/api/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQddwAAAA0"]
[Mon Jul 20 06:19:18.025738 2026] [security2:error] [pid 871012:tid 871199] [client 45.45.237.8:50608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/wp/.env"] [unique_id "al4SRrwiU-Jh5ncAILFypwAAAUI"]
[Mon Jul 20 06:19:18.026174 2026] [security2:error] [pid 874439:tid 874676] [client 45.45.237.8:50548] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.env.prod"] [unique_id "al4SRo6ZSrFvCrJJhtQdeAAAAGs"]
[Mon Jul 20 06:19:18.026463 2026] [security2:error] [pid 874439:tid 874650] [client 45.45.237.8:50976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/aws-exports.js"] [unique_id "al4SRo6ZSrFvCrJJhtQdgQAAAFE"]
[Mon Jul 20 06:19:18.026553 2026] [security2:error] [pid 874439:tid 874650] [client 45.45.237.8:50976] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/aws-exports.js"] [unique_id "al4SRo6ZSrFvCrJJhtQdgQAAAFE"]
[Mon Jul 20 06:19:18.027046 2026] [security2:error] [pid 871012:tid 871220] [client 45.45.237.8:50932] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/serverless.yml"] [unique_id "al4SRrwiU-Jh5ncAILFyrgAAAVc"]
[Mon Jul 20 06:19:18.027696 2026] [security2:error] [pid 874439:tid 874658] [client 45.45.237.8:50994] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/amplifyconfiguration.json"] [unique_id "al4SRo6ZSrFvCrJJhtQdgwAAAFk"]
[Mon Jul 20 06:19:18.027708 2026] [security2:error] [pid 874439:tid 874692] [client 45.45.237.8:50956] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.aws/credentials"] [unique_id "al4SRo6ZSrFvCrJJhtQdfwAAAHs"]
[Mon Jul 20 06:19:18.027875 2026] [security2:error] [pid 874439:tid 874635] [client 45.45.237.8:50936] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/terraform.tfstate"] [unique_id "al4SRo6ZSrFvCrJJhtQdfgAAAEI"]
[Mon Jul 20 06:19:18.028306 2026] [security2:error] [pid 874439:tid 874675] [client 45.45.237.8:51094] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/debug/vars"] [unique_id "al4SRo6ZSrFvCrJJhtQdhwAAAGo"]
[Mon Jul 20 06:19:18.028492 2026] [security2:error] [pid 871012:tid 871222] [client 45.45.237.8:51106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/app/.env"] [unique_id "al4SRrwiU-Jh5ncAILFyswAAAVk"]
[Mon Jul 20 06:19:18.028727 2026] [security2:error] [pid 871012:tid 871194] [client 45.45.237.8:50868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sumnn.com"] [uri "/wp-config.php.bak"] [unique_id "al4SRrwiU-Jh5ncAILFytwAAAT0"]
[Mon Jul 20 06:19:18.029433 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:50876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/web.config"] [unique_id "al4SRo6ZSrFvCrJJhtQdiwAAADc"]
[Mon Jul 20 06:19:18.031089 2026] [security2:error] [pid 874439:tid 874589] [client 45.45.237.8:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sumnn.com"] [uri "/wp-config.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdigAAABQ"]
[Mon Jul 20 06:19:18.053152 2026] [security2:error] [pid 871012:tid 871266] [client 152.249.210.239:44828] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4SRrwiU-Jh5ncAILFyuAAAAYU"]
[Mon Jul 20 06:19:18.080869 2026] [security2:error] [pid 874439:tid 874477] [remote 20.153.140.50:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdkQAAGCU"]
[Mon Jul 20 06:19:18.110604 2026] [security2:error] [pid 874439:tid 874685] [client 45.45.237.8:50462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/.env.old"] [unique_id "al4SRo6ZSrFvCrJJhtQdlAAAAHQ"]
[Mon Jul 20 06:19:18.110742 2026] [security2:error] [pid 874439:tid 874685] [client 45.45.237.8:50462] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/.env.old"] [unique_id "al4SRo6ZSrFvCrJJhtQdlAAAAHQ"]
[Mon Jul 20 06:19:18.153011 2026] [security2:error] [pid 874439:tid 874577] [client 66.249.73.4:39782] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ithurtsuntilyoudie.com"] [uri "/robots.txt"] [unique_id "al4SRo6ZSrFvCrJJhtQdlgAAAAg"]
[Mon Jul 20 06:19:18.170271 2026] [security2:error] [pid 874439:tid 874632] [client 102.203.137.16:34698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4SRo6ZSrFvCrJJhtQdmgAAAD8"]
[Mon Jul 20 06:19:18.215971 2026] [security2:error] [pid 871012:tid 871192] [client 186.129.21.194:44450] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4SRrwiU-Jh5ncAILFyvwAAATs"]
[Mon Jul 20 06:19:18.290285 2026] [security2:error] [pid 874439:tid 874684] [client 34.74.185.202:61008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SRo6ZSrFvCrJJhtQdnwAAAHM"]
[Mon Jul 20 06:19:18.344704 2026] [security2:error] [pid 874439:tid 874688] [client 45.45.237.8:50506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/.git/config"] [unique_id "al4SRo6ZSrFvCrJJhtQdpQAAAHc"]
[Mon Jul 20 06:19:18.344829 2026] [security2:error] [pid 874439:tid 874688] [client 45.45.237.8:50506] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/.git/config"] [unique_id "al4SRo6ZSrFvCrJJhtQdpQAAAHc"]
[Mon Jul 20 06:19:18.375133 2026] [security2:error] [pid 871012:tid 871208] [client 57.141.18.101:41422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQbwiU-Jh5ncAILFyGwABSzM"]
[Mon Jul 20 06:19:18.496834 2026] [security2:error] [pid 874439:tid 874446] [remote 20.153.140.50:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdrAAALwY"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:19:18.497492 2026] [security2:error] [pid 874439:tid 874589] [client 34.221.76.50:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdrQAAABQ"]
[Mon Jul 20 06:19:18.536206 2026] [security2:error] [pid 874439:tid 874575] [client 77.110.127.138:60000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4SRo6ZSrFvCrJJhtQdrwAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:18.605246 2026] [security2:error] [pid 874439:tid 874651] [client 185.132.186.100:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/alfa.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdtgAAAFI"]
[Mon Jul 20 06:19:18.718837 2026] [security2:error] [pid 871012:tid 871245] [client 77.110.127.138:60002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/cake-recipe/feed/"] [unique_id "al4SRrwiU-Jh5ncAILFyzgAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:18.879625 2026] [security2:error] [pid 871012:tid 871176] [client 34.74.185.202:63935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SRrwiU-Jh5ncAILFy0QAAASs"]
[Mon Jul 20 06:19:19.067982 2026] [security2:error] [pid 871012:tid 871184] [client 136.65.156.78:18426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "appelmanimages.com"] [uri "/wp-json/batch/v1"] [unique_id "al4SR7wiU-Jh5ncAILFy1AAAATM"]
[Mon Jul 20 06:19:19.113495 2026] [security2:error] [pid 871012:tid 871191] [client 136.65.156.78:18426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "appelmanimages.com"] [uri "/"] [unique_id "al4SR7wiU-Jh5ncAILFy1gAAATo"]
[Mon Jul 20 06:19:19.275419 2026] [security2:error] [pid 874439:tid 874598] [client 103.153.183.69:26396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../app/.env"] [unique_id "al4SR46ZSrFvCrJJhtQd6QAAAB0"], referer: https://t.co/91v3mtsfcm
[Mon Jul 20 06:19:19.342052 2026] [security2:error] [pid 871012:tid 871227] [client 112.208.70.94:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SR7wiU-Jh5ncAILFy3gAAAV4"]
[Mon Jul 20 06:19:19.342160 2026] [security2:error] [pid 871012:tid 871227] [client 112.208.70.94:43668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SR7wiU-Jh5ncAILFy3gAAAV4"]
[Mon Jul 20 06:19:19.417304 2026] [security2:error] [pid 874439:tid 874600] [client 181.224.94.124:33923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SR46ZSrFvCrJJhtQd8AAAAB8"]
[Mon Jul 20 06:19:19.417413 2026] [security2:error] [pid 874439:tid 874600] [client 181.224.94.124:33923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SR46ZSrFvCrJJhtQd8AAAAB8"]
[Mon Jul 20 06:19:19.488924 2026] [security2:error] [pid 874439:tid 874625] [client 34.74.185.202:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SR46ZSrFvCrJJhtQd_wAAADg"]
[Mon Jul 20 06:19:19.645907 2026] [security2:error] [pid 874439:tid 874601] [client 105.67.131.91:54808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff"] [unique_id "al4SR46ZSrFvCrJJhtQeDQAAACA"]
[Mon Jul 20 06:19:19.758623 2026] [security2:error] [pid 874439:tid 874662] [client 216.244.66.243:37550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/next"] [unique_id "al4SR46ZSrFvCrJJhtQeFAAAAF0"]
[Mon Jul 20 06:19:19.758758 2026] [security2:error] [pid 874439:tid 874662] [client 216.244.66.243:37550] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/next"] [unique_id "al4SR46ZSrFvCrJJhtQeFAAAAF0"]
[Mon Jul 20 06:19:19.794392 2026] [security2:error] [pid 871012:tid 871148] [client 57.141.18.64:44946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQ7wiU-Jh5ncAILFyTgABDz0"]
[Mon Jul 20 06:19:20.036241 2026] [security2:error] [pid 874439:tid 874648] [client 50.116.65.227:29168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SSI6ZSrFvCrJJhtQeIgAAAE8"]
[Mon Jul 20 06:19:20.048726 2026] [security2:error] [pid 871012:tid 871188] [client 50.116.65.227:15024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SSLwiU-Jh5ncAILFy8AAAASE"]
[Mon Jul 20 06:19:20.162706 2026] [autoindex:error] [pid 874439:tid 874574] [client 205.210.31.33:62336] AH01276: Cannot serve directory /home1/rhzsqgmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:19:20.192024 2026] [security2:error] [pid 874439:tid 874635] [client 103.153.183.69:26396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../srv/.env"] [unique_id "al4SSI6ZSrFvCrJJhtQeKwAAAEI"], referer: https://www.google.com/search?q=ecftvf
[Mon Jul 20 06:19:20.219049 2026] [security2:error] [pid 874439:tid 874696] [client 34.74.185.202:59311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SSI6ZSrFvCrJJhtQeMAAAAH8"]
[Mon Jul 20 06:19:20.220029 2026] [security2:error] [pid 874439:tid 874691] [client 103.153.183.69:26396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/.env"] [unique_id "al4SSI6ZSrFvCrJJhtQeMQAAAHo"], referer: https://t.co/swx4o69x0p
[Mon Jul 20 06:19:20.391722 2026] [security2:error] [pid 874439:tid 874573] [client 185.132.186.75:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al4SSI6ZSrFvCrJJhtQePwAAAAQ"]
[Mon Jul 20 06:19:20.447362 2026] [security2:error] [pid 874439:tid 874591] [client 57.141.18.83:28364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcsgAAFi4"]
[Mon Jul 20 06:19:20.768097 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:58858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SSI6ZSrFvCrJJhtQeUQAAABc"]
[Mon Jul 20 06:19:20.783272 2026] [security2:error] [pid 874439:tid 874660] [client 104.234.53.60:44163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SSI6ZSrFvCrJJhtQebQAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:20.871524 2026] [security2:error] [pid 874439:tid 874510] [remote 188.166.241.141:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SSI6ZSrFvCrJJhtQecgAAc0Y"]
[Mon Jul 20 06:19:20.913898 2026] [security2:error] [pid 874439:tid 874682] [client 34.74.185.202:60033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SSI6ZSrFvCrJJhtQeegAAAHE"]
[Mon Jul 20 06:19:21.156621 2026] [security2:error] [pid 871012:tid 871164] [client 14.225.17.146:57633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4SR7wiU-Jh5ncAILFy7wAAAR8"], referer: http://mcg.homes/wp
[Mon Jul 20 06:19:21.219879 2026] [security2:error] [pid 874439:tid 874688] [client 50.116.65.227:15072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SSY6ZSrFvCrJJhtQejgAAAHc"]
[Mon Jul 20 06:19:21.232482 2026] [security2:error] [pid 874439:tid 874600] [client 50.116.65.227:15088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SSY6ZSrFvCrJJhtQekAAAAB8"]
[Mon Jul 20 06:19:21.232824 2026] [security2:error] [pid 874439:tid 874496] [remote 188.166.241.141:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SSY6ZSrFvCrJJhtQekQAARDg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:21.371303 2026] [security2:error] [pid 874439:tid 874630] [client 57.141.18.16:52724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRI6ZSrFvCrJJhtQdBgAAPQc"]
[Mon Jul 20 06:19:21.483448 2026] [security2:error] [pid 874439:tid 874587] [client 50.116.65.227:29180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SSY6ZSrFvCrJJhtQenwAAABI"]
[Mon Jul 20 06:19:21.496848 2026] [security2:error] [pid 871012:tid 871261] [client 50.116.65.227:15102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SSbwiU-Jh5ncAILFzDgAAAYA"]
[Mon Jul 20 06:19:21.685321 2026] [security2:error] [pid 874439:tid 874652] [client 104.234.53.81:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SSY6ZSrFvCrJJhtQeswAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:21.724108 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:51046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/graphql"] [unique_id "al4SSY6ZSrFvCrJJhtQeuQAAADc"]
[Mon Jul 20 06:19:21.724227 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:51046] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/graphql"] [unique_id "al4SSY6ZSrFvCrJJhtQeuQAAADc"]
[Mon Jul 20 06:19:21.814868 2026] [security2:error] [pid 874439:tid 874578] [client 14.225.17.146:57667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SSY6ZSrFvCrJJhtQeqwAAAAk"], referer: http://falconarrowshop.com/wp
[Mon Jul 20 06:19:21.922694 2026] [security2:error] [pid 874439:tid 874575] [client 51.68.111.241:18191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atozgroup.biz"] [uri "/robots.txt"] [unique_id "al4SSY6ZSrFvCrJJhtQexQAAAAY"]
[Mon Jul 20 06:19:21.922820 2026] [security2:error] [pid 874439:tid 874575] [client 51.68.111.241:18191] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atozgroup.biz"] [uri "/robots.txt"] [unique_id "al4SSY6ZSrFvCrJJhtQexQAAAAY"]
[Mon Jul 20 06:19:21.933169 2026] [security2:error] [pid 874439:tid 874641] [client 57.141.18.126:44424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdIQAASGg"]
[Mon Jul 20 06:19:22.131695 2026] [security2:error] [pid 874439:tid 874640] [client 57.141.18.56:25452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdMwAARww"]
[Mon Jul 20 06:19:22.200923 2026] [security2:error] [pid 874439:tid 874666] [client 185.132.186.92:29387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wikindex.php"] [unique_id "al4SSo6ZSrFvCrJJhtQe1AAAAGE"]
[Mon Jul 20 06:19:22.341998 2026] [security2:error] [pid 874439:tid 874650] [client 47.128.121.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4SSI6ZSrFvCrJJhtQeeAAAAFE"]
[Mon Jul 20 06:19:22.425499 2026] [security2:error] [pid 871012:tid 871171] [client 86.147.190.227:50494] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4SSrwiU-Jh5ncAILFzJwAAASY"]
[Mon Jul 20 06:19:22.672607 2026] [security2:error] [pid 871012:tid 871144] [client 77.110.127.138:60029] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4SSrwiU-Jh5ncAILFzLAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:22.690268 2026] [security2:error] [pid 874439:tid 874654] [client 191.7.154.2:18835] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4SSo6ZSrFvCrJJhtQe_QAAAFU"]
[Mon Jul 20 06:19:22.733040 2026] [security2:error] [pid 874439:tid 874644] [client 57.141.18.62:23616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdWgAAS10"]
[Mon Jul 20 06:19:22.943095 2026] [security2:error] [pid 874439:tid 874443] [remote 152.228.213.32:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SSo6ZSrFvCrJJhtQfDAAACwM"]
[Mon Jul 20 06:19:23.140886 2026] [security2:error] [pid 874439:tid 874473] [remote 152.228.213.32:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SS46ZSrFvCrJJhtQfGgAAZSE"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:23.262616 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.7:29612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdngAAaAI"]
[Mon Jul 20 06:19:23.275544 2026] [security2:error] [pid 871012:tid 871163] [client 57.141.18.16:52732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRrwiU-Jh5ncAILFywQABHn4"]
[Mon Jul 20 06:19:23.291622 2026] [security2:error] [pid 874439:tid 874615] [client 77.110.127.138:60036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/cake-recipe/feed/"] [unique_id "al4SS46ZSrFvCrJJhtQfHwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:23.385370 2026] [security2:error] [pid 871012:tid 871243] [client 216.244.66.243:37558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/prev"] [unique_id "al4SS7wiU-Jh5ncAILFzQgAAAW4"]
[Mon Jul 20 06:19:23.385501 2026] [security2:error] [pid 871012:tid 871243] [client 216.244.66.243:37558] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/prev"] [unique_id "al4SS7wiU-Jh5ncAILFzQgAAAW4"]
[Mon Jul 20 06:19:23.560491 2026] [proxy:error] [pid 874439:tid 874659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:19:23.560570 2026] [proxy_http:error] [pid 874439:tid 874659] [client 205.210.31.22:61162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:19:23.561379 2026] [proxy:error] [pid 874439:tid 874659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:19:23.561414 2026] [proxy_http:error] [pid 874439:tid 874659] [client 205.210.31.22:61162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:19:23.653065 2026] [security2:error] [pid 874439:tid 874682] [client 91.186.254.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SSY6ZSrFvCrJJhtQewQAAAHE"]
[Mon Jul 20 06:19:23.862220 2026] [security2:error] [pid 874439:tid 874692] [client 57.141.18.22:44952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdxwAAeyI"]
[Mon Jul 20 06:19:24.004535 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.77:52081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/seoo/alfa.php"] [unique_id "al4STLwiU-Jh5ncAILFzVgAAAXo"]
[Mon Jul 20 06:19:24.211936 2026] [security2:error] [pid 874439:tid 874472] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4STI6ZSrFvCrJJhtQfTgAAJiA"]
[Mon Jul 20 06:19:24.212140 2026] [security2:error] [pid 874439:tid 874607] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4STI6ZSrFvCrJJhtQfTgAAJiA"]
[Mon Jul 20 06:19:24.381339 2026] [security2:error] [pid 874439:tid 874604] [client 57.141.18.17:44266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SR46ZSrFvCrJJhtQd_QAAI3Q"]
[Mon Jul 20 06:19:24.497146 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.67:27612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SR46ZSrFvCrJJhtQeCAAAAmQ"]
[Mon Jul 20 06:19:24.497516 2026] [security2:error] [pid 874439:tid 874678] [client 57.141.18.109:42274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SR46ZSrFvCrJJhtQeCQAAbUQ"]
[Mon Jul 20 06:19:24.787289 2026] [security2:error] [pid 874439:tid 874609] [client 14.225.17.146:58700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4SS46ZSrFvCrJJhtQfJgAAACg"], referer: http://mazzucelli.com/wp
[Mon Jul 20 06:19:25.351340 2026] [security2:error] [pid 874439:tid 874594] [client 5.24.182.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mezzacraft.com"] [uri "/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfjQAAABk"], referer: android-app://com.pinterest/
[Mon Jul 20 06:19:25.549786 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4STY6ZSrFvCrJJhtQfqgAAADk"]
[Mon Jul 20 06:19:25.549934 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:36860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4STY6ZSrFvCrJJhtQfqgAAADk"]
[Mon Jul 20 06:19:25.704957 2026] [security2:error] [pid 874439:tid 874645] [client 104.234.53.84:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4STY6ZSrFvCrJJhtQftAAAAEw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:25.761439 2026] [security2:error] [pid 874439:tid 874666] [client 14.225.17.146:57189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4STI6ZSrFvCrJJhtQfVgAAAGE"], referer: http://alchemygroup.ca/wp
[Mon Jul 20 06:19:25.799309 2026] [security2:error] [pid 874439:tid 874695] [client 185.132.186.69:56551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Cache/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfugAAAH4"]
[Mon Jul 20 06:19:26.201926 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:58041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4STo6ZSrFvCrJJhtQfxwAAAEM"], referer: http://friendlyspreadsheet.com/wp
[Mon Jul 20 06:19:26.277023 2026] [security2:error] [pid 871012:tid 871175] [client 57.141.18.46:30420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SSbwiU-Jh5ncAILFzEQABKj8"]
[Mon Jul 20 06:19:26.293046 2026] [security2:error] [pid 874439:tid 874496] [remote 173.212.252.15:46834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4STo6ZSrFvCrJJhtQf1AAAbTg"]
[Mon Jul 20 06:19:26.544961 2026] [security2:error] [pid 874439:tid 874499] [remote 173.212.252.15:46834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4STo6ZSrFvCrJJhtQf3QAARzs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:26.567020 2026] [security2:error] [pid 874439:tid 874604] [client 171.60.139.123:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4STo6ZSrFvCrJJhtQf3wAAACM"]
[Mon Jul 20 06:19:26.567150 2026] [security2:error] [pid 874439:tid 874604] [client 171.60.139.123:53841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4STo6ZSrFvCrJJhtQf3wAAACM"]
[Mon Jul 20 06:19:26.744321 2026] [security2:error] [pid 871012:tid 871214] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4STrwiU-Jh5ncAILFzfAAAAVE"]
[Mon Jul 20 06:19:26.747050 2026] [security2:error] [pid 874439:tid 874649] [client 184.154.76.35:58482] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4STo6ZSrFvCrJJhtQf2AAAAFA"]
[Mon Jul 20 06:19:26.837506 2026] [security2:error] [pid 874439:tid 874599] [client 57.141.18.53:49142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SSo6ZSrFvCrJJhtQezgAAHkM"]
[Mon Jul 20 06:19:27.273119 2026] [security2:error] [pid 874439:tid 874652] [client 14.225.17.146:57153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4ST46ZSrFvCrJJhtQgIQAAAFM"], referer: https://friendlyspreadsheet.com/wp
[Mon Jul 20 06:19:27.406261 2026] [security2:error] [pid 871012:tid 871253] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ST7wiU-Jh5ncAILFziQAAAXg"]
[Mon Jul 20 06:19:27.407618 2026] [security2:error] [pid 874439:tid 874604] [client 184.154.76.35:55540] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4ST46ZSrFvCrJJhtQgGAAAACM"]
[Mon Jul 20 06:19:27.461487 2026] [security2:error] [pid 871012:tid 871149] [client 45.116.69.230:61870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ST7wiU-Jh5ncAILFzkAAAARA"]
[Mon Jul 20 06:19:27.461600 2026] [security2:error] [pid 871012:tid 871149] [client 45.116.69.230:61870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ST7wiU-Jh5ncAILFzkAAAARA"]
[Mon Jul 20 06:19:27.600261 2026] [security2:error] [pid 874439:tid 874648] [client 185.132.186.79:20793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/about.php"] [unique_id "al4ST46ZSrFvCrJJhtQgSAAAAE8"]
[Mon Jul 20 06:19:27.688441 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:57280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4STo6ZSrFvCrJJhtQf7wAAAE4"], referer: http://nikkidesigns.net/wp
[Mon Jul 20 06:19:27.800138 2026] [cgid:error] [pid 874439:tid 874635] [client 158.173.77.85:46207] AH01265: stderr from /home4/safesys1/public_html/allweb/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 06:19:27.888471 2026] [security2:error] [pid 874439:tid 874650] [client 14.225.17.146:60510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ST46ZSrFvCrJJhtQgQwAAAFE"]
[Mon Jul 20 06:19:27.895416 2026] [security2:error] [pid 874439:tid 874593] [client 57.141.18.105:61806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SS46ZSrFvCrJJhtQfHQAAGA8"]
[Mon Jul 20 06:19:28.004334 2026] [security2:error] [pid 871012:tid 871190] [client 184.154.76.35:55542] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-admin/css/forms.min.css"] [unique_id "al4ST7wiU-Jh5ncAILFzmwAAATk"]
[Mon Jul 20 06:19:28.004592 2026] [security2:error] [pid 874439:tid 874536] [remote 5.252.52.249:40302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgZQAAKGA"]
[Mon Jul 20 06:19:28.004771 2026] [security2:error] [pid 874439:tid 874609] [client 5.252.52.249:40302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgZQAAKGA"]
[Mon Jul 20 06:19:28.042511 2026] [security2:error] [pid 874439:tid 874660] [client 103.141.108.143:63365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgaQAAAFs"]
[Mon Jul 20 06:19:28.042606 2026] [security2:error] [pid 874439:tid 874660] [client 103.141.108.143:63365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgaQAAAFs"]
[Mon Jul 20 06:19:28.132668 2026] [security2:error] [pid 874439:tid 874610] [client 103.77.203.233:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgcgAAACk"]
[Mon Jul 20 06:19:28.132912 2026] [security2:error] [pid 874439:tid 874610] [client 103.77.203.233:57798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgcgAAACk"]
[Mon Jul 20 06:19:28.493508 2026] [security2:error] [pid 871012:tid 871124] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzogABQ24"]
[Mon Jul 20 06:19:28.493698 2026] [security2:error] [pid 871012:tid 871200] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzogABQ24"]
[Mon Jul 20 06:19:28.754340 2026] [security2:error] [pid 871012:tid 871132] [remote 91.142.222.105:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SULwiU-Jh5ncAILFzqQABDHY"]
[Mon Jul 20 06:19:28.860785 2026] [security2:error] [pid 871012:tid 871164] [client 178.152.178.232:36145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzqwAAAR8"]
[Mon Jul 20 06:19:28.860892 2026] [security2:error] [pid 871012:tid 871164] [client 178.152.178.232:36145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzqwAAAR8"]
[Mon Jul 20 06:19:29.051756 2026] [security2:error] [pid 874439:tid 874624] [client 57.141.18.3:54508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STI6ZSrFvCrJJhtQfUAAAN00"]
[Mon Jul 20 06:19:29.069254 2026] [security2:error] [pid 871012:tid 871031] [remote 91.142.222.105:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SUbwiU-Jh5ncAILFzrQABFRE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:29.300791 2026] [security2:error] [pid 874439:tid 874638] [client 50.116.65.227:18454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SUY6ZSrFvCrJJhtQgvQAAAEU"]
[Mon Jul 20 06:19:29.311247 2026] [security2:error] [pid 874439:tid 874608] [client 50.116.65.227:42696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SUY6ZSrFvCrJJhtQgvwAAACc"]
[Mon Jul 20 06:19:29.405661 2026] [security2:error] [pid 874439:tid 874635] [client 185.132.186.62:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/as.php"] [unique_id "al4SUY6ZSrFvCrJJhtQgywAAAEI"]
[Mon Jul 20 06:19:29.616972 2026] [security2:error] [pid 874439:tid 874667] [client 104.234.53.48:56285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SUY6ZSrFvCrJJhtQg2gAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:29.626915 2026] [security2:error] [pid 874439:tid 874633] [client 57.141.18.9:25998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STI6ZSrFvCrJJhtQfaQAAQH4"]
[Mon Jul 20 06:19:29.937448 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:12391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SUbwiU-Jh5ncAILFzwAAAAYA"]
[Mon Jul 20 06:19:29.937559 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:12391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SUbwiU-Jh5ncAILFzwAAAAYA"]
[Mon Jul 20 06:19:30.197614 2026] [security2:error] [pid 871012:tid 871159] [client 98.159.234.160:37821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SUrwiU-Jh5ncAILFzywAAARo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:30.241106 2026] [security2:error] [pid 874439:tid 874581] [client 45.157.112.60:21333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SUo6ZSrFvCrJJhtQg8wAAAAw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:30.266122 2026] [security2:error] [pid 874439:tid 874639] [client 57.141.18.92:43404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfnQAARnw"]
[Mon Jul 20 06:19:30.493775 2026] [security2:error] [pid 874439:tid 874607] [client 14.225.17.146:57058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4SUY6ZSrFvCrJJhtQgrQAAACY"], referer: http://dadanetnet.net/wp
[Mon Jul 20 06:19:30.575270 2026] [security2:error] [pid 874439:tid 874600] [client 14.224.227.113:55672] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SUo6ZSrFvCrJJhtQhAwAAAB8"]
[Mon Jul 20 06:19:30.645073 2026] [security2:error] [pid 874439:tid 874664] [client 57.141.18.78:31118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfvAAAXxA"]
[Mon Jul 20 06:19:30.951029 2026] [security2:error] [pid 871012:tid 871243] [client 190.245.141.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SUrwiU-Jh5ncAILFz4AABbl8"]
[Mon Jul 20 06:19:30.983665 2026] [security2:error] [pid 874439:tid 874576] [client 57.141.18.117:41158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STo6ZSrFvCrJJhtQf0wAABwg"]
[Mon Jul 20 06:19:31.081759 2026] [security2:error] [pid 874439:tid 874670] [client 50.116.65.227:42758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SU46ZSrFvCrJJhtQhJQAAAGU"]
[Mon Jul 20 06:19:31.094601 2026] [security2:error] [pid 874439:tid 874571] [client 50.116.65.227:42764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SU46ZSrFvCrJJhtQhKQAAAAI"]
[Mon Jul 20 06:19:31.188835 2026] [security2:error] [pid 871012:tid 871261] [client 185.132.186.57:52479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/about.php"] [unique_id "al4SU7wiU-Jh5ncAILFz8QAAAYA"]
[Mon Jul 20 06:19:31.195349 2026] [security2:error] [pid 874439:tid 874507] [remote 100.42.189.89:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SU46ZSrFvCrJJhtQhLwAAIkM"]
[Mon Jul 20 06:19:31.438554 2026] [security2:error] [pid 874439:tid 874449] [remote 100.42.189.89:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SU46ZSrFvCrJJhtQhPQAASgk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:19:32.122229 2026] [security2:error] [pid 874439:tid 874683] [client 104.234.53.92:61857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhbgAAAHI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:32.149120 2026] [security2:error] [pid 874439:tid 874673] [client 74.208.214.194:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhcAAAAGg"]
[Mon Jul 20 06:19:32.225866 2026] [security2:error] [pid 874439:tid 874600] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SU46ZSrFvCrJJhtQhZQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:32.619642 2026] [security2:error] [pid 874439:tid 874500] [remote 152.228.213.32:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhjgAABjw"]
[Mon Jul 20 06:19:32.673618 2026] [security2:error] [pid 874439:tid 874607] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhhgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:32.728687 2026] [security2:error] [pid 874439:tid 874659] [client 14.225.17.146:64766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhjQAAAFo"], referer: http://maxenengineering.com/wp
[Mon Jul 20 06:19:32.782004 2026] [security2:error] [pid 871012:tid 871193] [client 114.119.155.13:32501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "latiendadejorge.com.gt"] [uri "/product/teami-superfood-cleanser/"] [unique_id "al4SVLwiU-Jh5ncAILF0HwAAATw"], referer: https://sexyzeed.com/tigsc374/teami-productos-para-la-cara
[Mon Jul 20 06:19:32.808615 2026] [security2:error] [pid 871012:tid 871148] [client 112.208.70.94:44048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SVLwiU-Jh5ncAILF0IAAAAQ8"]
[Mon Jul 20 06:19:32.808736 2026] [security2:error] [pid 871012:tid 871148] [client 112.208.70.94:44048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SVLwiU-Jh5ncAILF0IAAAAQ8"]
[Mon Jul 20 06:19:32.849620 2026] [security2:error] [pid 874439:tid 874464] [remote 152.228.213.32:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhlAAAWRg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:19:32.961209 2026] [security2:error] [pid 874439:tid 874695] [client 57.141.18.85:56404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgigAAfko"]
[Mon Jul 20 06:19:32.969674 2026] [security2:error] [pid 871012:tid 871194] [client 57.141.18.102:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SULwiU-Jh5ncAILFzowABPQs"]
[Mon Jul 20 06:19:32.989468 2026] [security2:error] [pid 874439:tid 874573] [client 185.132.186.81:23801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/simi.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhmQAAAAQ"]
[Mon Jul 20 06:19:33.014214 2026] [security2:error] [pid 874439:tid 874529] [remote 34.21.244.199:30380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4SVY6ZSrFvCrJJhtQhmgAAK1k"]
[Mon Jul 20 06:19:33.512459 2026] [security2:error] [pid 874439:tid 874687] [client 57.141.18.64:25446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SUY6ZSrFvCrJJhtQgqwAAdhk"]
[Mon Jul 20 06:19:33.598856 2026] [security2:error] [pid 874439:tid 874453] [remote 34.21.244.199:30380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4SVY6ZSrFvCrJJhtQhuAAAQA0"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:19:33.733049 2026] [security2:error] [pid 874439:tid 874572] [client 14.225.17.146:49487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SVY6ZSrFvCrJJhtQhuQAAAAM"], referer: https://maxenengineering.com/wp
[Mon Jul 20 06:19:33.785608 2026] [security2:error] [pid 871012:tid 871269] [client 184.154.76.35:55628] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "al4SVbwiU-Jh5ncAILF0RgAAAYg"]
[Mon Jul 20 06:19:34.046315 2026] [security2:error] [pid 874439:tid 874672] [client 184.154.76.35:55640] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-includes/js/underscore.min.js"] [unique_id "al4SVo6ZSrFvCrJJhtQh0wAAAGc"]
[Mon Jul 20 06:19:34.292622 2026] [security2:error] [pid 874439:tid 874624] [client 184.154.76.35:55654] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-admin/css/l10n.min.css"] [unique_id "al4SVo6ZSrFvCrJJhtQh4wAAADc"]
[Mon Jul 20 06:19:34.399500 2026] [security2:error] [pid 874439:tid 874591] [client 43.205.139.3:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh6gAAABY"]
[Mon Jul 20 06:19:34.399626 2026] [security2:error] [pid 874439:tid 874591] [client 43.205.139.3:53222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh6gAAABY"]
[Mon Jul 20 06:19:34.487201 2026] [security2:error] [pid 874439:tid 874634] [client 104.234.53.72:47609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh7AAAAEE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:34.523033 2026] [security2:error] [pid 874439:tid 874580] [client 103.160.213.205:25984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.213.160.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/wp-login.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh7gAAAAs"]
[Mon Jul 20 06:19:34.698715 2026] [security2:error] [pid 874439:tid 874602] [client 184.154.76.35:55668] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-includes/css/buttons.min.css"] [unique_id "al4SVo6ZSrFvCrJJhtQh_QAAACE"]
[Mon Jul 20 06:19:34.738007 2026] [security2:error] [pid 871012:tid 871149] [client 57.141.18.70:61866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SUrwiU-Jh5ncAILFz0AABEEE"]
[Mon Jul 20 06:19:34.780831 2026] [lsapi:error] [pid 871012:tid 871116] [remote 80.210.17.232:52592] [host jenfarley.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://jenfarley.com/about/
[Mon Jul 20 06:19:34.780882 2026] [lsapi:error] [pid 871012:tid 871116] [remote 80.210.17.232:52592] [host jenfarley.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://jenfarley.com/about/
[Mon Jul 20 06:19:34.780894 2026] [lsapi:error] [pid 871012:tid 871116] [remote 80.210.17.232:52592] [host jenfarley.com] Client error on sending request(POST /?wc-ajax=get_refreshed_fragments HTTP/2.0); uri(/?wc-ajax=get_refreshed_fragments) content-length(18): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://jenfarley.com/about/
[Mon Jul 20 06:19:34.798888 2026] [security2:error] [pid 874439:tid 874577] [client 185.132.186.77:22863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/chosen.php"] [unique_id "al4SVo6ZSrFvCrJJhtQiBQAAAAg"]
[Mon Jul 20 06:19:34.846277 2026] [security2:error] [pid 871012:tid 871067] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SVrwiU-Jh5ncAILF0VAABUTU"]
[Mon Jul 20 06:19:34.846532 2026] [security2:error] [pid 871012:tid 871214] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SVrwiU-Jh5ncAILF0VAABUTU"]
[Mon Jul 20 06:19:34.945693 2026] [security2:error] [pid 874439:tid 874616] [client 110.249.201.131:15162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karimnawfal.com"] [uri "/robots.txt"] [unique_id "al4SVo6ZSrFvCrJJhtQiDgAAAC8"]
[Mon Jul 20 06:19:35.212935 2026] [security2:error] [pid 874439:tid 874626] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SVo6ZSrFvCrJJhtQiDQAAADk"]
[Mon Jul 20 06:19:35.215522 2026] [security2:error] [pid 871012:tid 871153] [client 184.154.76.35:55680] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4SVrwiU-Jh5ncAILF0WAAAARQ"]
[Mon Jul 20 06:19:35.596945 2026] [security2:error] [pid 871012:tid 871040] [remote 199.189.225.40:45469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SV7wiU-Jh5ncAILF0agABLRo"]
[Mon Jul 20 06:19:35.767016 2026] [security2:error] [pid 874439:tid 874456] [remote 62.193.192.55:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SV46ZSrFvCrJJhtQiRQAANxA"]
[Mon Jul 20 06:19:35.782697 2026] [security2:error] [pid 871012:tid 871058] [remote 199.189.225.40:45469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SV7wiU-Jh5ncAILF0cwABMCw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:35.937690 2026] [security2:error] [pid 874439:tid 874468] [remote 62.193.192.55:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SV46ZSrFvCrJJhtQiTgAAIhw"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:19:36.027917 2026] [security2:error] [pid 874439:tid 874651] [client 14.225.17.146:49660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4SV46ZSrFvCrJJhtQiQQAAAFI"], referer: http://securingmemories.com/wp
[Mon Jul 20 06:19:36.422391 2026] [security2:error] [pid 871012:tid 871247] [client 57.141.18.81:39822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SU7wiU-Jh5ncAILFz9wABchI"]
[Mon Jul 20 06:19:36.440681 2026] [security2:error] [pid 874439:tid 874507] [remote 100.42.189.89:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SWI6ZSrFvCrJJhtQiXwAAS0M"]
[Mon Jul 20 06:19:36.455961 2026] [security2:error] [pid 871012:tid 871241] [client 27.96.94.195:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SWLwiU-Jh5ncAILF0hgAAAWw"]
[Mon Jul 20 06:19:36.456069 2026] [security2:error] [pid 871012:tid 871241] [client 27.96.94.195:37240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SWLwiU-Jh5ncAILF0hgAAAWw"]
[Mon Jul 20 06:19:36.605291 2026] [security2:error] [pid 874439:tid 874612] [client 185.132.186.72:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/gold.php"] [unique_id "al4SWI6ZSrFvCrJJhtQiawAAACs"]
[Mon Jul 20 06:19:36.649946 2026] [security2:error] [pid 874439:tid 874449] [remote 100.42.189.89:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SWI6ZSrFvCrJJhtQidAAAZwk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:19:36.835390 2026] [security2:error] [pid 871012:tid 871148] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SWLwiU-Jh5ncAILF0jQAAAQ8"]
[Mon Jul 20 06:19:36.837827 2026] [security2:error] [pid 874439:tid 874599] [client 184.154.76.35:55694] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4SWI6ZSrFvCrJJhtQiaAAAAB4"]
[Mon Jul 20 06:19:36.876141 2026] [security2:error] [pid 874439:tid 874603] [client 3.67.192.83:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SWI6ZSrFvCrJJhtQieAAAACI"]
[Mon Jul 20 06:19:36.876302 2026] [security2:error] [pid 874439:tid 874603] [client 3.67.192.83:58020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SWI6ZSrFvCrJJhtQieAAAACI"]
[Mon Jul 20 06:19:36.880981 2026] [security2:error] [pid 871012:tid 871137] [remote 5.161.225.162:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4SWLwiU-Jh5ncAILF0lAABNHs"]
[Mon Jul 20 06:19:37.017834 2026] [security2:error] [pid 874439:tid 874639] [client 57.141.18.69:41100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhdAAARjA"]
[Mon Jul 20 06:19:37.199401 2026] [security2:error] [pid 871012:tid 871182] [client 171.60.139.123:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SWbwiU-Jh5ncAILF0mgAAATE"]
[Mon Jul 20 06:19:37.199498 2026] [security2:error] [pid 871012:tid 871182] [client 171.60.139.123:54346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SWbwiU-Jh5ncAILF0mgAAATE"]
[Mon Jul 20 06:19:37.328613 2026] [security2:error] [pid 871012:tid 871055] [remote 5.161.225.162:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4SWbwiU-Jh5ncAILF0ngABhyk"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 06:19:37.444853 2026] [security2:error] [pid 874439:tid 874656] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SWY6ZSrFvCrJJhtQikQAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:37.871024 2026] [security2:error] [pid 874439:tid 874631] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SWY6ZSrFvCrJJhtQisAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:37.968958 2026] [security2:error] [pid 871012:tid 871146] [client 50.116.65.227:18478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SWbwiU-Jh5ncAILF0qwAAAQ0"]
[Mon Jul 20 06:19:37.982725 2026] [security2:error] [pid 871012:tid 871211] [client 50.116.65.227:42812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SWbwiU-Jh5ncAILF0rAAAAU4"]
[Mon Jul 20 06:19:38.137039 2026] [security2:error] [pid 874439:tid 874672] [client 45.116.69.230:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQixgAAAGc"]
[Mon Jul 20 06:19:38.137195 2026] [security2:error] [pid 874439:tid 874672] [client 45.116.69.230:62410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQixgAAAGc"]
[Mon Jul 20 06:19:38.214330 2026] [security2:error] [pid 871012:tid 871227] [client 57.141.18.78:37966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SVbwiU-Jh5ncAILF0MQABXjw"]
[Mon Jul 20 06:19:38.417370 2026] [security2:error] [pid 874439:tid 874639] [client 185.132.186.66:57139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Requests/Text/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi2AAAAEY"]
[Mon Jul 20 06:19:38.598666 2026] [security2:error] [pid 874439:tid 874680] [client 103.77.203.233:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi5AAAAG8"]
[Mon Jul 20 06:19:38.598832 2026] [security2:error] [pid 874439:tid 874680] [client 103.77.203.233:58440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi5AAAAG8"]
[Mon Jul 20 06:19:38.708181 2026] [security2:error] [pid 871012:tid 871177] [client 103.141.108.143:63848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SWrwiU-Jh5ncAILF0xwAAASw"]
[Mon Jul 20 06:19:38.708294 2026] [security2:error] [pid 871012:tid 871177] [client 103.141.108.143:63848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SWrwiU-Jh5ncAILF0xwAAASw"]
[Mon Jul 20 06:19:38.941484 2026] [security2:error] [pid 874439:tid 874660] [client 3.149.57.90:12428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi1gAAAFs"], referer: https://windowtx.com
[Mon Jul 20 06:19:39.018983 2026] [security2:error] [pid 871012:tid 871064] [remote 100.42.189.89:42400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF01wABVDI"]
[Mon Jul 20 06:19:39.019156 2026] [security2:error] [pid 871012:tid 871217] [client 100.42.189.89:42400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF01wABVDI"]
[Mon Jul 20 06:19:39.025973 2026] [security2:error] [pid 874439:tid 874474] [remote 81.173.115.7:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjAAAAfSI"]
[Mon Jul 20 06:19:39.047248 2026] [security2:error] [pid 874439:tid 874691] [client 34.73.38.214:57267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjAQAAAHo"]
[Mon Jul 20 06:19:39.067946 2026] [security2:error] [pid 871012:tid 871157] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SWrwiU-Jh5ncAILF00AAAARg"]
[Mon Jul 20 06:19:39.070504 2026] [security2:error] [pid 871012:tid 871159] [client 184.154.76.35:41658] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4SWrwiU-Jh5ncAILF0zQAAARo"]
[Mon Jul 20 06:19:39.152428 2026] [security2:error] [pid 871012:tid 871264] [client 34.73.38.214:57405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SW7wiU-Jh5ncAILF02QAAAYM"]
[Mon Jul 20 06:19:39.165714 2026] [security2:error] [pid 874439:tid 874626] [client 104.234.53.69:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SW46ZSrFvCrJJhtQjBwAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:39.173328 2026] [security2:error] [pid 874439:tid 874532] [remote 38.242.157.30:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjCQAAIFw"]
[Mon Jul 20 06:19:39.218410 2026] [security2:error] [pid 874439:tid 874466] [remote 81.173.115.7:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjDQAAJxo"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:19:39.266958 2026] [security2:error] [pid 874439:tid 874453] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SW46ZSrFvCrJJhtQjDwAAYg0"]
[Mon Jul 20 06:19:39.267179 2026] [security2:error] [pid 874439:tid 874667] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SW46ZSrFvCrJJhtQjDwAAYg0"]
[Mon Jul 20 06:19:39.272543 2026] [security2:error] [pid 874439:tid 874674] [client 34.73.38.214:57443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjEQAAAGk"]
[Mon Jul 20 06:19:39.272933 2026] [security2:error] [pid 871012:tid 871175] [client 57.141.18.37:30414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SVrwiU-Jh5ncAILF0TwABKlo"]
[Mon Jul 20 06:19:39.400136 2026] [security2:error] [pid 871012:tid 871229] [client 34.73.38.214:57483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SW7wiU-Jh5ncAILF06gAAAWA"]
[Mon Jul 20 06:19:39.435927 2026] [security2:error] [pid 874439:tid 874469] [remote 38.242.157.30:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjGAAAGB0"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:19:39.473939 2026] [security2:error] [pid 874439:tid 874540] [remote 72.167.132.114:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjGQAAfmQ"]
[Mon Jul 20 06:19:39.487451 2026] [security2:error] [pid 871012:tid 871209] [client 178.152.178.232:37242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF07AAAAUw"]
[Mon Jul 20 06:19:39.487579 2026] [security2:error] [pid 871012:tid 871209] [client 178.152.178.232:37242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF07AAAAUw"]
[Mon Jul 20 06:19:39.513473 2026] [security2:error] [pid 871012:tid 871208] [client 14.225.17.146:53042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4SWrwiU-Jh5ncAILF0uwAAAUs"], referer: http://collectingrealestate.com/wp
[Mon Jul 20 06:19:39.533889 2026] [security2:error] [pid 871012:tid 871260] [client 34.73.38.214:57526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SW7wiU-Jh5ncAILF07wAAAX8"]
[Mon Jul 20 06:19:39.640568 2026] [security2:error] [pid 871012:tid 871086] [remote 78.46.157.202:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SW7wiU-Jh5ncAILF08QABZUg"]
[Mon Jul 20 06:19:39.656870 2026] [security2:error] [pid 874439:tid 874615] [client 34.73.38.214:57567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjIgAAAC4"]
[Mon Jul 20 06:19:39.779910 2026] [security2:error] [pid 874439:tid 874685] [client 34.73.38.214:57622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjLgAAAHQ"]
[Mon Jul 20 06:19:39.834658 2026] [security2:error] [pid 871012:tid 871031] [remote 78.46.157.202:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SW7wiU-Jh5ncAILF0_AABaRE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:39.896101 2026] [security2:error] [pid 874439:tid 874667] [client 34.73.38.214:57682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjMwAAAGI"]
[Mon Jul 20 06:19:40.014786 2026] [security2:error] [pid 874439:tid 874603] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/readme.html"] [unique_id "al4SXI6ZSrFvCrJJhtQjPgAAACI"]
[Mon Jul 20 06:19:40.016578 2026] [security2:error] [pid 874439:tid 874659] [client 34.73.38.214:57727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SXI6ZSrFvCrJJhtQjPwAAAFo"]
[Mon Jul 20 06:19:40.020170 2026] [security2:error] [pid 874439:tid 874631] [client 184.154.76.35:41664] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/readme.html"] [unique_id "al4SW46ZSrFvCrJJhtQjOgAAAD4"]
[Mon Jul 20 06:19:40.072834 2026] [security2:error] [pid 874439:tid 874651] [client 50.116.65.227:53368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SXI6ZSrFvCrJJhtQjQQAAAFI"]
[Mon Jul 20 06:19:40.083789 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:53370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SXLwiU-Jh5ncAILF1AgAAATo"]
[Mon Jul 20 06:19:40.124594 2026] [security2:error] [pid 874439:tid 874565] [remote 72.167.132.114:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjSAAAQH0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:19:40.176696 2026] [security2:error] [pid 874439:tid 874653] [client 57.141.18.58:48894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SV46ZSrFvCrJJhtQiLgAAVHU"]
[Mon Jul 20 06:19:40.216933 2026] [security2:error] [pid 871012:tid 871225] [client 185.132.186.84:49787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/mu-plugins/index.php"] [unique_id "al4SXLwiU-Jh5ncAILF1BAAAAVw"]
[Mon Jul 20 06:19:40.345648 2026] [security2:error] [pid 874439:tid 874587] [client 57.141.18.2:46066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SV46ZSrFvCrJJhtQiNQAAEks"]
[Mon Jul 20 06:19:40.363644 2026] [security2:error] [pid 871012:tid 871176] [client 127.0.0.1:50878] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4SXLwiU-Jh5ncAILF1DQAAASs"], referer: https://www.google.com/
[Mon Jul 20 06:19:40.435789 2026] [security2:error] [pid 874439:tid 874552] [remote 217.61.143.92:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjWgAAHHA"]
[Mon Jul 20 06:19:40.439237 2026] [security2:error] [pid 874439:tid 874676] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXI6ZSrFvCrJJhtQjXAAAAGs"]
[Mon Jul 20 06:19:40.456682 2026] [security2:error] [pid 874439:tid 874635] [client 181.224.94.124:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjYgAAAEI"]
[Mon Jul 20 06:19:40.456800 2026] [security2:error] [pid 874439:tid 874635] [client 181.224.94.124:52242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjYgAAAEI"]
[Mon Jul 20 06:19:40.547038 2026] [security2:error] [pid 874439:tid 874510] [remote 217.61.143.92:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjZwAAA0Y"]
[Mon Jul 20 06:19:40.547217 2026] [security2:error] [pid 874439:tid 874572] [client 217.61.143.92:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjZwAAA0Y"]
[Mon Jul 20 06:19:40.642557 2026] [security2:error] [pid 874439:tid 874649] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXI6ZSrFvCrJJhtQjaQAAAFA"]
[Mon Jul 20 06:19:40.666070 2026] [security2:error] [pid 874439:tid 874459] [remote 217.61.143.92:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjawAAPhM"], referer: https://fluidtemple.org/wp-login.php
[Mon Jul 20 06:19:40.887519 2026] [security2:error] [pid 874439:tid 874648] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXI6ZSrFvCrJJhtQjbwAAAE8"]
[Mon Jul 20 06:19:41.058725 2026] [security2:error] [pid 871012:tid 871223] [client 54.169.146.187:25820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "curlsnpearlsss.com"] [uri "/wprm_print/rellenos-de-yuca-stuffed-cassava"] [unique_id "al4SXbwiU-Jh5ncAILF1GwAAAVo"], referer: https://curlsnpearlsss.com/rellenos-de-yuca-stuffed-cassava/
[Mon Jul 20 06:19:41.090939 2026] [security2:error] [pid 874439:tid 874669] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjeAAAAGQ"]
[Mon Jul 20 06:19:41.231526 2026] [security2:error] [pid 874439:tid 874650] [client 57.141.18.94:60030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SWI6ZSrFvCrJJhtQiZAAAUQs"]
[Mon Jul 20 06:19:41.303219 2026] [security2:error] [pid 874439:tid 874642] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjigAAAEk"]
[Mon Jul 20 06:19:41.479181 2026] [security2:error] [pid 874439:tid 874575] [client 14.225.17.146:60044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjZgAAAAY"], referer: http://claysharecon.com/wp
[Mon Jul 20 06:19:41.502677 2026] [security2:error] [pid 874439:tid 874622] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjmAAAADU"]
[Mon Jul 20 06:19:41.519465 2026] [security2:error] [pid 871012:tid 871202] [client 14.225.17.146:49708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4SW7wiU-Jh5ncAILF0-QAAAUU"]
[Mon Jul 20 06:19:41.767861 2026] [security2:error] [pid 874439:tid 874581] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjowAAAAw"]
[Mon Jul 20 06:19:42.012734 2026] [security2:error] [pid 871012:tid 871191] [client 185.132.186.101:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/abcd.php"] [unique_id "al4SXrwiU-Jh5ncAILF1QwAAATo"]
[Mon Jul 20 06:19:42.242110 2026] [core:error] [pid 874439:tid 874654] [client 14.225.17.146:52903] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wp
[Mon Jul 20 06:19:42.242133 2026] [core:error] [pid 874439:tid 874654] [client 14.225.17.146:52903] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wp
[Mon Jul 20 06:19:42.345605 2026] [security2:error] [pid 874439:tid 874675] [client 57.141.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SXo6ZSrFvCrJJhtQjtgAAAGo"]
[Mon Jul 20 06:19:42.452638 2026] [security2:error] [pid 874439:tid 874635] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SXo6ZSrFvCrJJhtQjwQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:42.498144 2026] [security2:error] [pid 874439:tid 874463] [remote 75.119.135.239:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.135.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj0AAANRc"]
[Mon Jul 20 06:19:42.572284 2026] [security2:error] [pid 874439:tid 874482] [remote 47.86.33.52:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj1AAAJSo"]
[Mon Jul 20 06:19:42.696949 2026] [security2:error] [pid 874439:tid 874501] [remote 75.119.135.239:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.135.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj3gAAUT0"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:19:42.878545 2026] [cgid:error] [pid 874439:tid 874680] [client 66.132.172.143:40292] AH01265: stderr from /home1/asliceo1/public_html/frontecinc/cgi-bin/: attempt to invoke directory as script, referer: https://www.frontecinc.asliceofleadership.com:443/cgi-bin
[Mon Jul 20 06:19:42.957922 2026] [security2:error] [pid 871012:tid 871199] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1VwAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:43.073959 2026] [security2:error] [pid 871012:tid 871250] [client 14.225.17.146:60405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1WAAAAXU"], referer: http://mtlegnews.gov/wp
[Mon Jul 20 06:19:43.135930 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:60426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj7QAAAFQ"], referer: http://longevityperformanceclinic.com/wp
[Mon Jul 20 06:19:43.174910 2026] [security2:error] [pid 874439:tid 874668] [client 57.141.18.108:23372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQiywAAYzw"]
[Mon Jul 20 06:19:43.200888 2026] [security2:error] [pid 874439:tid 874607] [client 57.141.18.119:61296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQizwAAJjY"]
[Mon Jul 20 06:19:43.755866 2026] [security2:error] [pid 871012:tid 871259] [client 14.225.17.146:60324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1SAAAAX4"], referer: http://reosportsboats.com/wp
[Mon Jul 20 06:19:43.896251 2026] [security2:error] [pid 871012:tid 871222] [client 14.225.17.146:50094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1TQAAAVk"], referer: http://sarahsnyder.net/wp
[Mon Jul 20 06:19:44.019909 2026] [security2:error] [pid 874439:tid 874619] [client 57.141.18.59:46588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SW46ZSrFvCrJJhtQjCwAAMiQ"]
[Mon Jul 20 06:19:44.293472 2026] [security2:error] [pid 871012:tid 871251] [client 57.141.18.62:38244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SW7wiU-Jh5ncAILF07gABdgQ"]
[Mon Jul 20 06:19:44.710163 2026] [security2:error] [pid 874439:tid 874475] [remote 97.74.87.194:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkYAAAVyM"]
[Mon Jul 20 06:19:44.728327 2026] [security2:error] [pid 874439:tid 874549] [remote 47.86.33.52:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkYQAAeW0"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 06:19:44.836616 2026] [security2:error] [pid 871012:tid 871183] [client 185.132.186.67:27585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/rk2.php"] [unique_id "al4SYLwiU-Jh5ncAILF1igAAATI"]
[Mon Jul 20 06:19:44.927142 2026] [security2:error] [pid 874439:tid 874626] [client 14.225.17.146:60145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkYgAAADk"], referer: https://sarahsnyder.net/wp
[Mon Jul 20 06:19:45.024411 2026] [security2:error] [pid 874439:tid 874652] [client 14.225.17.146:63312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkZwAAAFM"], referer: https://reosportsboats.com/wp
[Mon Jul 20 06:19:45.064879 2026] [security2:error] [pid 874439:tid 874609] [client 57.141.18.0:43824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjSQAAKAE"]
[Mon Jul 20 06:19:45.117667 2026] [security2:error] [pid 874439:tid 874481] [remote 97.74.87.194:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4SYY6ZSrFvCrJJhtQkcwAAGSk"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:19:45.430851 2026] [security2:error] [pid 874439:tid 874600] [client 14.225.17.146:55512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkbQAAAB8"]
[Mon Jul 20 06:19:45.533502 2026] [security2:error] [pid 871012:tid 871101] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SYbwiU-Jh5ncAILF1oQABbVc"]
[Mon Jul 20 06:19:45.533679 2026] [security2:error] [pid 871012:tid 871242] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SYbwiU-Jh5ncAILF1oQABbVc"]
[Mon Jul 20 06:19:45.567801 2026] [security2:error] [pid 871012:tid 871258] [client 158.173.89.95:57779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SYbwiU-Jh5ncAILF1owAAAX0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:45.640157 2026] [security2:error] [pid 874439:tid 874622] [client 14.225.17.146:49519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkPgAAADU"], referer: http://expertcultures.com/wp
[Mon Jul 20 06:19:45.988471 2026] [security2:error] [pid 874439:tid 874657] [client 57.141.18.64:46202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXY6ZSrFvCrJJhtQjdwAAWDg"]
[Mon Jul 20 06:19:46.478994 2026] [security2:error] [pid 871012:tid 871246] [client 66.249.69.65:40176] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "2sweetchicks.com"] [uri "/robots.txt"] [unique_id "al4SYrwiU-Jh5ncAILF1xAAAAXE"]
[Mon Jul 20 06:19:46.567472 2026] [security2:error] [pid 874439:tid 874599] [client 57.141.18.57:48916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXY6ZSrFvCrJJhtQjmwAAHk8"]
[Mon Jul 20 06:19:46.820315 2026] [autoindex:error] [pid 871012:tid 871174] [client 198.235.24.5:60984] AH01276: Cannot serve directory /home2/qxmjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:19:46.910853 2026] [security2:error] [pid 871012:tid 871233] [client 50.116.65.227:53986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SYrwiU-Jh5ncAILF13wAAAWQ"]
[Mon Jul 20 06:19:46.922622 2026] [security2:error] [pid 874439:tid 874677] [client 50.116.65.227:53524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SYo6ZSrFvCrJJhtQkxwAAAGw"]
[Mon Jul 20 06:19:47.104947 2026] [security2:error] [pid 871012:tid 871190] [client 185.132.186.72:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-search-interpreter.php"] [unique_id "al4SY7wiU-Jh5ncAILF15QAAATk"]
[Mon Jul 20 06:19:47.271964 2026] [security2:error] [pid 871012:tid 871155] [client 27.96.94.195:36878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SY7wiU-Jh5ncAILF16QAAARY"]
[Mon Jul 20 06:19:47.272652 2026] [security2:error] [pid 871012:tid 871155] [client 27.96.94.195:36878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SY7wiU-Jh5ncAILF16QAAARY"]
[Mon Jul 20 06:19:47.515438 2026] [security2:error] [pid 871012:tid 871172] [client 14.225.17.146:56817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4SYbwiU-Jh5ncAILF1mwAAASc"], referer: http://latiendadejorge.com.gt/wp
[Mon Jul 20 06:19:47.620425 2026] [security2:error] [pid 874439:tid 874682] [client 14.225.17.146:63711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4SY46ZSrFvCrJJhtQk2wAAAHE"], referer: http://thesoloceos.com/wp
[Mon Jul 20 06:19:47.712622 2026] [security2:error] [pid 874439:tid 874577] [client 34.74.185.202:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SY46ZSrFvCrJJhtQk8wAAAAg"]
[Mon Jul 20 06:19:47.732931 2026] [security2:error] [pid 874439:tid 874518] [remote 81.173.115.7:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SY46ZSrFvCrJJhtQk9QAAGk4"]
[Mon Jul 20 06:19:47.820185 2026] [security2:error] [pid 874439:tid 874680] [client 171.60.139.123:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SY46ZSrFvCrJJhtQk_gAAAG8"]
[Mon Jul 20 06:19:47.820282 2026] [security2:error] [pid 874439:tid 874680] [client 171.60.139.123:54846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SY46ZSrFvCrJJhtQk_gAAAG8"]
[Mon Jul 20 06:19:48.009394 2026] [security2:error] [pid 874439:tid 874558] [remote 188.138.102.156:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4SY46ZSrFvCrJJhtQlDwAAY3Y"]
[Mon Jul 20 06:19:48.018630 2026] [security2:error] [pid 874439:tid 874491] [remote 81.173.115.7:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlEQAAETM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:48.047854 2026] [security2:error] [pid 871012:tid 871162] [client 112.208.70.94:44408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF1_AAAAR0"]
[Mon Jul 20 06:19:48.047957 2026] [security2:error] [pid 871012:tid 871162] [client 112.208.70.94:44408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF1_AAAAR0"]
[Mon Jul 20 06:19:48.178768 2026] [security2:error] [pid 871012:tid 871173] [client 57.141.18.52:40606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1XwABKDM"]
[Mon Jul 20 06:19:48.250039 2026] [security2:error] [pid 874439:tid 874563] [remote 188.138.102.156:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlGgAAXXs"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 06:19:48.256188 2026] [security2:error] [pid 874439:tid 874652] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlEwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:48.266837 2026] [security2:error] [pid 874439:tid 874573] [client 93.84.97.4:34034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4SZI6ZSrFvCrJJhtQlHAAAAAQ"]
[Mon Jul 20 06:19:48.296007 2026] [security2:error] [pid 874439:tid 874614] [client 14.225.17.146:53964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4SY46ZSrFvCrJJhtQk2QAAAC0"], referer: http://nextlevelpressurewashing.com/wp
[Mon Jul 20 06:19:48.395762 2026] [security2:error] [pid 874439:tid 874603] [client 65.1.132.125:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlJAAAACI"]
[Mon Jul 20 06:19:48.450851 2026] [security2:error] [pid 874439:tid 874645] [client 93.84.97.4:57626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4SZI6ZSrFvCrJJhtQlKAAAAEw"]
[Mon Jul 20 06:19:48.490965 2026] [security2:error] [pid 874439:tid 874622] [client 34.74.185.202:63448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SZI6ZSrFvCrJJhtQlLgAAADU"]
[Mon Jul 20 06:19:48.660299 2026] [security2:error] [pid 874439:tid 874694] [client 14.225.17.146:63207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlIgAAAH0"], referer: http://guidehunting.com/wp
[Mon Jul 20 06:19:48.727891 2026] [security2:error] [pid 871012:tid 871254] [client 43.205.139.3:19988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF2DwAAAXk"]
[Mon Jul 20 06:19:48.727993 2026] [security2:error] [pid 871012:tid 871254] [client 43.205.139.3:19988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF2DwAAAXk"]
[Mon Jul 20 06:19:48.733108 2026] [security2:error] [pid 871012:tid 871270] [client 14.225.17.146:59993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4SZLwiU-Jh5ncAILF2CAAAAYk"], referer: https://thesoloceos.com/wp
[Mon Jul 20 06:19:48.761746 2026] [security2:error] [pid 874439:tid 874612] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlNAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:48.862193 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlRwAAAE0"]
[Mon Jul 20 06:19:48.862343 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:62945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlRwAAAE0"]
[Mon Jul 20 06:19:48.908923 2026] [security2:error] [pid 874439:tid 874576] [client 185.132.186.76:42187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/chosen.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlSgAAAAc"]
[Mon Jul 20 06:19:49.143001 2026] [security2:error] [pid 874439:tid 874596] [client 57.141.18.23:20022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SX46ZSrFvCrJJhtQkHwAAG1w"]
[Mon Jul 20 06:19:49.300204 2026] [security2:error] [pid 874439:tid 874652] [client 103.77.203.233:59171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlYAAAAFM"]
[Mon Jul 20 06:19:49.300319 2026] [security2:error] [pid 874439:tid 874652] [client 103.77.203.233:59171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlYAAAAFM"]
[Mon Jul 20 06:19:49.341556 2026] [security2:error] [pid 871012:tid 871203] [client 34.74.185.202:52813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SZbwiU-Jh5ncAILF2HQAAAUY"]
[Mon Jul 20 06:19:49.383120 2026] [security2:error] [pid 871012:tid 871193] [client 103.141.108.143:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SZbwiU-Jh5ncAILF2HgAAATw"]
[Mon Jul 20 06:19:49.383226 2026] [security2:error] [pid 871012:tid 871193] [client 103.141.108.143:64324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SZbwiU-Jh5ncAILF2HgAAATw"]
[Mon Jul 20 06:19:49.456406 2026] [security2:error] [pid 871012:tid 871155] [client 13.201.64.214:27830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4SZbwiU-Jh5ncAILF2HwAAARY"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:19:49.719219 2026] [security2:error] [pid 874439:tid 874696] [client 47.128.113.66:51402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "3dprintrecycling.com"] [uri "/robots.txt"] [unique_id "al4SZY6ZSrFvCrJJhtQlgAAAAH8"]
[Mon Jul 20 06:19:49.745987 2026] [security2:error] [pid 874439:tid 874663] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/static../etc/passwd"] [unique_id "al4SZY6ZSrFvCrJJhtQlgQAAAF4"], referer: https://www.google.com/
[Mon Jul 20 06:19:49.758202 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.98:64700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkUgAAAnE"]
[Mon Jul 20 06:19:49.766107 2026] [security2:error] [pid 874439:tid 874641] [client 34.74.185.202:62985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SZY6ZSrFvCrJJhtQlhAAAAEg"]
[Mon Jul 20 06:19:49.773645 2026] [security2:error] [pid 874439:tid 874609] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/static../.env"] [unique_id "al4SZY6ZSrFvCrJJhtQlhQAAACg"], referer: https://twitter.com/
[Mon Jul 20 06:19:49.807022 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:18702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SZbwiU-Jh5ncAILF2JQAAAXg"]
[Mon Jul 20 06:19:49.810100 2026] [security2:error] [pid 874439:tid 874570] [client 14.225.17.146:63224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlcQAAAAE"], referer: https://guidehunting.com/wp
[Mon Jul 20 06:19:49.814050 2026] [security2:error] [pid 874439:tid 874569] [client 57.141.18.85:39958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkXQAAAAA"]
[Mon Jul 20 06:19:49.819266 2026] [security2:error] [pid 874439:tid 874676] [client 50.116.65.227:18708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SZY6ZSrFvCrJJhtQliAAAAGs"]
[Mon Jul 20 06:19:49.894277 2026] [security2:error] [pid 874439:tid 874561] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQljwAAInk"]
[Mon Jul 20 06:19:49.894459 2026] [security2:error] [pid 874439:tid 874603] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQljwAAInk"]
[Mon Jul 20 06:19:50.198301 2026] [security2:error] [pid 871012:tid 871250] [client 178.152.178.232:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SZrwiU-Jh5ncAILF2MwAAAXU"]
[Mon Jul 20 06:19:50.198448 2026] [security2:error] [pid 871012:tid 871250] [client 178.152.178.232:37278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SZrwiU-Jh5ncAILF2MwAAAXU"]
[Mon Jul 20 06:19:50.653656 2026] [security2:error] [pid 871012:tid 871249] [client 57.141.18.110:57578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SYbwiU-Jh5ncAILF1qAABdFE"]
[Mon Jul 20 06:19:50.720259 2026] [security2:error] [pid 874439:tid 874594] [client 185.132.186.53:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/autoload_classmap.php"] [unique_id "al4SZo6ZSrFvCrJJhtQlsgAAABk"]
[Mon Jul 20 06:19:50.867120 2026] [security2:error] [pid 871012:tid 871226] [client 34.74.185.202:50848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SZrwiU-Jh5ncAILF2QQAAAV0"]
[Mon Jul 20 06:19:51.107631 2026] [security2:error] [pid 871012:tid 871242] [client 171.61.165.146:27907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2RQAAAW0"]
[Mon Jul 20 06:19:51.107850 2026] [security2:error] [pid 871012:tid 871242] [client 171.61.165.146:27907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2RQAAAW0"]
[Mon Jul 20 06:19:51.432399 2026] [security2:error] [pid 874439:tid 874595] [client 181.224.94.124:3568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl0wAAABo"]
[Mon Jul 20 06:19:51.432498 2026] [security2:error] [pid 874439:tid 874595] [client 181.224.94.124:3568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl0wAAABo"]
[Mon Jul 20 06:19:51.768875 2026] [security2:error] [pid 871012:tid 871124] [remote 45.90.123.233:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2VAABM24"]
[Mon Jul 20 06:19:51.774743 2026] [security2:error] [pid 874439:tid 874680] [client 34.74.185.202:57243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SZ46ZSrFvCrJJhtQl6gAAAG8"]
[Mon Jul 20 06:19:51.999545 2026] [security2:error] [pid 871012:tid 871051] [remote 45.90.123.233:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2YQABVCU"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:19:52.186315 2026] [security2:error] [pid 871012:tid 871160] [client 77.222.116.8:57166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "partnerselectricalllc.com"] [uri "/"] [unique_id "al4SaLwiU-Jh5ncAILF2ZwAAARs"]
[Mon Jul 20 06:19:52.259097 2026] [security2:error] [pid 871012:tid 871227] [client 54.184.226.94:64705] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2ZAAAAV4"]
[Mon Jul 20 06:19:52.428869 2026] [security2:error] [pid 871012:tid 871059] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.gitconfig"] [unique_id "al4SaLwiU-Jh5ncAILF2ewABdC0"]
[Mon Jul 20 06:19:52.451476 2026] [security2:error] [pid 871012:tid 871123] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.aws/config"] [unique_id "al4SaLwiU-Jh5ncAILF2gAABdG0"]
[Mon Jul 20 06:19:52.503590 2026] [security2:error] [pid 874439:tid 874676] [client 185.132.186.103:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/block-template-utils-other.php"] [unique_id "al4SaI6ZSrFvCrJJhtQmEgAAAGs"]
[Mon Jul 20 06:19:52.531006 2026] [security2:error] [pid 874439:tid 874635] [client 104.234.53.74:25193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SaI6ZSrFvCrJJhtQmFQAAAEI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:52.534673 2026] [security2:error] [pid 874439:tid 874615] [client 57.141.18.113:50390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SY46ZSrFvCrJJhtQk5gAALlc"]
[Mon Jul 20 06:19:52.614550 2026] [security2:error] [pid 874439:tid 874625] [client 77.222.116.8:57179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "partnerselectricalllc.com"] [uri "/_profiler/empty/search/results"] [unique_id "al4SaI6ZSrFvCrJJhtQmGQAAADg"]
[Mon Jul 20 06:19:52.705611 2026] [security2:error] [pid 871012:tid 871108] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.env"] [unique_id "al4SaLwiU-Jh5ncAILF2hQABdF4"]
[Mon Jul 20 06:19:52.914537 2026] [security2:error] [pid 874439:tid 874573] [client 34.74.185.202:53132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SaI6ZSrFvCrJJhtQmKAAAAAQ"]
[Mon Jul 20 06:19:53.072471 2026] [security2:error] [pid 874439:tid 874655] [client 57.141.18.123:41232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlFAAAVhQ"]
[Mon Jul 20 06:19:53.270623 2026] [security2:error] [pid 871012:tid 871109] [remote 57.141.18.75:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3566199"] [unique_id "al4SabwiU-Jh5ncAILF2mAABXF8"]
[Mon Jul 20 06:19:53.272383 2026] [security2:error] [pid 871012:tid 871266] [client 104.234.53.59:26393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SabwiU-Jh5ncAILF2mQAAAYU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:53.457925 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2fQABdHc"]
[Mon Jul 20 06:19:53.492575 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2eAABdCQ"]
[Mon Jul 20 06:19:53.515376 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2dgABdE0"]
[Mon Jul 20 06:19:53.545118 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2egABdDY"]
[Mon Jul 20 06:19:53.559766 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2dwABdAc"]
[Mon Jul 20 06:19:53.565125 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2gQABdDk"]
[Mon Jul 20 06:19:53.574672 2026] [security2:error] [pid 874439:tid 874685] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4SaY6ZSrFvCrJJhtQmOgAAdFU"], referer: http://assasalnazaha.com/wp
[Mon Jul 20 06:19:53.596347 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2fAABdEc"]
[Mon Jul 20 06:19:53.611109 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2eQABdEs"]
[Mon Jul 20 06:19:53.712147 2026] [security2:error] [pid 874439:tid 874651] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SaY6ZSrFvCrJJhtQmRQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:53.765416 2026] [security2:error] [pid 871012:tid 871224] [client 144.24.3.91:22591] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "thelastgamestandingexp.com"] [uri "/project-horned-owl-review"] [unique_id "al4SabwiU-Jh5ncAILF2owAAAVs"]
[Mon Jul 20 06:19:53.765558 2026] [security2:error] [pid 871012:tid 871224] [client 144.24.3.91:22591] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thelastgamestandingexp.com"] [uri "/project-horned-owl-review"] [unique_id "al4SabwiU-Jh5ncAILF2owAAAVs"]
[Mon Jul 20 06:19:53.831842 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2jQABdFk"]
[Mon Jul 20 06:19:53.832493 2026] [security2:error] [pid 871012:tid 871072] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.backup"] [unique_id "al4SabwiU-Jh5ncAILF2pgABdDo"]
[Mon Jul 20 06:19:53.864811 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2lAABdCI"]
[Mon Jul 20 06:19:53.927934 2026] [security2:error] [pid 871012:tid 871054] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.bak"] [unique_id "al4SabwiU-Jh5ncAILF2rQABLig"]
[Mon Jul 20 06:19:53.928124 2026] [security2:error] [pid 871012:tid 871179] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.bak"] [unique_id "al4SabwiU-Jh5ncAILF2rQABLig"]
[Mon Jul 20 06:19:54.161872 2026] [security2:error] [pid 874439:tid 874654] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/files../etc/passwd"] [unique_id "al4Sao6ZSrFvCrJJhtQmbAAAAFU"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:19:54.210489 2026] [security2:error] [pid 871012:tid 871202] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2tAAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:54.608618 2026] [security2:error] [pid 874439:tid 874581] [client 57.141.18.98:41802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlfQAADC0"]
[Mon Jul 20 06:19:54.673490 2026] [security2:error] [pid 874439:tid 874627] [client 34.74.185.202:63956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Sao6ZSrFvCrJJhtQmhQAAADo"]
[Mon Jul 20 06:19:54.710170 2026] [security2:error] [pid 871012:tid 871041] [remote 216.222.198.186:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.222.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4SarwiU-Jh5ncAILF2vwABKRs"]
[Mon Jul 20 06:19:54.872119 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:53881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sao6ZSrFvCrJJhtQmhwAAAE4"], referer: http://lifeisbetterlakeside.com/wp
[Mon Jul 20 06:19:54.918713 2026] [security2:error] [pid 871012:tid 871154] [client 103.153.183.69:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../root/.bash_history"] [unique_id "al4SarwiU-Jh5ncAILF2xQAAARU"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:19:54.941757 2026] [security2:error] [pid 871012:tid 871078] [remote 216.222.198.186:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.222.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4SarwiU-Jh5ncAILF2xgABU0A"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 06:19:55.054492 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:53550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4Sa7wiU-Jh5ncAILF2zwAAATo"]
[Mon Jul 20 06:19:55.068409 2026] [security2:error] [pid 874439:tid 874595] [client 50.116.65.227:18750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4Sa46ZSrFvCrJJhtQmngAAABE"]
[Mon Jul 20 06:19:55.116745 2026] [security2:error] [pid 874439:tid 874650] [client 14.225.17.146:56749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sao6ZSrFvCrJJhtQmjwAAAFE"], referer: http://mezzacraft.com/wp
[Mon Jul 20 06:19:55.309164 2026] [security2:error] [pid 874439:tid 874592] [client 185.132.186.78:38975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/alam.php"] [unique_id "al4Sa46ZSrFvCrJJhtQmrQAAABc"]
[Mon Jul 20 06:19:55.328486 2026] [security2:error] [pid 874439:tid 874622] [client 14.225.17.146:53836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Sa46ZSrFvCrJJhtQmoAAAADU"], referer: http://samdothan.org/wp
[Mon Jul 20 06:19:55.520297 2026] [security2:error] [pid 874439:tid 874647] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/files../.env"] [unique_id "al4Sa46ZSrFvCrJJhtQmvwAAAE4"], referer: https://duckduckgo.com/?q=j63fh
[Mon Jul 20 06:19:55.609551 2026] [security2:error] [pid 871012:tid 871211] [client 57.141.18.5:52720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZrwiU-Jh5ncAILF2PAABTkQ"]
[Mon Jul 20 06:19:55.874579 2026] [security2:error] [pid 874439:tid 874600] [client 57.141.18.38:36836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZo6ZSrFvCrJJhtQlvwAAH2c"]
[Mon Jul 20 06:19:55.963662 2026] [security2:error] [pid 874439:tid 874641] [client 34.74.185.202:63585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Sa46ZSrFvCrJJhtQm0gAAAEg"]
[Mon Jul 20 06:19:56.050430 2026] [security2:error] [pid 874439:tid 874695] [client 57.141.18.31:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZ46ZSrFvCrJJhtQlywAAfmU"]
[Mon Jul 20 06:19:56.186975 2026] [security2:error] [pid 874439:tid 874510] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SbI6ZSrFvCrJJhtQm5QAAFkY"]
[Mon Jul 20 06:19:56.187280 2026] [security2:error] [pid 874439:tid 874591] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SbI6ZSrFvCrJJhtQm5QAAFkY"]
[Mon Jul 20 06:19:56.275016 2026] [security2:error] [pid 871012:tid 871084] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.old"] [unique_id "al4SbLwiU-Jh5ncAILF27QABe0Y"]
[Mon Jul 20 06:19:56.276616 2026] [security2:error] [pid 871012:tid 871043] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/api/.env"] [unique_id "al4SbLwiU-Jh5ncAILF27AABex0"]
[Mon Jul 20 06:19:56.284837 2026] [security2:error] [pid 874439:tid 874450] [remote 57.141.18.105:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4SbI6ZSrFvCrJJhtQm8QAACQo"]
[Mon Jul 20 06:19:56.302259 2026] [security2:error] [pid 874439:tid 874661] [client 57.141.18.118:47276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl2wAAXGs"]
[Mon Jul 20 06:19:56.327074 2026] [security2:error] [pid 874439:tid 874597] [client 14.225.17.146:56819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Sa46ZSrFvCrJJhtQmnQAAABw"], referer: http://northbrookcpa.ca/wp
[Mon Jul 20 06:19:56.639357 2026] [security2:error] [pid 874439:tid 874569] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/assets../etc/passwd"] [unique_id "al4SbI6ZSrFvCrJJhtQnDAAAAAA"], referer: https://www.facebook.com/
[Mon Jul 20 06:19:56.666047 2026] [security2:error] [pid 874439:tid 874611] [client 57.141.18.85:26400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl9QAAKlA"]
[Mon Jul 20 06:19:56.749979 2026] [security2:error] [pid 871012:tid 871251] [client 34.74.185.202:58139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SbLwiU-Jh5ncAILF2-AAAAXY"]
[Mon Jul 20 06:19:56.795955 2026] [security2:error] [pid 874439:tid 874591] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/assets../.env"] [unique_id "al4SbI6ZSrFvCrJJhtQnEwAAABY"], referer: https://duckduckgo.com/?q=aiv3l
[Mon Jul 20 06:19:56.843268 2026] [security2:error] [pid 874439:tid 874618] [client 104.234.53.63:54329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SbI6ZSrFvCrJJhtQnFQAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:57.008740 2026] [security2:error] [pid 874439:tid 874648] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/uploads../.env"] [unique_id "al4SbY6ZSrFvCrJJhtQnHAAAAE8"], referer: https://www.bing.com/search?q=gpht2h
[Mon Jul 20 06:19:57.025143 2026] [security2:error] [pid 871012:tid 871180] [client 57.141.18.22:28030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2bgABL3E"]
[Mon Jul 20 06:19:57.108032 2026] [security2:error] [pid 871012:tid 871181] [client 185.132.186.103:37759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/adminfusm.php"] [unique_id "al4SbbwiU-Jh5ncAILF3CAAAATA"]
[Mon Jul 20 06:19:57.129475 2026] [security2:error] [pid 871012:tid 871140] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifeisbetterlakeside.com"] [uri "/graphql"] [unique_id "al4SbbwiU-Jh5ncAILF3CQABXH4"]
[Mon Jul 20 06:19:57.131869 2026] [security2:error] [pid 874439:tid 874676] [client 56.125.35.21:31796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SbI6ZSrFvCrJJhtQm_QAAAGs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:19:57.186484 2026] [security2:error] [pid 871012:tid 871164] [client 14.225.17.146:53284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4Sa7wiU-Jh5ncAILF25wAAAR8"], referer: http://lutheranphilosopher.com/wp
[Mon Jul 20 06:19:57.234740 2026] [security2:error] [pid 874439:tid 874526] [remote 188.166.241.141:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnJwAADFY"]
[Mon Jul 20 06:19:57.252263 2026] [security2:error] [pid 871012:tid 871138] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/backend/.env"] [unique_id "al4SbbwiU-Jh5ncAILF3EQABJXw"]
[Mon Jul 20 06:19:57.252293 2026] [security2:error] [pid 871012:tid 871017] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/serviceAccountKey.json"] [unique_id "al4SbbwiU-Jh5ncAILF3GgABJQM"]
[Mon Jul 20 06:19:57.252296 2026] [security2:error] [pid 871012:tid 871137] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/config/.env"] [unique_id "al4SbbwiU-Jh5ncAILF3FQABJXs"]
[Mon Jul 20 06:19:57.252301 2026] [security2:error] [pid 871012:tid 871114] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.docker/config.json"] [unique_id "al4SbbwiU-Jh5ncAILF3GwABJWQ"]
[Mon Jul 20 06:19:57.252333 2026] [security2:error] [pid 871012:tid 871062] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.npmrc"] [unique_id "al4SbbwiU-Jh5ncAILF3HAABJTA"]
[Mon Jul 20 06:19:57.252453 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/backend/.env"] [unique_id "al4SbbwiU-Jh5ncAILF3EQABJXw"]
[Mon Jul 20 06:19:57.252685 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/serviceAccountKey.json"] [unique_id "al4SbbwiU-Jh5ncAILF3GgABJQM"]
[Mon Jul 20 06:19:57.301432 2026] [security2:error] [pid 874439:tid 874602] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/media../.env"] [unique_id "al4SbY6ZSrFvCrJJhtQnKwAAACE"], referer: https://t.co/n35fe4djkj
[Mon Jul 20 06:19:57.434797 2026] [security2:error] [pid 874439:tid 874682] [client 57.141.18.10:33294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SaI6ZSrFvCrJJhtQmHQAAcRs"]
[Mon Jul 20 06:19:57.498833 2026] [security2:error] [pid 874439:tid 874604] [client 35.245.239.138:56367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uwl.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnMwAAACM"]
[Mon Jul 20 06:19:57.619426 2026] [security2:error] [pid 874439:tid 874569] [client 35.245.239.138:56367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SbY6ZSrFvCrJJhtQnPgAAAAA"]
[Mon Jul 20 06:19:57.627860 2026] [security2:error] [pid 874439:tid 874539] [remote 188.166.241.141:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnQQAAemM"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:57.659931 2026] [security2:error] [pid 871012:tid 871106] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifeisbetterlakeside.com"] [uri "/api/graphql"] [unique_id "al4SbbwiU-Jh5ncAILF3IQABJVw"]
[Mon Jul 20 06:19:57.775692 2026] [security2:error] [pid 871012:tid 871172] [client 57.141.18.90:40190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2lQABJ1I"]
[Mon Jul 20 06:19:57.782646 2026] [security2:error] [pid 874439:tid 874688] [client 34.74.185.202:65401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SbY6ZSrFvCrJJhtQnTgAAAHc"]
[Mon Jul 20 06:19:57.783630 2026] [authz_core:error] [pid 871012:tid 871075] [remote 104.28.251.190:64862] AH01630: client denied by server configuration: /home3/lakesix0/public_html/.htpasswd
[Mon Jul 20 06:19:57.837411 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3EwABJRQ"]
[Mon Jul 20 06:19:57.838641 2026] [core:error] [pid 874439:tid 874570] [client 74.7.241.135:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:19:57.838675 2026] [core:error] [pid 874439:tid 874570] [client 74.7.241.135:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:19:57.838841 2026] [security2:error] [pid 874439:tid 874570] [client 74.7.241.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elementfix.co.uk"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnUwAAAAE"]
[Mon Jul 20 06:19:57.844499 2026] [security2:error] [pid 874439:tid 874637] [client 74.7.241.135:33176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elementfix.co.uk"] [uri "/robots.txt"] [unique_id "al4SbY6ZSrFvCrJJhtQnUAAAAEQ"]
[Mon Jul 20 06:19:57.891831 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3FgABJXQ"]
[Mon Jul 20 06:19:57.981306 2026] [security2:error] [pid 871012:tid 871149] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3JwAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:58.033990 2026] [security2:error] [pid 871012:tid 871026] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.vscode/launch.json"] [unique_id "al4SbrwiU-Jh5ncAILF3LgABJQw"]
[Mon Jul 20 06:19:58.034060 2026] [security2:error] [pid 871012:tid 871077] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifeisbetterlakeside.com"] [uri "/v1/graphql"] [unique_id "al4SbrwiU-Jh5ncAILF3LQABJT8"]
[Mon Jul 20 06:19:58.034159 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/.vscode/launch.json"] [unique_id "al4SbrwiU-Jh5ncAILF3LgABJQw"]
[Mon Jul 20 06:19:58.043759 2026] [security2:error] [pid 874439:tid 874675] [client 14.225.17.146:53217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnNQAAAGo"]
[Mon Jul 20 06:19:58.096810 2026] [security2:error] [pid 871012:tid 871064] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.ssh/id_rsa"] [unique_id "al4SbrwiU-Jh5ncAILF3MgABJTI"]
[Mon Jul 20 06:19:58.102466 2026] [security2:error] [pid 874439:tid 874503] [remote 116.179.32.215:5588] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4Sbo6ZSrFvCrJJhtQnYwAAXD8"]
[Mon Jul 20 06:19:58.127094 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3FwABJU4"]
[Mon Jul 20 06:19:58.131384 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3GAABJTM"]
[Mon Jul 20 06:19:58.168642 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3EgABJXo"]
[Mon Jul 20 06:19:58.172671 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3GQABJXI"]
[Mon Jul 20 06:19:58.176476 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3FAABJTE"]
[Mon Jul 20 06:19:58.251486 2026] [security2:error] [pid 874439:tid 874684] [client 34.74.185.202:50514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Sbo6ZSrFvCrJJhtQndAAAAHM"]
[Mon Jul 20 06:19:58.386566 2026] [security2:error] [pid 871012:tid 871152] [client 35.245.239.138:63197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SbrwiU-Jh5ncAILF3QAAAARM"]
[Mon Jul 20 06:19:58.389851 2026] [security2:error] [pid 871012:tid 871240] [client 27.96.94.195:37377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SbrwiU-Jh5ncAILF3QQAAAWs"]
[Mon Jul 20 06:19:58.389962 2026] [security2:error] [pid 871012:tid 871240] [client 27.96.94.195:37377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SbrwiU-Jh5ncAILF3QQAAAWs"]
[Mon Jul 20 06:19:58.449510 2026] [security2:error] [pid 874439:tid 874584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQncgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:58.502242 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3JAABJW8"]
[Mon Jul 20 06:19:58.565235 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:55358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQngwAAAAI"]
[Mon Jul 20 06:19:58.565373 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:55358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQngwAAAAI"]
[Mon Jul 20 06:19:58.567171 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3JQABJUo"]
[Mon Jul 20 06:19:58.628955 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3LAABJUI"]
[Mon Jul 20 06:19:58.649350 2026] [security2:error] [pid 871012:tid 871205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3RgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:58.726653 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3KwABJWA"]
[Mon Jul 20 06:19:58.740150 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3MwABJRg"]
[Mon Jul 20 06:19:58.804971 2026] [security2:error] [pid 874439:tid 874680] [client 104.234.53.55:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQnnQAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:58.828820 2026] [security2:error] [pid 874439:tid 874611] [client 45.231.86.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQnlQAAACo"]
[Mon Jul 20 06:19:58.917828 2026] [security2:error] [pid 874439:tid 874649] [client 158.173.166.181:46513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQnpQAAAFA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:58.926072 2026] [security2:error] [pid 871012:tid 871265] [client 185.132.186.68:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sodium_compat/lib/widget-group.php"] [unique_id "al4SbrwiU-Jh5ncAILF3UQAAAYQ"]
[Mon Jul 20 06:19:58.947798 2026] [security2:error] [pid 871012:tid 871033] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/id_dsa"] [unique_id "al4SbrwiU-Jh5ncAILF3UgABVRM"]
[Mon Jul 20 06:19:58.948172 2026] [security2:error] [pid 871012:tid 871087] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.ssh/id_dsa"] [unique_id "al4SbrwiU-Jh5ncAILF3UwABVUk"]
[Mon Jul 20 06:19:59.007738 2026] [security2:error] [pid 871012:tid 871102] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.ssh/config"] [unique_id "al4Sb7wiU-Jh5ncAILF3XgABVVg"]
[Mon Jul 20 06:19:59.009145 2026] [security2:error] [pid 871012:tid 871132] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/id_rsa"] [unique_id "al4Sb7wiU-Jh5ncAILF3WwABVXY"]
[Mon Jul 20 06:19:59.192798 2026] [security2:error] [pid 871012:tid 871059] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/server.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3agABVS0"]
[Mon Jul 20 06:19:59.194706 2026] [security2:error] [pid 871012:tid 871057] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/key.pem"] [unique_id "al4Sb7wiU-Jh5ncAILF3bAABVSs"]
[Mon Jul 20 06:19:59.194711 2026] [security2:error] [pid 871012:tid 871042] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/privatekey.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3aQABVRw"]
[Mon Jul 20 06:19:59.200261 2026] [security2:error] [pid 871012:tid 871105] [remote 119.249.100.176:26094] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4Sb7wiU-Jh5ncAILF3bQABEVs"]
[Mon Jul 20 06:19:59.250857 2026] [security2:error] [pid 871012:tid 871207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3WgAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.299147 2026] [security2:error] [pid 871012:tid 871163] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3XwAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.396130 2026] [security2:error] [pid 874439:tid 874654] [client 34.74.185.202:55175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Sb46ZSrFvCrJJhtQnvgAAAFU"]
[Mon Jul 20 06:19:59.397647 2026] [security2:error] [pid 871012:tid 871197] [client 57.141.18.39:29231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SarwiU-Jh5ncAILF2wAABQGs"]
[Mon Jul 20 06:19:59.437252 2026] [security2:error] [pid 871012:tid 871204] [client 57.141.18.61:20354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SarwiU-Jh5ncAILF2wgABR1M"]
[Mon Jul 20 06:19:59.504590 2026] [security2:error] [pid 871012:tid 871055] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/localhost.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3egABVSk"]
[Mon Jul 20 06:19:59.514000 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:63462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnxAAAAE0"]
[Mon Jul 20 06:19:59.514142 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:63462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnxAAAAE0"]
[Mon Jul 20 06:19:59.517846 2026] [security2:error] [pid 874439:tid 874626] [client 57.141.18.59:26962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sao6ZSrFvCrJJhtQmjgAAORE"]
[Mon Jul 20 06:19:59.540518 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3VAABVUg"]
[Mon Jul 20 06:19:59.542349 2026] [security2:error] [pid 874439:tid 874630] [client 14.225.17.146:65092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnQwAAAD0"], referer: http://partnerselectricalllc.com/wp
[Mon Jul 20 06:19:59.552012 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3VQABVQg"]
[Mon Jul 20 06:19:59.566912 2026] [security2:error] [pid 871012:tid 871083] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/host.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3gQABVUU"]
[Mon Jul 20 06:19:59.567185 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/host.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3gQABVUU"]
[Mon Jul 20 06:19:59.573420 2026] [security2:error] [pid 871012:tid 871149] [client 173.230.133.164:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3dgAAARA"]
[Mon Jul 20 06:19:59.575971 2026] [security2:error] [pid 871012:tid 871209] [client 173.230.133.164:56356] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/"] [unique_id "al4Sb7wiU-Jh5ncAILF3dAAAAUw"]
[Mon Jul 20 06:19:59.577221 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3XQABVSc"]
[Mon Jul 20 06:19:59.602446 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3XAABVW4"]
[Mon Jul 20 06:19:59.623398 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3YgABVSU"]
[Mon Jul 20 06:19:59.632212 2026] [security2:error] [pid 874439:tid 874691] [client 35.245.239.138:53865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Sb46ZSrFvCrJJhtQn0QAAAHo"]
[Mon Jul 20 06:19:59.745371 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3aAABVQY"]
[Mon Jul 20 06:19:59.814592 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3awABVW0"]
[Mon Jul 20 06:19:59.937509 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnzQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.962538 2026] [security2:error] [pid 871012:tid 871216] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3gwAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.989503 2026] [security2:error] [pid 874439:tid 874608] [client 103.77.203.233:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQn5QAAACc"]
[Mon Jul 20 06:19:59.989637 2026] [security2:error] [pid 874439:tid 874608] [client 103.77.203.233:59781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQn5QAAACc"]
[Mon Jul 20 06:20:00.038648 2026] [security2:error] [pid 874439:tid 874586] [client 173.230.133.164:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4Sb46ZSrFvCrJJhtQn2wAAABE"]
[Mon Jul 20 06:20:00.053590 2026] [security2:error] [pid 871012:tid 871202] [client 173.230.133.164:59914] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4Sb7wiU-Jh5ncAILF3jQAAAUU"]
[Mon Jul 20 06:20:00.087449 2026] [security2:error] [pid 871012:tid 871165] [client 103.141.108.143:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ScLwiU-Jh5ncAILF3kAAAASA"]
[Mon Jul 20 06:20:00.087584 2026] [security2:error] [pid 871012:tid 871165] [client 103.141.108.143:64799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ScLwiU-Jh5ncAILF3kAAAASA"]
[Mon Jul 20 06:20:00.141332 2026] [security2:error] [pid 874439:tid 874678] [client 35.245.239.138:58067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ScI6ZSrFvCrJJhtQn8QAAAG0"]
[Mon Jul 20 06:20:00.269987 2026] [security2:error] [pid 871012:tid 871050] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.continue/config.json"] [unique_id "al4ScLwiU-Jh5ncAILF3lQABgiQ"]
[Mon Jul 20 06:20:00.270243 2026] [security2:error] [pid 871012:tid 871263] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/.continue/config.json"] [unique_id "al4ScLwiU-Jh5ncAILF3lQABgiQ"]
[Mon Jul 20 06:20:00.287422 2026] [security2:error] [pid 874439:tid 874475] [remote 119.249.100.241:2687] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4ScI6ZSrFvCrJJhtQn_wAANSM"]
[Mon Jul 20 06:20:00.581938 2026] [security2:error] [pid 874439:tid 874643] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQn-wAAAEo"]
[Mon Jul 20 06:20:00.597235 2026] [security2:error] [pid 874439:tid 874631] [client 34.208.80.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoCAAAAD4"]
[Mon Jul 20 06:20:00.602619 2026] [security2:error] [pid 874439:tid 874445] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoEAAAUQU"]
[Mon Jul 20 06:20:00.602825 2026] [security2:error] [pid 874439:tid 874650] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoEAAAUQU"]
[Mon Jul 20 06:20:00.605775 2026] [security2:error] [pid 871012:tid 871166] [client 34.208.80.94:60798] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/"] [unique_id "al4ScLwiU-Jh5ncAILF3nAAAASE"]
[Mon Jul 20 06:20:00.619666 2026] [security2:error] [pid 874439:tid 874676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQn_AAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:00.687174 2026] [security2:error] [pid 871012:tid 871085] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.openclaw/.env"] [unique_id "al4ScLwiU-Jh5ncAILF3nwABc0c"]
[Mon Jul 20 06:20:00.724633 2026] [security2:error] [pid 871012:tid 871247] [client 185.132.186.64:23717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/raw.php"] [unique_id "al4ScLwiU-Jh5ncAILF3oQAAAXI"]
[Mon Jul 20 06:20:00.725797 2026] [security2:error] [pid 874439:tid 874574] [client 35.245.239.138:63442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ScI6ZSrFvCrJJhtQoHwAAAAU"]
[Mon Jul 20 06:20:00.746555 2026] [security2:error] [pid 871012:tid 871016] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.hermes/auth.json"] [unique_id "al4ScLwiU-Jh5ncAILF3qAABcwI"]
[Mon Jul 20 06:20:00.747293 2026] [security2:error] [pid 871012:tid 871103] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.hermes/.env"] [unique_id "al4ScLwiU-Jh5ncAILF3pQABc1k"]
[Mon Jul 20 06:20:00.765825 2026] [security2:error] [pid 871012:tid 871173] [client 14.225.17.146:59662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3cAAAASg"], referer: http://eframiproperties.com/wp
[Mon Jul 20 06:20:00.849012 2026] [security2:error] [pid 874439:tid 874584] [client 50.116.65.227:29460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4ScI6ZSrFvCrJJhtQoLgAAAEs"]
[Mon Jul 20 06:20:00.866188 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3mQABczY"]
[Mon Jul 20 06:20:00.887736 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3mgABc00"]
[Mon Jul 20 06:20:00.889337 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3mwABcwc"]
[Mon Jul 20 06:20:01.024918 2026] [security2:error] [pid 874439:tid 874600] [client 34.208.80.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoKQAAAB8"]
[Mon Jul 20 06:20:01.028363 2026] [security2:error] [pid 871012:tid 871163] [client 34.208.80.94:50822] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4ScLwiU-Jh5ncAILF3rQAAAR4"]
[Mon Jul 20 06:20:01.233627 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:44827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoUAAAAHY"]
[Mon Jul 20 06:20:01.233765 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:44827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoUAAAAHY"]
[Mon Jul 20 06:20:01.249896 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3owABc0s"]
[Mon Jul 20 06:20:01.278224 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3pAABc3M"]
[Mon Jul 20 06:20:01.281912 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoRAAAAFw"]
[Mon Jul 20 06:20:01.360309 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3qgABcwo"]
[Mon Jul 20 06:20:01.389570 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3pgABczo"]
[Mon Jul 20 06:20:01.396771 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3pwABcyI"]
[Mon Jul 20 06:20:01.477999 2026] [security2:error] [pid 874439:tid 874695] [client 181.224.94.124:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoYwAAAH4"]
[Mon Jul 20 06:20:01.478427 2026] [security2:error] [pid 874439:tid 874695] [client 181.224.94.124:11257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoYwAAAH4"]
[Mon Jul 20 06:20:01.479454 2026] [security2:error] [pid 871012:tid 871257] [client 135.132.71.159:24014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "maxenengineering.com"] [uri "/wp-content/plugins/kirki/readme.txt"] [unique_id "al4ScbwiU-Jh5ncAILF3uwAAAXw"]
[Mon Jul 20 06:20:01.481310 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3qQABcyg"]
[Mon Jul 20 06:20:01.614585 2026] [security2:error] [pid 871012:tid 871199] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScbwiU-Jh5ncAILF3tgAAAUI"]
[Mon Jul 20 06:20:01.697894 2026] [security2:error] [pid 874439:tid 874581] [client 35.245.239.138:63297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ScY6ZSrFvCrJJhtQocQAAAAw"]
[Mon Jul 20 06:20:01.815992 2026] [security2:error] [pid 874439:tid 874591] [client 14.182.195.220:52125] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ScY6ZSrFvCrJJhtQofgAAABY"]
[Mon Jul 20 06:20:01.816577 2026] [security2:error] [pid 874439:tid 874652] [client 14.182.195.220:52126] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ScY6ZSrFvCrJJhtQogAAAAFM"]
[Mon Jul 20 06:20:01.819767 2026] [security2:error] [pid 874439:tid 874646] [client 14.182.195.220:52124] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ScY6ZSrFvCrJJhtQogQAAAE0"]
[Mon Jul 20 06:20:01.853819 2026] [security2:error] [pid 874439:tid 874603] [client 171.61.165.146:15397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQohQAAACI"]
[Mon Jul 20 06:20:01.853926 2026] [security2:error] [pid 874439:tid 874603] [client 171.61.165.146:15397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQohQAAACI"]
[Mon Jul 20 06:20:01.967481 2026] [security2:error] [pid 874439:tid 874578] [client 178.152.178.232:37130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQokwAAAAk"]
[Mon Jul 20 06:20:01.967646 2026] [security2:error] [pid 874439:tid 874578] [client 178.152.178.232:37130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQokwAAAAk"]
[Mon Jul 20 06:20:02.037892 2026] [security2:error] [pid 871012:tid 871219] [client 14.225.17.146:60037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3ewAAAVY"], referer: http://healthylifegourmet.org/wp
[Mon Jul 20 06:20:02.272397 2026] [security2:error] [pid 874439:tid 874683] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQojQAAAHI"]
[Mon Jul 20 06:20:02.402759 2026] [security2:error] [pid 871012:tid 871029] [remote 57.141.18.41:26880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3HQABNA8"]
[Mon Jul 20 06:20:02.450512 2026] [security2:error] [pid 874439:tid 874648] [client 77.110.127.138:60410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4Sco6ZSrFvCrJJhtQougAAAE8"]
[Mon Jul 20 06:20:02.470319 2026] [security2:error] [pid 874439:tid 874580] [client 35.245.239.138:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Sco6ZSrFvCrJJhtQowQAAAAs"]
[Mon Jul 20 06:20:02.541557 2026] [security2:error] [pid 874439:tid 874652] [client 185.132.186.78:40727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/jcrop/about.php"] [unique_id "al4Sco6ZSrFvCrJJhtQoxAAAAFM"]
[Mon Jul 20 06:20:02.598468 2026] [security2:error] [pid 874439:tid 874624] [client 57.141.18.55:52036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnOwAAN1c"]
[Mon Jul 20 06:20:02.642304 2026] [security2:error] [pid 874439:tid 874693] [client 57.141.18.40:32704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnOgAAfCs"]
[Mon Jul 20 06:20:02.666665 2026] [security2:error] [pid 874439:tid 874582] [client 20.199.97.14:2688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Sco6ZSrFvCrJJhtQozQAAAA0"]
[Mon Jul 20 06:20:02.804586 2026] [security2:error] [pid 874439:tid 874658] [client 57.141.18.64:46156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnTAAAWSU"]
[Mon Jul 20 06:20:02.819007 2026] [security2:error] [pid 874439:tid 874642] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQoywAAAEk"], referer: 1'"3000
[Mon Jul 20 06:20:02.819126 2026] [security2:error] [pid 874439:tid 874573] [client 20.199.97.14:2688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Sco6ZSrFvCrJJhtQo3wAAAAQ"]
[Mon Jul 20 06:20:03.088254 2026] [security2:error] [pid 874439:tid 874687] [client 50.116.65.227:55654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Sc46ZSrFvCrJJhtQo9gAAAHY"]
[Mon Jul 20 06:20:03.100939 2026] [security2:error] [pid 874439:tid 874649] [client 50.116.65.227:29480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Sc46ZSrFvCrJJhtQo-AAAAFA"]
[Mon Jul 20 06:20:03.123586 2026] [security2:error] [pid 871012:tid 871095] [remote 57.141.18.28:36480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3OgABP1E"]
[Mon Jul 20 06:20:03.415803 2026] [security2:error] [pid 874439:tid 874646] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQo8QAAAE0"], referer: 1'"3000
[Mon Jul 20 06:20:03.485833 2026] [security2:error] [pid 874439:tid 874532] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-config.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpGgAAA1w"]
[Mon Jul 20 06:20:03.485832 2026] [security2:error] [pid 874439:tid 874508] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-config.php.old"] [unique_id "al4Sc46ZSrFvCrJJhtQpHAAAA0Q"]
[Mon Jul 20 06:20:03.486249 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-config.php.old"] [unique_id "al4Sc46ZSrFvCrJJhtQpHAAAA0Q"]
[Mon Jul 20 06:20:03.487558 2026] [security2:error] [pid 874439:tid 874508] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/core/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpIAAAA0Q"]
[Mon Jul 20 06:20:03.487561 2026] [security2:error] [pid 874439:tid 874472] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/laravel/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpIgAAAyA"]
[Mon Jul 20 06:20:03.488814 2026] [security2:error] [pid 874439:tid 874565] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpIQAAA30"]
[Mon Jul 20 06:20:03.527279 2026] [security2:error] [pid 874439:tid 874532] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/config/.env.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpHwAAA1w"]
[Mon Jul 20 06:20:03.692444 2026] [security2:error] [pid 874439:tid 874692] [client 104.234.53.53:63883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpKQAAAHs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:03.850701 2026] [security2:error] [pid 874439:tid 874650] [client 35.245.239.138:56698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Sc46ZSrFvCrJJhtQpQgAAAFE"]
[Mon Jul 20 06:20:03.855120 2026] [security2:error] [pid 874439:tid 874481] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/web/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpQwAAAyk"]
[Mon Jul 20 06:20:03.913696 2026] [security2:error] [pid 874439:tid 874547] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/config.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpTgAAA2s"]
[Mon Jul 20 06:20:03.913790 2026] [security2:error] [pid 874439:tid 874511] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/configuration.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpUQAAA0c"]
[Mon Jul 20 06:20:03.914422 2026] [security2:error] [pid 874439:tid 874554] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/public/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpTwAAA3I"]
[Mon Jul 20 06:20:03.914838 2026] [security2:error] [pid 874439:tid 874479] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.swp"] [unique_id "al4Sc46ZSrFvCrJJhtQpUAAAAyc"]
[Mon Jul 20 06:20:04.000172 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpEAAAAyQ"]
[Mon Jul 20 06:20:04.062375 2026] [security2:error] [pid 874439:tid 874657] [client 50.116.65.227:29508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpZwAAAFg"]
[Mon Jul 20 06:20:04.065507 2026] [security2:error] [pid 874439:tid 874675] [client 14.225.17.146:59524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQowAAAAGo"], referer: http://recruitinginsight.us/wp
[Mon Jul 20 06:20:04.086647 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:59109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpXAAAAA0"]
[Mon Jul 20 06:20:04.087990 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpHQAAAyM"]
[Mon Jul 20 06:20:04.122013 2026] [security2:error] [pid 874439:tid 874633] [client 104.234.53.53:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpbwAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:04.140821 2026] [security2:error] [pid 874439:tid 874690] [client 57.141.18.5:47738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnswAAeWA"]
[Mon Jul 20 06:20:04.146541 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpHgAAAy4"]
[Mon Jul 20 06:20:04.146886 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpIwAAA3E"]
[Mon Jul 20 06:20:04.181467 2026] [security2:error] [pid 874439:tid 874680] [client 50.116.65.227:29516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4SdI6ZSrFvCrJJhtQpeAAAADc"]
[Mon Jul 20 06:20:04.196865 2026] [http2:info] [pid 884009:tid 884009] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:20:04.200615 2026] [autoindex:error] [pid 874439:tid 874644] [client 67.205.140.53:0] AH01276: Cannot serve directory /home4/elemeph8/public_html/elementfix/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:04.224029 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpJAAAA3k"]
[Mon Jul 20 06:20:04.280482 2026] [security2:error] [pid 871012:tid 871028] [remote 57.141.18.39:29247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3fwABNQ4"]
[Mon Jul 20 06:20:04.390700 2026] [security2:error] [pid 874439:tid 874676] [client 185.132.186.103:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/admin.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpfwAAAGs"]
[Mon Jul 20 06:20:04.466425 2026] [security2:error] [pid 874439:tid 874546] [remote 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpUwAAA2o"]
[Mon Jul 20 06:20:04.548990 2026] [security2:error] [pid 874439:tid 874509] [remote 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpTQAAA0U"]
[Mon Jul 20 06:20:04.630853 2026] [security2:error] [pid 874439:tid 874467] [remote 34.21.244.199:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpjwAAKRs"]
[Mon Jul 20 06:20:04.740338 2026] [security2:error] [pid 874439:tid 874666] [client 34.207.130.29:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpSwAAAGE"]
[Mon Jul 20 06:20:04.743993 2026] [security2:error] [pid 874439:tid 874599] [client 34.207.130.29:51640] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4Sc46ZSrFvCrJJhtQpRwAAAB4"]
[Mon Jul 20 06:20:04.755037 2026] [security2:error] [pid 874439:tid 874584] [client 14.225.17.146:59971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpjgAAAA8"], referer: http://koaconsultants.com/wp
[Mon Jul 20 06:20:05.229456 2026] [security2:error] [pid 884009:tid 884017] [remote 95.217.78.234:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SdRKaHUf6J8d3elJB2wAApQY"]
[Mon Jul 20 06:20:05.246723 2026] [security2:error] [pid 874439:tid 874518] [remote 34.21.244.199:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SdY6ZSrFvCrJJhtQpuQAAcU4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:05.362244 2026] [security2:error] [pid 874439:tid 874637] [client 57.141.18.9:47916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoEQAARGc"]
[Mon Jul 20 06:20:05.382897 2026] [security2:error] [pid 874439:tid 874642] [client 34.74.185.202:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SdY6ZSrFvCrJJhtQpvwAAAEk"]
[Mon Jul 20 06:20:05.412218 2026] [security2:error] [pid 884009:tid 884174] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SdRKaHUf6J8d3elJBzwAAAKY"], referer: 1'"3000
[Mon Jul 20 06:20:05.465771 2026] [security2:error] [pid 884009:tid 884021] [remote 95.217.78.234:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SdRKaHUf6J8d3elJB5AAAyAo"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:05.588424 2026] [security2:error] [pid 874439:tid 874651] [client 35.245.239.138:56484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SdY6ZSrFvCrJJhtQpzAAAAFI"]
[Mon Jul 20 06:20:05.813985 2026] [security2:error] [pid 884009:tid 884217] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SdRKaHUf6J8d3elJB6AAAANE"], referer: 1'"3000
[Mon Jul 20 06:20:05.852111 2026] [security2:error] [pid 874439:tid 874585] [client 57.141.18.14:34136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoSAAAEFA"]
[Mon Jul 20 06:20:06.080833 2026] [security2:error] [pid 884009:tid 884238] [client 14.225.17.146:52542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4SdhKaHUf6J8d3elJB9AAAAOY"], referer: http://grndl.com/wp
[Mon Jul 20 06:20:06.184905 2026] [security2:error] [pid 884009:tid 884262] [client 185.132.186.63:26055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/chosen.php"] [unique_id "al4SdhKaHUf6J8d3elJB-gAAAP4"]
[Mon Jul 20 06:20:06.352616 2026] [security2:error] [pid 874439:tid 874607] [client 57.141.18.40:32720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQodwAAJgc"]
[Mon Jul 20 06:20:06.366042 2026] [security2:error] [pid 884009:tid 884258] [client 34.74.185.202:61738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SdhKaHUf6J8d3elJCAwAAAPo"]
[Mon Jul 20 06:20:06.402286 2026] [security2:error] [pid 874439:tid 874611] [client 57.141.18.88:39650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoiAAAKgM"]
[Mon Jul 20 06:20:06.438500 2026] [security2:error] [pid 874439:tid 874636] [client 50.116.65.227:29534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4Sdo6ZSrFvCrJJhtQp6wAAAAE"]
[Mon Jul 20 06:20:06.477783 2026] [security2:error] [pid 874439:tid 874655] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SdY6ZSrFvCrJJhtQp1gAAVhg"]
[Mon Jul 20 06:20:06.705705 2026] [security2:error] [pid 884009:tid 884028] [remote 5.161.225.162:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SdhKaHUf6J8d3elJCEQAA5xE"]
[Mon Jul 20 06:20:06.764509 2026] [security2:error] [pid 884009:tid 884030] [remote 72.167.132.114:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4SdhKaHUf6J8d3elJCFwAAkRM"]
[Mon Jul 20 06:20:06.774071 2026] [security2:error] [pid 874439:tid 874545] [remote 57.141.18.113:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5561908"] [unique_id "al4Sdo6ZSrFvCrJJhtQp_QAAf2k"]
[Mon Jul 20 06:20:06.803541 2026] [security2:error] [pid 884009:tid 884032] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SdhKaHUf6J8d3elJCHAAAxxU"]
[Mon Jul 20 06:20:06.803767 2026] [security2:error] [pid 884009:tid 884207] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SdhKaHUf6J8d3elJCHAAAxxU"]
[Mon Jul 20 06:20:06.873920 2026] [security2:error] [pid 884009:tid 884188] [client 34.74.185.202:63953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SdhKaHUf6J8d3elJCHwAAALQ"]
[Mon Jul 20 06:20:06.874346 2026] [security2:error] [pid 884009:tid 884213] [client 114.119.144.64:59241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amberhillstyle.com"] [uri "/robots.txt"] [unique_id "al4SdhKaHUf6J8d3elJCIAAAAM0"], referer: http://amberhillstyle.com/robots.txt
[Mon Jul 20 06:20:06.979496 2026] [security2:error] [pid 884009:tid 884035] [remote 72.167.132.114:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4SdhKaHUf6J8d3elJCJgAA1Rg"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:20:07.027903 2026] [security2:error] [pid 884009:tid 884034] [remote 5.161.225.162:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SdxKaHUf6J8d3elJCKAAA1hc"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:20:07.035553 2026] [security2:error] [pid 874439:tid 874694] [client 57.141.18.33:58726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQoyQAAfUk"]
[Mon Jul 20 06:20:07.051689 2026] [security2:error] [pid 874439:tid 874612] [client 35.245.239.138:62813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Sd46ZSrFvCrJJhtQqBgAAACs"]
[Mon Jul 20 06:20:07.175409 2026] [security2:error] [pid 874439:tid 874562] [remote 72.167.132.114:40384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqDgAASno"]
[Mon Jul 20 06:20:07.385416 2026] [security2:error] [pid 874439:tid 874664] [client 57.141.18.22:36760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQo5wAAX0o"]
[Mon Jul 20 06:20:07.500937 2026] [security2:error] [pid 874439:tid 874459] [remote 72.167.132.114:40384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqHAAAcRM"], referer: https://ncsynchro.com/wp-login.php
[Mon Jul 20 06:20:07.687634 2026] [security2:error] [pid 884009:tid 884148] [client 34.74.185.202:54745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SdxKaHUf6J8d3elJCQQAAAI0"]
[Mon Jul 20 06:20:07.827386 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.108:37390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpDQAATg8"]
[Mon Jul 20 06:20:07.846892 2026] [security2:error] [pid 884009:tid 884147] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SdxKaHUf6J8d3elJCPQAAAIw"]
[Mon Jul 20 06:20:07.986291 2026] [security2:error] [pid 884009:tid 884176] [client 185.132.186.55:38689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/2021/wp-works.php"] [unique_id "al4SdxKaHUf6J8d3elJCUAAAAKg"]
[Mon Jul 20 06:20:08.143141 2026] [security2:error] [pid 884009:tid 884263] [client 47.128.61.212:63398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "querenciapartners.com"] [uri "/robots.txt"] [unique_id "al4SeBKaHUf6J8d3elJCUgAAAP8"]
[Mon Jul 20 06:20:08.247251 2026] [security2:error] [pid 874439:tid 874653] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqWwAAAFQ"], referer: 1'"3000
[Mon Jul 20 06:20:08.344409 2026] [security2:error] [pid 884009:tid 884229] [client 68.235.52.68:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SeBKaHUf6J8d3elJCWQAAAN0"]
[Mon Jul 20 06:20:08.344513 2026] [security2:error] [pid 884009:tid 884229] [client 68.235.52.68:60216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SeBKaHUf6J8d3elJCWQAAAN0"]
[Mon Jul 20 06:20:08.497665 2026] [security2:error] [pid 874439:tid 874520] [remote 142.93.10.93:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqegAAMlA"]
[Mon Jul 20 06:20:08.497914 2026] [security2:error] [pid 874439:tid 874619] [client 142.93.10.93:46162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqegAAMlA"]
[Mon Jul 20 06:20:08.653931 2026] [security2:error] [pid 874439:tid 874592] [client 57.141.18.15:44408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpYQAAF2Y"]
[Mon Jul 20 06:20:08.756691 2026] [security2:error] [pid 874439:tid 874655] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqgAAAAFY"], referer: 1'"3000
[Mon Jul 20 06:20:08.946890 2026] [security2:error] [pid 874439:tid 874648] [client 34.74.185.202:50331] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SeI6ZSrFvCrJJhtQqmgAAAE8"]
[Mon Jul 20 06:20:09.078513 2026] [security2:error] [pid 884009:tid 884155] [client 35.245.239.138:58973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SeRKaHUf6J8d3elJCeAAAAJQ"]
[Mon Jul 20 06:20:09.189600 2026] [security2:error] [pid 874439:tid 874629] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqnQAAADw"], referer: 1'"3000
[Mon Jul 20 06:20:09.226899 2026] [cgid:error] [pid 874439:tid 874636] [client 66.132.195.34:63894] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: https://www.smtracking.genesismbs.com:443/cgi-bin
[Mon Jul 20 06:20:09.244978 2026] [security2:error] [pid 884009:tid 884162] [client 57.141.18.60:64348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdBKaHUf6J8d3elJByQAAmwM"]
[Mon Jul 20 06:20:09.363433 2026] [security2:error] [pid 884009:tid 884146] [client 171.60.139.123:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SeRKaHUf6J8d3elJCigAAAIs"]
[Mon Jul 20 06:20:09.363568 2026] [security2:error] [pid 884009:tid 884146] [client 171.60.139.123:55865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SeRKaHUf6J8d3elJCigAAAIs"]
[Mon Jul 20 06:20:09.407298 2026] [security2:error] [pid 874439:tid 874669] [client 14.225.17.146:59797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqXAAAAGQ"], referer: http://thechancersband.com/wp
[Mon Jul 20 06:20:09.575392 2026] [security2:error] [pid 874439:tid 874625] [client 77.110.127.138:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqtAAAADg"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.575528 2026] [security2:error] [pid 874439:tid 874625] [client 77.110.127.138:60434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqtAAAADg"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.576540 2026] [security2:error] [pid 874439:tid 874576] [client 77.110.127.138:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqswAAAAc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.576658 2026] [security2:error] [pid 874439:tid 874576] [client 77.110.127.138:60435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqswAAAAc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.581634 2026] [security2:error] [pid 884009:tid 884181] [client 34.74.185.202:50781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SeRKaHUf6J8d3elJClgAAAK0"]
[Mon Jul 20 06:20:09.645130 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoAAAAO8"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.645279 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:60448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoAAAAO8"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.645617 2026] [security2:error] [pid 884009:tid 884236] [client 77.110.127.138:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoQAAAOQ"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.645736 2026] [security2:error] [pid 884009:tid 884236] [client 77.110.127.138:60449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoQAAAOQ"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.690482 2026] [security2:error] [pid 874439:tid 874654] [client 77.110.127.138:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/501/amp/xlnlverl5yxp.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqxgAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:09.747964 2026] [security2:error] [pid 884009:tid 884183] [client 57.141.18.101:37768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdRKaHUf6J8d3elJB2gAArwU"]
[Mon Jul 20 06:20:09.798897 2026] [security2:error] [pid 884009:tid 884211] [client 185.132.186.81:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/media-new.php"] [unique_id "al4SeRKaHUf6J8d3elJCrQAAAMs"]
[Mon Jul 20 06:20:10.012640 2026] [security2:error] [pid 884009:tid 884144] [client 34.74.185.202:50796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SehKaHUf6J8d3elJCvQAAAIk"]
[Mon Jul 20 06:20:10.088688 2026] [security2:error] [pid 874439:tid 874607] [client 50.116.65.227:42864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Seo6ZSrFvCrJJhtQq3gAAACY"]
[Mon Jul 20 06:20:10.099114 2026] [security2:error] [pid 884009:tid 884168] [client 50.116.65.227:42872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SehKaHUf6J8d3elJCvwAAAKE"]
[Mon Jul 20 06:20:10.183318 2026] [security2:error] [pid 884009:tid 884141] [client 45.116.69.230:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJCwgAAAIY"]
[Mon Jul 20 06:20:10.183460 2026] [security2:error] [pid 884009:tid 884141] [client 45.116.69.230:63992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJCwgAAAIY"]
[Mon Jul 20 06:20:10.254507 2026] [security2:error] [pid 874439:tid 874634] [client 14.182.195.220:52129] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Seo6ZSrFvCrJJhtQq6gAAAEE"]
[Mon Jul 20 06:20:10.255824 2026] [security2:error] [pid 874439:tid 874592] [client 14.182.195.220:52128] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Seo6ZSrFvCrJJhtQq6wAAABc"]
[Mon Jul 20 06:20:10.276359 2026] [security2:error] [pid 884009:tid 884206] [client 14.182.195.220:52130] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SehKaHUf6J8d3elJCxAAAAMY"]
[Mon Jul 20 06:20:10.387136 2026] [security2:error] [pid 874439:tid 874625] [client 35.245.239.138:65292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Seo6ZSrFvCrJJhtQq7wAAADg"]
[Mon Jul 20 06:20:10.393386 2026] [security2:error] [pid 884009:tid 884199] [client 34.74.185.202:54976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SehKaHUf6J8d3elJCzwAAAL8"]
[Mon Jul 20 06:20:10.459160 2026] [security2:error] [pid 884009:tid 884248] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeRKaHUf6J8d3elJCpAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:10.490552 2026] [security2:error] [pid 884009:tid 884253] [client 77.110.127.138:60439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeRKaHUf6J8d3elJCqQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:10.509637 2026] [security2:error] [pid 874439:tid 874659] [client 104.234.53.88:37041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq8wAAAFo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:10.535064 2026] [security2:error] [pid 874439:tid 874666] [client 103.77.203.233:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq9AAAAGE"]
[Mon Jul 20 06:20:10.535273 2026] [security2:error] [pid 874439:tid 874666] [client 103.77.203.233:60351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq9AAAAGE"]
[Mon Jul 20 06:20:10.650010 2026] [security2:error] [pid 884009:tid 884153] [client 14.225.17.146:62020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4SeRKaHUf6J8d3elJCegAAAJI"], referer: http://bnb-engineering.com/wp
[Mon Jul 20 06:20:10.791068 2026] [security2:error] [pid 874439:tid 874675] [client 103.141.108.143:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq_AAAAGo"]
[Mon Jul 20 06:20:10.792136 2026] [security2:error] [pid 874439:tid 874675] [client 103.141.108.143:65284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq_AAAAGo"]
[Mon Jul 20 06:20:10.806846 2026] [security2:error] [pid 884009:tid 884065] [remote 91.142.222.105:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SehKaHUf6J8d3elJC2wAArjY"]
[Mon Jul 20 06:20:10.895199 2026] [security2:error] [pid 884009:tid 884066] [remote 57.141.18.70:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4SehKaHUf6J8d3elJC3wAArzc"]
[Mon Jul 20 06:20:10.954988 2026] [security2:error] [pid 884009:tid 884209] [client 13.229.223.11:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJC4QAAAMk"]
[Mon Jul 20 06:20:10.955137 2026] [security2:error] [pid 884009:tid 884209] [client 13.229.223.11:35160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJC4QAAAMk"]
[Mon Jul 20 06:20:11.020552 2026] [security2:error] [pid 874439:tid 874575] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeY6ZSrFvCrJJhtQq1AAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.068533 2026] [security2:error] [pid 884009:tid 884215] [client 34.74.185.202:55148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SexKaHUf6J8d3elJC5wAAAM8"]
[Mon Jul 20 06:20:11.071346 2026] [security2:error] [pid 874439:tid 874646] [client 50.116.65.227:51238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Se46ZSrFvCrJJhtQrCwAAAE0"]
[Mon Jul 20 06:20:11.078929 2026] [security2:error] [pid 884009:tid 884068] [remote 91.142.222.105:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SexKaHUf6J8d3elJC5gAAoTk"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:20:11.082113 2026] [security2:error] [pid 874439:tid 874637] [client 50.116.65.227:42880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Se46ZSrFvCrJJhtQrDAAAADw"]
[Mon Jul 20 06:20:11.149205 2026] [autoindex:error] [pid 874439:tid 874619] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:11.231126 2026] [security2:error] [pid 874439:tid 874544] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Se46ZSrFvCrJJhtQrGgAAKWg"]
[Mon Jul 20 06:20:11.231290 2026] [security2:error] [pid 874439:tid 874610] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Se46ZSrFvCrJJhtQrGgAAKWg"]
[Mon Jul 20 06:20:11.339255 2026] [autoindex:error] [pid 884009:tid 884166] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.380591 2026] [security2:error] [pid 884009:tid 884260] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4SehKaHUf6J8d3elJC2gAAAPw"]
[Mon Jul 20 06:20:11.382935 2026] [security2:error] [pid 884009:tid 884199] [client 77.110.127.138:60460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/js/aagjkqj7r4y9.php"] [unique_id "al4SexKaHUf6J8d3elJC-QAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.582566 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:52760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq3QAAAFQ"], referer: http://solkeetw.com/wp
[Mon Jul 20 06:20:11.606139 2026] [security2:error] [pid 884009:tid 884224] [client 185.132.186.102:51329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/media-new.php"] [unique_id "al4SexKaHUf6J8d3elJDCAAAANg"]
[Mon Jul 20 06:20:11.630368 2026] [security2:error] [pid 884009:tid 884165] [client 77.110.127.138:60436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SexKaHUf6J8d3elJC8QAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.631702 2026] [security2:error] [pid 884009:tid 884198] [client 178.152.178.232:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SexKaHUf6J8d3elJDCQAAAL4"]
[Mon Jul 20 06:20:11.631840 2026] [security2:error] [pid 884009:tid 884198] [client 178.152.178.232:37720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SexKaHUf6J8d3elJDCQAAAL4"]
[Mon Jul 20 06:20:11.668879 2026] [security2:error] [pid 874439:tid 874589] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Se46ZSrFvCrJJhtQrHwAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.687215 2026] [security2:error] [pid 874439:tid 874455] [remote 57.141.18.22:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5417502"] [unique_id "al4Se46ZSrFvCrJJhtQrMAAASg8"]
[Mon Jul 20 06:20:11.714170 2026] [security2:error] [pid 884009:tid 884256] [client 34.74.185.202:55906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SexKaHUf6J8d3elJDDgAAAPg"]
[Mon Jul 20 06:20:11.930022 2026] [security2:error] [pid 884009:tid 884208] [client 50.116.65.227:42908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4SexKaHUf6J8d3elJDFQAAAIw"]
[Mon Jul 20 06:20:11.971946 2026] [security2:error] [pid 884009:tid 884210] [client 34.74.185.202:63330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SexKaHUf6J8d3elJDFwAAAMo"]
[Mon Jul 20 06:20:12.047027 2026] [security2:error] [pid 874439:tid 874612] [client 181.224.94.124:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SfI6ZSrFvCrJJhtQrRgAAACs"]
[Mon Jul 20 06:20:12.047197 2026] [security2:error] [pid 874439:tid 874612] [client 181.224.94.124:6528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SfI6ZSrFvCrJJhtQrRgAAACs"]
[Mon Jul 20 06:20:12.083244 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.90:44446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdxKaHUf6J8d3elJCOwAA9xw"]
[Mon Jul 20 06:20:12.281588 2026] [security2:error] [pid 874439:tid 874630] [client 14.225.17.146:54191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4Seo6ZSrFvCrJJhtQrAAAAAD0"], referer: http://bbwipartnerconference.com/wp
[Mon Jul 20 06:20:12.380540 2026] [autoindex:error] [pid 874439:tid 874615] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:12.381603 2026] [autoindex:error] [pid 874439:tid 874587] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.449272 2026] [security2:error] [pid 874439:tid 874618] [client 77.110.127.138:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/js/integrations/pqmqe4uwxwye.php"] [unique_id "al4SfI6ZSrFvCrJJhtQrYQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.603679 2026] [security2:error] [pid 884009:tid 884202] [client 171.61.165.146:14416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SfBKaHUf6J8d3elJDLgAAAMI"]
[Mon Jul 20 06:20:12.603854 2026] [security2:error] [pid 884009:tid 884202] [client 171.61.165.146:14416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SfBKaHUf6J8d3elJDLgAAAMI"]
[Mon Jul 20 06:20:12.693580 2026] [security2:error] [pid 884009:tid 884241] [client 34.74.185.202:51441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SfBKaHUf6J8d3elJDNAAAAOk"]
[Mon Jul 20 06:20:12.800626 2026] [security2:error] [pid 884009:tid 884232] [client 57.141.18.22:33428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SeBKaHUf6J8d3elJCYAAA4CM"]
[Mon Jul 20 06:20:12.801837 2026] [security2:error] [pid 884009:tid 884266] [client 77.110.127.138:60466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfBKaHUf6J8d3elJDJQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.844857 2026] [security2:error] [pid 884009:tid 884204] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfBKaHUf6J8d3elJDKAAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.869174 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:52323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4SexKaHUf6J8d3elJC9AAAAIk"], referer: http://alexsandbergmusic.com/wp
[Mon Jul 20 06:20:13.070879 2026] [security2:error] [pid 884009:tid 884267] [client 34.74.185.202:58755] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SfRKaHUf6J8d3elJDVAAAAQM"]
[Mon Jul 20 06:20:13.136509 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SfRKaHUf6J8d3elJDVwAAANg"]
[Mon Jul 20 06:20:13.136634 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SfRKaHUf6J8d3elJDVwAAANg"]
[Mon Jul 20 06:20:13.141675 2026] [security2:error] [pid 884009:tid 884206] [client 77.110.127.138:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/js/integrations/stripe/56w8agrny1hp.php"] [unique_id "al4SfRKaHUf6J8d3elJDWQAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:13.183977 2026] [autoindex:error] [pid 884009:tid 884213] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/stripe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:13.197652 2026] [autoindex:error] [pid 874439:tid 874683] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/stripe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:20:13.385189 2026] [security2:error] [pid 884009:tid 884219] [client 50.116.65.227:42940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4SfRKaHUf6J8d3elJDYwAAANs"]
[Mon Jul 20 06:20:13.402731 2026] [security2:error] [pid 874439:tid 874608] [client 185.132.186.96:45819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/class_api.php"] [unique_id "al4SfY6ZSrFvCrJJhtQrhAAAACc"]
[Mon Jul 20 06:20:13.500666 2026] [security2:error] [pid 874439:tid 874607] [client 77.110.127.138:60414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfY6ZSrFvCrJJhtQrdgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:13.539510 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfY6ZSrFvCrJJhtQreAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:14.525830 2026] [security2:error] [pid 874439:tid 874657] [client 14.225.17.146:61748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Sfo6ZSrFvCrJJhtQrtgAAAFg"], referer: http://omenana.com/wp
[Mon Jul 20 06:20:14.710634 2026] [security2:error] [pid 874439:tid 874648] [client 157.55.39.61:58900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4Sfo6ZSrFvCrJJhtQruAAAT30"]
[Mon Jul 20 06:20:15.030174 2026] [security2:error] [pid 884009:tid 884242] [client 34.74.185.202:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SfxKaHUf6J8d3elJDoAAAAOo"]
[Mon Jul 20 06:20:15.201956 2026] [security2:error] [pid 874439:tid 874654] [client 185.132.186.100:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/2021/themes.php"] [unique_id "al4Sf46ZSrFvCrJJhtQr3QAAAFU"]
[Mon Jul 20 06:20:15.442262 2026] [security2:error] [pid 884009:tid 884201] [client 34.74.185.202:50838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SfxKaHUf6J8d3elJDsAAAAME"]
[Mon Jul 20 06:20:15.723409 2026] [security2:error] [pid 884009:tid 884188] [client 34.74.185.202:63344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SfxKaHUf6J8d3elJDuwAAALQ"]
[Mon Jul 20 06:20:15.758011 2026] [security2:error] [pid 884009:tid 884172] [client 98.159.234.160:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SfxKaHUf6J8d3elJDvQAAAKQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:15.981454 2026] [security2:error] [pid 884009:tid 884160] [client 57.141.18.41:25892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SexKaHUf6J8d3elJDBgAAmT0"]
[Mon Jul 20 06:20:16.071567 2026] [security2:error] [pid 884009:tid 884164] [client 104.234.53.51:40859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SgBKaHUf6J8d3elJDygAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:16.101643 2026] [security2:error] [pid 874439:tid 874606] [client 14.225.17.146:52328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4SfY6ZSrFvCrJJhtQrrAAAACU"], referer: http://dollpassionista.com/wp
[Mon Jul 20 06:20:16.190683 2026] [security2:error] [pid 884009:tid 884198] [client 14.225.17.146:51686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4SfxKaHUf6J8d3elJDngAAAL4"], referer: http://getgarrison.com/wp
[Mon Jul 20 06:20:16.210773 2026] [security2:error] [pid 874439:tid 874600] [client 34.74.185.202:63424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SgI6ZSrFvCrJJhtQr_QAAAB8"]
[Mon Jul 20 06:20:16.440734 2026] [security2:error] [pid 884009:tid 884252] [client 50.116.65.227:42998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/01/IMG_8522.jpeg"] [unique_id "al4SgBKaHUf6J8d3elJD3QAAAPQ"]
[Mon Jul 20 06:20:16.641910 2026] [security2:error] [pid 884009:tid 884244] [client 34.74.185.202:65333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SgBKaHUf6J8d3elJD5AAAAOw"]
[Mon Jul 20 06:20:16.679486 2026] [security2:error] [pid 874439:tid 874688] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SgI6ZSrFvCrJJhtQsAgAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:16.701476 2026] [security2:error] [pid 874439:tid 874639] [client 74.7.227.179:34500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SgI6ZSrFvCrJJhtQsFAAARnw"], referer: https://tejasenvironmental.com/p=821518
[Mon Jul 20 06:20:16.751822 2026] [security2:error] [pid 884009:tid 884172] [client 173.239.218.6:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "arrazoado.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4SgBKaHUf6J8d3elJD5wAAAKQ"]
[Mon Jul 20 06:20:16.988624 2026] [security2:error] [pid 874439:tid 874695] [client 34.74.185.202:56960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SgI6ZSrFvCrJJhtQsJQAAAH4"]
[Mon Jul 20 06:20:17.006172 2026] [security2:error] [pid 874439:tid 874675] [client 185.132.186.59:38635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin/install.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsJwAAAGo"]
[Mon Jul 20 06:20:17.140994 2026] [security2:error] [pid 884009:tid 884219] [client 14.225.17.146:51869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4SgBKaHUf6J8d3elJD8AAAANM"], referer: https://dollpassionista.com/wp
[Mon Jul 20 06:20:17.295323 2026] [security2:error] [pid 884009:tid 884220] [client 34.74.185.202:52511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SgRKaHUf6J8d3elJD-QAAANQ"]
[Mon Jul 20 06:20:17.448521 2026] [security2:error] [pid 874439:tid 874449] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsNwAAKwk"]
[Mon Jul 20 06:20:17.448690 2026] [security2:error] [pid 874439:tid 874612] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsNwAAKwk"]
[Mon Jul 20 06:20:17.673790 2026] [security2:error] [pid 884009:tid 884179] [client 77.110.127.138:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SgRKaHUf6J8d3elJEAgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:17.673898 2026] [security2:error] [pid 884009:tid 884179] [client 77.110.127.138:60492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SgRKaHUf6J8d3elJEAgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:17.856188 2026] [security2:error] [pid 884009:tid 884232] [client 114.119.141.112:40401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/category-s/26.htm"] [unique_id "al4SgRKaHUf6J8d3elJEEAAAAOA"], referer: http://www.sarakety.com/Chimney-12-18-Months-p/121zsqz01.htm
[Mon Jul 20 06:20:17.935418 2026] [security2:error] [pid 884009:tid 884239] [client 34.74.185.202:51954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SgRKaHUf6J8d3elJEFAAAAOc"]
[Mon Jul 20 06:20:17.972764 2026] [security2:error] [pid 884009:tid 884166] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SgRKaHUf6J8d3elJD-AAAAJ8"]
[Mon Jul 20 06:20:17.995058 2026] [security2:error] [pid 884009:tid 884187] [client 3.85.28.216:61412] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pegao-puerto-rican-crispy-rice/"] [unique_id "al4SgRKaHUf6J8d3elJD9gAAALM"]
[Mon Jul 20 06:20:18.090986 2026] [security2:error] [pid 884009:tid 884126] [remote 57.141.18.48:48420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2596330"] [unique_id "al4SghKaHUf6J8d3elJEHgAAhXM"]
[Mon Jul 20 06:20:18.102041 2026] [security2:error] [pid 884009:tid 884165] [client 57.141.18.22:33458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SfRKaHUf6J8d3elJDagAAnks"]
[Mon Jul 20 06:20:18.296637 2026] [security2:error] [pid 874439:tid 874602] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQsTwAAITU"]
[Mon Jul 20 06:20:18.414916 2026] [security2:error] [pid 874439:tid 874602] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsSwAAIQU"]
[Mon Jul 20 06:20:18.490392 2026] [security2:error] [pid 884009:tid 884151] [client 34.74.185.202:54783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SghKaHUf6J8d3elJEKQAAAJA"]
[Mon Jul 20 06:20:18.666923 2026] [security2:error] [pid 884009:tid 884216] [client 50.116.65.227:51250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SghKaHUf6J8d3elJELwAAANA"]
[Mon Jul 20 06:20:18.678724 2026] [security2:error] [pid 884009:tid 884156] [client 50.116.65.227:43002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SghKaHUf6J8d3elJEMQAAAJU"]
[Mon Jul 20 06:20:18.727628 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:60677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsNAAAAHY"], referer: http://wathenbartlett.co.uk/wp
[Mon Jul 20 06:20:18.816553 2026] [security2:error] [pid 874439:tid 874571] [client 185.132.186.79:21215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/plugin.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQsdgAAAAI"]
[Mon Jul 20 06:20:18.867565 2026] [security2:error] [pid 884009:tid 884178] [client 34.74.185.202:51733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SghKaHUf6J8d3elJEOAAAAKo"]
[Mon Jul 20 06:20:19.099169 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQseAAAJTc"]
[Mon Jul 20 06:20:19.369737 2026] [security2:error] [pid 874439:tid 874619] [client 34.74.185.202:63564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Sg46ZSrFvCrJJhtQsjQAAADI"]
[Mon Jul 20 06:20:19.474580 2026] [security2:error] [pid 874439:tid 874614] [client 14.225.17.146:61473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsMQAAAC0"], referer: http://younutrition.gr/wp
[Mon Jul 20 06:20:19.565817 2026] [security2:error] [pid 884009:tid 884148] [client 104.234.53.89:23265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SgxKaHUf6J8d3elJEZgAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:19.675193 2026] [security2:error] [pid 884009:tid 884210] [client 45.157.112.60:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SgxKaHUf6J8d3elJEawAAAMo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:19.738814 2026] [security2:error] [pid 884009:tid 884176] [client 14.225.17.146:51728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4SghKaHUf6J8d3elJEJQAAAKg"]
[Mon Jul 20 06:20:19.760444 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:51592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4SghKaHUf6J8d3elJEKAAAAJ0"], referer: http://christiancountytrumpet.com/wp
[Mon Jul 20 06:20:19.761043 2026] [security2:error] [pid 884009:tid 884259] [client 14.225.17.146:52758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SgxKaHUf6J8d3elJEbAAAAPs"], referer: https://wathenbartlett.co.uk/wp
[Mon Jul 20 06:20:19.854886 2026] [security2:error] [pid 884009:tid 884204] [client 34.74.185.202:59537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SgxKaHUf6J8d3elJEdAAAAMQ"]
[Mon Jul 20 06:20:20.055009 2026] [security2:error] [pid 884009:tid 884208] [client 50.116.65.227:50468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ShBKaHUf6J8d3elJEfgAAAMg"]
[Mon Jul 20 06:20:20.066708 2026] [security2:error] [pid 884009:tid 884173] [client 50.116.65.227:50476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ShBKaHUf6J8d3elJEgAAAAKU"]
[Mon Jul 20 06:20:20.099548 2026] [security2:error] [pid 884009:tid 884236] [client 27.96.94.195:37304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEgwAAAOQ"]
[Mon Jul 20 06:20:20.099707 2026] [security2:error] [pid 884009:tid 884236] [client 27.96.94.195:37304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEgwAAAOQ"]
[Mon Jul 20 06:20:20.265550 2026] [security2:error] [pid 884009:tid 884247] [client 171.60.139.123:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEigAAAO8"]
[Mon Jul 20 06:20:20.265704 2026] [security2:error] [pid 884009:tid 884247] [client 171.60.139.123:56377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEigAAAO8"]
[Mon Jul 20 06:20:20.624234 2026] [security2:error] [pid 884009:tid 884189] [client 185.132.186.62:58867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-scripts-query.php"] [unique_id "al4ShBKaHUf6J8d3elJEpgAAALU"]
[Mon Jul 20 06:20:20.624854 2026] [security2:error] [pid 884009:tid 884230] [client 50.116.65.227:50504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEmAAAAN4"]
[Mon Jul 20 06:20:20.630402 2026] [security2:error] [pid 874439:tid 874586] [client 34.74.185.202:59980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ShI6ZSrFvCrJJhtQsvgAAABE"]
[Mon Jul 20 06:20:20.708961 2026] [security2:error] [pid 884009:tid 884141] [client 57.141.18.49:23750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SgBKaHUf6J8d3elJD2AAAhmM"]
[Mon Jul 20 06:20:20.741445 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEmgAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:20.757487 2026] [security2:error] [pid 884009:tid 884162] [client 15.237.142.234:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ShBKaHUf6J8d3elJErAAAAJs"]
[Mon Jul 20 06:20:20.799963 2026] [security2:error] [pid 884009:tid 884034] [remote 192.241.143.148:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ShBKaHUf6J8d3elJErQAAkRc"]
[Mon Jul 20 06:20:20.816999 2026] [security2:error] [pid 884009:tid 884153] [client 50.116.65.227:50520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEpwAAAJI"]
[Mon Jul 20 06:20:20.927261 2026] [security2:error] [pid 874439:tid 874688] [client 45.116.69.230:64522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ShI6ZSrFvCrJJhtQswgAAAHc"]
[Mon Jul 20 06:20:20.927370 2026] [security2:error] [pid 874439:tid 874688] [client 45.116.69.230:64522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ShI6ZSrFvCrJJhtQswgAAAHc"]
[Mon Jul 20 06:20:21.001441 2026] [security2:error] [pid 884009:tid 884044] [remote 192.241.143.148:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ShRKaHUf6J8d3elJEvwAAvCE"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:20:21.010600 2026] [security2:error] [pid 884009:tid 884184] [client 77.110.127.138:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ShRKaHUf6J8d3elJEwQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.010701 2026] [security2:error] [pid 884009:tid 884184] [client 77.110.127.138:60523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ShRKaHUf6J8d3elJEwQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.343498 2026] [security2:error] [pid 884009:tid 884164] [client 50.116.65.227:50530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/11/IMG_2111.jpeg"] [unique_id "al4ShRKaHUf6J8d3elJE3gAAAJ0"]
[Mon Jul 20 06:20:21.373108 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQsggAAJTE"]
[Mon Jul 20 06:20:21.448825 2026] [security2:error] [pid 884009:tid 884154] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJEzwAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.459399 2026] [security2:error] [pid 874439:tid 874490] [remote 57.141.18.12:32188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SgI6ZSrFvCrJJhtQsIAAAOTI"]
[Mon Jul 20 06:20:21.505378 2026] [security2:error] [pid 884009:tid 884175] [client 15.237.142.234:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ShRKaHUf6J8d3elJE7QAAAKc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:20:21.555884 2026] [security2:error] [pid 884009:tid 884218] [client 57.141.18.13:50942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SgBKaHUf6J8d3elJD7wAA0mc"]
[Mon Jul 20 06:20:21.631474 2026] [security2:error] [pid 884009:tid 884259] [client 77.110.127.138:60530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJE0wAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.657458 2026] [security2:error] [pid 884009:tid 884230] [client 14.225.17.146:63159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJE7wAAAN4"], referer: http://ivetstrategies.com/wp
[Mon Jul 20 06:20:21.660337 2026] [security2:error] [pid 884009:tid 884191] [client 103.141.108.143:49373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ShRKaHUf6J8d3elJE_QAAALc"]
[Mon Jul 20 06:20:21.660455 2026] [security2:error] [pid 884009:tid 884191] [client 103.141.108.143:49373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ShRKaHUf6J8d3elJE_QAAALc"]
[Mon Jul 20 06:20:21.750456 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQshwAAJSY"]
[Mon Jul 20 06:20:22.065961 2026] [security2:error] [pid 884009:tid 884076] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFJQAA0EE"]
[Mon Jul 20 06:20:22.066148 2026] [security2:error] [pid 884009:tid 884216] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFJQAA0EE"]
[Mon Jul 20 06:20:22.142822 2026] [security2:error] [pid 884009:tid 884258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJFDQAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:22.429552 2026] [security2:error] [pid 884009:tid 884160] [client 185.132.186.89:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/item.php"] [unique_id "al4ShhKaHUf6J8d3elJFPgAAAJk"]
[Mon Jul 20 06:20:22.451183 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQsowAAJQE"]
[Mon Jul 20 06:20:22.488245 2026] [security2:error] [pid 884009:tid 884206] [client 178.152.178.232:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFRgAAAMY"]
[Mon Jul 20 06:20:22.495140 2026] [security2:error] [pid 884009:tid 884206] [client 178.152.178.232:36559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFRgAAAMY"]
[Mon Jul 20 06:20:22.535820 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:60535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJFHQAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:22.568950 2026] [security2:error] [pid 884009:tid 884231] [client 181.224.94.124:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFTAAAAN8"]
[Mon Jul 20 06:20:22.569069 2026] [security2:error] [pid 884009:tid 884231] [client 181.224.94.124:63075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFTAAAAN8"]
[Mon Jul 20 06:20:22.614662 2026] [security2:error] [pid 884009:tid 884218] [client 103.153.183.69:18302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/apache2/apache2.conf"] [unique_id "al4ShhKaHUf6J8d3elJFUQAAANI"], referer: https://t.co/04z1t837ro
[Mon Jul 20 06:20:22.691475 2026] [security2:error] [pid 884009:tid 884250] [client 104.234.53.65:35675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFVQAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:22.755697 2026] [security2:error] [pid 884009:tid 884220] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFPAAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:23.042302 2026] [autoindex:error] [pid 884009:tid 884268] [client 34.85.238.37:51896] AH01276: Cannot serve directory /home2/flhkrvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:23.134059 2026] [security2:error] [pid 884009:tid 884115] [remote 192.241.143.148:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFhAAA42g"]
[Mon Jul 20 06:20:23.296493 2026] [security2:error] [pid 884009:tid 884118] [remote 192.241.143.148:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFjAAA1Gs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:23.317539 2026] [security2:error] [pid 884009:tid 884119] [remote 104.28.251.190:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFiAAAlWw"], referer: https://lifeisbetterlakeside.com/wp-admin/
[Mon Jul 20 06:20:23.321537 2026] [security2:error] [pid 884009:tid 884124] [remote 104.28.251.190:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFjgAAlXE"], referer: https://lifeisbetterlakeside.com/wp-admin/
[Mon Jul 20 06:20:23.484802 2026] [security2:error] [pid 884009:tid 884185] [client 171.61.165.146:26690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShxKaHUf6J8d3elJFpAAAALE"]
[Mon Jul 20 06:20:23.484966 2026] [security2:error] [pid 884009:tid 884185] [client 171.61.165.146:26690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShxKaHUf6J8d3elJFpAAAALE"]
[Mon Jul 20 06:20:23.633923 2026] [security2:error] [pid 884009:tid 884232] [client 34.85.238.37:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.238.85.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flh.krv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ShxKaHUf6J8d3elJFtQAAAOA"]
[Mon Jul 20 06:20:23.646374 2026] [security2:error] [pid 874439:tid 874540] [remote 57.141.18.21:45734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQscAAAEGQ"]
[Mon Jul 20 06:20:23.761870 2026] [security2:error] [pid 884009:tid 884154] [client 14.225.17.146:64699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFKwAAAJM"], referer: http://lelandumc.org/wp
[Mon Jul 20 06:20:23.778643 2026] [security2:error] [pid 874439:tid 874630] [client 23.236.222.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQsigAAAD0"]
[Mon Jul 20 06:20:23.800018 2026] [security2:error] [pid 884009:tid 884174] [client 34.85.238.37:54936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ShxKaHUf6J8d3elJFugAAAKY"]
[Mon Jul 20 06:20:23.976162 2026] [security2:error] [pid 884009:tid 884227] [client 104.234.53.94:24259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ShxKaHUf6J8d3elJFwwAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:23.987632 2026] [security2:error] [pid 884009:tid 884226] [client 34.85.238.37:54237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ShxKaHUf6J8d3elJFxgAAANo"]
[Mon Jul 20 06:20:24.204906 2026] [security2:error] [pid 884009:tid 884200] [client 34.85.238.37:59257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJF3QAAAMA"]
[Mon Jul 20 06:20:24.242460 2026] [security2:error] [pid 884009:tid 884163] [client 185.132.186.86:52425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/pages.php"] [unique_id "al4SiBKaHUf6J8d3elJF4AAAAJw"]
[Mon Jul 20 06:20:24.493027 2026] [security2:error] [pid 884009:tid 884159] [client 34.85.238.37:57404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJF6QAAAJg"]
[Mon Jul 20 06:20:24.708673 2026] [security2:error] [pid 884009:tid 884248] [client 34.85.238.37:51818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJF-wAAAPA"]
[Mon Jul 20 06:20:24.762934 2026] [security2:error] [pid 884009:tid 884150] [client 57.141.18.13:50958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEfQAAjxE"]
[Mon Jul 20 06:20:24.879615 2026] [security2:error] [pid 884009:tid 884213] [client 34.85.238.37:56904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJGBwAAAM0"]
[Mon Jul 20 06:20:25.201574 2026] [security2:error] [pid 884009:tid 884235] [client 34.85.238.37:63216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGIAAAAOM"]
[Mon Jul 20 06:20:25.416484 2026] [security2:error] [pid 884009:tid 884266] [client 34.73.38.214:50260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGNAAAAQI"]
[Mon Jul 20 06:20:25.432510 2026] [security2:error] [pid 884009:tid 884210] [client 34.85.238.37:63216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGNwAAAMo"]
[Mon Jul 20 06:20:25.541558 2026] [security2:error] [pid 884009:tid 884250] [client 34.73.38.214:50437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGQwAAAPI"]
[Mon Jul 20 06:20:25.545462 2026] [security2:error] [pid 884009:tid 884259] [client 68.235.52.68:55958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGRAAAAPs"]
[Mon Jul 20 06:20:25.545537 2026] [security2:error] [pid 884009:tid 884259] [client 68.235.52.68:55958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGRAAAAPs"]
[Mon Jul 20 06:20:25.632888 2026] [security2:error] [pid 884009:tid 884186] [client 50.116.65.227:49020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SiRKaHUf6J8d3elJGTAAAALI"]
[Mon Jul 20 06:20:25.644705 2026] [security2:error] [pid 884009:tid 884176] [client 50.116.65.227:50558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SiRKaHUf6J8d3elJGTQAAAO8"]
[Mon Jul 20 06:20:25.650438 2026] [security2:error] [pid 884009:tid 884204] [client 34.85.238.37:55719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGTgAAAMQ"]
[Mon Jul 20 06:20:25.658044 2026] [security2:error] [pid 884009:tid 884218] [client 112.208.70.94:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGTwAAANI"]
[Mon Jul 20 06:20:25.658203 2026] [security2:error] [pid 884009:tid 884218] [client 112.208.70.94:45634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGTwAAANI"]
[Mon Jul 20 06:20:25.658650 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:50498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGUAAAAQQ"]
[Mon Jul 20 06:20:25.698402 2026] [security2:error] [pid 884009:tid 884245] [client 57.141.18.45:53674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJExAAA7R8"]
[Mon Jul 20 06:20:25.714302 2026] [autoindex:error] [pid 884009:tid 884165] [client 146.190.134.17:0] AH01276: Cannot serve directory /home1/nodoqpmy/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:25.757126 2026] [security2:error] [pid 884009:tid 884080] [remote 5.161.225.162:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SiRKaHUf6J8d3elJGVAABAUU"]
[Mon Jul 20 06:20:25.804998 2026] [security2:error] [pid 884009:tid 884222] [client 34.73.38.214:50558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGXQAAANY"]
[Mon Jul 20 06:20:25.851130 2026] [security2:error] [pid 884009:tid 884207] [client 34.85.238.37:51353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGYgAAAMc"]
[Mon Jul 20 06:20:25.957088 2026] [security2:error] [pid 884009:tid 884257] [client 34.73.38.214:50606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGZwAAAPk"]
[Mon Jul 20 06:20:26.015771 2026] [security2:error] [pid 884009:tid 884224] [client 34.85.238.37:53461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGawAAANg"]
[Mon Jul 20 06:20:26.049459 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.57:44817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/module.audio-license.php"] [unique_id "al4SihKaHUf6J8d3elJGbwAAAME"]
[Mon Jul 20 06:20:26.071884 2026] [security2:error] [pid 884009:tid 884225] [client 57.141.18.109:42062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJE4wAA2S4"]
[Mon Jul 20 06:20:26.074370 2026] [security2:error] [pid 884009:tid 884188] [client 34.73.38.214:50650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGcAAAALQ"]
[Mon Jul 20 06:20:26.200117 2026] [security2:error] [pid 884009:tid 884218] [client 34.73.38.214:50696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGfAAAANI"]
[Mon Jul 20 06:20:26.310499 2026] [security2:error] [pid 884009:tid 884238] [client 34.73.38.214:50739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGiQAAAOY"]
[Mon Jul 20 06:20:26.426416 2026] [security2:error] [pid 884009:tid 884202] [client 34.73.38.214:50772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGlgAAAMI"]
[Mon Jul 20 06:20:26.545030 2026] [security2:error] [pid 884009:tid 884162] [client 34.73.38.214:50800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGmwAAAJs"]
[Mon Jul 20 06:20:26.651588 2026] [security2:error] [pid 884009:tid 884154] [client 34.73.38.214:50839] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGrAAAAJM"]
[Mon Jul 20 06:20:26.653582 2026] [security2:error] [pid 884009:tid 884118] [remote 157.180.59.124:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.59.180.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4SihKaHUf6J8d3elJGqgAA_Ws"]
[Mon Jul 20 06:20:26.759301 2026] [security2:error] [pid 884009:tid 884120] [remote 5.161.225.162:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SihKaHUf6J8d3elJGtgAA-m0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:26.899512 2026] [security2:error] [pid 884009:tid 884133] [remote 157.180.59.124:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.59.180.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4SihKaHUf6J8d3elJGxwAAqno"], referer: https://website-5ab144f7.uritems.net/wp-login.php
[Mon Jul 20 06:20:26.904549 2026] [security2:error] [pid 884009:tid 884206] [client 103.153.183.69:46272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/public../.env"] [unique_id "al4SihKaHUf6J8d3elJGyAAAAMY"], referer: https://www.facebook.com/
[Mon Jul 20 06:20:27.017026 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.80:39436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFNwAA00w"]
[Mon Jul 20 06:20:27.227691 2026] [security2:error] [pid 884009:tid 884207] [client 34.73.38.214:50900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG5gAAAMc"]
[Mon Jul 20 06:20:27.245629 2026] [security2:error] [pid 884009:tid 884241] [client 14.225.17.146:61013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4SiRKaHUf6J8d3elJGYwAAAOk"], referer: http://colinkeyphotography.com/wp
[Mon Jul 20 06:20:27.321873 2026] [core:error] [pid 884009:tid 884258] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:27.321899 2026] [core:error] [pid 884009:tid 884258] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:27.338541 2026] [security2:error] [pid 884009:tid 884212] [client 34.73.38.214:51032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG7QAAAMw"]
[Mon Jul 20 06:20:27.400121 2026] [security2:error] [pid 884009:tid 884268] [client 14.225.17.146:60643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4SihKaHUf6J8d3elJGxQAAAQQ"], referer: http://onewingpictures.com/wp
[Mon Jul 20 06:20:27.458692 2026] [security2:error] [pid 884009:tid 884206] [client 34.73.38.214:51068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG-gAAAMY"]
[Mon Jul 20 06:20:27.575363 2026] [security2:error] [pid 884009:tid 884189] [client 34.73.38.214:51107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG_wAAALU"]
[Mon Jul 20 06:20:27.682044 2026] [security2:error] [pid 884009:tid 884171] [client 34.73.38.214:51128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJHDAAAAKM"]
[Mon Jul 20 06:20:27.719728 2026] [security2:error] [pid 884009:tid 884141] [client 57.141.18.125:23096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFcQAAhmA"]
[Mon Jul 20 06:20:27.788416 2026] [security2:error] [pid 884009:tid 884221] [client 34.73.38.214:51154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJHFAAAANU"]
[Mon Jul 20 06:20:27.846052 2026] [security2:error] [pid 884009:tid 884182] [client 185.132.186.67:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/classwithtostring.php%20"] [unique_id "al4SixKaHUf6J8d3elJHFgAAAK4"]
[Mon Jul 20 06:20:27.908573 2026] [security2:error] [pid 884009:tid 884258] [client 34.73.38.214:51185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJHGAAAAPo"]
[Mon Jul 20 06:20:28.021996 2026] [security2:error] [pid 884009:tid 884185] [client 34.73.38.214:51219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SjBKaHUf6J8d3elJHJAAAALE"]
[Mon Jul 20 06:20:28.033684 2026] [security2:error] [pid 884009:tid 884032] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SjBKaHUf6J8d3elJHJQAA7RU"]
[Mon Jul 20 06:20:28.033835 2026] [security2:error] [pid 884009:tid 884245] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SjBKaHUf6J8d3elJHJQAA7RU"]
[Mon Jul 20 06:20:28.158580 2026] [security2:error] [pid 884009:tid 884219] [client 34.73.38.214:51256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SjBKaHUf6J8d3elJHMQAAANM"]
[Mon Jul 20 06:20:28.186094 2026] [security2:error] [pid 884009:tid 884174] [client 14.225.17.146:54413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4SihKaHUf6J8d3elJGaAAAAKY"], referer: http://worbals.com/wp
[Mon Jul 20 06:20:28.763844 2026] [security2:error] [pid 884009:tid 884194] [client 104.234.53.76:55397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SjBKaHUf6J8d3elJHXwAAALo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:28.802893 2026] [security2:error] [pid 884009:tid 884218] [client 74.7.175.149:40258] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "elite-pk.com"] [uri "/robots.txt"] [unique_id "al4SjBKaHUf6J8d3elJHYgAAANI"]
[Mon Jul 20 06:20:28.985385 2026] [security2:error] [pid 884009:tid 884067] [remote 103.90.234.13:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjBKaHUf6J8d3elJHawAAvjg"]
[Mon Jul 20 06:20:29.308832 2026] [security2:error] [pid 884009:tid 884221] [client 114.119.158.234:47549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mazzucelli.com"] [uri "/pub-type/article"] [unique_id "al4SjRKaHUf6J8d3elJHjgAAANU"], referer: https://mazzucelli.com/pub-type/article/page/1
[Mon Jul 20 06:20:29.321691 2026] [security2:error] [pid 884009:tid 884144] [client 57.141.18.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4SjBKaHUf6J8d3elJHRAAAAIk"]
[Mon Jul 20 06:20:29.409156 2026] [security2:error] [pid 884009:tid 884207] [client 103.153.183.69:46272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/resources../.env"] [unique_id "al4SjRKaHUf6J8d3elJHlwAAAMc"], referer: https://t.co/8upezausu7
[Mon Jul 20 06:20:29.459135 2026] [security2:error] [pid 884009:tid 884050] [remote 103.90.234.13:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHnAAA6Sc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:29.497263 2026] [security2:error] [pid 884009:tid 884213] [client 104.234.53.56:39229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SjRKaHUf6J8d3elJHlQAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:29.524017 2026] [security2:error] [pid 884009:tid 884206] [client 103.153.183.69:46272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/etc/passwd"] [unique_id "al4SjRKaHUf6J8d3elJHogAAAMY"], referer: https://www.google.com/
[Mon Jul 20 06:20:29.554691 2026] [security2:error] [pid 884009:tid 884217] [client 52.187.75.220:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SjRKaHUf6J8d3elJHowAAANE"]
[Mon Jul 20 06:20:29.572329 2026] [security2:error] [pid 884009:tid 884257] [client 50.116.65.227:36710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SjRKaHUf6J8d3elJHpwAAAPk"]
[Mon Jul 20 06:20:29.582526 2026] [security2:error] [pid 884009:tid 884179] [client 50.116.65.227:36722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SjRKaHUf6J8d3elJHqgAAAKs"]
[Mon Jul 20 06:20:29.583021 2026] [security2:error] [pid 884009:tid 884159] [client 52.109.68.130:3264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SjRKaHUf6J8d3elJHqAAAAJg"]
[Mon Jul 20 06:20:29.654307 2026] [security2:error] [pid 884009:tid 884221] [client 185.132.186.89:49661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/function.php"] [unique_id "al4SjRKaHUf6J8d3elJHrgAAANU"]
[Mon Jul 20 06:20:29.687530 2026] [security2:error] [pid 884009:tid 884174] [client 104.234.53.56:39229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHsAAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:29.687599 2026] [security2:error] [pid 884009:tid 884097] [remote 152.228.213.32:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHrwAAjFY"]
[Mon Jul 20 06:20:29.733658 2026] [security2:error] [pid 884009:tid 884229] [client 193.148.56.61:63861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SjRKaHUf6J8d3elJHtwAAAN0"]
[Mon Jul 20 06:20:29.740645 2026] [security2:error] [pid 884009:tid 884167] [client 52.109.68.130:3264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SjRKaHUf6J8d3elJHuAAAAKA"]
[Mon Jul 20 06:20:29.743886 2026] [security2:error] [pid 884009:tid 884197] [client 52.187.75.220:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SjRKaHUf6J8d3elJHuQAAAL0"]
[Mon Jul 20 06:20:29.920553 2026] [security2:error] [pid 884009:tid 884072] [remote 152.228.213.32:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHxwAAlj0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:30.135123 2026] [security2:error] [pid 884009:tid 884262] [client 173.252.70.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "darkknightsolutions.com"] [uri "/index.php"] [unique_id "al4SjBKaHUf6J8d3elJHQwAAAP4"]
[Mon Jul 20 06:20:30.807975 2026] [core:error] [pid 884009:tid 884242] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:30.807997 2026] [core:error] [pid 884009:tid 884242] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:30.845087 2026] [security2:error] [pid 884009:tid 884220] [client 27.96.94.195:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFAAAANQ"]
[Mon Jul 20 06:20:30.845202 2026] [security2:error] [pid 884009:tid 884220] [client 27.96.94.195:37624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFAAAANQ"]
[Mon Jul 20 06:20:30.881434 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.125:23114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SiRKaHUf6J8d3elJGUwAAtkc"]
[Mon Jul 20 06:20:30.914696 2026] [security2:error] [pid 884009:tid 884155] [client 171.60.139.123:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFgAAAJQ"]
[Mon Jul 20 06:20:30.914817 2026] [security2:error] [pid 884009:tid 884155] [client 171.60.139.123:56879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFgAAAJQ"]
[Mon Jul 20 06:20:31.201104 2026] [security2:error] [pid 884009:tid 884180] [client 52.109.108.111:33921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SjxKaHUf6J8d3elJINQAAAKw"]
[Mon Jul 20 06:20:31.360951 2026] [security2:error] [pid 884009:tid 884144] [client 52.109.108.111:33921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SjxKaHUf6J8d3elJIQAAAAIk"]
[Mon Jul 20 06:20:31.381022 2026] [security2:error] [pid 884009:tid 884151] [client 163.172.182.64:32868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4SjxKaHUf6J8d3elJIQgAAAJA"]
[Mon Jul 20 06:20:31.456056 2026] [security2:error] [pid 884009:tid 884240] [client 185.132.186.62:40835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/js/doc.php"] [unique_id "al4SjxKaHUf6J8d3elJIRQAAAOg"]
[Mon Jul 20 06:20:31.803224 2026] [security2:error] [pid 884009:tid 884148] [client 193.148.56.61:49507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SjxKaHUf6J8d3elJIbQAAAI0"]
[Mon Jul 20 06:20:31.836072 2026] [security2:error] [pid 884009:tid 884156] [client 77.110.127.138:60556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SjxKaHUf6J8d3elJIUgAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:31.885987 2026] [security2:error] [pid 884009:tid 884213] [client 216.73.217.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.robiem.com"] [uri "/index.php"] [unique_id "al4SjxKaHUf6J8d3elJIawAAAM0"]
[Mon Jul 20 06:20:32.096552 2026] [security2:error] [pid 884009:tid 884250] [client 57.141.18.20:50480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SihKaHUf6J8d3elJGzQAA8nY"]
[Mon Jul 20 06:20:32.137949 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:65082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIfAAAAPk"]
[Mon Jul 20 06:20:32.138073 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:65082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIfAAAAPk"]
[Mon Jul 20 06:20:32.269952 2026] [security2:error] [pid 884009:tid 884023] [remote 162.19.86.63:35960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4SkBKaHUf6J8d3elJIjQAA9gw"]
[Mon Jul 20 06:20:32.337642 2026] [security2:error] [pid 884009:tid 884256] [client 103.141.108.143:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIlwAAAPg"]
[Mon Jul 20 06:20:32.338417 2026] [security2:error] [pid 884009:tid 884256] [client 103.141.108.143:49872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIlwAAAPg"]
[Mon Jul 20 06:20:32.453972 2026] [security2:error] [pid 884009:tid 884065] [remote 162.19.86.63:35960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4SkBKaHUf6J8d3elJImwAA4DY"], referer: https://get.learnthissecret.com/wp-login.php
[Mon Jul 20 06:20:32.674003 2026] [security2:error] [pid 884009:tid 884178] [client 57.141.18.76:23012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SixKaHUf6J8d3elJG-QAAqgg"]
[Mon Jul 20 06:20:32.738238 2026] [security2:error] [pid 884009:tid 884067] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIpQAA2Dg"]
[Mon Jul 20 06:20:32.738403 2026] [security2:error] [pid 884009:tid 884224] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIpQAA2Dg"]
[Mon Jul 20 06:20:32.842607 2026] [security2:error] [pid 884009:tid 884188] [client 193.148.56.61:50482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SkBKaHUf6J8d3elJIuQAAALQ"]
[Mon Jul 20 06:20:32.950980 2026] [security2:error] [pid 884009:tid 884153] [client 57.141.18.60:45102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SixKaHUf6J8d3elJHBgAAkhc"]
[Mon Jul 20 06:20:33.113830 2026] [security2:error] [pid 884009:tid 884168] [client 181.224.94.124:21349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SkRKaHUf6J8d3elJIwgAAAKE"]
[Mon Jul 20 06:20:33.113941 2026] [security2:error] [pid 884009:tid 884168] [client 181.224.94.124:21349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SkRKaHUf6J8d3elJIwgAAAKE"]
[Mon Jul 20 06:20:33.159733 2026] [security2:error] [pid 884009:tid 884194] [client 185.132.186.97:41813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/comfunctions.php"] [unique_id "al4SkRKaHUf6J8d3elJIxQAAALo"]
[Mon Jul 20 06:20:33.504995 2026] [security2:error] [pid 884009:tid 884188] [client 34.90.235.227:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.sih.bgd.mybluehost.me"] [uri "/"] [unique_id "al4SkRKaHUf6J8d3elJI4QAAALQ"]
[Mon Jul 20 06:20:33.505071 2026] [security2:error] [pid 884009:tid 884188] [client 34.90.235.227:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.sih.bgd.mybluehost.me"] [uri "/"] [unique_id "al4SkRKaHUf6J8d3elJI4QAAALQ"]
[Mon Jul 20 06:20:33.764273 2026] [security2:error] [pid 884009:tid 884159] [client 50.116.65.227:29314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SkRKaHUf6J8d3elJI9QAAAJg"]
[Mon Jul 20 06:20:33.774598 2026] [security2:error] [pid 884009:tid 884240] [client 50.116.65.227:36758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SkRKaHUf6J8d3elJI9wAAAMo"]
[Mon Jul 20 06:20:33.898012 2026] [security2:error] [pid 884009:tid 884172] [client 193.148.56.61:51722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SkRKaHUf6J8d3elJJBwAAAKQ"]
[Mon Jul 20 06:20:34.394033 2026] [security2:error] [pid 884009:tid 884187] [client 171.61.165.146:31146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkhKaHUf6J8d3elJJKgAAALM"]
[Mon Jul 20 06:20:34.400476 2026] [security2:error] [pid 884009:tid 884187] [client 171.61.165.146:31146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkhKaHUf6J8d3elJJKgAAALM"]
[Mon Jul 20 06:20:34.764720 2026] [security2:error] [pid 884009:tid 884212] [client 185.132.186.91:40047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-error-module.php"] [unique_id "al4SkhKaHUf6J8d3elJJTwAAAMw"]
[Mon Jul 20 06:20:34.850114 2026] [security2:error] [pid 884009:tid 884137] [remote 57.141.18.50:29218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4SkhKaHUf6J8d3elJJWgAA434"]
[Mon Jul 20 06:20:34.916538 2026] [security2:error] [pid 884009:tid 884183] [client 193.148.56.61:52826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SkhKaHUf6J8d3elJJYAAAAK8"]
[Mon Jul 20 06:20:35.069383 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:60567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkhKaHUf6J8d3elJJRAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.108264 2026] [security2:error] [pid 884009:tid 884211] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkhKaHUf6J8d3elJJRQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.224117 2026] [security2:error] [pid 884009:tid 884202] [client 57.141.18.9:42378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SjRKaHUf6J8d3elJHzgAAwlc"]
[Mon Jul 20 06:20:35.816033 2026] [security2:error] [pid 884009:tid 884215] [client 77.110.127.138:60585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkxKaHUf6J8d3elJJiAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.849186 2026] [security2:error] [pid 884009:tid 884240] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkxKaHUf6J8d3elJJjQAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.962672 2026] [security2:error] [pid 884009:tid 884156] [client 158.173.89.95:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SkxKaHUf6J8d3elJJpgAAAJU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:36.063151 2026] [core:error] [pid 884009:tid 884056] [remote 157.55.39.225:2664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:36.063171 2026] [core:error] [pid 884009:tid 884056] [remote 157.55.39.225:2664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:36.380788 2026] [security2:error] [pid 884009:tid 884154] [client 185.132.186.61:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/adminfus.php"] [unique_id "al4SlBKaHUf6J8d3elJJyQAAAJM"]
[Mon Jul 20 06:20:36.577304 2026] [security2:error] [pid 884009:tid 884225] [client 41.173.37.102:5809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ2gAAANk"]
[Mon Jul 20 06:20:36.577500 2026] [security2:error] [pid 884009:tid 884225] [client 41.173.37.102:5809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ2gAAANk"]
[Mon Jul 20 06:20:36.705939 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:60593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlBKaHUf6J8d3elJJ0QAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:36.734129 2026] [security2:error] [pid 884009:tid 884189] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlBKaHUf6J8d3elJJ0gAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:36.790685 2026] [security2:error] [pid 884009:tid 884245] [client 36.68.54.12:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.54.68.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ7gAAAO0"]
[Mon Jul 20 06:20:36.790884 2026] [security2:error] [pid 884009:tid 884245] [client 36.68.54.12:7029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ7gAAAO0"]
[Mon Jul 20 06:20:36.986898 2026] [security2:error] [pid 884009:tid 884057] [remote 57.141.18.125:53368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4SlBKaHUf6J8d3elJJ_wAAhS4"]
[Mon Jul 20 06:20:37.015902 2026] [security2:error] [pid 884009:tid 884184] [client 74.208.214.194:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SlRKaHUf6J8d3elJKAQAAALA"]
[Mon Jul 20 06:20:37.193524 2026] [proxy:error] [pid 884009:tid 884267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.193555 2026] [proxy_http:error] [pid 884009:tid 884267] [client 94.154.43.185:39990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.193992 2026] [proxy:error] [pid 884009:tid 884267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.194015 2026] [proxy_http:error] [pid 884009:tid 884267] [client 94.154.43.185:39990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.212955 2026] [proxy:error] [pid 884009:tid 884212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.213012 2026] [proxy_http:error] [pid 884009:tid 884212] [client 94.154.43.179:23140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.213628 2026] [proxy:error] [pid 884009:tid 884212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.213660 2026] [proxy_http:error] [pid 884009:tid 884212] [client 94.154.43.179:23140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.272308 2026] [security2:error] [pid 884009:tid 884208] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlRKaHUf6J8d3elJKCgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:37.299990 2026] [security2:error] [pid 884009:tid 884246] [client 77.110.127.138:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlRKaHUf6J8d3elJKCwAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:37.487840 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.82:54330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SkBKaHUf6J8d3elJIswAAtjs"]
[Mon Jul 20 06:20:37.537622 2026] [security2:error] [pid 884009:tid 884250] [client 57.141.18.91:34268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SkBKaHUf6J8d3elJItwAA8kU"]
[Mon Jul 20 06:20:37.562068 2026] [security2:error] [pid 884009:tid 884266] [client 74.208.214.194:56122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SlRKaHUf6J8d3elJKSwAAAQI"]
[Mon Jul 20 06:20:37.982964 2026] [security2:error] [pid 884009:tid 884145] [client 185.132.186.70:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/adminfus.php"] [unique_id "al4SlRKaHUf6J8d3elJKawAAAIo"]
[Mon Jul 20 06:20:38.139467 2026] [security2:error] [pid 884009:tid 884165] [client 112.208.70.94:42071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKcQAAAJ4"]
[Mon Jul 20 06:20:38.139577 2026] [security2:error] [pid 884009:tid 884165] [client 112.208.70.94:42071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKcQAAAJ4"]
[Mon Jul 20 06:20:38.646872 2026] [security2:error] [pid 884009:tid 884011] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKkgAAvwA"]
[Mon Jul 20 06:20:38.647068 2026] [security2:error] [pid 884009:tid 884199] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKkgAAvwA"]
[Mon Jul 20 06:20:38.675546 2026] [security2:error] [pid 884009:tid 884015] [remote 124.55.178.99:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SlhKaHUf6J8d3elJKlAAAjQQ"]
[Mon Jul 20 06:20:39.091199 2026] [security2:error] [pid 884009:tid 884018] [remote 124.55.178.99:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SlxKaHUf6J8d3elJKswAAoAc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:39.165320 2026] [security2:error] [pid 884009:tid 884140] [client 50.116.65.227:52882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SlxKaHUf6J8d3elJKtQAAAIU"]
[Mon Jul 20 06:20:39.175919 2026] [security2:error] [pid 884009:tid 884155] [client 50.116.65.227:52886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SlxKaHUf6J8d3elJKuAAAAJQ"]
[Mon Jul 20 06:20:39.619603 2026] [security2:error] [pid 884009:tid 884198] [client 185.132.186.71:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/litespeed.php"] [unique_id "al4SlxKaHUf6J8d3elJKzgAAAL4"]
[Mon Jul 20 06:20:39.712172 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SlxKaHUf6J8d3elJKzAAAANM"]
[Mon Jul 20 06:20:39.963402 2026] [security2:error] [pid 884009:tid 884200] [client 57.141.18.88:50814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SkxKaHUf6J8d3elJJewAAwBo"]
[Mon Jul 20 06:20:40.436943 2026] [security2:error] [pid 884009:tid 884261] [client 77.110.127.138:60627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmBKaHUf6J8d3elJK9QAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:40.476638 2026] [security2:error] [pid 884009:tid 884224] [client 45.95.169.104:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SmBKaHUf6J8d3elJLEQAAANg"]
[Mon Jul 20 06:20:40.554769 2026] [security2:error] [pid 884009:tid 884039] [remote 20.153.140.50:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SmBKaHUf6J8d3elJLFgABAhw"]
[Mon Jul 20 06:20:40.864222 2026] [security2:error] [pid 884009:tid 884170] [client 57.141.18.90:38528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlBKaHUf6J8d3elJJwgAAoj4"]
[Mon Jul 20 06:20:40.956638 2026] [security2:error] [pid 884009:tid 884084] [remote 20.153.140.50:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SmBKaHUf6J8d3elJLOQAAoEk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:41.228226 2026] [security2:error] [pid 884009:tid 884174] [client 185.132.186.96:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/as.php"] [unique_id "al4SmRKaHUf6J8d3elJLSwAAAKY"]
[Mon Jul 20 06:20:41.338302 2026] [security2:error] [pid 884009:tid 884189] [client 77.110.127.138:60656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmRKaHUf6J8d3elJLQgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:41.666820 2026] [security2:error] [pid 884009:tid 884222] [client 98.92.1.119:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SmBKaHUf6J8d3elJLIAAAANY"]
[Mon Jul 20 06:20:41.699270 2026] [security2:error] [pid 884009:tid 884232] [client 98.92.1.119:26852] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/ensalada-de-coditos-puerto-rican-macaroni-salad/"] [unique_id "al4SmBKaHUf6J8d3elJLGwAAAOA"]
[Mon Jul 20 06:20:41.735782 2026] [security2:error] [pid 884009:tid 884168] [client 171.60.139.123:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLcgAAAKE"]
[Mon Jul 20 06:20:41.735911 2026] [security2:error] [pid 884009:tid 884168] [client 171.60.139.123:57391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLcgAAAKE"]
[Mon Jul 20 06:20:41.751229 2026] [security2:error] [pid 884009:tid 884257] [client 27.96.94.195:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLdAAAAPk"]
[Mon Jul 20 06:20:41.751358 2026] [security2:error] [pid 884009:tid 884257] [client 27.96.94.195:36896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLdAAAAPk"]
[Mon Jul 20 06:20:41.771696 2026] [security2:error] [pid 884009:tid 884265] [client 77.110.127.138:60666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmRKaHUf6J8d3elJLZAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:41.942929 2026] [security2:error] [pid 884009:tid 884149] [client 50.116.65.227:36256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SmRKaHUf6J8d3elJLiAAAAI4"]
[Mon Jul 20 06:20:41.956081 2026] [security2:error] [pid 884009:tid 884191] [client 50.116.65.227:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SmRKaHUf6J8d3elJLiwAAALc"]
[Mon Jul 20 06:20:42.032098 2026] [security2:error] [pid 884009:tid 884205] [client 57.141.18.87:42678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlRKaHUf6J8d3elJKMgAAxVU"]
[Mon Jul 20 06:20:42.072556 2026] [security2:error] [pid 884009:tid 884117] [remote 57.141.18.2:21496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3688465"] [unique_id "al4SmhKaHUf6J8d3elJLlAAAyGo"]
[Mon Jul 20 06:20:42.265462 2026] [security2:error] [pid 884009:tid 884163] [client 103.153.183.69:23316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/ssh/sshd_config"] [unique_id "al4SmhKaHUf6J8d3elJLmQAAAJw"], referer: https://www.google.com/
[Mon Jul 20 06:20:42.293091 2026] [security2:error] [pid 884009:tid 884161] [client 103.153.183.69:23316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../root/.ssh/id_rsa"] [unique_id "al4SmhKaHUf6J8d3elJLnQAAAJo"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:20:42.330120 2026] [security2:error] [pid 884009:tid 884184] [client 77.110.127.138:60675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmRKaHUf6J8d3elJLjQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:42.804217 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SmhKaHUf6J8d3elJLvgAAAPI"]
[Mon Jul 20 06:20:42.804325 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:49227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SmhKaHUf6J8d3elJLvgAAAPI"]
[Mon Jul 20 06:20:42.848302 2026] [security2:error] [pid 884009:tid 884198] [client 77.110.127.138:60683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLtgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:42.854428 2026] [security2:error] [pid 884009:tid 884222] [client 185.132.186.87:43331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/setup-config.php"] [unique_id "al4SmhKaHUf6J8d3elJLwwAAANY"]
[Mon Jul 20 06:20:43.028177 2026] [security2:error] [pid 884009:tid 884231] [client 103.141.108.143:50355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL3gAAAN8"]
[Mon Jul 20 06:20:43.028264 2026] [security2:error] [pid 884009:tid 884231] [client 103.141.108.143:50355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL3gAAAN8"]
[Mon Jul 20 06:20:43.112217 2026] [security2:error] [pid 884009:tid 884265] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLowAAAQE"]
[Mon Jul 20 06:20:43.349325 2026] [security2:error] [pid 884009:tid 884045] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL7gAAxCI"]
[Mon Jul 20 06:20:43.349442 2026] [security2:error] [pid 884009:tid 884204] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL7gAAxCI"]
[Mon Jul 20 06:20:43.364167 2026] [security2:error] [pid 884009:tid 884206] [client 57.141.18.41:43074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlhKaHUf6J8d3elJKrAAAxhI"]
[Mon Jul 20 06:20:43.665989 2026] [security2:error] [pid 884009:tid 884195] [client 181.224.94.124:26761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMCwAAALs"]
[Mon Jul 20 06:20:43.666114 2026] [security2:error] [pid 884009:tid 884195] [client 181.224.94.124:26761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMCwAAALs"]
[Mon Jul 20 06:20:43.763648 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:60699] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4SmxKaHUf6J8d3elJMDgAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:43.884226 2026] [security2:error] [pid 884009:tid 884158] [client 178.152.178.232:36563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMGQAAAJc"]
[Mon Jul 20 06:20:43.884335 2026] [security2:error] [pid 884009:tid 884158] [client 178.152.178.232:36563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMGQAAAJc"]
[Mon Jul 20 06:20:43.946454 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.62:27152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlxKaHUf6J8d3elJKxwAAthQ"]
[Mon Jul 20 06:20:44.227070 2026] [security2:error] [pid 884009:tid 884043] [remote 162.19.86.63:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMPQAAyyA"]
[Mon Jul 20 06:20:44.392687 2026] [security2:error] [pid 884009:tid 884071] [remote 217.61.143.92:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnBKaHUf6J8d3elJMRwAA9jw"]
[Mon Jul 20 06:20:44.392887 2026] [security2:error] [pid 884009:tid 884254] [client 217.61.143.92:43858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnBKaHUf6J8d3elJMRwAA9jw"]
[Mon Jul 20 06:20:44.419849 2026] [core:error] [pid 884009:tid 884263] [client 14.225.17.146:50357] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wp
[Mon Jul 20 06:20:44.419881 2026] [core:error] [pid 884009:tid 884263] [client 14.225.17.146:50357] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wp
[Mon Jul 20 06:20:44.443874 2026] [security2:error] [pid 884009:tid 884039] [remote 162.19.86.63:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMUAAAxBw"], referer: https://oldracelimited.com/wp-login.php
[Mon Jul 20 06:20:44.456490 2026] [security2:error] [pid 884009:tid 884159] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SnBKaHUf6J8d3elJMQgAAAJg"]
[Mon Jul 20 06:20:44.474593 2026] [security2:error] [pid 884009:tid 884227] [client 185.132.186.95:60411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/alam.php"] [unique_id "al4SnBKaHUf6J8d3elJMUgAAANs"]
[Mon Jul 20 06:20:44.568983 2026] [security2:error] [pid 884009:tid 884258] [client 57.141.18.66:29358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmBKaHUf6J8d3elJK-QAA-g4"]
[Mon Jul 20 06:20:44.639246 2026] [security2:error] [pid 884009:tid 884207] [client 104.234.53.80:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMWQAAAMc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:44.848974 2026] [security2:error] [pid 884009:tid 884176] [client 158.173.166.181:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SnBKaHUf6J8d3elJMawAAAKg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:44.915950 2026] [security2:error] [pid 884009:tid 884227] [client 45.95.169.104:23362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMbwAAANs"]
[Mon Jul 20 06:20:44.934877 2026] [security2:error] [pid 884009:tid 884084] [remote 97.74.87.194:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMcAAAqkk"]
[Mon Jul 20 06:20:45.319982 2026] [security2:error] [pid 884009:tid 884074] [remote 97.74.87.194:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SnRKaHUf6J8d3elJMlQAAjj8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:20:45.386947 2026] [security2:error] [pid 884009:tid 884204] [client 171.61.165.146:30990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SnRKaHUf6J8d3elJMnQAAAMQ"]
[Mon Jul 20 06:20:45.387062 2026] [security2:error] [pid 884009:tid 884204] [client 171.61.165.146:30990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SnRKaHUf6J8d3elJMnQAAAMQ"]
[Mon Jul 20 06:20:45.839522 2026] [security2:error] [pid 884009:tid 884153] [client 14.225.17.146:50662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4SnRKaHUf6J8d3elJMmwAAAJI"], referer: http://backandneckpainrelieflaceychiropractor.com/Wp
[Mon Jul 20 06:20:45.876879 2026] [security2:error] [pid 884009:tid 884093] [remote 100.42.189.89:43252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4SnRKaHUf6J8d3elJMzAAAzFI"]
[Mon Jul 20 06:20:46.091070 2026] [security2:error] [pid 884009:tid 884194] [client 185.132.186.87:44809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/cong.php"] [unique_id "al4SnhKaHUf6J8d3elJM6wAAALo"]
[Mon Jul 20 06:20:46.177548 2026] [security2:error] [pid 884009:tid 884185] [client 186.194.46.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SnRKaHUf6J8d3elJMwwAAALE"]
[Mon Jul 20 06:20:46.214354 2026] [security2:error] [pid 884009:tid 884138] [remote 100.42.189.89:43252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4SnhKaHUf6J8d3elJM9gAAjX8"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:20:46.245644 2026] [security2:error] [pid 884009:tid 884225] [client 14.225.17.146:50606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4SnRKaHUf6J8d3elJM1gAAANk"], referer: http://mrbambooplus.com/Wp
[Mon Jul 20 06:20:46.459063 2026] [security2:error] [pid 884009:tid 884143] [client 57.141.18.25:32236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLkwAAiEQ"]
[Mon Jul 20 06:20:46.517309 2026] [security2:error] [pid 884009:tid 884127] [remote 103.255.134.61:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SnhKaHUf6J8d3elJNBgAAn3Q"]
[Mon Jul 20 06:20:46.567873 2026] [security2:error] [pid 884009:tid 884237] [client 57.141.18.19:33842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLmgAA5VE"]
[Mon Jul 20 06:20:46.579880 2026] [security2:error] [pid 884009:tid 884029] [remote 20.153.140.50:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnhKaHUf6J8d3elJNEAAAohI"]
[Mon Jul 20 06:20:46.580033 2026] [security2:error] [pid 884009:tid 884170] [client 20.153.140.50:49542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnhKaHUf6J8d3elJNEAAAohI"]
[Mon Jul 20 06:20:46.817622 2026] [security2:error] [pid 884009:tid 884168] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4SnhKaHUf6J8d3elJNLAAAAKE"], referer: https://www.reddit.com/
[Mon Jul 20 06:20:47.082147 2026] [security2:error] [pid 884009:tid 884220] [client 57.141.18.33:34880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLzAAA1GQ"]
[Mon Jul 20 06:20:47.094491 2026] [security2:error] [pid 884009:tid 884114] [remote 103.255.134.61:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SnxKaHUf6J8d3elJNOAAApWc"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:20:47.161659 2026] [security2:error] [pid 884009:tid 884161] [client 57.141.18.117:62902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLzQAAmlc"]
[Mon Jul 20 06:20:47.224016 2026] [security2:error] [pid 884009:tid 884239] [client 41.173.37.102:6738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNQAAAAOc"]
[Mon Jul 20 06:20:47.224124 2026] [security2:error] [pid 884009:tid 884239] [client 41.173.37.102:6738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNQAAAAOc"]
[Mon Jul 20 06:20:47.567652 2026] [security2:error] [pid 884009:tid 884162] [client 104.234.53.90:43847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNXQAAAJs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:47.699298 2026] [security2:error] [pid 884009:tid 884161] [client 185.132.186.93:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/block-bindings/imagess.php"] [unique_id "al4SnxKaHUf6J8d3elJNbQAAAJo"]
[Mon Jul 20 06:20:47.699581 2026] [security2:error] [pid 884009:tid 884039] [remote 152.228.213.32:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4SnxKaHUf6J8d3elJNagAAwhw"]
[Mon Jul 20 06:20:47.752989 2026] [security2:error] [pid 884009:tid 884243] [client 14.225.17.146:64226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNSAAAAOs"], referer: http://overloadcomedy.com/Wp
[Mon Jul 20 06:20:47.905275 2026] [security2:error] [pid 884009:tid 884081] [remote 152.228.213.32:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4SnxKaHUf6J8d3elJNjgAAokY"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 06:20:47.934955 2026] [security2:error] [pid 884009:tid 884156] [client 68.235.52.68:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNkwAAAJU"]
[Mon Jul 20 06:20:47.935058 2026] [security2:error] [pid 884009:tid 884156] [client 68.235.52.68:47784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNkwAAAJU"]
[Mon Jul 20 06:20:47.970316 2026] [security2:error] [pid 884009:tid 884208] [client 77.110.127.138:60743] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4SnxKaHUf6J8d3elJNmQAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:48.046106 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.108:56054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmxKaHUf6J8d3elJMIAAAwTo"]
[Mon Jul 20 06:20:48.181725 2026] [security2:error] [pid 884009:tid 884077] [remote 38.242.157.30:33122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4SoBKaHUf6J8d3elJNqQAA40I"]
[Mon Jul 20 06:20:48.193117 2026] [security2:error] [pid 884009:tid 884203] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNYQAAAMM"]
[Mon Jul 20 06:20:48.365351 2026] [security2:error] [pid 884009:tid 884122] [remote 38.242.157.30:33122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4SoBKaHUf6J8d3elJNuAAA528"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:20:48.555512 2026] [security2:error] [pid 884009:tid 884251] [client 136.107.64.51:52148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4SnBKaHUf6J8d3elJMMAAAAPM"]
[Mon Jul 20 06:20:48.669506 2026] [security2:error] [pid 884009:tid 884219] [client 136.107.64.51:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SoBKaHUf6J8d3elJNyQAAANM"]
[Mon Jul 20 06:20:48.807039 2026] [security2:error] [pid 884009:tid 884170] [client 77.110.127.138:60752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4SoBKaHUf6J8d3elJN1gAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:49.048992 2026] [security2:error] [pid 884009:tid 884222] [client 57.141.18.16:38868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnRKaHUf6J8d3elJMfQAA1mk"]
[Mon Jul 20 06:20:49.182693 2026] [security2:error] [pid 884009:tid 884174] [client 136.107.64.51:56199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SoRKaHUf6J8d3elJN8QAAAKY"]
[Mon Jul 20 06:20:49.266059 2026] [security2:error] [pid 884009:tid 884015] [remote 182.77.62.24:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SoRKaHUf6J8d3elJN-QAA9wQ"]
[Mon Jul 20 06:20:49.293721 2026] [security2:error] [pid 884009:tid 884011] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SoRKaHUf6J8d3elJN_wAA0wA"]
[Mon Jul 20 06:20:49.294040 2026] [security2:error] [pid 884009:tid 884219] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SoRKaHUf6J8d3elJN_wAA0wA"]
[Mon Jul 20 06:20:49.312165 2026] [security2:error] [pid 884009:tid 884223] [client 185.132.186.72:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/adminfus.php"] [unique_id "al4SoRKaHUf6J8d3elJOBAAAANc"]
[Mon Jul 20 06:20:49.793779 2026] [security2:error] [pid 884009:tid 884051] [remote 182.77.62.24:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SoRKaHUf6J8d3elJOOAAA_Cg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:49.796546 2026] [security2:error] [pid 884009:tid 884182] [client 136.107.64.51:53679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SoRKaHUf6J8d3elJOOgAAAK4"]
[Mon Jul 20 06:20:49.811473 2026] [security2:error] [pid 884009:tid 884184] [client 57.141.18.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SoRKaHUf6J8d3elJOLgAAALA"]
[Mon Jul 20 06:20:49.843157 2026] [security2:error] [pid 884009:tid 884219] [client 50.116.65.227:34196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SoRKaHUf6J8d3elJOOwAAANM"]
[Mon Jul 20 06:20:49.856912 2026] [security2:error] [pid 884009:tid 884158] [client 50.116.65.227:34198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SoRKaHUf6J8d3elJOPAAAAJc"]
[Mon Jul 20 06:20:50.020993 2026] [security2:error] [pid 884009:tid 884179] [client 15.204.80.170:51048] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "gearwaterproof.com"] [uri "/"] [unique_id "al4SohKaHUf6J8d3elJORgAAAKs"]
[Mon Jul 20 06:20:50.030062 2026] [security2:error] [pid 884009:tid 884247] [client 57.141.18.55:56772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnhKaHUf6J8d3elJM8QAA72A"]
[Mon Jul 20 06:20:50.038971 2026] [security2:error] [pid 884009:tid 884253] [client 57.141.18.2:59346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnhKaHUf6J8d3elJM8wAA9XU"]
[Mon Jul 20 06:20:50.062412 2026] [security2:error] [pid 884009:tid 884173] [client 14.225.17.146:62440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4SoRKaHUf6J8d3elJOQAAAAKU"], referer: http://aberballet.co.uk/Wp
[Mon Jul 20 06:20:50.170009 2026] [security2:error] [pid 884009:tid 884143] [client 112.208.70.94:42516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SohKaHUf6J8d3elJOVAAAAIg"]
[Mon Jul 20 06:20:50.170209 2026] [security2:error] [pid 884009:tid 884143] [client 112.208.70.94:42516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SohKaHUf6J8d3elJOVAAAAIg"]
[Mon Jul 20 06:20:50.284964 2026] [security2:error] [pid 884009:tid 884242] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/etc/passwd"] [unique_id "al4SohKaHUf6J8d3elJOXwAAAOo"], referer: https://twitter.com/
[Mon Jul 20 06:20:50.293243 2026] [security2:error] [pid 884009:tid 884149] [client 50.116.65.227:34166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4SoRKaHUf6J8d3elJN9wAAAI4"]
[Mon Jul 20 06:20:50.408841 2026] [security2:error] [pid 884009:tid 884187] [client 57.141.18.107:63688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnhKaHUf6J8d3elJNFAAAsyI"]
[Mon Jul 20 06:20:50.431511 2026] [security2:error] [pid 884009:tid 884175] [client 14.225.17.146:62314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJN4QAAAKc"], referer: http://phillipbloch.com/Wp
[Mon Jul 20 06:20:50.489177 2026] [security2:error] [pid 884009:tid 884163] [client 14.225.17.146:50608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJN1QAAAJw"], referer: http://nurturemarple.co.uk/Wp
[Mon Jul 20 06:20:50.499513 2026] [security2:error] [pid 884009:tid 884245] [client 136.107.64.51:50613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SohKaHUf6J8d3elJOdwAAAO0"]
[Mon Jul 20 06:20:50.672687 2026] [security2:error] [pid 884009:tid 884252] [client 14.225.17.146:55978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOdQAAAPQ"], referer: http://margaretspeckogawa.com/Wp
[Mon Jul 20 06:20:50.676660 2026] [security2:error] [pid 884009:tid 884172] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOUQAAAKQ"]
[Mon Jul 20 06:20:50.835878 2026] [security2:error] [pid 884009:tid 884151] [client 50.116.65.227:49452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4SohKaHUf6J8d3elJOlAAAAJA"]
[Mon Jul 20 06:20:50.847789 2026] [security2:error] [pid 884009:tid 884210] [client 50.116.65.227:34264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4SohKaHUf6J8d3elJOlgAAAMo"]
[Mon Jul 20 06:20:50.853950 2026] [security2:error] [pid 884009:tid 884233] [client 57.141.18.105:22738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNNQAA4RQ"]
[Mon Jul 20 06:20:50.897213 2026] [security2:error] [pid 884009:tid 884263] [client 50.116.65.227:34240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOYgAAAP8"]
[Mon Jul 20 06:20:50.915220 2026] [security2:error] [pid 884009:tid 884160] [client 136.107.64.51:61261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SohKaHUf6J8d3elJOnQAAAJk"]
[Mon Jul 20 06:20:50.930867 2026] [security2:error] [pid 884009:tid 884071] [remote 147.50.252.213:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SohKaHUf6J8d3elJOoAABBDw"]
[Mon Jul 20 06:20:50.935866 2026] [security2:error] [pid 884009:tid 884192] [client 185.132.186.61:47159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/default-filters-edit.php"] [unique_id "al4SohKaHUf6J8d3elJOogAAALg"]
[Mon Jul 20 06:20:51.016763 2026] [security2:error] [pid 884009:tid 884190] [client 50.116.65.227:34252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOgAAAALY"]
[Mon Jul 20 06:20:51.224278 2026] [security2:error] [pid 884009:tid 884191] [client 50.116.65.227:34274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SoxKaHUf6J8d3elJOrAAAALc"]
[Mon Jul 20 06:20:51.398542 2026] [security2:error] [pid 884009:tid 884233] [client 136.107.64.51:57093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SoxKaHUf6J8d3elJOzgAAAOE"]
[Mon Jul 20 06:20:51.408899 2026] [core:error] [pid 884009:tid 884239] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.408922 2026] [core:error] [pid 884009:tid 884239] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.411790 2026] [core:error] [pid 884009:tid 884254] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.411816 2026] [core:error] [pid 884009:tid 884254] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.433968 2026] [security2:error] [pid 884009:tid 884196] [client 14.225.17.146:55753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SoxKaHUf6J8d3elJOuAAAALw"], referer: https://nurturemarple.co.uk/Wp
[Mon Jul 20 06:20:51.436354 2026] [security2:error] [pid 884009:tid 884046] [remote 147.50.252.213:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO1AAA5SM"], referer: https://amalia-capital.com/wp-login.php
[Mon Jul 20 06:20:51.466895 2026] [security2:error] [pid 884009:tid 884184] [client 14.225.17.146:55764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4SoxKaHUf6J8d3elJOtwAAALA"], referer: http://dadanetnet.net/Wp
[Mon Jul 20 06:20:51.570836 2026] [security2:error] [pid 884009:tid 884053] [remote 81.173.115.7:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO4gAAwyo"]
[Mon Jul 20 06:20:51.767736 2026] [security2:error] [pid 884009:tid 884064] [remote 81.173.115.7:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO7QAA5zU"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:20:51.772383 2026] [security2:error] [pid 884009:tid 884220] [client 136.107.64.51:53826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SoxKaHUf6J8d3elJO7wAAANQ"]
[Mon Jul 20 06:20:51.778785 2026] [security2:error] [pid 884009:tid 884097] [remote 167.233.114.32:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO7gAA6lY"]
[Mon Jul 20 06:20:51.801036 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:60785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4SoxKaHUf6J8d3elJO9QAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:51.812425 2026] [security2:error] [pid 884009:tid 884217] [client 57.141.18.91:44892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJNmwAA0Vw"]
[Mon Jul 20 06:20:51.902933 2026] [security2:error] [pid 884009:tid 884072] [remote 173.212.252.15:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJPCwAAzj0"]
[Mon Jul 20 06:20:52.040434 2026] [security2:error] [pid 884009:tid 884220] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4SpBKaHUf6J8d3elJPGwAAANQ"], referer: https://twitter.com/
[Mon Jul 20 06:20:52.102950 2026] [security2:error] [pid 884009:tid 884121] [remote 167.233.114.32:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SpBKaHUf6J8d3elJPHQAA4G4"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:52.163968 2026] [security2:error] [pid 884009:tid 884179] [client 136.107.64.51:59932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SpBKaHUf6J8d3elJPIQAAAKs"]
[Mon Jul 20 06:20:52.361837 2026] [security2:error] [pid 884009:tid 884117] [remote 173.212.252.15:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SpBKaHUf6J8d3elJPKgAAzmo"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:20:52.402205 2026] [security2:error] [pid 884009:tid 884216] [client 104.234.53.90:50539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SpBKaHUf6J8d3elJPMAAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:52.429933 2026] [security2:error] [pid 884009:tid 884266] [client 57.141.18.45:30994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJN0QABAlg"]
[Mon Jul 20 06:20:52.502122 2026] [security2:error] [pid 884009:tid 884255] [client 171.60.139.123:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SpBKaHUf6J8d3elJPPQAAAPc"]
[Mon Jul 20 06:20:52.502297 2026] [security2:error] [pid 884009:tid 884255] [client 171.60.139.123:57896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SpBKaHUf6J8d3elJPPQAAAPc"]
[Mon Jul 20 06:20:52.541109 2026] [security2:error] [pid 884009:tid 884223] [client 136.107.64.51:59098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SpBKaHUf6J8d3elJPPwAAANc"]
[Mon Jul 20 06:20:52.545065 2026] [security2:error] [pid 884009:tid 884212] [client 185.132.186.94:30463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/install.php"] [unique_id "al4SpBKaHUf6J8d3elJPQAAAAMw"]
[Mon Jul 20 06:20:52.569482 2026] [security2:error] [pid 884009:tid 884239] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4SpBKaHUf6J8d3elJPQQAAAOc"], referer: https://www.bing.com/search?q=n2iwn9
[Mon Jul 20 06:20:52.619828 2026] [security2:error] [pid 884009:tid 884227] [client 77.110.127.138:60796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4SpBKaHUf6J8d3elJPQwAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:52.795721 2026] [security2:error] [pid 884009:tid 884156] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SpBKaHUf6J8d3elJPFwAAAJU"]
[Mon Jul 20 06:20:52.930822 2026] [security2:error] [pid 884009:tid 884207] [client 136.107.64.51:52501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SpBKaHUf6J8d3elJPXAAAAMc"]
[Mon Jul 20 06:20:53.084642 2026] [security2:error] [pid 884009:tid 884157] [client 104.234.53.63:32443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SpBKaHUf6J8d3elJPXgAAAJY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:53.443323 2026] [security2:error] [pid 884009:tid 884170] [client 136.107.64.51:58718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SpRKaHUf6J8d3elJPgAAAAKI"]
[Mon Jul 20 06:20:53.559466 2026] [security2:error] [pid 884009:tid 884254] [client 45.116.69.230:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPhgAAAPY"]
[Mon Jul 20 06:20:53.559606 2026] [security2:error] [pid 884009:tid 884254] [client 45.116.69.230:49789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPhgAAAPY"]
[Mon Jul 20 06:20:53.562694 2026] [security2:error] [pid 884009:tid 884163] [client 104.234.53.63:32443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SpRKaHUf6J8d3elJPhwAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:53.619397 2026] [security2:error] [pid 884009:tid 884262] [client 103.141.108.143:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPjwAAAP4"]
[Mon Jul 20 06:20:53.620196 2026] [security2:error] [pid 884009:tid 884262] [client 103.141.108.143:50828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPjwAAAP4"]
[Mon Jul 20 06:20:53.669522 2026] [security2:error] [pid 884009:tid 884184] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPZwAAsBM"], referer: http://ardhalwafaa.com/Wp
[Mon Jul 20 06:20:53.695482 2026] [core:error] [pid 884009:tid 884210] [client 14.225.17.146:61822] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:53.695512 2026] [core:error] [pid 884009:tid 884210] [client 14.225.17.146:61822] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:53.874698 2026] [security2:error] [pid 884009:tid 884148] [client 57.141.18.103:63608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOWwAAjWQ"]
[Mon Jul 20 06:20:53.944924 2026] [security2:error] [pid 884009:tid 884061] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPqwAArDI"]
[Mon Jul 20 06:20:53.945151 2026] [security2:error] [pid 884009:tid 884180] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPqwAArDI"]
[Mon Jul 20 06:20:54.014012 2026] [security2:error] [pid 884009:tid 884213] [client 27.96.94.195:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPswAAAM0"]
[Mon Jul 20 06:20:54.014193 2026] [security2:error] [pid 884009:tid 884213] [client 27.96.94.195:37591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPswAAAM0"]
[Mon Jul 20 06:20:54.032700 2026] [security2:error] [pid 884009:tid 884045] [remote 182.77.62.24:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SphKaHUf6J8d3elJPtAAA7CI"]
[Mon Jul 20 06:20:54.149488 2026] [security2:error] [pid 884009:tid 884251] [client 185.132.186.75:28925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/av.php"] [unique_id "al4SphKaHUf6J8d3elJPxQAAAPM"]
[Mon Jul 20 06:20:54.186270 2026] [security2:error] [pid 884009:tid 884145] [client 181.224.94.124:55111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPzgAAAIo"]
[Mon Jul 20 06:20:54.186389 2026] [security2:error] [pid 884009:tid 884145] [client 181.224.94.124:55111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPzgAAAIo"]
[Mon Jul 20 06:20:54.263483 2026] [security2:error] [pid 884009:tid 884160] [client 104.234.53.89:50651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SphKaHUf6J8d3elJP1wAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:54.485180 2026] [security2:error] [pid 884009:tid 884222] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPmgAAANY"]
[Mon Jul 20 06:20:54.668967 2026] [security2:error] [pid 884009:tid 884065] [remote 182.77.62.24:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SphKaHUf6J8d3elJP9gAA6jY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:54.691085 2026] [security2:error] [pid 884009:tid 884167] [client 178.152.178.232:37015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJP_QAAAKA"]
[Mon Jul 20 06:20:54.691181 2026] [security2:error] [pid 884009:tid 884167] [client 178.152.178.232:37015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJP_QAAAKA"]
[Mon Jul 20 06:20:55.108491 2026] [security2:error] [pid 884009:tid 884103] [remote 194.164.192.228:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4SpxKaHUf6J8d3elJQGQAA0Fw"]
[Mon Jul 20 06:20:55.123216 2026] [security2:error] [pid 884009:tid 884227] [client 14.225.17.146:56476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQEwAAANs"], referer: http://daseighty.net/Wp
[Mon Jul 20 06:20:55.299760 2026] [security2:error] [pid 884009:tid 884089] [remote 194.164.192.228:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4SpxKaHUf6J8d3elJQKgAA-k4"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 06:20:55.352263 2026] [security2:error] [pid 884009:tid 884207] [client 158.173.241.141:52951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQHgAAAMc"], referer: http://sesamegreenbeans.com/tag/south-africa/
[Mon Jul 20 06:20:55.391733 2026] [security2:error] [pid 884009:tid 884057] [remote 18.61.192.253:58632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SpxKaHUf6J8d3elJQMgAA7y4"]
[Mon Jul 20 06:20:55.391961 2026] [security2:error] [pid 884009:tid 884247] [client 18.61.192.253:58632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SpxKaHUf6J8d3elJQMgAA7y4"]
[Mon Jul 20 06:20:55.611103 2026] [security2:error] [pid 884009:tid 884242] [client 14.225.17.146:61884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQNwAAAOo"], referer: http://39ishlife.com/Wp
[Mon Jul 20 06:20:55.770634 2026] [security2:error] [pid 884009:tid 884205] [client 185.132.186.88:52977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/autoload_classmap/about.php"] [unique_id "al4SpxKaHUf6J8d3elJQUwAAAMU"]
[Mon Jul 20 06:20:55.828521 2026] [security2:error] [pid 884009:tid 884249] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQTAAAAPE"]
[Mon Jul 20 06:20:56.239002 2026] [security2:error] [pid 884009:tid 884229] [client 77.110.127.138:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4SqBKaHUf6J8d3elJQdwAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:56.318176 2026] [security2:error] [pid 884009:tid 884199] [client 57.141.18.62:48520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SpBKaHUf6J8d3elJPSQAAvwY"]
[Mon Jul 20 06:20:56.330235 2026] [security2:error] [pid 884009:tid 884194] [client 14.225.17.146:56188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQdAAAALo"], referer: http://lutheranphilosopher.com/Wp
[Mon Jul 20 06:20:56.538282 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:62540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQigAAAJ0"], referer: https://39ishlife.com/Wp
[Mon Jul 20 06:20:56.688361 2026] [security2:error] [pid 884009:tid 884162] [client 171.61.165.146:28995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqBKaHUf6J8d3elJQnQAAAJs"]
[Mon Jul 20 06:20:56.688524 2026] [security2:error] [pid 884009:tid 884162] [client 171.61.165.146:28995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqBKaHUf6J8d3elJQnQAAAJs"]
[Mon Jul 20 06:20:56.947109 2026] [security2:error] [pid 884009:tid 884024] [remote 122.8.47.155:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.47.8.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wesmclucas.com"] [uri "/wp-login.php"] [unique_id "al4SqBKaHUf6J8d3elJQuwAAzg0"]
[Mon Jul 20 06:20:57.203783 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.49:54736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPhQAAwRI"]
[Mon Jul 20 06:20:57.379178 2026] [security2:error] [pid 884009:tid 884267] [client 185.132.186.59:55229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-configs.php"] [unique_id "al4SqRKaHUf6J8d3elJQ1wAAAQM"]
[Mon Jul 20 06:20:57.464492 2026] [security2:error] [pid 884009:tid 884206] [client 104.234.53.50:54533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SqRKaHUf6J8d3elJQ2wAAAMY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:57.587534 2026] [security2:error] [pid 884009:tid 884218] [client 45.95.169.104:23364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SqRKaHUf6J8d3elJQ5wAAANI"]
[Mon Jul 20 06:20:57.757317 2026] [security2:error] [pid 884009:tid 884243] [client 41.173.37.102:7207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SqRKaHUf6J8d3elJQ-QAAAOs"]
[Mon Jul 20 06:20:57.757456 2026] [security2:error] [pid 884009:tid 884243] [client 41.173.37.102:7207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SqRKaHUf6J8d3elJQ-QAAAOs"]
[Mon Jul 20 06:20:57.758803 2026] [security2:error] [pid 884009:tid 884199] [client 14.225.17.146:62545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SqRKaHUf6J8d3elJQ7QAAAL8"], referer: http://wathenbartlett.co.uk/Wp
[Mon Jul 20 06:20:58.141300 2026] [security2:error] [pid 884009:tid 884154] [client 57.141.18.76:29334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SphKaHUf6J8d3elJP3wAAkw8"]
[Mon Jul 20 06:20:58.172225 2026] [security2:error] [pid 884009:tid 884151] [client 57.141.18.81:37396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SphKaHUf6J8d3elJP4QAAkBw"]
[Mon Jul 20 06:20:58.307408 2026] [security2:error] [pid 884009:tid 884143] [client 104.234.53.85:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRGAAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:58.396375 2026] [security2:error] [pid 884009:tid 884060] [remote 104.248.157.6:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.157.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4SqhKaHUf6J8d3elJRIAAA6DE"]
[Mon Jul 20 06:20:58.668615 2026] [security2:error] [pid 884009:tid 884245] [client 14.225.17.146:62039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRKgAAAO0"], referer: https://wathenbartlett.co.uk/Wp
[Mon Jul 20 06:20:58.774146 2026] [security2:error] [pid 884009:tid 884076] [remote 104.248.157.6:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.157.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4SqhKaHUf6J8d3elJRQgAAjUE"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:20:58.848676 2026] [security2:error] [pid 884009:tid 884232] [client 14.225.17.146:64611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4SqRKaHUf6J8d3elJQygAAAOA"], referer: http://transparentservices.online/Wp
[Mon Jul 20 06:20:58.908556 2026] [security2:error] [pid 884009:tid 884106] [remote 154.66.198.148:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4SqhKaHUf6J8d3elJRUQAAj18"]
[Mon Jul 20 06:20:58.987121 2026] [security2:error] [pid 884009:tid 884165] [client 185.132.186.92:35393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRVAAAAJ4"]
[Mon Jul 20 06:20:59.216413 2026] [security2:error] [pid 884009:tid 884248] [client 50.116.65.227:59528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SqxKaHUf6J8d3elJRXwAAAPA"]
[Mon Jul 20 06:20:59.227631 2026] [security2:error] [pid 884009:tid 884221] [client 50.116.65.227:47268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SqxKaHUf6J8d3elJRYQAAAMY"]
[Mon Jul 20 06:20:59.398541 2026] [security2:error] [pid 884009:tid 884220] [client 216.73.217.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theprocess.oldcartsconsulting.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPbQAAANQ"]
[Mon Jul 20 06:20:59.580913 2026] [security2:error] [pid 884009:tid 884258] [client 50.116.65.227:47296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SqxKaHUf6J8d3elJRgwAAAPo"]
[Mon Jul 20 06:20:59.595263 2026] [security2:error] [pid 884009:tid 884216] [client 50.116.65.227:47308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SqxKaHUf6J8d3elJRhAAAANA"]
[Mon Jul 20 06:20:59.735155 2026] [security2:error] [pid 884009:tid 884093] [remote 154.66.198.148:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4SqxKaHUf6J8d3elJRiwAAq1I"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:20:59.909202 2026] [security2:error] [pid 884009:tid 884229] [client 14.225.17.146:61924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4SqRKaHUf6J8d3elJQ5AAAAN0"], referer: http://adastra.love/Wp
[Mon Jul 20 06:20:59.960733 2026] [security2:error] [pid 884009:tid 884013] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqxKaHUf6J8d3elJRnwAA3AI"]
[Mon Jul 20 06:20:59.960922 2026] [security2:error] [pid 884009:tid 884228] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqxKaHUf6J8d3elJRnwAA3AI"]
[Mon Jul 20 06:21:00.358251 2026] [security2:error] [pid 884009:tid 884223] [client 57.141.18.95:58800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQpAAA13w"]
[Mon Jul 20 06:21:00.494135 2026] [security2:error] [pid 884009:tid 884193] [client 57.141.18.106:31852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQvgAAuXQ"]
[Mon Jul 20 06:21:00.535099 2026] [security2:error] [pid 884009:tid 884011] [remote 97.74.87.194:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SrBKaHUf6J8d3elJR0wAA0AA"]
[Mon Jul 20 06:21:00.576700 2026] [security2:error] [pid 884009:tid 884251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJRvwAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:00.595038 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.62:57671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/bless2.php"] [unique_id "al4SrBKaHUf6J8d3elJR1QAAAME"]
[Mon Jul 20 06:21:00.612210 2026] [security2:error] [pid 884009:tid 884153] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJRzQAAAJI"]
[Mon Jul 20 06:21:00.625038 2026] [security2:error] [pid 884009:tid 884172] [client 14.225.17.146:55288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJR0gAAAKQ"], referer: http://ncsynchro.com/Wp
[Mon Jul 20 06:21:00.936467 2026] [security2:error] [pid 884009:tid 884040] [remote 97.74.87.194:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SrBKaHUf6J8d3elJR6QAA0h0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:01.134546 2026] [security2:error] [pid 884009:tid 884216] [client 77.110.127.138:60809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4SrRKaHUf6J8d3elJR8wAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:01.153411 2026] [security2:error] [pid 884009:tid 884051] [remote 57.141.18.67:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4SrRKaHUf6J8d3elJR9QAA4Sg"]
[Mon Jul 20 06:21:01.182703 2026] [core:error] [pid 884009:tid 884147] [client 14.225.17.146:55325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wp
[Mon Jul 20 06:21:01.182729 2026] [core:error] [pid 884009:tid 884147] [client 14.225.17.146:55325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wp
[Mon Jul 20 06:21:01.526678 2026] [security2:error] [pid 884009:tid 884147] [client 98.159.234.160:20027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SrRKaHUf6J8d3elJSDQAAAIw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:01.762210 2026] [security2:error] [pid 884009:tid 884180] [client 14.182.195.220:52135] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SrRKaHUf6J8d3elJSGwAAAKw"]
[Mon Jul 20 06:21:02.057478 2026] [security2:error] [pid 884009:tid 884173] [client 114.119.134.79:40903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nevelow.com"] [uri "/managing-health-care/"] [unique_id "al4SrhKaHUf6J8d3elJSNwAAAKU"], referer: https://nevelow.com/category/launching/
[Mon Jul 20 06:21:02.202412 2026] [security2:error] [pid 884009:tid 884187] [client 185.132.186.100:42421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/about.php"] [unique_id "al4SrhKaHUf6J8d3elJSRAAAALM"]
[Mon Jul 20 06:21:02.278274 2026] [security2:error] [pid 884009:tid 884183] [client 50.116.65.227:59536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4SrhKaHUf6J8d3elJSSgAAAK8"]
[Mon Jul 20 06:21:02.281481 2026] [security2:error] [pid 884009:tid 884265] [client 14.225.17.146:55252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJR4QAAAQE"]
[Mon Jul 20 06:21:02.463011 2026] [security2:error] [pid 884009:tid 884195] [client 57.141.18.91:64084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRUwAAu1w"]
[Mon Jul 20 06:21:02.524850 2026] [security2:error] [pid 884009:tid 884224] [client 45.95.169.104:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SrhKaHUf6J8d3elJSZgAAANg"]
[Mon Jul 20 06:21:02.680003 2026] [security2:error] [pid 884009:tid 884247] [client 104.234.53.57:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SrhKaHUf6J8d3elJSeQAAAO8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:02.951425 2026] [security2:error] [pid 884009:tid 884160] [client 14.225.17.146:55306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4SrRKaHUf6J8d3elJR9AAAAJk"], referer: http://superiorcopywriting.com/Wp
[Mon Jul 20 06:21:03.024401 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:58415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSjwAAAME"]
[Mon Jul 20 06:21:03.024548 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:58415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSjwAAAME"]
[Mon Jul 20 06:21:03.063017 2026] [security2:error] [pid 884009:tid 884228] [client 50.116.65.227:59548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SrxKaHUf6J8d3elJSkAAAANw"]
[Mon Jul 20 06:21:03.075025 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:47386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SrxKaHUf6J8d3elJSkwAAAMw"]
[Mon Jul 20 06:21:03.143897 2026] [security2:error] [pid 884009:tid 884214] [client 112.208.70.94:42983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSlgAAAM4"]
[Mon Jul 20 06:21:03.144062 2026] [security2:error] [pid 884009:tid 884214] [client 112.208.70.94:42983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSlgAAAM4"]
[Mon Jul 20 06:21:03.578513 2026] [security2:error] [pid 884009:tid 884201] [client 114.119.141.100:63345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4SrxKaHUf6J8d3elJSvQAAAME"], referer: https://newstral.com/en/article/en/1132411982/drug-use-leads-to-bowen-man-s-crime
[Mon Jul 20 06:21:03.814356 2026] [security2:error] [pid 884009:tid 884174] [client 185.132.186.83:36579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/item.php"] [unique_id "al4SrxKaHUf6J8d3elJSzwAAAKY"]
[Mon Jul 20 06:21:03.923950 2026] [security2:error] [pid 884009:tid 884183] [client 27.96.94.195:37155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJS2wAAAK8"]
[Mon Jul 20 06:21:03.924061 2026] [security2:error] [pid 884009:tid 884183] [client 27.96.94.195:37155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJS2wAAAK8"]
[Mon Jul 20 06:21:04.246348 2026] [security2:error] [pid 884009:tid 884266] [client 45.116.69.230:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS8AAAAQI"]
[Mon Jul 20 06:21:04.246453 2026] [security2:error] [pid 884009:tid 884266] [client 45.116.69.230:50326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS8AAAAQI"]
[Mon Jul 20 06:21:04.301622 2026] [security2:error] [pid 884009:tid 884149] [client 103.141.108.143:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS9QAAAI4"]
[Mon Jul 20 06:21:04.302588 2026] [security2:error] [pid 884009:tid 884149] [client 103.141.108.143:51304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS9QAAAI4"]
[Mon Jul 20 06:21:04.505045 2026] [security2:error] [pid 884009:tid 884237] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SsBKaHUf6J8d3elJS9AAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:04.635897 2026] [security2:error] [pid 884009:tid 884182] [client 114.119.153.53:21707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bruceledewitz.com"] [uri "/history-and-reason-reveal-truth-and-that-is-why-politics-is-not-war/"] [unique_id "al4SsBKaHUf6J8d3elJTEgAAAK4"], referer: https://bruceledewitz.com/blog/
[Mon Jul 20 06:21:04.650355 2026] [security2:error] [pid 884009:tid 884132] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTFAAAjXk"]
[Mon Jul 20 06:21:04.650678 2026] [security2:error] [pid 884009:tid 884148] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTFAAAjXk"]
[Mon Jul 20 06:21:04.711697 2026] [security2:error] [pid 884009:tid 884243] [client 181.224.94.124:17093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTGgAAAOs"]
[Mon Jul 20 06:21:04.711834 2026] [security2:error] [pid 884009:tid 884243] [client 181.224.94.124:17093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTGgAAAOs"]
[Mon Jul 20 06:21:04.718148 2026] [security2:error] [pid 884009:tid 884186] [client 77.110.127.138:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpfkQABJaS'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4SsBKaHUf6J8d3elJTGwAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:04.917660 2026] [security2:error] [pid 884009:tid 884232] [client 34.73.38.214:63250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SsBKaHUf6J8d3elJTKQAAAOA"]
[Mon Jul 20 06:21:05.072603 2026] [security2:error] [pid 884009:tid 884226] [client 34.73.38.214:54966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTMQAAANo"]
[Mon Jul 20 06:21:05.213516 2026] [security2:error] [pid 884009:tid 884242] [client 34.73.38.214:56991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTPAAAAOo"]
[Mon Jul 20 06:21:05.330699 2026] [security2:error] [pid 884009:tid 884239] [client 34.73.38.214:59706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTRgAAAOc"]
[Mon Jul 20 06:21:05.367967 2026] [security2:error] [pid 884009:tid 884018] [remote 156.59.198.135:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/menu/wp-content/uploads/2026/03/Aosta-lunch-MAR26.pdf"] [unique_id "al4SsRKaHUf6J8d3elJTRwAAlwc"]
[Mon Jul 20 06:21:05.389322 2026] [security2:error] [pid 884009:tid 884203] [client 57.141.18.59:59884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SrRKaHUf6J8d3elJSNQAAwwM"]
[Mon Jul 20 06:21:05.427744 2026] [security2:error] [pid 884009:tid 884191] [client 185.132.186.103:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Engine/theme.php"] [unique_id "al4SsRKaHUf6J8d3elJTTwAAALc"]
[Mon Jul 20 06:21:05.438308 2026] [security2:error] [pid 884009:tid 884170] [client 34.73.38.214:61428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTUQAAAKI"]
[Mon Jul 20 06:21:05.457233 2026] [security2:error] [pid 884009:tid 884268] [client 57.141.18.48:28300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SrhKaHUf6J8d3elJSNgABBBY"]
[Mon Jul 20 06:21:05.597406 2026] [security2:error] [pid 884009:tid 884265] [client 34.73.38.214:63220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTZgAAAQE"]
[Mon Jul 20 06:21:05.704873 2026] [security2:error] [pid 884009:tid 884223] [client 34.73.38.214:65059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTagAAANc"]
[Mon Jul 20 06:21:05.730894 2026] [security2:error] [pid 884009:tid 884253] [client 54.162.148.64:23042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.148.162.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SsRKaHUf6J8d3elJTaQAAAPU"]
[Mon Jul 20 06:21:05.845121 2026] [security2:error] [pid 884009:tid 884231] [client 34.73.38.214:51026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTdAAAAN8"]
[Mon Jul 20 06:21:05.962000 2026] [security2:error] [pid 884009:tid 884191] [client 34.73.38.214:54273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTggAAALc"]
[Mon Jul 20 06:21:05.980329 2026] [security2:error] [pid 884009:tid 884201] [client 34.73.38.214:61610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTgwAAAME"]
[Mon Jul 20 06:21:06.109882 2026] [security2:error] [pid 884009:tid 884176] [client 34.73.38.214:56793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTkAAAAKg"]
[Mon Jul 20 06:21:06.159647 2026] [security2:error] [pid 884009:tid 884259] [client 34.201.171.57:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.171.201.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SshKaHUf6J8d3elJTjwAAAPs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:21:06.268137 2026] [security2:error] [pid 884009:tid 884215] [client 34.73.38.214:60987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTmwAAAM8"]
[Mon Jul 20 06:21:06.300769 2026] [security2:error] [pid 884009:tid 884209] [client 57.141.18.65:39830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SrxKaHUf6J8d3elJSjgAAyS0"]
[Mon Jul 20 06:21:06.428370 2026] [security2:error] [pid 884009:tid 884194] [client 34.73.38.214:63639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTrwAAALo"]
[Mon Jul 20 06:21:06.518258 2026] [security2:error] [pid 884009:tid 884230] [client 50.116.65.227:59558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SshKaHUf6J8d3elJTtgAAAN4"]
[Mon Jul 20 06:21:06.529710 2026] [security2:error] [pid 884009:tid 884217] [client 50.116.65.227:47398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SshKaHUf6J8d3elJTuAAAANE"]
[Mon Jul 20 06:21:06.545376 2026] [security2:error] [pid 884009:tid 884149] [client 34.73.38.214:49863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTugAAAI4"]
[Mon Jul 20 06:21:06.560390 2026] [security2:error] [pid 884009:tid 884239] [client 114.119.159.26:24699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jvcmotorsports.com"] [uri "/cart/"] [unique_id "al4SshKaHUf6J8d3elJTvAAAAOc"], referer: https://jvcmotorsports.com?action=yith-woocompare-add-product&id=5646
[Mon Jul 20 06:21:06.658009 2026] [security2:error] [pid 884009:tid 884259] [client 34.73.38.214:53371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTvwAAAPs"]
[Mon Jul 20 06:21:06.796024 2026] [security2:error] [pid 884009:tid 884143] [client 34.73.38.214:55948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTxQAAAIg"]
[Mon Jul 20 06:21:06.933356 2026] [security2:error] [pid 884009:tid 884174] [client 34.73.38.214:60748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJT1QAAAKY"]
[Mon Jul 20 06:21:07.039261 2026] [security2:error] [pid 884009:tid 884260] [client 104.234.53.76:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SsxKaHUf6J8d3elJT3wAAAPw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:07.049869 2026] [security2:error] [pid 884009:tid 884253] [client 185.132.186.90:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/mah.php"] [unique_id "al4SsxKaHUf6J8d3elJT4AAAAPU"]
[Mon Jul 20 06:21:07.050627 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:63064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SsxKaHUf6J8d3elJT4gAAAQQ"]
[Mon Jul 20 06:21:07.124182 2026] [security2:error] [pid 884009:tid 884218] [client 14.225.17.146:54571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4SsRKaHUf6J8d3elJTTAAAANI"], referer: http://nomorewetsheets.net/Wp
[Mon Jul 20 06:21:07.178135 2026] [security2:error] [pid 884009:tid 884251] [client 14.225.17.146:49321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJT5gAAAPM"], referer: http://musichaven.info/Wp
[Mon Jul 20 06:21:07.180673 2026] [security2:error] [pid 884009:tid 884186] [client 34.73.38.214:50734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SsxKaHUf6J8d3elJT7QAAALI"]
[Mon Jul 20 06:21:07.296481 2026] [security2:error] [pid 884009:tid 884144] [client 34.73.38.214:55144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SsxKaHUf6J8d3elJT8wAAAIk"]
[Mon Jul 20 06:21:07.299707 2026] [security2:error] [pid 884009:tid 884058] [remote 57.141.18.113:62136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3831221"] [unique_id "al4SsxKaHUf6J8d3elJT9AAA6S8"]
[Mon Jul 20 06:21:07.300966 2026] [security2:error] [pid 884009:tid 884171] [client 57.141.18.4:20606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SsBKaHUf6J8d3elJS7AAAo0U"]
[Mon Jul 20 06:21:07.337282 2026] [security2:error] [pid 884009:tid 884262] [client 171.61.165.146:19904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsxKaHUf6J8d3elJT9gAAAP4"]
[Mon Jul 20 06:21:07.338521 2026] [security2:error] [pid 884009:tid 884262] [client 171.61.165.146:19904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsxKaHUf6J8d3elJT9gAAAP4"]
[Mon Jul 20 06:21:07.383975 2026] [security2:error] [pid 884009:tid 884191] [client 14.225.17.146:57570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJT6QAAALc"]
[Mon Jul 20 06:21:07.901554 2026] [security2:error] [pid 884009:tid 884163] [client 104.234.53.71:29999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SsxKaHUf6J8d3elJULAAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:08.086071 2026] [security2:error] [pid 884009:tid 884214] [client 14.225.17.146:54690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUOwAAAM4"], referer: https://musichaven.info/Wp
[Mon Jul 20 06:21:08.313907 2026] [security2:error] [pid 884009:tid 884168] [client 41.173.37.102:7623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4StBKaHUf6J8d3elJUWQAAAKE"]
[Mon Jul 20 06:21:08.314042 2026] [security2:error] [pid 884009:tid 884168] [client 41.173.37.102:7623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4StBKaHUf6J8d3elJUWQAAAKE"]
[Mon Jul 20 06:21:08.549380 2026] [security2:error] [pid 884009:tid 884208] [client 57.141.18.120:51846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SsRKaHUf6J8d3elJTSQAAyC4"]
[Mon Jul 20 06:21:08.654177 2026] [security2:error] [pid 884009:tid 884152] [client 185.132.186.103:57029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/shell.php"] [unique_id "al4StBKaHUf6J8d3elJUdgAAAJE"]
[Mon Jul 20 06:21:09.076401 2026] [security2:error] [pid 884009:tid 884172] [client 104.234.53.52:58809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4StRKaHUf6J8d3elJUngAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:09.105033 2026] [security2:error] [pid 884009:tid 884162] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUhgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:09.200036 2026] [security2:error] [pid 884009:tid 884215] [client 50.116.65.227:24666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StRKaHUf6J8d3elJUpwAAAM8"]
[Mon Jul 20 06:21:09.200771 2026] [security2:error] [pid 884009:tid 884185] [client 50.116.65.227:24684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StRKaHUf6J8d3elJUqQAAALE"]
[Mon Jul 20 06:21:09.200772 2026] [security2:error] [pid 884009:tid 884254] [client 50.116.65.227:24668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StRKaHUf6J8d3elJUqAAAAPY"]
[Mon Jul 20 06:21:09.205849 2026] [security2:error] [pid 884009:tid 884239] [client 124.156.119.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUGgAAAOc"]
[Mon Jul 20 06:21:09.206582 2026] [security2:error] [pid 884009:tid 884209] [client 43.173.78.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUBwAAAMk"]
[Mon Jul 20 06:21:09.206899 2026] [security2:error] [pid 884009:tid 884220] [client 43.156.21.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUHwAAANQ"]
[Mon Jul 20 06:21:09.232614 2026] [security2:error] [pid 884009:tid 884157] [client 124.156.160.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUNwAAAJY"]
[Mon Jul 20 06:21:09.232914 2026] [security2:error] [pid 884009:tid 884205] [client 43.173.73.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUJgAAAMU"]
[Mon Jul 20 06:21:09.232914 2026] [security2:error] [pid 884009:tid 884260] [client 43.134.185.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUPwAAAPw"]
[Mon Jul 20 06:21:09.316124 2026] [security2:error] [pid 884009:tid 884170] [client 77.110.127.138:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpUVvV1ePP'%20OR%20635=(SELECT%20635%20FROM%20PG_SLEEP(15))--"] [unique_id "al4StRKaHUf6J8d3elJUsQAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:09.433464 2026] [security2:error] [pid 884009:tid 884224] [client 14.225.17.146:54456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUbwAAANg"]
[Mon Jul 20 06:21:09.568727 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:55689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4StRKaHUf6J8d3elJUsgAAAJo"], referer: http://soloceos.com/Wp
[Mon Jul 20 06:21:09.813099 2026] [security2:error] [pid 884009:tid 884265] [client 45.157.112.60:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4StRKaHUf6J8d3elJU0QAAAQE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:09.820808 2026] [security2:error] [pid 884009:tid 884215] [client 4.194.217.15:7469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/nine2code.php"] [unique_id "al4StRKaHUf6J8d3elJU0gAAAM8"]
[Mon Jul 20 06:21:10.021051 2026] [security2:error] [pid 884009:tid 884221] [client 57.141.18.4:47294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SshKaHUf6J8d3elJTzAAA1Ro"]
[Mon Jul 20 06:21:10.094020 2026] [security2:error] [pid 884009:tid 884187] [client 14.225.17.146:65307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4StRKaHUf6J8d3elJUwQAAALM"]
[Mon Jul 20 06:21:10.269874 2026] [security2:error] [pid 884009:tid 884260] [client 185.132.186.75:37185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh-library.php"] [unique_id "al4SthKaHUf6J8d3elJU_wAAAPw"]
[Mon Jul 20 06:21:10.363812 2026] [security2:error] [pid 884009:tid 884164] [client 57.141.18.7:41118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJT7AAAnR8"]
[Mon Jul 20 06:21:10.392998 2026] [security2:error] [pid 884009:tid 884176] [client 4.194.217.15:12008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/num.php"] [unique_id "al4SthKaHUf6J8d3elJVBwAAAKg"]
[Mon Jul 20 06:21:10.400854 2026] [core:error] [pid 884009:tid 884174] [client 205.210.31.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:10.400876 2026] [core:error] [pid 884009:tid 884174] [client 205.210.31.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:10.432822 2026] [security2:error] [pid 884009:tid 884061] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SthKaHUf6J8d3elJVDgAAzDI"]
[Mon Jul 20 06:21:10.433025 2026] [security2:error] [pid 884009:tid 884212] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SthKaHUf6J8d3elJVDgAAzDI"]
[Mon Jul 20 06:21:10.445622 2026] [security2:error] [pid 884009:tid 884254] [client 14.225.17.146:55469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4SthKaHUf6J8d3elJU9wAAAPY"]
[Mon Jul 20 06:21:10.464238 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:58036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SthKaHUf6J8d3elJVEgAAAOw"]
[Mon Jul 20 06:21:10.476284 2026] [security2:error] [pid 884009:tid 884258] [client 50.116.65.227:58040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SthKaHUf6J8d3elJVFgAAAPo"]
[Mon Jul 20 06:21:10.943988 2026] [security2:error] [pid 884009:tid 884205] [client 4.194.217.15:11995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4SthKaHUf6J8d3elJVPQAAAMU"]
[Mon Jul 20 06:21:11.174179 2026] [security2:error] [pid 884009:tid 884195] [client 50.116.65.227:24686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StxKaHUf6J8d3elJVYgAAALs"]
[Mon Jul 20 06:21:11.177625 2026] [security2:error] [pid 884009:tid 884200] [client 43.173.74.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVUQAAAMA"]
[Mon Jul 20 06:21:11.179608 2026] [security2:error] [pid 884009:tid 884168] [client 101.32.14.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVVQAAAKE"]
[Mon Jul 20 06:21:11.209557 2026] [security2:error] [pid 884009:tid 884177] [client 43.134.142.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVWQAAAKk"]
[Mon Jul 20 06:21:11.318716 2026] [security2:error] [pid 884009:tid 884145] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVYwAAAIo"]
[Mon Jul 20 06:21:11.486031 2026] [security2:error] [pid 884009:tid 884154] [client 4.194.217.15:7427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/option.php"] [unique_id "al4StxKaHUf6J8d3elJVewAAAJM"]
[Mon Jul 20 06:21:11.619093 2026] [security2:error] [pid 884009:tid 884150] [client 57.141.18.39:54377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUZQAAjx4"]
[Mon Jul 20 06:21:11.885426 2026] [security2:error] [pid 884009:tid 884202] [client 185.132.186.62:61311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ms-users.php"] [unique_id "al4StxKaHUf6J8d3elJVlwAAAMI"]
[Mon Jul 20 06:21:11.965707 2026] [security2:error] [pid 884009:tid 884223] [client 14.225.17.146:63641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVhgAAANc"], referer: http://securingmemories.com/Wp
[Mon Jul 20 06:21:12.044806 2026] [security2:error] [pid 884009:tid 884175] [client 4.194.217.15:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/p.php"] [unique_id "al4SuBKaHUf6J8d3elJVqQAAAKc"]
[Mon Jul 20 06:21:12.586790 2026] [security2:error] [pid 884009:tid 884238] [client 4.194.217.15:12600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/past.php"] [unique_id "al4SuBKaHUf6J8d3elJV0QAAAOY"]
[Mon Jul 20 06:21:12.625183 2026] [security2:error] [pid 884009:tid 884190] [client 14.225.17.146:58188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJVwAAAALY"]
[Mon Jul 20 06:21:12.699623 2026] [security2:error] [pid 884009:tid 884104] [remote 51.79.215.219:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4SuBKaHUf6J8d3elJV0wAApl0"]
[Mon Jul 20 06:21:13.155899 2026] [security2:error] [pid 884009:tid 884113] [remote 51.79.215.219:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4SuRKaHUf6J8d3elJV-QAAp2Y"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:21:13.172561 2026] [autoindex:error] [pid 884009:tid 884226] [client 147.93.171.185:63379] AH01276: Cannot serve directory /home1/aberball/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:21:13.176292 2026] [security2:error] [pid 884009:tid 884220] [client 4.194.217.15:12599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/php.php"] [unique_id "al4SuRKaHUf6J8d3elJV-gAAANQ"]
[Mon Jul 20 06:21:13.325882 2026] [fcgid:warn] [pid 884009:tid 884213] (70014)End of file found: [client 66.132.172.131:16214] mod_fcgid: can't get data from http client
[Mon Jul 20 06:21:13.369135 2026] [security2:error] [pid 884009:tid 884154] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJV-AAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:13.508399 2026] [security2:error] [pid 884009:tid 884236] [client 185.132.186.83:24549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/cc.php"] [unique_id "al4SuRKaHUf6J8d3elJWCgAAAOQ"]
[Mon Jul 20 06:21:13.578642 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpYCtJrgIc')%20OR%20518=(SELECT%20518%20FROM%20PG_SLEEP(15))--"] [unique_id "al4SuRKaHUf6J8d3elJWEwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:13.591570 2026] [security2:error] [pid 884009:tid 884148] [client 171.60.139.123:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SuRKaHUf6J8d3elJWFwAAAI0"]
[Mon Jul 20 06:21:13.591684 2026] [security2:error] [pid 884009:tid 884148] [client 171.60.139.123:58928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SuRKaHUf6J8d3elJWFwAAAI0"]
[Mon Jul 20 06:21:13.740212 2026] [security2:error] [pid 884009:tid 884267] [client 4.194.217.15:12019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/php8.php"] [unique_id "al4SuRKaHUf6J8d3elJWHwAAAQM"]
[Mon Jul 20 06:21:13.776945 2026] [autoindex:error] [pid 884009:tid 884175] [client 66.132.172.131:16224] AH01276: Cannot serve directory /home4/gpmvvomy/funnels.allandbeckson.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:21:14.149728 2026] [security2:error] [pid 884009:tid 884173] [client 57.141.18.111:24302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVWAAApVw"]
[Mon Jul 20 06:21:14.159824 2026] [security2:error] [pid 884009:tid 884246] [client 14.225.17.146:63584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWRAAAAO4"], referer: http://claysharecon.com/Wp
[Mon Jul 20 06:21:14.199778 2026] [security2:error] [pid 884009:tid 884153] [client 14.225.17.146:58130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJVtAAAAJI"], referer: http://outlookturf.com/Wp
[Mon Jul 20 06:21:14.320516 2026] [security2:error] [pid 884009:tid 884245] [client 4.194.217.15:12585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/phpinfo.php"] [unique_id "al4SuhKaHUf6J8d3elJWVAAAAO0"]
[Mon Jul 20 06:21:14.341293 2026] [security2:error] [pid 884009:tid 884188] [client 14.225.17.146:58265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJV5AAAALQ"], referer: http://detroitcsc.com/Wp
[Mon Jul 20 06:21:14.640039 2026] [security2:error] [pid 884009:tid 884209] [client 45.95.169.104:57516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWWwAAAMk"]
[Mon Jul 20 06:21:14.724204 2026] [core:error] [pid 884009:tid 884220] [client 103.153.183.69:4102] AH10244: invalid URI path (/%2e%2e/etc/passwd?_=2tiol3ps&v=epb6f), referer: https://twitter.com/
[Mon Jul 20 06:21:14.727443 2026] [security2:error] [pid 884009:tid 884153] [client 127.0.0.1:20248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4SuhKaHUf6J8d3elJWaQAAAJI"], referer: https://twitter.com/
[Mon Jul 20 06:21:14.749219 2026] [security2:error] [pid 884009:tid 884154] [client 104.234.53.72:40397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWbAAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:14.787825 2026] [security2:error] [pid 884009:tid 884178] [client 45.116.69.230:50865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SuhKaHUf6J8d3elJWcgAAAKo"]
[Mon Jul 20 06:21:14.787972 2026] [security2:error] [pid 884009:tid 884178] [client 45.116.69.230:50865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SuhKaHUf6J8d3elJWcgAAAKo"]
[Mon Jul 20 06:21:14.833101 2026] [security2:error] [pid 884009:tid 884163] [client 57.141.18.63:23322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVhQAAnCs"]
[Mon Jul 20 06:21:15.034834 2026] [security2:error] [pid 884009:tid 884247] [client 27.96.94.195:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjAAAAO8"]
[Mon Jul 20 06:21:15.034963 2026] [security2:error] [pid 884009:tid 884247] [client 27.96.94.195:37552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjAAAAO8"]
[Mon Jul 20 06:21:15.041596 2026] [security2:error] [pid 884009:tid 884187] [client 14.225.17.146:65174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJV6QAAALM"], referer: http://itdynamix.com/Wp
[Mon Jul 20 06:21:15.076027 2026] [security2:error] [pid 884009:tid 884208] [client 103.141.108.143:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjwAAAMg"]
[Mon Jul 20 06:21:15.076580 2026] [security2:error] [pid 884009:tid 884180] [client 4.194.217.15:11973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/post.php"] [unique_id "al4SuxKaHUf6J8d3elJWkAAAAKw"]
[Mon Jul 20 06:21:15.076854 2026] [security2:error] [pid 884009:tid 884208] [client 103.141.108.143:51793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjwAAAMg"]
[Mon Jul 20 06:21:15.167200 2026] [security2:error] [pid 884009:tid 884234] [client 185.132.186.94:29989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Requests/library/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJWkgAAAOI"]
[Mon Jul 20 06:21:15.236064 2026] [security2:error] [pid 884009:tid 884252] [client 181.224.94.124:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWoAAAAPQ"]
[Mon Jul 20 06:21:15.236245 2026] [security2:error] [pid 884009:tid 884252] [client 181.224.94.124:21476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWoAAAAPQ"]
[Mon Jul 20 06:21:15.330921 2026] [security2:error] [pid 884009:tid 884190] [client 45.95.169.104:57526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJWkQAAALY"]
[Mon Jul 20 06:21:15.411625 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SuxKaHUf6J8d3elJWsgAAAOw"]
[Mon Jul 20 06:21:15.422818 2026] [security2:error] [pid 884009:tid 884228] [client 50.116.65.227:58114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SuxKaHUf6J8d3elJWswAAANw"]
[Mon Jul 20 06:21:15.498414 2026] [security2:error] [pid 884009:tid 884218] [client 103.153.183.69:44380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env"] [unique_id "al4SuxKaHUf6J8d3elJWvAAAANI"], referer: https://twitter.com/
[Mon Jul 20 06:21:15.605872 2026] [security2:error] [pid 884009:tid 884202] [client 45.95.169.104:57540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJWsAAAAMI"]
[Mon Jul 20 06:21:15.642168 2026] [security2:error] [pid 884009:tid 884056] [remote 100.42.189.89:43586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJWxAAA0S0"]
[Mon Jul 20 06:21:15.663266 2026] [security2:error] [pid 884009:tid 884138] [remote 130.185.118.215:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJWyAAAln8"]
[Mon Jul 20 06:21:15.669509 2026] [security2:error] [pid 884009:tid 884159] [client 4.194.217.15:7457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4SuxKaHUf6J8d3elJWywAAAJg"]
[Mon Jul 20 06:21:15.809117 2026] [security2:error] [pid 884009:tid 884194] [client 14.225.17.146:55139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJWzQAAALo"], referer: http://christiancountytrumpet.com/Wp
[Mon Jul 20 06:21:15.838724 2026] [security2:error] [pid 884009:tid 884110] [remote 100.42.189.89:43586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJW4AAAkGM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:21:15.848932 2026] [security2:error] [pid 884009:tid 884039] [remote 130.185.118.215:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJW4QAA_xw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:21:15.854693 2026] [security2:error] [pid 884009:tid 884208] [client 178.152.178.232:36646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJW4gAAAMg"]
[Mon Jul 20 06:21:15.854850 2026] [security2:error] [pid 884009:tid 884208] [client 178.152.178.232:36646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJW4gAAAMg"]
[Mon Jul 20 06:21:15.924836 2026] [security2:error] [pid 884009:tid 884207] [client 45.95.169.104:57546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJW0wAAAMc"]
[Mon Jul 20 06:21:16.055381 2026] [security2:error] [pid 884009:tid 884249] [client 104.234.53.59:59231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SvBKaHUf6J8d3elJW9wAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:16.059540 2026] [security2:error] [pid 884009:tid 884183] [client 14.225.17.146:51004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJW5wAAAK8"], referer: https://itdynamix.com/Wp
[Mon Jul 20 06:21:16.178964 2026] [security2:error] [pid 884009:tid 884150] [client 112.208.70.94:43458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SvBKaHUf6J8d3elJXAQAAAI8"]
[Mon Jul 20 06:21:16.179121 2026] [security2:error] [pid 884009:tid 884150] [client 112.208.70.94:43458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SvBKaHUf6J8d3elJXAQAAAI8"]
[Mon Jul 20 06:21:16.196406 2026] [security2:error] [pid 884009:tid 884210] [client 57.141.18.60:31938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJV6gAAylY"]
[Mon Jul 20 06:21:16.223217 2026] [security2:error] [pid 884009:tid 884168] [client 4.194.217.15:4736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/public/css.php"] [unique_id "al4SvBKaHUf6J8d3elJXBwAAAKE"]
[Mon Jul 20 06:21:16.291297 2026] [security2:error] [pid 884009:tid 884203] [client 57.141.18.41:48610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJV7gAAw04"]
[Mon Jul 20 06:21:16.401254 2026] [security2:error] [pid 884009:tid 884265] [client 14.251.3.155:55713] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SvBKaHUf6J8d3elJXFAAAAQE"]
[Mon Jul 20 06:21:16.451442 2026] [security2:error] [pid 884009:tid 884250] [client 45.95.169.104:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXCQAAAPI"]
[Mon Jul 20 06:21:16.467808 2026] [security2:error] [pid 884009:tid 884263] [client 57.141.18.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXDgAAAP8"]
[Mon Jul 20 06:21:16.650301 2026] [security2:error] [pid 884009:tid 884140] [client 45.95.169.104:57556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXGwAAAIU"]
[Mon Jul 20 06:21:16.764513 2026] [security2:error] [pid 884009:tid 884201] [client 4.194.217.15:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/r.php"] [unique_id "al4SvBKaHUf6J8d3elJXMwAAAME"]
[Mon Jul 20 06:21:16.781360 2026] [security2:error] [pid 884009:tid 884203] [client 185.132.186.65:51199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/interactivity-api/about.php"] [unique_id "al4SvBKaHUf6J8d3elJXNgAAAMM"]
[Mon Jul 20 06:21:17.224894 2026] [security2:error] [pid 884009:tid 884206] [client 57.141.18.95:22660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJWMQAAxk8"]
[Mon Jul 20 06:21:17.244021 2026] [security2:error] [pid 884009:tid 884237] [client 57.141.18.2:40962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJWNwAA5Uc"]
[Mon Jul 20 06:21:17.307111 2026] [security2:error] [pid 884009:tid 884204] [client 4.194.217.15:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/radio.php"] [unique_id "al4SvRKaHUf6J8d3elJXaAAAAMQ"]
[Mon Jul 20 06:21:17.386561 2026] [security2:error] [pid 884009:tid 884194] [client 74.7.227.179:57090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXXgAAunI"], referer: https://tejasenvironmental.com/p=735184
[Mon Jul 20 06:21:17.527427 2026] [security2:error] [pid 884009:tid 884231] [client 45.95.169.104:57562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXaQAAAN8"]
[Mon Jul 20 06:21:17.572970 2026] [security2:error] [pid 884009:tid 884213] [client 45.95.169.104:57598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXawAAAM0"]
[Mon Jul 20 06:21:17.645351 2026] [security2:error] [pid 884009:tid 884196] [client 45.95.169.104:57572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXcwAAALw"]
[Mon Jul 20 06:21:17.669657 2026] [security2:error] [pid 884009:tid 884162] [client 45.95.169.104:57586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXeAAAAJs"]
[Mon Jul 20 06:21:17.682206 2026] [security2:error] [pid 884009:tid 884265] [client 14.225.17.146:65327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXfwAAAQE"], referer: http://getgarrison.com/Wp
[Mon Jul 20 06:21:17.827584 2026] [security2:error] [pid 884009:tid 884191] [client 14.225.17.146:57855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJW8gAAALc"], referer: http://aandarealtygroup.com/Wp
[Mon Jul 20 06:21:17.866576 2026] [security2:error] [pid 884009:tid 884210] [client 57.141.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXhwAAAMo"]
[Mon Jul 20 06:21:17.881527 2026] [security2:error] [pid 884009:tid 884228] [client 4.194.217.15:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/randkeyword.php7"] [unique_id "al4SvRKaHUf6J8d3elJXlgAAANw"]
[Mon Jul 20 06:21:17.882829 2026] [security2:error] [pid 884009:tid 884160] [client 45.95.169.104:57606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXhQAAAJk"]
[Mon Jul 20 06:21:18.063191 2026] [security2:error] [pid 884009:tid 884158] [client 14.225.17.146:58026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXKgAAAJc"], referer: http://alaraycreative.com/Wp
[Mon Jul 20 06:21:18.250783 2026] [security2:error] [pid 884009:tid 884166] [client 57.141.18.109:24450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWcQAAnx0"]
[Mon Jul 20 06:21:18.288065 2026] [security2:error] [pid 884009:tid 884164] [client 171.61.165.146:15500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJXwQAAAJ0"]
[Mon Jul 20 06:21:18.288238 2026] [security2:error] [pid 884009:tid 884164] [client 171.61.165.146:15500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJXwQAAAJ0"]
[Mon Jul 20 06:21:18.301626 2026] [security2:error] [pid 884009:tid 884185] [client 57.141.18.22:27834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWdwAAsXo"]
[Mon Jul 20 06:21:18.418880 2026] [security2:error] [pid 884009:tid 884174] [client 185.132.186.64:45567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/file.php"] [unique_id "al4SvhKaHUf6J8d3elJXzAAAAKY"]
[Mon Jul 20 06:21:18.473766 2026] [security2:error] [pid 884009:tid 884157] [client 4.194.217.15:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/readme.php"] [unique_id "al4SvhKaHUf6J8d3elJX0QAAAJY"]
[Mon Jul 20 06:21:18.808348 2026] [security2:error] [pid 884009:tid 884015] [remote 147.50.252.213:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SvhKaHUf6J8d3elJX7AAAswQ"]
[Mon Jul 20 06:21:18.934144 2026] [security2:error] [pid 884009:tid 884221] [client 41.173.37.102:8036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJX-QAAANU"]
[Mon Jul 20 06:21:18.934222 2026] [security2:error] [pid 884009:tid 884221] [client 41.173.37.102:8036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJX-QAAANU"]
[Mon Jul 20 06:21:19.025332 2026] [security2:error] [pid 884009:tid 884189] [client 4.194.217.15:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/reze.php"] [unique_id "al4SvxKaHUf6J8d3elJYCAAAALU"]
[Mon Jul 20 06:21:19.269575 2026] [security2:error] [pid 884009:tid 884180] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/deploy/.ssh/id_rsa"] [unique_id "al4SvxKaHUf6J8d3elJYKQAAAKw"], referer: https://www.google.com/
[Mon Jul 20 06:21:19.297940 2026] [security2:error] [pid 884009:tid 884238] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4SvxKaHUf6J8d3elJYKgAAAOY"], referer: https://www.reddit.com/
[Mon Jul 20 06:21:19.316374 2026] [security2:error] [pid 884009:tid 884101] [remote 147.50.252.213:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SvxKaHUf6J8d3elJYKwAAjVo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:21:19.325768 2026] [security2:error] [pid 884009:tid 884261] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/www-data/.ssh/id_rsa"] [unique_id "al4SvxKaHUf6J8d3elJYLAAAAP0"], referer: https://t.co/arq0ebe4k3
[Mon Jul 20 06:21:19.443819 2026] [security2:error] [pid 884009:tid 884215] [client 82.102.18.116:56076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4SvxKaHUf6J8d3elJYOAAAAM8"]
[Mon Jul 20 06:21:19.570265 2026] [security2:error] [pid 884009:tid 884144] [client 4.194.217.15:9274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/rh.php"] [unique_id "al4SvxKaHUf6J8d3elJYRAAAAIk"]
[Mon Jul 20 06:21:19.640631 2026] [security2:error] [pid 884009:tid 884156] [client 93.152.221.118:49356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4SvxKaHUf6J8d3elJYSgAAAJU"]
[Mon Jul 20 06:21:19.694251 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.81:38572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXFgAA0xg"]
[Mon Jul 20 06:21:19.768854 2026] [security2:error] [pid 884009:tid 884196] [client 82.102.18.116:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.southernswinggolfco.com"] [uri "/xmlrpc.php"] [unique_id "al4SvxKaHUf6J8d3elJYWwAAALw"]
[Mon Jul 20 06:21:19.783409 2026] [security2:error] [pid 884009:tid 884176] [client 50.116.65.227:20958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SvxKaHUf6J8d3elJYXAAAAKg"]
[Mon Jul 20 06:21:19.795561 2026] [security2:error] [pid 884009:tid 884249] [client 50.116.65.227:20960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SvxKaHUf6J8d3elJYXQAAAPE"]
[Mon Jul 20 06:21:19.973823 2026] [security2:error] [pid 884009:tid 884242] [client 57.141.18.43:41922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXMgAA6j4"]
[Mon Jul 20 06:21:20.015122 2026] [security2:error] [pid 884009:tid 884172] [client 93.152.221.118:49786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4SwBKaHUf6J8d3elJYdQAAAKQ"]
[Mon Jul 20 06:21:20.033997 2026] [security2:error] [pid 884009:tid 884268] [client 185.132.186.79:55111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/classic-editor/alam.php"] [unique_id "al4SwBKaHUf6J8d3elJYeAAAAQQ"]
[Mon Jul 20 06:21:20.114392 2026] [security2:error] [pid 884009:tid 884159] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYaAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:20.181191 2026] [security2:error] [pid 884009:tid 884222] [client 4.194.217.15:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/rip.php"] [unique_id "al4SwBKaHUf6J8d3elJYhgAAANY"]
[Mon Jul 20 06:21:20.193899 2026] [security2:error] [pid 884009:tid 884216] [client 14.225.17.146:64055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYGQAAANA"]
[Mon Jul 20 06:21:20.250838 2026] [security2:error] [pid 884009:tid 884143] [client 193.47.62.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYgAAAiCc"], referer: http://nzfoodstory.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:21:20.257943 2026] [security2:error] [pid 884009:tid 884262] [client 82.102.18.116:56084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SwBKaHUf6J8d3elJYiwAAAP4"]
[Mon Jul 20 06:21:20.627179 2026] [security2:error] [pid 884009:tid 884268] [client 82.102.18.116:56094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SwBKaHUf6J8d3elJYqwAAAQQ"]
[Mon Jul 20 06:21:20.739358 2026] [security2:error] [pid 884009:tid 884214] [client 4.194.217.15:1416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/root.php"] [unique_id "al4SwBKaHUf6J8d3elJYtwAAAM4"]
[Mon Jul 20 06:21:20.950795 2026] [security2:error] [pid 884009:tid 884165] [client 82.102.18.116:56106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SwBKaHUf6J8d3elJYywAAAJ4"]
[Mon Jul 20 06:21:21.007361 2026] [security2:error] [pid 884009:tid 884052] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SwRKaHUf6J8d3elJY0gABAik"]
[Mon Jul 20 06:21:21.007519 2026] [security2:error] [pid 884009:tid 884266] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SwRKaHUf6J8d3elJY0gABAik"]
[Mon Jul 20 06:21:21.123971 2026] [core:error] [pid 884009:tid 884268] [client 103.153.183.69:11562] AH10244: invalid URI path (/%2e%2e/.env?_=parirvul&v=sk7vh), referer: https://t.co/unafqwh6am
[Mon Jul 20 06:21:21.168080 2026] [security2:error] [pid 884009:tid 884267] [client 93.152.221.118:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4SwRKaHUf6J8d3elJY3wAAAQM"]
[Mon Jul 20 06:21:21.255132 2026] [security2:error] [pid 884009:tid 884221] [client 14.225.17.146:58414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYSwAAANU"], referer: http://ironcitywellness.com/Wp
[Mon Jul 20 06:21:21.274291 2026] [security2:error] [pid 884009:tid 884156] [client 82.102.18.116:63308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4SwRKaHUf6J8d3elJY7wAAAJU"]
[Mon Jul 20 06:21:21.313095 2026] [security2:error] [pid 884009:tid 884168] [client 4.194.217.15:7450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/s.php"] [unique_id "al4SwRKaHUf6J8d3elJY8gAAAKE"]
[Mon Jul 20 06:21:21.445735 2026] [security2:error] [pid 884009:tid 884149] [client 77.110.127.138:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpHWFmZkzP'))%20OR%20928=(SELECT%20928%20FROM%20PG_SLEEP(15))--"] [unique_id "al4SwRKaHUf6J8d3elJY9QAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:21.611599 2026] [security2:error] [pid 884009:tid 884171] [client 82.102.18.116:56122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SwRKaHUf6J8d3elJZBAAAAKM"]
[Mon Jul 20 06:21:21.652292 2026] [security2:error] [pid 884009:tid 884140] [client 185.132.186.68:63337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wordpress/wp-admin/includes/admin-filters.php"] [unique_id "al4SwRKaHUf6J8d3elJZBwAAAIU"]
[Mon Jul 20 06:21:21.779005 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:65272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYvgAAAIk"], referer: http://retzkolonglogistics.com/Wp
[Mon Jul 20 06:21:21.854206 2026] [security2:error] [pid 884009:tid 884245] [client 4.194.217.15:1437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sang.php"] [unique_id "al4SwRKaHUf6J8d3elJZFgAAAO0"]
[Mon Jul 20 06:21:21.949547 2026] [security2:error] [pid 884009:tid 884206] [client 82.102.18.116:56136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4SwRKaHUf6J8d3elJZHwAAAMY"]
[Mon Jul 20 06:21:22.268238 2026] [security2:error] [pid 884009:tid 884210] [client 82.102.18.116:56138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4SwhKaHUf6J8d3elJZPwAAAMo"]
[Mon Jul 20 06:21:22.331533 2026] [security2:error] [pid 884009:tid 884018] [remote 91.142.222.105:54874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SwhKaHUf6J8d3elJZQwAArwc"]
[Mon Jul 20 06:21:22.331722 2026] [security2:error] [pid 884009:tid 884183] [client 91.142.222.105:54874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SwhKaHUf6J8d3elJZQwAArwc"]
[Mon Jul 20 06:21:22.394261 2026] [security2:error] [pid 884009:tid 884152] [client 57.141.18.103:39018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYDgAAkSY"]
[Mon Jul 20 06:21:22.395647 2026] [security2:error] [pid 884009:tid 884163] [client 4.194.217.15:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/scxy.php"] [unique_id "al4SwhKaHUf6J8d3elJZRwAAAJw"]
[Mon Jul 20 06:21:22.587845 2026] [security2:error] [pid 884009:tid 884242] [client 82.102.18.116:56152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SwhKaHUf6J8d3elJZWQAAAOo"]
[Mon Jul 20 06:21:22.810169 2026] [security2:error] [pid 884009:tid 884186] [client 50.116.65.227:58816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SwhKaHUf6J8d3elJZbAAAALI"]
[Mon Jul 20 06:21:22.821560 2026] [security2:error] [pid 884009:tid 884175] [client 50.116.65.227:20992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SwhKaHUf6J8d3elJZbwAAAKc"]
[Mon Jul 20 06:21:22.901953 2026] [security2:error] [pid 884009:tid 884233] [client 82.102.18.116:56158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SwhKaHUf6J8d3elJZcgAAAOE"]
[Mon Jul 20 06:21:22.974386 2026] [security2:error] [pid 884009:tid 884241] [client 4.194.217.15:7447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sd.php"] [unique_id "al4SwhKaHUf6J8d3elJZdgAAAOk"]
[Mon Jul 20 06:21:23.049677 2026] [security2:error] [pid 884009:tid 884212] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/git/.ssh/id_rsa"] [unique_id "al4SwxKaHUf6J8d3elJZfgAAAMw"], referer: https://t.co/cnk1sjj716
[Mon Jul 20 06:21:23.128422 2026] [security2:error] [pid 884009:tid 884150] [client 57.141.18.14:30440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYYwAAj1Y"]
[Mon Jul 20 06:21:23.198292 2026] [security2:error] [pid 884009:tid 884199] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/admin/.ssh/id_rsa"] [unique_id "al4SwxKaHUf6J8d3elJZjgAAAL8"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:21:23.232684 2026] [security2:error] [pid 884009:tid 884253] [client 82.102.18.116:56174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZkQAAAPU"]
[Mon Jul 20 06:21:23.258030 2026] [security2:error] [pid 884009:tid 884157] [client 185.132.186.96:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/content.php"] [unique_id "al4SwxKaHUf6J8d3elJZlQAAAJY"]
[Mon Jul 20 06:21:23.285006 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.104:27552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYdgAAwTM"]
[Mon Jul 20 06:21:23.317658 2026] [security2:error] [pid 884009:tid 884188] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/passwd"] [unique_id "al4SwxKaHUf6J8d3elJZmwAAALQ"], referer: https://www.bing.com/search?q=pewasl
[Mon Jul 20 06:21:23.428058 2026] [security2:error] [pid 884009:tid 884222] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/shadow"] [unique_id "al4SwxKaHUf6J8d3elJZpgAAANY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:21:23.517717 2026] [security2:error] [pid 884009:tid 884218] [client 4.194.217.15:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sf.php"] [unique_id "al4SwxKaHUf6J8d3elJZsgAAANI"]
[Mon Jul 20 06:21:23.553853 2026] [security2:error] [pid 884009:tid 884236] [client 82.102.18.116:56188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZuAAAAOQ"]
[Mon Jul 20 06:21:23.560315 2026] [security2:error] [pid 884009:tid 884253] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/hosts"] [unique_id "al4SwxKaHUf6J8d3elJZuQAAAPU"], referer: https://www.reddit.com/
[Mon Jul 20 06:21:23.697210 2026] [security2:error] [pid 884009:tid 884168] [client 14.225.17.146:64147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4SwhKaHUf6J8d3elJZOQAAAKE"], referer: http://uritems.net/Wp
[Mon Jul 20 06:21:23.808930 2026] [security2:error] [pid 884009:tid 884266] [client 34.73.38.214:54089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZywAAAQI"]
[Mon Jul 20 06:21:23.870571 2026] [security2:error] [pid 884009:tid 884238] [client 82.102.18.116:56202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZ0QAAAOY"]
[Mon Jul 20 06:21:23.986373 2026] [security2:error] [pid 884009:tid 884183] [client 34.74.185.202:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SwxKaHUf6J8d3elJZ2QAAAK8"]
[Mon Jul 20 06:21:24.031878 2026] [security2:error] [pid 884009:tid 884153] [client 34.73.38.214:49384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJZ3wAAAJI"]
[Mon Jul 20 06:21:24.068653 2026] [security2:error] [pid 884009:tid 884144] [client 4.194.217.15:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/shell.php"] [unique_id "al4SxBKaHUf6J8d3elJZ4gAAAIk"]
[Mon Jul 20 06:21:24.095338 2026] [security2:error] [pid 884009:tid 884173] [client 57.141.18.65:40506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYuAAApTs"]
[Mon Jul 20 06:21:24.123961 2026] [security2:error] [pid 884009:tid 884178] [client 14.225.17.146:58952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4SwhKaHUf6J8d3elJZYwAAAKo"], referer: http://ghivs.com/Wp
[Mon Jul 20 06:21:24.219617 2026] [security2:error] [pid 884009:tid 884185] [client 82.102.18.116:56214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJZ9QAAALE"]
[Mon Jul 20 06:21:24.237920 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:59433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJZ-QAAAME"]
[Mon Jul 20 06:21:24.238012 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:59433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJZ-QAAAME"]
[Mon Jul 20 06:21:24.475088 2026] [security2:error] [pid 884009:tid 884220] [client 34.73.38.214:50230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaDAAAANQ"]
[Mon Jul 20 06:21:24.563301 2026] [security2:error] [pid 884009:tid 884187] [client 14.225.17.146:57500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZkgAAALM"], referer: http://effingweirdmuseums.com/Wp
[Mon Jul 20 06:21:24.563787 2026] [security2:error] [pid 884009:tid 884174] [client 82.102.18.116:56220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaEgAAAKY"]
[Mon Jul 20 06:21:24.721165 2026] [security2:error] [pid 884009:tid 884152] [client 34.73.38.214:52675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaHgAAAJE"]
[Mon Jul 20 06:21:24.799972 2026] [security2:error] [pid 884009:tid 884265] [client 4.194.217.15:1431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sid3.php"] [unique_id "al4SxBKaHUf6J8d3elJaIwAAAQE"]
[Mon Jul 20 06:21:24.807801 2026] [security2:error] [pid 884009:tid 884256] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaEwAA-CQ"], referer: http://assasalnazaha.com/Wp
[Mon Jul 20 06:21:24.870976 2026] [security2:error] [pid 884009:tid 884191] [client 185.132.186.53:23819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/fm.php%20"] [unique_id "al4SxBKaHUf6J8d3elJaLAAAALc"]
[Mon Jul 20 06:21:24.883032 2026] [security2:error] [pid 884009:tid 884234] [client 34.73.38.214:50632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaLgAAAOI"]
[Mon Jul 20 06:21:24.889150 2026] [security2:error] [pid 884009:tid 884254] [client 82.102.18.116:7013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaMQAAAPY"]
[Mon Jul 20 06:21:24.930933 2026] [security2:error] [pid 884009:tid 884223] [client 18.140.64.130:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJaQgAAANc"]
[Mon Jul 20 06:21:24.931034 2026] [security2:error] [pid 884009:tid 884223] [client 18.140.64.130:23998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJaQgAAANc"]
[Mon Jul 20 06:21:25.171270 2026] [security2:error] [pid 884009:tid 884214] [client 34.73.38.214:64018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJafgAAAM4"]
[Mon Jul 20 06:21:25.189389 2026] [security2:error] [pid 884009:tid 884243] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaTQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:25.233384 2026] [security2:error] [pid 884009:tid 884156] [client 14.225.17.146:64198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZxgAAAJU"], referer: http://cephasnext.com/Wp
[Mon Jul 20 06:21:25.240251 2026] [security2:error] [pid 884009:tid 884212] [client 82.102.18.116:56232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJaiAAAAMw"]
[Mon Jul 20 06:21:25.341900 2026] [security2:error] [pid 884009:tid 884232] [client 4.194.217.15:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/simple.php"] [unique_id "al4SxRKaHUf6J8d3elJakwAAAOA"]
[Mon Jul 20 06:21:25.360298 2026] [security2:error] [pid 884009:tid 884202] [client 34.74.185.202:52124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJalQAAAMI"]
[Mon Jul 20 06:21:25.453102 2026] [security2:error] [pid 884009:tid 884159] [client 34.73.38.214:51843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJaoAAAAJg"]
[Mon Jul 20 06:21:25.465459 2026] [security2:error] [pid 884009:tid 884180] [client 57.141.18.112:28778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwhKaHUf6J8d3elJZSAAArBI"]
[Mon Jul 20 06:21:25.495393 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJapQAAALk"]
[Mon Jul 20 06:21:25.495492 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJapQAAALk"]
[Mon Jul 20 06:21:25.517524 2026] [security2:error] [pid 884009:tid 884207] [client 14.225.17.146:58861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJangAAAMc"], referer: https://effingweirdmuseums.com/Wp
[Mon Jul 20 06:21:25.546273 2026] [security2:error] [pid 884009:tid 884025] [remote 67.193.12.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJalAAAow4"], referer: https://www.aleishapenny.ca/
[Mon Jul 20 06:21:25.716164 2026] [security2:error] [pid 884009:tid 884267] [client 34.73.38.214:50084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJasQAAAQM"]
[Mon Jul 20 06:21:25.757144 2026] [security2:error] [pid 884009:tid 884225] [client 181.224.94.124:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJasgAAANk"]
[Mon Jul 20 06:21:25.757313 2026] [security2:error] [pid 884009:tid 884225] [client 181.224.94.124:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJasgAAANk"]
[Mon Jul 20 06:21:25.862981 2026] [security2:error] [pid 884009:tid 884260] [client 103.141.108.143:52265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJatAAAAPw"]
[Mon Jul 20 06:21:25.863109 2026] [security2:error] [pid 884009:tid 884260] [client 103.141.108.143:52265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJatAAAAPw"]
[Mon Jul 20 06:21:25.894217 2026] [security2:error] [pid 884009:tid 884165] [client 4.194.217.15:6903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sitemap.php"] [unique_id "al4SxRKaHUf6J8d3elJauQAAAJ4"]
[Mon Jul 20 06:21:25.943895 2026] [security2:error] [pid 884009:tid 884246] [client 14.225.17.146:58878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJZ-AAAAO4"], referer: http://swafforddetailing.com/Wp
[Mon Jul 20 06:21:25.944535 2026] [security2:error] [pid 884009:tid 884194] [client 34.73.38.214:50729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJavgAAALo"]
[Mon Jul 20 06:21:26.115028 2026] [security2:error] [pid 884009:tid 884147] [client 27.96.94.195:37203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJazgAAAIw"]
[Mon Jul 20 06:21:26.115153 2026] [security2:error] [pid 884009:tid 884147] [client 27.96.94.195:37203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJazgAAAIw"]
[Mon Jul 20 06:21:26.120327 2026] [security2:error] [pid 884009:tid 884078] [remote 91.142.222.105:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJazQAAykM"]
[Mon Jul 20 06:21:26.173209 2026] [security2:error] [pid 884009:tid 884162] [client 57.141.18.24:21320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZfQAAm1o"]
[Mon Jul 20 06:21:26.237957 2026] [security2:error] [pid 884009:tid 884168] [client 34.73.38.214:52502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SxhKaHUf6J8d3elJa2AAAAKE"]
[Mon Jul 20 06:21:26.255359 2026] [security2:error] [pid 884009:tid 884189] [client 14.225.17.146:57446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaJAAAALU"], referer: http://blaizeaccountingservices.com/Wp
[Mon Jul 20 06:21:26.259675 2026] [security2:error] [pid 884009:tid 884172] [client 74.208.214.194:38146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SxhKaHUf6J8d3elJa3QAAAKQ"]
[Mon Jul 20 06:21:26.317041 2026] [security2:error] [pid 884009:tid 884184] [client 57.141.18.32:33282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZiwAAsC0"]
[Mon Jul 20 06:21:26.439141 2026] [security2:error] [pid 884009:tid 884191] [client 4.194.217.15:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/size.php"] [unique_id "al4SxhKaHUf6J8d3elJa6gAAALc"]
[Mon Jul 20 06:21:26.440503 2026] [security2:error] [pid 884009:tid 884104] [remote 91.142.222.105:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJa6QAAul0"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 06:21:26.458822 2026] [security2:error] [pid 884009:tid 884177] [client 93.152.221.118:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grant-mechanical.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJa7wAAAKk"], referer: https://wordpress.org/
[Mon Jul 20 06:21:26.476725 2026] [security2:error] [pid 884009:tid 884158] [client 185.132.186.53:37469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/goods.php"] [unique_id "al4SxhKaHUf6J8d3elJa8AAAAJc"]
[Mon Jul 20 06:21:26.557640 2026] [security2:error] [pid 884009:tid 884166] [client 158.173.89.95:52685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SxhKaHUf6J8d3elJa_wAAAJ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:26.734882 2026] [security2:error] [pid 884009:tid 884141] [client 178.152.178.232:36003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbDgAAAIY"]
[Mon Jul 20 06:21:26.734986 2026] [security2:error] [pid 884009:tid 884141] [client 178.152.178.232:36003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbDgAAAIY"]
[Mon Jul 20 06:21:26.765513 2026] [security2:error] [pid 884009:tid 884263] [client 93.152.221.118:54722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grant-mechanical.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbFgAAAP8"]
[Mon Jul 20 06:21:26.792308 2026] [security2:error] [pid 884009:tid 884069] [remote 188.40.28.4:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbGAAAmzo"]
[Mon Jul 20 06:21:26.792643 2026] [security2:error] [pid 884009:tid 884103] [remote 188.166.241.141:36906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbGgAA9Vw"]
[Mon Jul 20 06:21:26.800256 2026] [security2:error] [pid 884009:tid 884251] [client 14.225.17.146:57478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4SxhKaHUf6J8d3elJa3gAAAPM"], referer: http://gearwaterproof.com/Wp
[Mon Jul 20 06:21:26.839771 2026] [security2:error] [pid 884009:tid 884099] [remote 78.46.157.202:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbHgAAiVg"]
[Mon Jul 20 06:21:26.840103 2026] [security2:error] [pid 884009:tid 884099] [remote 124.55.178.99:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbIQAA7Vg"]
[Mon Jul 20 06:21:26.840215 2026] [security2:error] [pid 884009:tid 884245] [client 124.55.178.99:53376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbIQAA7Vg"]
[Mon Jul 20 06:21:26.845157 2026] [security2:error] [pid 884009:tid 884165] [client 34.74.185.202:56418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SxhKaHUf6J8d3elJbIgAAAJ4"]
[Mon Jul 20 06:21:26.848494 2026] [security2:error] [pid 884009:tid 884081] [remote 20.153.140.50:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbIAAAq0Y"]
[Mon Jul 20 06:21:26.998484 2026] [security2:error] [pid 884009:tid 884100] [remote 188.40.28.4:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbKQAAxVk"], referer: https://crimargroup.com/wp-login.php
[Mon Jul 20 06:21:27.022526 2026] [security2:error] [pid 884009:tid 884185] [client 4.194.217.15:1449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sm.php"] [unique_id "al4SxxKaHUf6J8d3elJbLgAAALE"]
[Mon Jul 20 06:21:27.036563 2026] [security2:error] [pid 884009:tid 884023] [remote 78.46.157.202:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbMwAA3ww"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:21:27.171017 2026] [security2:error] [pid 884009:tid 884172] [client 77.110.127.138:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4SxxKaHUf6J8d3elJbPgAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:27.186343 2026] [security2:error] [pid 884009:tid 884049] [remote 188.166.241.141:36906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbQAAA3iY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:21:27.199408 2026] [security2:error] [pid 884009:tid 884170] [client 104.234.53.79:20903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SxxKaHUf6J8d3elJbOAAAAKI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:27.232030 2026] [security2:error] [pid 884009:tid 884110] [remote 20.153.140.50:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbRwAA5WM"], referer: https://spencersadventures.com/wp-login.php
[Mon Jul 20 06:21:27.391229 2026] [security2:error] [pid 884009:tid 884186] [client 103.153.183.69:11694] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//proc/self/environ"] [unique_id "al4SxxKaHUf6J8d3elJbUwAAALI"], referer: https://www.facebook.com/
[Mon Jul 20 06:21:27.426743 2026] [security2:error] [pid 884009:tid 884218] [client 57.141.18.38:63838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaBgAA0i4"]
[Mon Jul 20 06:21:27.474707 2026] [security2:error] [pid 884009:tid 884236] [client 104.234.53.79:20903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbVwAAAOQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:27.596567 2026] [security2:error] [pid 884009:tid 884250] [client 4.194.217.15:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sql.php"] [unique_id "al4SxxKaHUf6J8d3elJbawAAAPI"]
[Mon Jul 20 06:21:27.705355 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:57362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbZgAAAKk"], referer: http://longevityperformanceclinic.com/Wp
[Mon Jul 20 06:21:27.977231 2026] [security2:error] [pid 884009:tid 884256] [client 34.74.185.202:51843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SxxKaHUf6J8d3elJbfgAAAPg"]
[Mon Jul 20 06:21:28.087410 2026] [security2:error] [pid 884009:tid 884166] [client 185.132.186.103:51337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp-2019.php"] [unique_id "al4SyBKaHUf6J8d3elJbigAAAJ8"]
[Mon Jul 20 06:21:28.113614 2026] [security2:error] [pid 884009:tid 884178] [client 93.152.221.118:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4SyBKaHUf6J8d3elJbkAAAAKo"]
[Mon Jul 20 06:21:28.151355 2026] [security2:error] [pid 884009:tid 884215] [client 4.194.217.15:1444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/ss.php"] [unique_id "al4SyBKaHUf6J8d3elJblwAAAM8"]
[Mon Jul 20 06:21:28.187219 2026] [security2:error] [pid 884009:tid 884163] [client 14.225.17.146:58810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4SyBKaHUf6J8d3elJbjAAAAJw"], referer: http://travelbyfire.com/Wp
[Mon Jul 20 06:21:28.462383 2026] [security2:error] [pid 884009:tid 884265] [client 93.152.221.118:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4SyBKaHUf6J8d3elJbrQAAAQE"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:21:28.505974 2026] [security2:error] [pid 884009:tid 884182] [client 57.141.18.92:35852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJamgAArhE"]
[Mon Jul 20 06:21:28.509959 2026] [security2:error] [pid 884009:tid 884143] [client 57.141.18.109:26820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJamwAAiCA"]
[Mon Jul 20 06:21:28.733699 2026] [security2:error] [pid 884009:tid 884195] [client 4.194.217.15:6887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/stats.php"] [unique_id "al4SyBKaHUf6J8d3elJbxQAAALs"]
[Mon Jul 20 06:21:28.801441 2026] [security2:error] [pid 884009:tid 884180] [client 43.205.139.3:62190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SyBKaHUf6J8d3elJbywAAAKw"]
[Mon Jul 20 06:21:28.801561 2026] [security2:error] [pid 884009:tid 884180] [client 43.205.139.3:62190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SyBKaHUf6J8d3elJbywAAAKw"]
[Mon Jul 20 06:21:28.845065 2026] [security2:error] [pid 884009:tid 884153] [client 34.74.185.202:61879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SyBKaHUf6J8d3elJb0gAAAJI"]
[Mon Jul 20 06:21:29.064104 2026] [security2:error] [pid 884009:tid 884213] [client 14.225.17.146:58923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb3QAAAM0"], referer: https://travelbyfire.com/Wp
[Mon Jul 20 06:21:29.074079 2026] [security2:error] [pid 884009:tid 884207] [client 14.225.17.146:58872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyBKaHUf6J8d3elJb1QAAAMc"], referer: http://fkconstructionfunding.com/Wp
[Mon Jul 20 06:21:29.317454 2026] [security2:error] [pid 884009:tid 884179] [client 4.194.217.15:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sump1.php"] [unique_id "al4SyRKaHUf6J8d3elJb9wAAAKs"]
[Mon Jul 20 06:21:29.356669 2026] [security2:error] [pid 884009:tid 884239] [client 112.208.70.94:43855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_AAAAOc"]
[Mon Jul 20 06:21:29.356796 2026] [security2:error] [pid 884009:tid 884239] [client 112.208.70.94:43855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_AAAAOc"]
[Mon Jul 20 06:21:29.389330 2026] [security2:error] [pid 884009:tid 884166] [client 50.116.65.227:15224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb6gAAAJ8"]
[Mon Jul 20 06:21:29.450035 2026] [security2:error] [pid 884009:tid 884170] [client 171.61.165.146:18762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_wAAAKI"]
[Mon Jul 20 06:21:29.450217 2026] [security2:error] [pid 884009:tid 884170] [client 171.61.165.146:18762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_wAAAKI"]
[Mon Jul 20 06:21:29.502769 2026] [security2:error] [pid 884009:tid 884165] [client 41.173.37.102:8447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJcAgAAAJ4"]
[Mon Jul 20 06:21:29.502914 2026] [security2:error] [pid 884009:tid 884165] [client 41.173.37.102:8447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJcAgAAAJ4"]
[Mon Jul 20 06:21:29.580676 2026] [security2:error] [pid 884009:tid 884184] [client 50.116.65.227:15226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb_QAAALA"]
[Mon Jul 20 06:21:29.585972 2026] [security2:error] [pid 884009:tid 884257] [client 34.74.185.202:50254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SyRKaHUf6J8d3elJcBwAAAPk"]
[Mon Jul 20 06:21:29.702407 2026] [security2:error] [pid 884009:tid 884167] [client 185.132.186.104:38701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/info.php"] [unique_id "al4SyRKaHUf6J8d3elJcEwAAAKA"]
[Mon Jul 20 06:21:29.789788 2026] [security2:error] [pid 884009:tid 884258] [client 57.141.18.20:38590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxhKaHUf6J8d3elJbFQAA-lI"]
[Mon Jul 20 06:21:29.845375 2026] [security2:error] [pid 884009:tid 884122] [remote 167.233.114.32:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SyRKaHUf6J8d3elJcHgAA7m8"]
[Mon Jul 20 06:21:29.853646 2026] [security2:error] [pid 884009:tid 884166] [client 50.116.65.227:15234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SyRKaHUf6J8d3elJcIAAAAJ8"]
[Mon Jul 20 06:21:29.864383 2026] [security2:error] [pid 884009:tid 884201] [client 50.116.65.227:15236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SyRKaHUf6J8d3elJcIwAAAME"]
[Mon Jul 20 06:21:29.899352 2026] [security2:error] [pid 884009:tid 884256] [client 4.194.217.15:1459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system.php"] [unique_id "al4SyRKaHUf6J8d3elJcJwAAAPg"]
[Mon Jul 20 06:21:30.038534 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.100:20136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbLwAA0wQ"]
[Mon Jul 20 06:21:30.108724 2026] [security2:error] [pid 884009:tid 884168] [client 14.225.17.146:58993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJcKQAAAKE"], referer: https://fkconstructionfunding.com/Wp
[Mon Jul 20 06:21:30.126886 2026] [security2:error] [pid 884009:tid 884023] [remote 167.233.114.32:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJcTwAAjww"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:21:30.221901 2026] [security2:error] [pid 884009:tid 884178] [client 104.234.53.75:24617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SyhKaHUf6J8d3elJcZQAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:30.331870 2026] [security2:error] [pid 884009:tid 884114] [remote 188.95.113.76:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJcmQAAw2c"]
[Mon Jul 20 06:21:30.351372 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.114:62152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbTwAA90Q"]
[Mon Jul 20 06:21:30.359968 2026] [security2:error] [pid 884009:tid 884023] [remote 38.242.157.30:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJczQAA1gw"]
[Mon Jul 20 06:21:30.382225 2026] [security2:error] [pid 884009:tid 884018] [remote 5.161.225.162:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "careysheatingandcooling.com"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJc0AAAwgc"]
[Mon Jul 20 06:21:30.490840 2026] [security2:error] [pid 884009:tid 884176] [client 4.194.217.15:6900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4SyhKaHUf6J8d3elJdEQAAAKg"]
[Mon Jul 20 06:21:30.562743 2026] [security2:error] [pid 884009:tid 884121] [remote 38.242.157.30:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdHwAAom4"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:21:30.564130 2026] [security2:error] [pid 884009:tid 884135] [remote 188.95.113.76:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdIAAA9Hw"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 06:21:30.634610 2026] [security2:error] [pid 884009:tid 884105] [remote 47.128.48.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atyourconveniencehealth.com"] [uri "/robots.txt"] [unique_id "al4SyhKaHUf6J8d3elJdKAAA8l4"]
[Mon Jul 20 06:21:30.743883 2026] [security2:error] [pid 884009:tid 884067] [remote 5.161.225.162:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "careysheatingandcooling.com"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdLgAA4Tg"], referer: https://careysheatingandcooling.com/wp-login.php
[Mon Jul 20 06:21:30.749157 2026] [security2:error] [pid 884009:tid 884245] [client 14.224.227.113:54372] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4SyhKaHUf6J8d3elJdLwAAAO0"]
[Mon Jul 20 06:21:30.769613 2026] [security2:error] [pid 884009:tid 884229] [client 50.116.65.227:33476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SyhKaHUf6J8d3elJdMgAAAN0"]
[Mon Jul 20 06:21:30.780003 2026] [security2:error] [pid 884009:tid 884171] [client 50.116.65.227:15266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SyhKaHUf6J8d3elJdNAAAAKM"]
[Mon Jul 20 06:21:30.801095 2026] [security2:error] [pid 884009:tid 884240] [client 34.74.185.202:50276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SyhKaHUf6J8d3elJdNwAAAOg"]
[Mon Jul 20 06:21:30.811795 2026] [security2:error] [pid 884009:tid 884151] [client 57.141.18.22:25834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbeAAAkHY"]
[Mon Jul 20 06:21:30.852986 2026] [security2:error] [pid 884009:tid 884093] [remote 95.217.78.234:34956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdOwAA6VI"]
[Mon Jul 20 06:21:31.045127 2026] [security2:error] [pid 884009:tid 884238] [client 4.194.217.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4SyxKaHUf6J8d3elJdSwAAAOY"]
[Mon Jul 20 06:21:31.080558 2026] [security2:error] [pid 884009:tid 884047] [remote 95.217.78.234:34956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4SyxKaHUf6J8d3elJdTQAA2CQ"], referer: https://according2plant.com/wp-login.php
[Mon Jul 20 06:21:31.143797 2026] [security2:error] [pid 884009:tid 884074] [remote 45.90.123.233:37904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdUQAAqD8"]
[Mon Jul 20 06:21:31.144051 2026] [security2:error] [pid 884009:tid 884176] [client 45.90.123.233:37904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdUQAAqD8"]
[Mon Jul 20 06:21:31.197968 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:57663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4SyhKaHUf6J8d3elJdKwAAAJ0"], referer: http://onewingpictures.com/Wp
[Mon Jul 20 06:21:31.320346 2026] [security2:error] [pid 884009:tid 884173] [client 185.132.186.65:42881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/images/cloud.php"] [unique_id "al4SyxKaHUf6J8d3elJdYgAAAKU"]
[Mon Jul 20 06:21:31.339347 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SyxKaHUf6J8d3elJdZAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:31.339440 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:60972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SyxKaHUf6J8d3elJdZAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:31.430595 2026] [security2:error] [pid 884009:tid 884211] [client 34.74.185.202:61322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SyxKaHUf6J8d3elJdagAAAMs"]
[Mon Jul 20 06:21:31.446505 2026] [security2:error] [pid 884009:tid 884179] [client 74.208.214.194:38160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SyxKaHUf6J8d3elJdbQAAAKs"]
[Mon Jul 20 06:21:31.588726 2026] [security2:error] [pid 884009:tid 884190] [client 158.173.166.181:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SyxKaHUf6J8d3elJddQAAALY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:31.591806 2026] [security2:error] [pid 884009:tid 884227] [client 4.194.217.15:1927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system_log.php"] [unique_id "al4SyxKaHUf6J8d3elJddgAAANs"]
[Mon Jul 20 06:21:31.672682 2026] [security2:error] [pid 884009:tid 884015] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdewAAoQQ"]
[Mon Jul 20 06:21:31.672864 2026] [security2:error] [pid 884009:tid 884168] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdewAAoQQ"]
[Mon Jul 20 06:21:32.075394 2026] [security2:error] [pid 884009:tid 884127] [remote 216.73.217.138:3235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4SzBKaHUf6J8d3elJdmQAA8XQ"]
[Mon Jul 20 06:21:32.133424 2026] [security2:error] [pid 884009:tid 884173] [client 4.194.217.15:9951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/t.php"] [unique_id "al4SzBKaHUf6J8d3elJdmwAAAKU"]
[Mon Jul 20 06:21:32.265550 2026] [security2:error] [pid 884009:tid 884267] [client 57.141.18.54:34614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb4QABA3I"]
[Mon Jul 20 06:21:32.350084 2026] [security2:error] [pid 884009:tid 884183] [client 34.74.185.202:54031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SzBKaHUf6J8d3elJdrAAAAK8"]
[Mon Jul 20 06:21:32.454030 2026] [security2:error] [pid 884009:tid 884205] [client 14.251.3.155:61285] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SzBKaHUf6J8d3elJdugAAAMU"]
[Mon Jul 20 06:21:32.757468 2026] [security2:error] [pid 884009:tid 884151] [client 4.194.217.15:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/term.php"] [unique_id "al4SzBKaHUf6J8d3elJd0QAAAJA"]
[Mon Jul 20 06:21:32.768478 2026] [core:error] [pid 884009:tid 884228] [client 103.153.183.69:33978] AH10244: invalid URI path (/%2e%2e/.env?_=kuccc95i&v=g4acr), referer: https://t.co/r3gn8iifs1
[Mon Jul 20 06:21:32.926003 2026] [security2:error] [pid 884009:tid 884222] [client 185.132.186.61:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/log.php"] [unique_id "al4SzBKaHUf6J8d3elJd4gAAANY"]
[Mon Jul 20 06:21:33.143840 2026] [security2:error] [pid 884009:tid 884257] [client 108.174.8.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4SyhKaHUf6J8d3elJc7gAA-Rk"]
[Mon Jul 20 06:21:33.217395 2026] [security2:error] [pid 884009:tid 884180] [client 57.141.18.47:36128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJcJgAArDk"]
[Mon Jul 20 06:21:33.313158 2026] [security2:error] [pid 884009:tid 884199] [client 57.141.18.78:24008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJcLwAAv3k"]
[Mon Jul 20 06:21:33.317448 2026] [security2:error] [pid 884009:tid 884161] [client 4.194.217.15:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/test.php"] [unique_id "al4SzRKaHUf6J8d3elJeAQAAAJo"]
[Mon Jul 20 06:21:33.722086 2026] [security2:error] [pid 884009:tid 884237] [client 34.74.185.202:62858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SzRKaHUf6J8d3elJeJwAAAOU"]
[Mon Jul 20 06:21:33.902326 2026] [security2:error] [pid 884009:tid 884167] [client 4.194.217.15:9924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/test1.php"] [unique_id "al4SzRKaHUf6J8d3elJeNwAAAKA"]
[Mon Jul 20 06:21:33.941631 2026] [security2:error] [pid 884009:tid 884121] [remote 152.228.213.32:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzRKaHUf6J8d3elJePAAA6W4"]
[Mon Jul 20 06:21:33.941769 2026] [security2:error] [pid 884009:tid 884241] [client 152.228.213.32:58046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzRKaHUf6J8d3elJePAAA6W4"]
[Mon Jul 20 06:21:34.276017 2026] [security2:error] [pid 884009:tid 884055] [remote 97.74.93.24:47460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SzhKaHUf6J8d3elJeWAAAvSw"]
[Mon Jul 20 06:21:34.536116 2026] [security2:error] [pid 884009:tid 884233] [client 185.132.186.66:30067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-react-refresh-runtime-num.php"] [unique_id "al4SzhKaHUf6J8d3elJebQAAAOE"]
[Mon Jul 20 06:21:34.601449 2026] [security2:error] [pid 884009:tid 884253] [client 4.194.217.15:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/tfm.php"] [unique_id "al4SzhKaHUf6J8d3elJedAAAAPU"]
[Mon Jul 20 06:21:34.608411 2026] [security2:error] [pid 884009:tid 884058] [remote 109.123.245.117:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.245.123.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJecwAA_y8"]
[Mon Jul 20 06:21:34.608613 2026] [security2:error] [pid 884009:tid 884263] [client 109.123.245.117:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJecwAA_y8"]
[Mon Jul 20 06:21:34.695290 2026] [security2:error] [pid 884009:tid 884074] [remote 91.142.222.105:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SzhKaHUf6J8d3elJeegAAoz8"]
[Mon Jul 20 06:21:34.760924 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:49444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4SzhKaHUf6J8d3elJedQAAAJo"], referer: http://nextlvlmarketingco.com/Wp
[Mon Jul 20 06:21:34.780457 2026] [security2:error] [pid 884009:tid 884053] [remote 97.74.93.24:47460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SzhKaHUf6J8d3elJefgAA0Co"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:21:34.904372 2026] [security2:error] [pid 884009:tid 884259] [client 171.60.139.123:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJegwAAAPs"]
[Mon Jul 20 06:21:34.904503 2026] [security2:error] [pid 884009:tid 884259] [client 171.60.139.123:59933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJegwAAAPs"]
[Mon Jul 20 06:21:34.928485 2026] [proxy:error] [pid 884009:tid 884255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:34.928518 2026] [proxy_http:error] [pid 884009:tid 884255] [client 159.65.202.56:39586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:21:34.929216 2026] [proxy:error] [pid 884009:tid 884255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:34.929241 2026] [proxy_http:error] [pid 884009:tid 884255] [client 159.65.202.56:39586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:21:35.025177 2026] [security2:error] [pid 884009:tid 884254] [client 34.74.185.202:58659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SzxKaHUf6J8d3elJekAAAAPY"]
[Mon Jul 20 06:21:35.065854 2026] [security2:error] [pid 884009:tid 884103] [remote 91.142.222.105:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SzxKaHUf6J8d3elJelgAAq1w"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:21:35.184841 2026] [security2:error] [pid 884009:tid 884145] [client 4.194.217.15:9920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/thebe.php"] [unique_id "al4SzxKaHUf6J8d3elJeoQAAAIo"]
[Mon Jul 20 06:21:35.218184 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:35.218281 2026] [proxy_http:error] [pid 884009:tid 884208] [client 159.65.202.56:39602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dadanetnet.net/
[Mon Jul 20 06:21:35.219963 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:35.220024 2026] [proxy_http:error] [pid 884009:tid 884208] [client 159.65.202.56:39602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dadanetnet.net/
[Mon Jul 20 06:21:35.258856 2026] [security2:error] [pid 884009:tid 884212] [client 52.109.124.141:28746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SzxKaHUf6J8d3elJepAAAAMw"]
[Mon Jul 20 06:21:35.352028 2026] [security2:error] [pid 884009:tid 884239] [client 52.109.124.141:30656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SzxKaHUf6J8d3elJesQAAAOc"]
[Mon Jul 20 06:21:35.438823 2026] [security2:error] [pid 884009:tid 884156] [client 52.109.124.141:28746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SzxKaHUf6J8d3elJexQAAAJU"]
[Mon Jul 20 06:21:35.533355 2026] [security2:error] [pid 884009:tid 884228] [client 52.109.124.141:30656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SzxKaHUf6J8d3elJezAAAANw"]
[Mon Jul 20 06:21:35.761393 2026] [security2:error] [pid 884009:tid 884208] [client 4.194.217.15:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/themes.php"] [unique_id "al4SzxKaHUf6J8d3elJe3gAAAMg"]
[Mon Jul 20 06:21:35.859793 2026] [core:error] [pid 884009:tid 884267] [client 159.65.202.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:35.859815 2026] [core:error] [pid 884009:tid 884267] [client 159.65.202.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:35.890917 2026] [security2:error] [pid 884009:tid 884176] [client 77.110.127.138:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4SzxKaHUf6J8d3elJe6wAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:36.084416 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJe-wAAALk"]
[Mon Jul 20 06:21:36.084505 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJe-wAAALk"]
[Mon Jul 20 06:21:36.168496 2026] [security2:error] [pid 884009:tid 884252] [client 185.132.186.75:37137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-react-refresh-entry.min-object.php"] [unique_id "al4S0BKaHUf6J8d3elJe_wAAAPQ"]
[Mon Jul 20 06:21:36.325293 2026] [security2:error] [pid 884009:tid 884232] [client 4.194.217.15:1737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/tiny.php"] [unique_id "al4S0BKaHUf6J8d3elJfBgAAAOA"]
[Mon Jul 20 06:21:36.400785 2026] [security2:error] [pid 884009:tid 884173] [client 34.74.185.202:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S0BKaHUf6J8d3elJfCAAAAKU"]
[Mon Jul 20 06:21:36.404644 2026] [security2:error] [pid 884009:tid 884186] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SzxKaHUf6J8d3elJe8QAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:36.497008 2026] [security2:error] [pid 884009:tid 884244] [client 103.141.108.143:52746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfEgAAAOw"]
[Mon Jul 20 06:21:36.497352 2026] [security2:error] [pid 884009:tid 884244] [client 103.141.108.143:52746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfEgAAAOw"]
[Mon Jul 20 06:21:36.549730 2026] [security2:error] [pid 884009:tid 884144] [client 57.141.18.30:55976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzRKaHUf6J8d3elJd_AAAiWY"]
[Mon Jul 20 06:21:36.715304 2026] [security2:error] [pid 884009:tid 884170] [client 57.141.18.126:63920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzRKaHUf6J8d3elJeAgAAojc"]
[Mon Jul 20 06:21:36.865887 2026] [security2:error] [pid 884009:tid 884175] [client 34.73.38.214:54317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S0BKaHUf6J8d3elJfNwAAAKc"]
[Mon Jul 20 06:21:36.867032 2026] [security2:error] [pid 884009:tid 884228] [client 4.194.217.15:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/tmp/byp.php"] [unique_id "al4S0BKaHUf6J8d3elJfOAAAANw"]
[Mon Jul 20 06:21:36.917830 2026] [security2:error] [pid 884009:tid 884232] [client 34.74.185.202:63550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S0BKaHUf6J8d3elJfPAAAAOA"]
[Mon Jul 20 06:21:36.945790 2026] [security2:error] [pid 884009:tid 884235] [client 27.96.94.195:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfQQAAAOM"]
[Mon Jul 20 06:21:36.945905 2026] [security2:error] [pid 884009:tid 884235] [client 27.96.94.195:37522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfQQAAAOM"]
[Mon Jul 20 06:21:37.783442 2026] [security2:error] [pid 884009:tid 884144] [client 185.132.186.61:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/aw.php"] [unique_id "al4S0RKaHUf6J8d3elJfeAAAAIk"]
[Mon Jul 20 06:21:37.846196 2026] [security2:error] [pid 884009:tid 884203] [client 34.73.38.214:56996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S0RKaHUf6J8d3elJfgQAAAMM"]
[Mon Jul 20 06:21:37.917459 2026] [security2:error] [pid 884009:tid 884191] [client 14.225.17.146:53112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4S0BKaHUf6J8d3elJfKAAAALc"], referer: http://elitetax-mi.com/Wp
[Mon Jul 20 06:21:38.016593 2026] [security2:error] [pid 884009:tid 884168] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S0RKaHUf6J8d3elJffQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:38.216413 2026] [security2:error] [pid 884009:tid 884226] [client 104.234.53.62:31589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfnwAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:38.281873 2026] [security2:error] [pid 884009:tid 884104] [remote 217.61.143.92:48906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfoQAAyV0"]
[Mon Jul 20 06:21:38.320794 2026] [security2:error] [pid 884009:tid 884175] [client 50.116.65.227:33492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S0hKaHUf6J8d3elJfowAAAKc"]
[Mon Jul 20 06:21:38.332832 2026] [security2:error] [pid 884009:tid 884199] [client 50.116.65.227:15326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S0hKaHUf6J8d3elJfpQAAAME"]
[Mon Jul 20 06:21:38.590396 2026] [security2:error] [pid 884009:tid 884126] [remote 217.61.143.92:48906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfuwAAsnM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:38.626575 2026] [security2:error] [pid 884009:tid 884046] [remote 209.42.18.223:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfvQAA9yM"]
[Mon Jul 20 06:21:38.842901 2026] [security2:error] [pid 884009:tid 884069] [remote 209.42.18.223:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJf2gAA5Do"], referer: https://mail.transamericagrid.com/wp-login.php
[Mon Jul 20 06:21:39.389763 2026] [security2:error] [pid 884009:tid 884238] [client 14.225.17.146:49546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4S0RKaHUf6J8d3elJfegAAAOY"], referer: http://maplerespiteservices.com/Wp
[Mon Jul 20 06:21:39.403854 2026] [security2:error] [pid 884009:tid 884162] [client 185.132.186.61:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/update/gely.php"] [unique_id "al4S0xKaHUf6J8d3elJgBAAAAJs"]
[Mon Jul 20 06:21:39.458531 2026] [security2:error] [pid 884009:tid 884210] [client 77.110.127.138:60996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4S0xKaHUf6J8d3elJgCgAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:39.473414 2026] [security2:error] [pid 884009:tid 884190] [client 34.73.38.214:51727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S0xKaHUf6J8d3elJgDAAAALY"]
[Mon Jul 20 06:21:39.640581 2026] [security2:error] [pid 884009:tid 884260] [client 57.141.18.47:36132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzxKaHUf6J8d3elJe0gAA_A0"]
[Mon Jul 20 06:21:39.787655 2026] [security2:error] [pid 884009:tid 884112] [remote 100.42.189.89:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4S0xKaHUf6J8d3elJgJwAAvmU"]
[Mon Jul 20 06:21:39.812985 2026] [security2:error] [pid 884009:tid 884212] [client 57.141.18.23:41992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzxKaHUf6J8d3elJe5AAAzC4"]
[Mon Jul 20 06:21:39.839786 2026] [core:error] [pid 884009:tid 884231] [client 14.225.17.146:55389] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wp
[Mon Jul 20 06:21:39.839809 2026] [core:error] [pid 884009:tid 884231] [client 14.225.17.146:55389] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wp
[Mon Jul 20 06:21:40.018194 2026] [security2:error] [pid 884009:tid 884133] [remote 100.42.189.89:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgSAAA0Xo"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:21:40.088104 2026] [security2:error] [pid 884009:tid 884256] [client 41.173.37.102:8863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgUAAAAPg"]
[Mon Jul 20 06:21:40.088252 2026] [security2:error] [pid 884009:tid 884256] [client 41.173.37.102:8863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgUAAAAPg"]
[Mon Jul 20 06:21:40.111655 2026] [security2:error] [pid 884009:tid 884209] [client 40.77.167.152:55831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgPgAAyX0"]
[Mon Jul 20 06:21:40.162873 2026] [security2:error] [pid 884009:tid 884258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgNgAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:40.226996 2026] [security2:error] [pid 884009:tid 884187] [client 104.234.53.87:27737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgTQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:40.252800 2026] [security2:error] [pid 884009:tid 884203] [client 171.61.165.146:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgWwAAAMM"]
[Mon Jul 20 06:21:40.252907 2026] [security2:error] [pid 884009:tid 884203] [client 171.61.165.146:16181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgWwAAAMM"]
[Mon Jul 20 06:21:40.288190 2026] [security2:error] [pid 884009:tid 884079] [remote 188.138.102.156:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgXgAA_EQ"]
[Mon Jul 20 06:21:40.375823 2026] [security2:error] [pid 884009:tid 884156] [client 50.116.65.227:59192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S1BKaHUf6J8d3elJgYgAAAJU"]
[Mon Jul 20 06:21:40.386253 2026] [security2:error] [pid 884009:tid 884201] [client 50.116.65.227:59204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S1BKaHUf6J8d3elJgYwAAAME"]
[Mon Jul 20 06:21:40.482364 2026] [security2:error] [pid 884009:tid 884107] [remote 188.138.102.156:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgawAA0WA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:21:40.523469 2026] [security2:error] [pid 884009:tid 884182] [client 14.225.17.146:55471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgMgAAAK4"], referer: http://carolinapressurewashers.com/Wp
[Mon Jul 20 06:21:40.726184 2026] [security2:error] [pid 884009:tid 884224] [client 34.73.38.214:53152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S1BKaHUf6J8d3elJghgAAANg"]
[Mon Jul 20 06:21:40.815467 2026] [security2:error] [pid 884009:tid 884147] [client 104.234.53.87:27737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgiAAAAIw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:41.011929 2026] [security2:error] [pid 884009:tid 884217] [client 185.132.186.88:44211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/c99shell.php"] [unique_id "al4S1RKaHUf6J8d3elJgmgAAANE"]
[Mon Jul 20 06:21:41.260869 2026] [security2:error] [pid 884009:tid 884179] [client 14.225.17.146:55358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgLgAAAKs"], referer: http://dnsplumbing.com/Wp
[Mon Jul 20 06:21:41.266355 2026] [security2:error] [pid 884009:tid 884026] [remote 81.173.115.7:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4S1RKaHUf6J8d3elJgsQAAmw8"]
[Mon Jul 20 06:21:41.382362 2026] [security2:error] [pid 884009:tid 884252] [client 57.141.18.115:37548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S0RKaHUf6J8d3elJfYAAA9AM"]
[Mon Jul 20 06:21:41.454926 2026] [security2:error] [pid 884009:tid 884170] [client 185.192.69.18:55357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/000.php"] [unique_id "al4S1RKaHUf6J8d3elJguwAAAKI"]
[Mon Jul 20 06:21:41.508882 2026] [security2:error] [pid 884009:tid 884129] [remote 81.173.115.7:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4S1RKaHUf6J8d3elJgwAAAtnY"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:21:41.554384 2026] [security2:error] [pid 884009:tid 884214] [client 40.77.167.152:55831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgjAAAzhY"]
[Mon Jul 20 06:21:41.866984 2026] [security2:error] [pid 884009:tid 884182] [client 77.110.127.138:61021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgzAAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:41.907862 2026] [security2:error] [pid 884009:tid 884240] [client 185.192.69.19:52385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-admin/css/index.php"] [unique_id "al4S1RKaHUf6J8d3elJg4gAAAOg"]
[Mon Jul 20 06:21:42.139664 2026] [security2:error] [pid 884009:tid 884088] [remote 152.228.213.32:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJg-QAAhk0"]
[Mon Jul 20 06:21:42.139925 2026] [security2:error] [pid 884009:tid 884141] [client 152.228.213.32:47944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJg-QAAhk0"]
[Mon Jul 20 06:21:42.267489 2026] [security2:error] [pid 884009:tid 884263] [client 57.141.18.82:55130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S0hKaHUf6J8d3elJfrwAA_y8"]
[Mon Jul 20 06:21:42.360305 2026] [security2:error] [pid 884009:tid 884183] [client 185.192.69.33:39277] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-content/plugins/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhCwAAAK8"]
[Mon Jul 20 06:21:42.398517 2026] [security2:error] [pid 884009:tid 884070] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhEAAAuTs"]
[Mon Jul 20 06:21:42.398704 2026] [security2:error] [pid 884009:tid 884193] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhEAAAuTs"]
[Mon Jul 20 06:21:42.418162 2026] [security2:error] [pid 884009:tid 884144] [client 74.7.230.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgyAAAAIk"]
[Mon Jul 20 06:21:42.418183 2026] [security2:error] [pid 884009:tid 884144] [client 74.7.230.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgyAAAAIk"]
[Mon Jul 20 06:21:42.428877 2026] [security2:error] [pid 884009:tid 884230] [client 74.7.230.29:56142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/robots.txt"] [unique_id "al4S1RKaHUf6J8d3elJgwwAA3jE"]
[Mon Jul 20 06:21:42.446693 2026] [security2:error] [pid 884009:tid 884017] [remote 84.247.172.23:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4S1hKaHUf6J8d3elJhEwAA_QY"]
[Mon Jul 20 06:21:42.540825 2026] [security2:error] [pid 884009:tid 884232] [client 57.141.18.31:41934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S0hKaHUf6J8d3elJf0wAA4Fw"]
[Mon Jul 20 06:21:42.552555 2026] [security2:error] [pid 884009:tid 884174] [client 34.73.38.214:53539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S1hKaHUf6J8d3elJhGgAAAKY"]
[Mon Jul 20 06:21:42.620011 2026] [security2:error] [pid 884009:tid 884215] [client 185.132.186.73:51699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/admin-footer.php"] [unique_id "al4S1hKaHUf6J8d3elJhHwAAAM8"]
[Mon Jul 20 06:21:42.667596 2026] [security2:error] [pid 884009:tid 884256] [client 74.7.230.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhIAAAAPg"], referer: https://processorstudio.com/robots.txt
[Mon Jul 20 06:21:42.712545 2026] [security2:error] [pid 884009:tid 884221] [client 74.7.230.29:56146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/robots.txt"] [unique_id "al4S1hKaHUf6J8d3elJhHAAA1VU"], referer: https://processorstudio.com/robots.txt
[Mon Jul 20 06:21:42.748473 2026] [security2:error] [pid 884009:tid 884127] [remote 84.247.172.23:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4S1hKaHUf6J8d3elJhJQAAnHQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:21:42.815159 2026] [security2:error] [pid 884009:tid 884216] [client 185.192.69.16:42477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-content/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhLAAAANA"]
[Mon Jul 20 06:21:42.824602 2026] [security2:error] [pid 884009:tid 884222] [client 112.208.70.94:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhKwAAANY"]
[Mon Jul 20 06:21:42.824760 2026] [security2:error] [pid 884009:tid 884222] [client 112.208.70.94:44267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhKwAAANY"]
[Mon Jul 20 06:21:43.183346 2026] [security2:error] [pid 884009:tid 884234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhNgAAAOI"]
[Mon Jul 20 06:21:43.271057 2026] [security2:error] [pid 884009:tid 884167] [client 185.192.69.14:58731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4S1xKaHUf6J8d3elJhUwAAAKA"]
[Mon Jul 20 06:21:43.344695 2026] [security2:error] [pid 884009:tid 884163] [client 34.73.38.214:52016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S1xKaHUf6J8d3elJhWgAAAJw"]
[Mon Jul 20 06:21:43.392830 2026] [security2:error] [pid 884009:tid 884175] [client 14.225.17.146:60223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4S1xKaHUf6J8d3elJhVQAAAKc"], referer: http://hammadownenterprises.com/Wp
[Mon Jul 20 06:21:43.570811 2026] [security2:error] [pid 884009:tid 884207] [client 34.73.38.214:53227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S1xKaHUf6J8d3elJhZQAAAMc"]
[Mon Jul 20 06:21:43.691142 2026] [fcgid:warn] [pid 884009:tid 884212] (70014)End of file found: [client 199.45.155.75:46296] mod_fcgid: can't get data from http client
[Mon Jul 20 06:21:43.852481 2026] [security2:error] [pid 884009:tid 884170] [client 14.225.17.146:55656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhCQAAAKI"], referer: http://olearyplumbingllc.com/Wp
[Mon Jul 20 06:21:44.060204 2026] [security2:error] [pid 884009:tid 884257] [client 34.73.38.214:57886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S2BKaHUf6J8d3elJhkQAAAPk"]
[Mon Jul 20 06:21:44.232850 2026] [security2:error] [pid 884009:tid 884152] [client 185.132.186.91:30687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/lala.php"] [unique_id "al4S2BKaHUf6J8d3elJhngAAAJE"]
[Mon Jul 20 06:21:44.332591 2026] [security2:error] [pid 884009:tid 884108] [remote 47.86.33.52:1892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S2BKaHUf6J8d3elJhqgAAjWE"]
[Mon Jul 20 06:21:44.338703 2026] [security2:error] [pid 884009:tid 884233] [client 34.73.38.214:63379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S2BKaHUf6J8d3elJhsAAAAOE"]
[Mon Jul 20 06:21:44.439022 2026] [security2:error] [pid 884009:tid 884061] [remote 130.51.180.8:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4S2BKaHUf6J8d3elJhuQAAuDI"]
[Mon Jul 20 06:21:44.530597 2026] [security2:error] [pid 884009:tid 884268] [client 57.141.18.33:37360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgZwABBDk"]
[Mon Jul 20 06:21:44.646700 2026] [security2:error] [pid 884009:tid 884114] [remote 130.51.180.8:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4S2BKaHUf6J8d3elJhwQAA5Gc"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:21:44.817477 2026] [security2:error] [pid 884009:tid 884174] [client 34.73.38.214:57820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S2BKaHUf6J8d3elJh1QAAAKY"]
[Mon Jul 20 06:21:44.939406 2026] [security2:error] [pid 884009:tid 884216] [client 104.234.53.66:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4S2BKaHUf6J8d3elJh4QAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:44.977666 2026] [fcgid:warn] [pid 884009:tid 884248] (70014)End of file found: [client 66.132.195.70:57698] mod_fcgid: can't get data from http client
[Mon Jul 20 06:21:45.039888 2026] [security2:error] [pid 884009:tid 884167] [client 77.110.127.138:61037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJhxQAAAKA"]
[Mon Jul 20 06:21:45.053970 2026] [security2:error] [pid 884009:tid 884140] [client 34.73.38.214:56669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S2RKaHUf6J8d3elJh5gAAAIU"]
[Mon Jul 20 06:21:45.094131 2026] [security2:error] [pid 884009:tid 884186] [client 57.141.18.8:54888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgiQAAsn4"]
[Mon Jul 20 06:21:45.099479 2026] [security2:error] [pid 884009:tid 884253] [client 57.141.18.85:40406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgiwAA9U4"]
[Mon Jul 20 06:21:45.409691 2026] [security2:error] [pid 884009:tid 884245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJh2gAAAO0"]
[Mon Jul 20 06:21:45.489159 2026] [security2:error] [pid 884009:tid 884206] [client 66.249.74.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.oohlovely.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJh5AAAAMY"]
[Mon Jul 20 06:21:45.536775 2026] [security2:error] [pid 884009:tid 884246] [client 103.153.183.69:32172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/etc/passwd"] [unique_id "al4S2RKaHUf6J8d3elJiFwAAAO4"], referer: https://www.reddit.com/
[Mon Jul 20 06:21:45.547456 2026] [security2:error] [pid 884009:tid 884242] [client 77.110.127.138:61008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJh-gAAAOo"]
[Mon Jul 20 06:21:45.607203 2026] [security2:error] [pid 884009:tid 884160] [client 34.73.38.214:58394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S2RKaHUf6J8d3elJiHgAAAJk"]
[Mon Jul 20 06:21:45.618462 2026] [security2:error] [pid 884009:tid 884162] [client 171.60.139.123:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S2RKaHUf6J8d3elJiIAAAAJs"]
[Mon Jul 20 06:21:45.618572 2026] [security2:error] [pid 884009:tid 884162] [client 171.60.139.123:60450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S2RKaHUf6J8d3elJiIAAAAJs"]
[Mon Jul 20 06:21:45.719636 2026] [security2:error] [pid 884009:tid 884166] [client 14.225.17.146:55741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4S1xKaHUf6J8d3elJhhQAAAJ8"], referer: http://fluidtemple.org/Wp
[Mon Jul 20 06:21:45.758188 2026] [security2:error] [pid 884009:tid 884204] [client 57.141.18.52:39144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgxwAAxFI"]
[Mon Jul 20 06:21:45.805010 2026] [security2:error] [pid 884009:tid 884164] [client 34.73.38.214:53412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S2RKaHUf6J8d3elJiOQAAAJ0"]
[Mon Jul 20 06:21:45.847869 2026] [security2:error] [pid 884009:tid 884238] [client 185.132.186.79:54207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/db.php"] [unique_id "al4S2RKaHUf6J8d3elJiPQAAAOY"]
[Mon Jul 20 06:21:45.857010 2026] [security2:error] [pid 884009:tid 884201] [client 14.225.17.146:60429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiMwAAAME"], referer: http://iagdevelopments.com/Wp
[Mon Jul 20 06:21:45.901635 2026] [security2:error] [pid 884009:tid 884219] [client 14.225.17.146:55804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4S1xKaHUf6J8d3elJhigAAANM"], referer: http://areitoproducciones.com/Wp
[Mon Jul 20 06:21:45.929941 2026] [security2:error] [pid 884009:tid 884017] [remote 47.86.33.52:1892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S2RKaHUf6J8d3elJiRAAA3wY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:45.935044 2026] [security2:error] [pid 884009:tid 884229] [client 103.153.183.69:32172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/.env"] [unique_id "al4S2RKaHUf6J8d3elJiSAAAAN0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:21:46.024886 2026] [security2:error] [pid 884009:tid 884165] [client 114.119.147.42:26735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hedgerow-crafts.com"] [uri "/2019/02"] [unique_id "al4S2hKaHUf6J8d3elJiTwAAAJ4"], referer: https://www.hedgerow-crafts.com/img_1927/
[Mon Jul 20 06:21:46.196159 2026] [security2:error] [pid 884009:tid 884262] [client 14.251.3.155:54397] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4S2hKaHUf6J8d3elJiWAAAAP4"]
[Mon Jul 20 06:21:46.334397 2026] [security2:error] [pid 884009:tid 884202] [client 35.90.38.209:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4S2hKaHUf6J8d3elJiYQAAAMI"]
[Mon Jul 20 06:21:46.379714 2026] [security2:error] [pid 884009:tid 884230] [client 44.245.170.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cryptomeaning.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJhrQAAAN4"]
[Mon Jul 20 06:21:46.429211 2026] [security2:error] [pid 884009:tid 884263] [client 50.116.65.227:45976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4S2hKaHUf6J8d3elJiZQAAAP8"]
[Mon Jul 20 06:21:46.441422 2026] [security2:error] [pid 884009:tid 884186] [client 50.116.65.227:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4S2hKaHUf6J8d3elJiZgAAALI"]
[Mon Jul 20 06:21:46.500037 2026] [security2:error] [pid 884009:tid 884196] [client 34.73.38.214:53084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S2hKaHUf6J8d3elJibgAAALw"]
[Mon Jul 20 06:21:46.735589 2026] [security2:error] [pid 884009:tid 884158] [client 34.73.38.214:57959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S2hKaHUf6J8d3elJihAAAAJc"]
[Mon Jul 20 06:21:46.743441 2026] [security2:error] [pid 884009:tid 884201] [client 45.116.69.230:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S2hKaHUf6J8d3elJigAAAAME"]
[Mon Jul 20 06:21:46.743579 2026] [security2:error] [pid 884009:tid 884201] [client 45.116.69.230:52454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S2hKaHUf6J8d3elJigAAAAME"]
[Mon Jul 20 06:21:46.755579 2026] [security2:error] [pid 884009:tid 884163] [client 14.225.17.146:49819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJh8gAAAJw"], referer: http://eduardsales.com/Wp
[Mon Jul 20 06:21:46.874123 2026] [security2:error] [pid 884009:tid 884159] [client 14.225.17.146:50147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4S2hKaHUf6J8d3elJihwAAAJg"], referer: https://iagdevelopments.com/Wp
[Mon Jul 20 06:21:47.136914 2026] [security2:error] [pid 884009:tid 884082] [remote 95.217.78.234:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4S2xKaHUf6J8d3elJipwAAoEc"]
[Mon Jul 20 06:21:47.180911 2026] [security2:error] [pid 884009:tid 884239] [client 103.141.108.143:53221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJirAAAAOc"]
[Mon Jul 20 06:21:47.181184 2026] [security2:error] [pid 884009:tid 884239] [client 103.141.108.143:53221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJirAAAAOc"]
[Mon Jul 20 06:21:47.391644 2026] [security2:error] [pid 884009:tid 884040] [remote 95.217.78.234:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4S2xKaHUf6J8d3elJiuwAA0h0"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 06:21:47.453006 2026] [security2:error] [pid 884009:tid 884263] [client 185.132.186.60:63667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/install.php"] [unique_id "al4S2xKaHUf6J8d3elJivgAAAP8"]
[Mon Jul 20 06:21:47.577062 2026] [security2:error] [pid 884009:tid 884240] [client 46.110.96.34:64610] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4S2xKaHUf6J8d3elJizgAAAOg"]
[Mon Jul 20 06:21:47.577401 2026] [security2:error] [pid 884009:tid 884193] [client 34.73.38.214:57210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S2xKaHUf6J8d3elJizwAAALk"]
[Mon Jul 20 06:21:47.594213 2026] [security2:error] [pid 884009:tid 884230] [client 13.229.223.11:30032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi0gAAAN4"]
[Mon Jul 20 06:21:47.594329 2026] [security2:error] [pid 884009:tid 884230] [client 13.229.223.11:30032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi0gAAAN4"]
[Mon Jul 20 06:21:47.645093 2026] [security2:error] [pid 884009:tid 884256] [client 178.152.178.232:36445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi1gAAAPg"]
[Mon Jul 20 06:21:47.645215 2026] [security2:error] [pid 884009:tid 884256] [client 178.152.178.232:36445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi1gAAAPg"]
[Mon Jul 20 06:21:47.929857 2026] [security2:error] [pid 884009:tid 884232] [client 14.224.227.113:58410] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4S2xKaHUf6J8d3elJi7AAAAOA"]
[Mon Jul 20 06:21:48.037964 2026] [security2:error] [pid 884009:tid 884249] [client 114.119.142.73:47885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "massagelacey.com"] [uri "/ptsd-and-massage-therapy-in-lacey-wa/"] [unique_id "al4S3BKaHUf6J8d3elJi-QAAAPE"], referer: https://massagelacey.com/category/massage/page/6/
[Mon Jul 20 06:21:48.244993 2026] [security2:error] [pid 884009:tid 884145] [client 104.234.53.65:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4S3BKaHUf6J8d3elJjBwAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:48.288349 2026] [security2:error] [pid 884009:tid 884258] [client 14.225.17.146:50369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4S2xKaHUf6J8d3elJisgAAAPo"], referer: http://intelligentengineeringsolutions.com/Wp
[Mon Jul 20 06:21:48.320377 2026] [security2:error] [pid 884009:tid 884166] [client 77.110.127.138:61031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S3BKaHUf6J8d3elJjDQAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:48.320490 2026] [security2:error] [pid 884009:tid 884166] [client 77.110.127.138:61031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S3BKaHUf6J8d3elJjDQAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:48.545802 2026] [security2:error] [pid 884009:tid 884142] [client 34.73.38.214:50823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S3BKaHUf6J8d3elJjIQAAAIc"]
[Mon Jul 20 06:21:48.636775 2026] [security2:error] [pid 884009:tid 884222] [client 57.141.18.53:52262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJhkgAA1jc"]
[Mon Jul 20 06:21:48.808968 2026] [security2:error] [pid 884009:tid 884223] [client 104.234.53.52:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4S3BKaHUf6J8d3elJjOQAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:49.063019 2026] [security2:error] [pid 884009:tid 884242] [client 185.132.186.77:29697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/wp-theme-editor/include.php%20"] [unique_id "al4S3RKaHUf6J8d3elJjTQAAAOo"]
[Mon Jul 20 06:21:49.150487 2026] [security2:error] [pid 884009:tid 884202] [client 27.96.94.195:37622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S3RKaHUf6J8d3elJjVwAAAMI"]
[Mon Jul 20 06:21:49.150579 2026] [security2:error] [pid 884009:tid 884202] [client 27.96.94.195:37622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S3RKaHUf6J8d3elJjVwAAAMI"]
[Mon Jul 20 06:21:49.432994 2026] [security2:error] [pid 884009:tid 884176] [client 34.73.38.214:52986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S3RKaHUf6J8d3elJjcAAAAKg"]
[Mon Jul 20 06:21:49.770635 2026] [security2:error] [pid 884009:tid 884199] [client 98.159.234.160:29811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S3RKaHUf6J8d3elJjhAAAAL8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:49.831682 2026] [security2:error] [pid 884009:tid 884183] [client 104.234.53.64:46135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4S3RKaHUf6J8d3elJjjAAAAK8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:49.937298 2026] [security2:error] [pid 884009:tid 884243] [client 57.141.18.20:33526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiBwAA63M"]
[Mon Jul 20 06:21:49.990900 2026] [security2:error] [pid 884009:tid 884220] [client 34.73.38.214:60650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S3RKaHUf6J8d3elJjmQAAANQ"]
[Mon Jul 20 06:21:50.051615 2026] [security2:error] [pid 884009:tid 884156] [client 50.116.65.227:29736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S3hKaHUf6J8d3elJjnAAAAJU"]
[Mon Jul 20 06:21:50.062721 2026] [security2:error] [pid 884009:tid 884203] [client 50.116.65.227:29750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S3hKaHUf6J8d3elJjnQAAAMM"]
[Mon Jul 20 06:21:50.179631 2026] [security2:error] [pid 884009:tid 884212] [client 57.141.18.49:26992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiGQAAzE0"]
[Mon Jul 20 06:21:50.360300 2026] [security2:error] [pid 884009:tid 884217] [client 57.141.18.104:36734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiKAAA0SI"]
[Mon Jul 20 06:21:50.621729 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:52910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjZQAAAIk"], referer: http://scott-assist.com/Wp
[Mon Jul 20 06:21:50.666285 2026] [security2:error] [pid 884009:tid 884225] [client 185.132.186.71:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/top.php"] [unique_id "al4S3hKaHUf6J8d3elJj2QAAANk"]
[Mon Jul 20 06:21:50.718051 2026] [security2:error] [pid 884009:tid 884196] [client 41.173.37.102:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S3hKaHUf6J8d3elJj2wAAALw"]
[Mon Jul 20 06:21:50.718176 2026] [security2:error] [pid 884009:tid 884196] [client 41.173.37.102:9280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S3hKaHUf6J8d3elJj2wAAALw"]
[Mon Jul 20 06:21:50.744290 2026] [security2:error] [pid 884009:tid 884140] [client 34.73.38.214:55614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S3hKaHUf6J8d3elJj3wAAAIU"]
[Mon Jul 20 06:21:50.876214 2026] [security2:error] [pid 884009:tid 884120] [remote 45.90.123.233:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S3hKaHUf6J8d3elJj7gAAv20"]
[Mon Jul 20 06:21:50.933939 2026] [security2:error] [pid 884009:tid 884195] [client 34.74.185.202:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4S3hKaHUf6J8d3elJj9AAAALs"]
[Mon Jul 20 06:21:51.081607 2026] [security2:error] [pid 884009:tid 884182] [client 34.73.38.214:51268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S3xKaHUf6J8d3elJj_AAAAK4"]
[Mon Jul 20 06:21:51.083809 2026] [security2:error] [pid 884009:tid 884037] [remote 45.90.123.233:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S3xKaHUf6J8d3elJj_QAA6Ro"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:51.126175 2026] [security2:error] [pid 884009:tid 884236] [client 14.225.17.146:64887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJj-gAAAOQ"], referer: http://grndl.com/Wp
[Mon Jul 20 06:21:51.252095 2026] [security2:error] [pid 884009:tid 884229] [client 14.225.17.146:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4S3hKaHUf6J8d3elJj9gAAAN0"], referer: http://dollpassionista.com/Wp
[Mon Jul 20 06:21:51.296487 2026] [security2:error] [pid 884009:tid 884192] [client 171.61.165.146:28243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S3xKaHUf6J8d3elJkGAAAALg"]
[Mon Jul 20 06:21:51.296665 2026] [security2:error] [pid 884009:tid 884192] [client 171.61.165.146:28243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S3xKaHUf6J8d3elJkGAAAALg"]
[Mon Jul 20 06:21:51.424407 2026] [security2:error] [pid 884009:tid 884168] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkFgAAAKE"]
[Mon Jul 20 06:21:51.506377 2026] [security2:error] [pid 884009:tid 884142] [client 14.225.17.146:63333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjkwAAAIc"], referer: http://idigress.group/Wp
[Mon Jul 20 06:21:51.523966 2026] [security2:error] [pid 884009:tid 884160] [client 34.73.38.214:56556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S3xKaHUf6J8d3elJkJQAAAJk"]
[Mon Jul 20 06:21:51.583719 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:56843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkHwAAAJ0"], referer: http://koaconsultants.com/Wp
[Mon Jul 20 06:21:51.664168 2026] [security2:error] [pid 884009:tid 884248] [client 57.141.18.2:49222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2hKaHUf6J8d3elJikAAA8BA"]
[Mon Jul 20 06:21:51.842025 2026] [security2:error] [pid 884009:tid 884151] [client 34.74.185.202:60121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S3xKaHUf6J8d3elJkPwAAAJA"]
[Mon Jul 20 06:21:51.880175 2026] [security2:error] [pid 884009:tid 884059] [remote 81.173.115.7:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S3xKaHUf6J8d3elJkRQAAszA"]
[Mon Jul 20 06:21:52.074528 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkXAAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.074647 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkXAAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.075043 2026] [security2:error] [pid 884009:tid 884031] [remote 81.173.115.7:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S4BKaHUf6J8d3elJkXQAA8BQ"], referer: https://str.cly.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:52.170530 2026] [security2:error] [pid 884009:tid 884171] [client 34.74.185.202:65358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S4BKaHUf6J8d3elJkaAAAAKM"]
[Mon Jul 20 06:21:52.180151 2026] [security2:error] [pid 884009:tid 884138] [remote 188.166.241.141:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S4BKaHUf6J8d3elJkawAAkX8"]
[Mon Jul 20 06:21:52.180307 2026] [security2:error] [pid 884009:tid 884152] [client 188.166.241.141:58924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S4BKaHUf6J8d3elJkawAAkX8"]
[Mon Jul 20 06:21:52.229205 2026] [security2:error] [pid 884009:tid 884192] [client 77.110.127.138:61099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkbwAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.229301 2026] [security2:error] [pid 884009:tid 884192] [client 77.110.127.138:61099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkbwAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.234868 2026] [security2:error] [pid 884009:tid 884148] [client 14.225.17.146:63808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4S4BKaHUf6J8d3elJkWgAAAI0"], referer: https://dollpassionista.com/Wp
[Mon Jul 20 06:21:52.276638 2026] [security2:error] [pid 884009:tid 884265] [client 185.132.186.69:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/install.php"] [unique_id "al4S4BKaHUf6J8d3elJkeAAAAQE"]
[Mon Jul 20 06:21:52.333785 2026] [security2:error] [pid 884009:tid 884194] [client 57.141.18.64:33742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2xKaHUf6J8d3elJiygAAuk8"]
[Mon Jul 20 06:21:52.371460 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:63878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4S4BKaHUf6J8d3elJkVwAAAIk"], referer: http://massagelacey.com/Wp
[Mon Jul 20 06:21:52.616104 2026] [security2:error] [pid 884009:tid 884214] [client 14.225.17.146:58590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4S4BKaHUf6J8d3elJkgwAAAM4"], referer: http://keywayconstructionclt.com/Wp
[Mon Jul 20 06:21:52.880538 2026] [security2:error] [pid 884009:tid 884160] [client 77.110.127.138:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkpwAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.880645 2026] [security2:error] [pid 884009:tid 884160] [client 77.110.127.138:61106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkpwAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.915883 2026] [security2:error] [pid 884009:tid 884243] [client 50.116.65.227:40892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4S4BKaHUf6J8d3elJkqwAAAOs"]
[Mon Jul 20 06:21:52.927218 2026] [security2:error] [pid 884009:tid 884184] [client 50.116.65.227:29832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4S4BKaHUf6J8d3elJkrQAAALA"]
[Mon Jul 20 06:21:52.949294 2026] [security2:error] [pid 884009:tid 884074] [remote 100.42.189.89:44062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4S4BKaHUf6J8d3elJkrgAApT8"]
[Mon Jul 20 06:21:53.072268 2026] [security2:error] [pid 884009:tid 884085] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S4RKaHUf6J8d3elJkswAAjEo"]
[Mon Jul 20 06:21:53.072407 2026] [security2:error] [pid 884009:tid 884147] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S4RKaHUf6J8d3elJkswAAjEo"]
[Mon Jul 20 06:21:53.117371 2026] [security2:error] [pid 884009:tid 884267] [client 77.110.127.138:61108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJktgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.117471 2026] [security2:error] [pid 884009:tid 884267] [client 77.110.127.138:61108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJktgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.151951 2026] [security2:error] [pid 884009:tid 884053] [remote 100.42.189.89:44062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4S4RKaHUf6J8d3elJkvQAAoio"], referer: https://jvcmotorsports.com/wp-login.php
[Mon Jul 20 06:21:53.168634 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJkwAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.168769 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJkwAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.223152 2026] [security2:error] [pid 884009:tid 884240] [client 14.225.17.146:49990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJksAAAAOg"], referer: http://oldracelimited.com/Wp
[Mon Jul 20 06:21:53.319575 2026] [security2:error] [pid 884009:tid 884261] [client 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4S4RKaHUf6J8d3elJkzgAAAP0"]
[Mon Jul 20 06:21:53.334521 2026] [security2:error] [pid 884009:tid 884217] [client 77.110.127.138:61110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk0QAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.334618 2026] [security2:error] [pid 884009:tid 884217] [client 77.110.127.138:61110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk0QAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.412941 2026] [security2:error] [pid 884009:tid 884196] [client 34.74.185.202:49683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S4RKaHUf6J8d3elJk3gAAALw"]
[Mon Jul 20 06:21:53.423024 2026] [security2:error] [pid 884009:tid 884244] [client 57.141.18.107:24620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3BKaHUf6J8d3elJjLAAA7Cw"]
[Mon Jul 20 06:21:53.490247 2026] [security2:error] [pid 884009:tid 884266] [client 14.225.17.146:56900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk4AAAAQI"], referer: https://keywayconstructionclt.com/Wp
[Mon Jul 20 06:21:53.515929 2026] [security2:error] [pid 884009:tid 884145] [client 77.110.127.138:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk5AAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.516025 2026] [security2:error] [pid 884009:tid 884145] [client 77.110.127.138:61112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk5AAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.563162 2026] [security2:error] [pid 884009:tid 884214] [client 50.116.65.227:29854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk2AAAAM4"]
[Mon Jul 20 06:21:53.706348 2026] [security2:error] [pid 884009:tid 884147] [client 171.22.217.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk2QAAAIw"]
[Mon Jul 20 06:21:53.733149 2026] [security2:error] [pid 884009:tid 884247] [client 171.22.217.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk2wAAAO8"]
[Mon Jul 20 06:21:53.733982 2026] [security2:error] [pid 884009:tid 884181] [client 14.225.17.146:56798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk5gAAAK0"], referer: http://bbwipartnerconference.com/Wp
[Mon Jul 20 06:21:53.749549 2026] [security2:error] [pid 884009:tid 884265] [client 50.116.65.227:29864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk6AAAAQE"]
[Mon Jul 20 06:21:53.817472 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.4:63342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjXAAAwQs"]
[Mon Jul 20 06:21:53.820191 2026] [security2:error] [pid 884009:tid 884154] [client 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4S4RKaHUf6J8d3elJlAwAAAJM"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:21:53.869029 2026] [security2:error] [pid 884009:tid 884171] [client 34.74.185.202:52831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S4RKaHUf6J8d3elJlCAAAAKM"]
[Mon Jul 20 06:21:53.892179 2026] [security2:error] [pid 884009:tid 884180] [client 185.132.186.64:32343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/dedi1.php"] [unique_id "al4S4RKaHUf6J8d3elJlCgAAAKw"]
[Mon Jul 20 06:21:53.952338 2026] [security2:error] [pid 884009:tid 884213] [client 50.116.65.227:40904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4S4RKaHUf6J8d3elJlEgAAAM0"]
[Mon Jul 20 06:21:53.962740 2026] [security2:error] [pid 884009:tid 884168] [client 50.116.65.227:29894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4S4RKaHUf6J8d3elJlFAAAAKE"]
[Mon Jul 20 06:21:54.306574 2026] [http2:info] [pid 915741:tid 915741] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:21:54.400862 2026] [security2:error] [pid 884009:tid 884237] [client 57.141.18.12:33226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjfQAA5V8"]
[Mon Jul 20 06:21:54.569234 2026] [security2:error] [pid 915741:tid 915743] [remote 188.40.28.4:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4S4q-615n1P-attmyuMAABjwE"]
[Mon Jul 20 06:21:54.673402 2026] [security2:error] [pid 884009:tid 884166] [client 57.141.18.51:63390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjlwAAn2w"]
[Mon Jul 20 06:21:54.747284 2026] [security2:error] [pid 884009:tid 884141] [client 57.141.18.43:50208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjmAAAhmo"]
[Mon Jul 20 06:21:54.851216 2026] [security2:error] [pid 915741:tid 915745] [remote 188.40.28.4:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4S4q-615n1P-attmyuNQABngM"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:21:54.957601 2026] [security2:error] [pid 915741:tid 915880] [client 34.74.185.202:49462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S4q-615n1P-attmyuOwAAAZg"]
[Mon Jul 20 06:21:55.093263 2026] [security2:error] [pid 915741:tid 915879] [client 14.225.17.146:49963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4S4q-615n1P-attmyuPAAAAZc"], referer: http://northbrookcpa.ca/Wp
[Mon Jul 20 06:21:55.103315 2026] [autoindex:error] [pid 915741:tid 915900] [client 171.22.217.12:0] AH01276: Cannot serve directory /home3/soloceos/public_html/wp-content/themes/Divi/includes/builder/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:21:55.111604 2026] [autoindex:error] [pid 884009:tid 884218] [client 171.22.217.12:0] AH01276: Cannot serve directory /home3/soloceos/public_html/wp-content/themes/Divi/includes/builder/frontend-builder/assets/vendors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:21:55.249464 2026] [security2:error] [pid 884009:tid 884193] [client 34.73.38.214:56125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S4xKaHUf6J8d3elJlgQAAALk"]
[Mon Jul 20 06:21:55.367540 2026] [security2:error] [pid 884009:tid 884250] [client 57.141.18.76:57522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3hKaHUf6J8d3elJj0wAA8h8"]
[Mon Jul 20 06:21:55.502519 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.90:27233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/adminfusm.php"] [unique_id "al4S4xKaHUf6J8d3elJlkwAAAME"]
[Mon Jul 20 06:21:55.519151 2026] [security2:error] [pid 884009:tid 884140] [client 14.225.17.146:57007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4S4hKaHUf6J8d3elJlRwAAAIU"], referer: http://idigress.agency/Wp
[Mon Jul 20 06:21:55.620226 2026] [security2:error] [pid 884009:tid 884253] [client 57.141.18.119:26974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3hKaHUf6J8d3elJj7AAA9T0"]
[Mon Jul 20 06:21:55.815221 2026] [security2:error] [pid 884009:tid 884199] [client 34.73.38.214:61306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S4xKaHUf6J8d3elJlqQAAAL8"]
[Mon Jul 20 06:21:56.075019 2026] [security2:error] [pid 915741:tid 915929] [client 112.208.70.94:44677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S5K-615n1P-attmyuVwAAAck"]
[Mon Jul 20 06:21:56.075162 2026] [security2:error] [pid 915741:tid 915929] [client 112.208.70.94:44677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S5K-615n1P-attmyuVwAAAck"]
[Mon Jul 20 06:21:56.134686 2026] [security2:error] [pid 884009:tid 884176] [client 34.74.185.202:59377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S5BKaHUf6J8d3elJlvQAAAKg"]
[Mon Jul 20 06:21:56.362544 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:53979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4S5BKaHUf6J8d3elJlwQAAAKk"], referer: http://mcg.homes/Wp
[Mon Jul 20 06:21:56.376093 2026] [security2:error] [pid 884009:tid 884183] [client 171.60.139.123:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S5BKaHUf6J8d3elJlzQAAAK8"]
[Mon Jul 20 06:21:56.376224 2026] [security2:error] [pid 884009:tid 884183] [client 171.60.139.123:60959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S5BKaHUf6J8d3elJlzQAAAK8"]
[Mon Jul 20 06:21:56.436480 2026] [security2:error] [pid 915741:tid 915976] [client 34.73.38.214:64537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S5K-615n1P-attmyuaAAAAfg"]
[Mon Jul 20 06:21:56.548531 2026] [security2:error] [pid 884009:tid 884185] [client 57.141.18.2:24532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkQQAAsVc"]
[Mon Jul 20 06:21:56.549205 2026] [security2:error] [pid 915741:tid 915759] [remote 47.86.33.52:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S5K-615n1P-attmyucAABwxE"]
[Mon Jul 20 06:21:56.563634 2026] [security2:error] [pid 884009:tid 884162] [client 57.141.18.111:44928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkSQAAmxE"]
[Mon Jul 20 06:21:56.650697 2026] [security2:error] [pid 915741:tid 915954] [client 113.44.115.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4S5K-615n1P-attmyuXAAB4gw"], referer: https://www.aleishapenny.ca/listing/page/258?paged=258&view=list
[Mon Jul 20 06:21:57.017870 2026] [security2:error] [pid 884009:tid 884074] [remote 8.217.108.67:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S5RKaHUf6J8d3elJl5gAAjz8"]
[Mon Jul 20 06:21:57.094714 2026] [security2:error] [pid 915741:tid 915883] [client 34.74.185.202:55888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S5a-615n1P-attmyuegAAAZs"]
[Mon Jul 20 06:21:57.126344 2026] [security2:error] [pid 915741:tid 915884] [client 185.132.186.74:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/click.php"] [unique_id "al4S5a-615n1P-attmyufAAAAZw"]
[Mon Jul 20 06:21:57.146235 2026] [security2:error] [pid 884009:tid 884223] [client 52.187.75.220:22850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4S5RKaHUf6J8d3elJl7QAAANc"]
[Mon Jul 20 06:21:57.219064 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:59583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S5RKaHUf6J8d3elJl8wAAAQQ"]
[Mon Jul 20 06:21:57.330380 2026] [security2:error] [pid 884009:tid 884267] [client 52.187.75.220:22850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4S5RKaHUf6J8d3elJl-AAAAQM"]
[Mon Jul 20 06:21:57.456230 2026] [security2:error] [pid 915741:tid 915892] [client 45.116.69.230:52989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyujgAAAaQ"]
[Mon Jul 20 06:21:57.456704 2026] [security2:error] [pid 915741:tid 915892] [client 45.116.69.230:52989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyujgAAAaQ"]
[Mon Jul 20 06:21:57.579054 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S5RKaHUf6J8d3elJl8QAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:57.781241 2026] [security2:error] [pid 915741:tid 915937] [client 34.74.185.202:59288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S5a-615n1P-attmyumgAAAdE"]
[Mon Jul 20 06:21:57.861737 2026] [security2:error] [pid 915741:tid 915939] [client 103.141.108.143:53695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyunAAAAdM"]
[Mon Jul 20 06:21:57.861888 2026] [security2:error] [pid 915741:tid 915939] [client 103.141.108.143:53695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyunAAAAdM"]
[Mon Jul 20 06:21:57.956760 2026] [security2:error] [pid 915741:tid 915770] [remote 47.86.33.52:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S5a-615n1P-attmyunwAB6Rw"], referer: https://mail.yok.mqz.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:58.009871 2026] [security2:error] [pid 884009:tid 884199] [client 34.73.38.214:49883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S5hKaHUf6J8d3elJmFwAAAL8"]
[Mon Jul 20 06:21:58.123162 2026] [security2:error] [pid 884009:tid 884127] [remote 8.217.108.67:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S5hKaHUf6J8d3elJmHQAA93Q"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:21:58.151503 2026] [security2:error] [pid 884009:tid 884065] [remote 148.251.82.243:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.82.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4S5hKaHUf6J8d3elJmHwAAljY"]
[Mon Jul 20 06:21:58.336452 2026] [security2:error] [pid 884009:tid 884143] [client 34.74.185.202:61777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S5hKaHUf6J8d3elJmJgAAAIg"]
[Mon Jul 20 06:21:58.356719 2026] [security2:error] [pid 884009:tid 884115] [remote 148.251.82.243:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.82.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4S5hKaHUf6J8d3elJmKgAA9mg"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 06:21:58.486539 2026] [security2:error] [pid 884009:tid 884206] [client 45.157.112.60:29877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S5hKaHUf6J8d3elJmMgAAAMY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:58.740756 2026] [security2:error] [pid 915741:tid 915898] [client 185.132.186.88:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/template-less.php"] [unique_id "al4S5q-615n1P-attmyuvgAAAao"]
[Mon Jul 20 06:21:58.758986 2026] [security2:error] [pid 884009:tid 884220] [client 57.141.18.61:40446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S4hKaHUf6J8d3elJlLwAA1C4"]
[Mon Jul 20 06:21:58.959326 2026] [security2:error] [pid 915741:tid 915953] [client 52.109.20.47:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4S5a-615n1P-attmyuoAAAAeE"]
[Mon Jul 20 06:21:58.984050 2026] [security2:error] [pid 915741:tid 915779] [remote 41.186.86.12:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4S5q-615n1P-attmyuxgACDSU"]
[Mon Jul 20 06:21:58.984852 2026] [security2:error] [pid 884009:tid 884167] [client 34.74.185.202:61125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S5hKaHUf6J8d3elJmSgAAAKA"]
[Mon Jul 20 06:21:58.987891 2026] [security2:error] [pid 915741:tid 915920] [client 52.109.20.47:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4S5q-615n1P-attmyuxwAAAcA"]
[Mon Jul 20 06:21:59.201769 2026] [security2:error] [pid 884009:tid 884266] [client 57.141.18.5:48042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S4hKaHUf6J8d3elJlWAABAmY"]
[Mon Jul 20 06:21:59.359957 2026] [security2:error] [pid 884009:tid 884201] [client 77.110.127.138:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S5xKaHUf6J8d3elJmXQAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:59.360065 2026] [security2:error] [pid 884009:tid 884201] [client 77.110.127.138:61138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S5xKaHUf6J8d3elJmXQAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:59.443832 2026] [security2:error] [pid 915741:tid 915915] [client 178.152.178.232:37396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S56-615n1P-attmyu0wAAAbs"]
[Mon Jul 20 06:21:59.450960 2026] [security2:error] [pid 915741:tid 915915] [client 178.152.178.232:37396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S56-615n1P-attmyu0wAAAbs"]
[Mon Jul 20 06:21:59.473774 2026] [security2:error] [pid 915741:tid 915781] [remote 41.186.86.12:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4S56-615n1P-attmyu1gAB1yc"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 06:21:59.960128 2026] [security2:error] [pid 884009:tid 884152] [client 34.73.38.214:61676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S5xKaHUf6J8d3elJmgAAAAJE"]
[Mon Jul 20 06:21:59.991439 2026] [security2:error] [pid 884009:tid 884261] [client 57.141.18.64:39490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S4xKaHUf6J8d3elJlhAAA_Rg"]
[Mon Jul 20 06:22:00.061152 2026] [security2:error] [pid 915741:tid 915955] [client 34.74.185.202:53145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S6K-615n1P-attmyu5QAAAeM"]
[Mon Jul 20 06:22:00.119932 2026] [security2:error] [pid 884009:tid 884255] [client 34.73.38.214:63913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S6BKaHUf6J8d3elJmiwAAAPc"]
[Mon Jul 20 06:22:00.244897 2026] [security2:error] [pid 915741:tid 915962] [client 27.96.94.195:37799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S6K-615n1P-attmyu6wAAAeo"]
[Mon Jul 20 06:22:00.245026 2026] [security2:error] [pid 915741:tid 915962] [client 27.96.94.195:37799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S6K-615n1P-attmyu6wAAAeo"]
[Mon Jul 20 06:22:00.346052 2026] [security2:error] [pid 884009:tid 884228] [client 185.132.186.66:20531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/pomo/alfa-rex.php"] [unique_id "al4S6BKaHUf6J8d3elJmmAAAANw"]
[Mon Jul 20 06:22:00.519883 2026] [security2:error] [pid 884009:tid 884260] [client 34.74.185.202:57510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S6BKaHUf6J8d3elJmoAAAAPw"]
[Mon Jul 20 06:22:00.828808 2026] [security2:error] [pid 915741:tid 915953] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4S6K-615n1P-attmyu9gAAAeE"]
[Mon Jul 20 06:22:00.953629 2026] [security2:error] [pid 915741:tid 915792] [remote 103.187.169.251:52438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4S6K-615n1P-attmyvBAABvDI"]
[Mon Jul 20 06:22:01.094673 2026] [security2:error] [pid 884009:tid 884195] [client 14.225.17.146:60057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4S6BKaHUf6J8d3elJmtwAAALs"], referer: http://laceycaraccident.com/Wp
[Mon Jul 20 06:22:01.166569 2026] [security2:error] [pid 884009:tid 884265] [client 104.234.53.62:48505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4S6RKaHUf6J8d3elJmxQAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:01.223674 2026] [security2:error] [pid 884009:tid 884140] [client 34.73.38.214:60701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S6RKaHUf6J8d3elJmygAAAIU"]
[Mon Jul 20 06:22:01.226385 2026] [security2:error] [pid 884009:tid 884157] [client 34.73.38.214:60767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S6RKaHUf6J8d3elJmywAAAJY"]
[Mon Jul 20 06:22:01.303363 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:9703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S6a-615n1P-attmyvCQAAAfU"]
[Mon Jul 20 06:22:01.303508 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:9703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S6a-615n1P-attmyvCQAAAfU"]
[Mon Jul 20 06:22:01.363174 2026] [security2:error] [pid 915741:tid 915793] [remote 103.187.169.251:52438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvCwABzzM"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:22:01.389222 2026] [security2:error] [pid 915741:tid 915794] [remote 113.160.142.119:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvDAAB0TQ"]
[Mon Jul 20 06:22:01.418041 2026] [security2:error] [pid 915741:tid 915795] [remote 97.74.93.24:39678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvDgAB6TU"]
[Mon Jul 20 06:22:01.433130 2026] [security2:error] [pid 915741:tid 915956] [client 14.225.17.146:63840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4S6a-615n1P-attmyvCAAAAeQ"], referer: http://lifeisbetterlakeside.com/Wp
[Mon Jul 20 06:22:01.787853 2026] [security2:error] [pid 915741:tid 915932] [client 50.116.65.227:60028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S6a-615n1P-attmyvFwAAAcw"]
[Mon Jul 20 06:22:01.801965 2026] [security2:error] [pid 884009:tid 884238] [client 50.116.65.227:56886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S6RKaHUf6J8d3elJm4wAAALE"]
[Mon Jul 20 06:22:01.857917 2026] [security2:error] [pid 915741:tid 915799] [remote 97.74.93.24:39678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvGwAB6jk"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 06:22:01.888704 2026] [security2:error] [pid 915741:tid 915800] [remote 113.160.142.119:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvHgABtDo"], referer: https://iagdevelopments.com/wp-login.php
[Mon Jul 20 06:22:01.963610 2026] [security2:error] [pid 915741:tid 915889] [client 185.132.186.66:20141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/abcd.php"] [unique_id "al4S6a-615n1P-attmyvIAAAAaE"]
[Mon Jul 20 06:22:02.036119 2026] [security2:error] [pid 884009:tid 884209] [client 57.141.18.84:37316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5RKaHUf6J8d3elJl-wAAyS8"]
[Mon Jul 20 06:22:02.088325 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4S6a-615n1P-attmyvHwAAAds"]
[Mon Jul 20 06:22:02.222103 2026] [security2:error] [pid 884009:tid 884156] [client 171.61.165.146:29108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S6hKaHUf6J8d3elJm9QAAAJU"]
[Mon Jul 20 06:22:02.222294 2026] [security2:error] [pid 884009:tid 884156] [client 171.61.165.146:29108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S6hKaHUf6J8d3elJm9QAAAJU"]
[Mon Jul 20 06:22:02.459242 2026] [security2:error] [pid 915741:tid 915937] [client 34.73.38.214:54380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S6q-615n1P-attmyvNgAAAdE"]
[Mon Jul 20 06:22:02.464375 2026] [security2:error] [pid 915741:tid 915961] [client 34.73.38.214:60401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S6q-615n1P-attmyvNwAAAek"]
[Mon Jul 20 06:22:02.599699 2026] [security2:error] [pid 915741:tid 915957] [client 57.141.18.50:36468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5a-615n1P-attmyuoQAB5R0"]
[Mon Jul 20 06:22:02.821997 2026] [security2:error] [pid 884009:tid 884166] [client 57.141.18.123:47854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5hKaHUf6J8d3elJmHAAAn00"]
[Mon Jul 20 06:22:02.970722 2026] [security2:error] [pid 884009:tid 884230] [client 34.73.38.214:53272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S6hKaHUf6J8d3elJnEQAAAN4"]
[Mon Jul 20 06:22:03.312792 2026] [security2:error] [pid 884009:tid 884235] [client 34.73.38.214:60717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S6xKaHUf6J8d3elJnIwAAAOM"]
[Mon Jul 20 06:22:03.571954 2026] [security2:error] [pid 884009:tid 884197] [client 185.132.186.84:22159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/admin-footer.php"] [unique_id "al4S6xKaHUf6J8d3elJnMgAAAL0"]
[Mon Jul 20 06:22:03.637375 2026] [security2:error] [pid 915741:tid 915918] [client 57.141.18.51:64692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5q-615n1P-attmyuwwABviQ"]
[Mon Jul 20 06:22:03.763215 2026] [security2:error] [pid 915741:tid 915924] [client 114.119.133.182:33125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.geo-ver.ca"] [uri "/robots.txt"] [unique_id "al4S66-615n1P-attmyvUwAAAcQ"], referer: http://www.geo-ver.ca/robots.txt
[Mon Jul 20 06:22:03.798881 2026] [security2:error] [pid 915741:tid 915809] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S66-615n1P-attmyvVAABzkM"]
[Mon Jul 20 06:22:03.799145 2026] [security2:error] [pid 915741:tid 915934] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S66-615n1P-attmyvVAABzkM"]
[Mon Jul 20 06:22:03.998794 2026] [security2:error] [pid 884009:tid 884232] [client 34.73.38.214:60776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S6xKaHUf6J8d3elJnRQAAAOA"]
[Mon Jul 20 06:22:04.063286 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7K-615n1P-attmyvWwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:04.063404 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7K-615n1P-attmyvWwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:04.465355 2026] [security2:error] [pid 884009:tid 884213] [client 57.141.18.62:54882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5xKaHUf6J8d3elJmegAAzVA"]
[Mon Jul 20 06:22:04.524031 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.33:45726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S56-615n1P-attmyu4gACBCo"]
[Mon Jul 20 06:22:04.603039 2026] [security2:error] [pid 884009:tid 884209] [client 34.73.38.214:61783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S7BKaHUf6J8d3elJnYgAAAMk"]
[Mon Jul 20 06:22:05.116119 2026] [security2:error] [pid 915741:tid 915883] [client 34.73.38.214:62459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S7a-615n1P-attmyvxgAAAZs"]
[Mon Jul 20 06:22:05.179882 2026] [security2:error] [pid 915741:tid 915907] [client 14.225.17.146:60138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4S7K-615n1P-attmyvwQAAAbM"], referer: http://sesamegreenbeans.com/Wp
[Mon Jul 20 06:22:05.249041 2026] [security2:error] [pid 884009:tid 884259] [client 57.141.18.103:23890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S6BKaHUf6J8d3elJmpwAA-38"]
[Mon Jul 20 06:22:05.718242 2026] [security2:error] [pid 915741:tid 915761] [remote 182.77.62.24:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gearwaterproof.com"] [uri "/wp-login.php"] [unique_id "al4S7a-615n1P-attmyv1AABvBM"]
[Mon Jul 20 06:22:05.952436 2026] [security2:error] [pid 884009:tid 884158] [client 127.0.0.1:33958] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4S7RKaHUf6J8d3elJnnQAAAJc"], referer: https://www.google.com/
[Mon Jul 20 06:22:06.074335 2026] [security2:error] [pid 915741:tid 915873] [client 185.132.186.79:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/bypass.php"] [unique_id "al4S7q-615n1P-attmyv6wAAAZE"]
[Mon Jul 20 06:22:06.220724 2026] [security2:error] [pid 915741:tid 915985] [client 14.225.17.146:59336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4S7q-615n1P-attmyv6gAAAgE"], referer: http://thechancersband.com/Wp
[Mon Jul 20 06:22:06.240183 2026] [security2:error] [pid 915741:tid 915899] [client 14.225.17.146:59332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4S7q-615n1P-attmyv6QAAAas"], referer: https://sesamegreenbeans.com/Wp
[Mon Jul 20 06:22:06.244561 2026] [security2:error] [pid 915741:tid 915757] [remote 182.77.62.24:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gearwaterproof.com"] [uri "/wp-login.php"] [unique_id "al4S7q-615n1P-attmyv8AAB3g8"], referer: https://gearwaterproof.com/wp-login.php
[Mon Jul 20 06:22:06.396080 2026] [security2:error] [pid 915741:tid 915981] [client 34.73.38.214:62797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S7q-615n1P-attmywAQAAAf0"]
[Mon Jul 20 06:22:06.625105 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7q-615n1P-attmywCgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:06.625263 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:61165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7q-615n1P-attmywCgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:07.129431 2026] [security2:error] [pid 915741:tid 915982] [client 171.60.139.123:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywHAAAAf4"]
[Mon Jul 20 06:22:07.129552 2026] [security2:error] [pid 915741:tid 915982] [client 171.60.139.123:61473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywHAAAAf4"]
[Mon Jul 20 06:22:07.235601 2026] [security2:error] [pid 884009:tid 884203] [client 57.141.18.76:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S6hKaHUf6J8d3elJnBwAAwws"]
[Mon Jul 20 06:22:07.418462 2026] [security2:error] [pid 884009:tid 884235] [client 34.73.38.214:59313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S7xKaHUf6J8d3elJn2gAAAOM"]
[Mon Jul 20 06:22:07.432732 2026] [security2:error] [pid 915741:tid 915930] [client 14.225.17.146:59253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4S7a-615n1P-attmyv3AAAAco"], referer: http://xp-design.co/Wp
[Mon Jul 20 06:22:07.485339 2026] [security2:error] [pid 915741:tid 915941] [client 139.28.219.68:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "socialputty.co"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywOQAAAdU"]
[Mon Jul 20 06:22:07.485509 2026] [security2:error] [pid 915741:tid 915941] [client 139.28.219.68:36772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "socialputty.co"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywOQAAAdU"]
[Mon Jul 20 06:22:07.598760 2026] [security2:error] [pid 884009:tid 884115] [remote 57.141.18.42:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2998026"] [unique_id "al4S7xKaHUf6J8d3elJn4QAAqmg"]
[Mon Jul 20 06:22:07.666351 2026] [security2:error] [pid 915741:tid 915939] [client 14.225.17.146:59426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywMQAAAdM"], referer: http://windowtx.com/Wp
[Mon Jul 20 06:22:07.746089 2026] [security2:error] [pid 884009:tid 884233] [client 57.141.18.29:21200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S6xKaHUf6J8d3elJnJAAA4SY"]
[Mon Jul 20 06:22:07.836437 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywOwAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:07.877965 2026] [security2:error] [pid 915741:tid 915985] [client 185.132.186.58:25945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/elementskit.php"] [unique_id "al4S76-615n1P-attmywQAAAAgE"]
[Mon Jul 20 06:22:07.920619 2026] [security2:error] [pid 915741:tid 915910] [client 14.225.17.146:53477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4S7q-615n1P-attmywAgAAAbY"], referer: http://slutilities.com/Wp
[Mon Jul 20 06:22:07.979594 2026] [security2:error] [pid 915741:tid 915921] [client 57.141.18.50:36472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S66-615n1P-attmyvUQABwUI"]
[Mon Jul 20 06:22:08.228330 2026] [security2:error] [pid 915741:tid 915928] [client 57.141.18.56:39790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7K-615n1P-attmyvVwAByEQ"]
[Mon Jul 20 06:22:08.270148 2026] [security2:error] [pid 915741:tid 915963] [client 34.73.38.214:63032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S8K-615n1P-attmywUAAAAes"]
[Mon Jul 20 06:22:08.334670 2026] [fcgid:warn] [pid 915741:tid 915951] (70014)End of file found: [client 66.132.172.201:58794] mod_fcgid: can't get data from http client
[Mon Jul 20 06:22:08.615313 2026] [security2:error] [pid 884009:tid 884268] [client 103.141.108.143:54173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S8BKaHUf6J8d3elJoBAAAAQQ"]
[Mon Jul 20 06:22:08.615574 2026] [security2:error] [pid 884009:tid 884268] [client 103.141.108.143:54173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S8BKaHUf6J8d3elJoBAAAAQQ"]
[Mon Jul 20 06:22:08.831193 2026] [security2:error] [pid 915741:tid 915962] [client 13.201.64.214:37404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4S8K-615n1P-attmywagAAAeo"]
[Mon Jul 20 06:22:08.842562 2026] [security2:error] [pid 915741:tid 915972] [client 112.208.70.94:45059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywawAAAfQ"]
[Mon Jul 20 06:22:08.842734 2026] [security2:error] [pid 915741:tid 915972] [client 112.208.70.94:45059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywawAAAfQ"]
[Mon Jul 20 06:22:08.843211 2026] [security2:error] [pid 884009:tid 884236] [client 66.249.68.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.zzzwillowzzz.com"] [uri "/index.php"] [unique_id "al4S7xKaHUf6J8d3elJnyQAA5BM"]
[Mon Jul 20 06:22:08.862926 2026] [security2:error] [pid 915741:tid 915918] [client 45.116.69.230:53512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywbAAAAb4"]
[Mon Jul 20 06:22:08.863124 2026] [security2:error] [pid 915741:tid 915918] [client 45.116.69.230:53512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywbAAAAb4"]
[Mon Jul 20 06:22:08.899803 2026] [security2:error] [pid 884009:tid 884221] [client 34.73.38.214:63616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S8BKaHUf6J8d3elJoDgAAANU"]
[Mon Jul 20 06:22:08.941368 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:46886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S8BKaHUf6J8d3elJoEQAAAOw"]
[Mon Jul 20 06:22:08.952278 2026] [security2:error] [pid 915741:tid 915988] [client 50.116.65.227:46900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S8K-615n1P-attmywcQAAAgQ"]
[Mon Jul 20 06:22:08.991407 2026] [security2:error] [pid 915741:tid 915932] [client 103.153.183.69:61772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env%00.php"] [unique_id "al4S8K-615n1P-attmywdwAAAcw"], referer: https://www.facebook.com/
[Mon Jul 20 06:22:09.024746 2026] [security2:error] [pid 915741:tid 915893] [client 57.141.18.5:62736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7K-615n1P-attmyvdwABpU4"]
[Mon Jul 20 06:22:09.087381 2026] [security2:error] [pid 915741:tid 915983] [client 50.116.65.227:26114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4S8a-615n1P-attmywfAAAAf8"]
[Mon Jul 20 06:22:09.097688 2026] [security2:error] [pid 884009:tid 884177] [client 50.116.65.227:46902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4S8RKaHUf6J8d3elJoGwAAAMA"]
[Mon Jul 20 06:22:09.171445 2026] [security2:error] [pid 884009:tid 884247] [client 14.225.17.146:60046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4S7xKaHUf6J8d3elJn7wAAAO8"], referer: http://mourgroup.com/Wp
[Mon Jul 20 06:22:09.450201 2026] [security2:error] [pid 915741:tid 915800] [remote 192.241.143.148:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4S8a-615n1P-attmywjAAB_Do"]
[Mon Jul 20 06:22:09.580852 2026] [security2:error] [pid 915741:tid 915947] [client 66.249.89.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4S8a-615n1P-attmywhgAB2zY"], referer: https://tiokubito.cl/producto/preventa-happy-life-one-piece-monkey-d-luffy/
[Mon Jul 20 06:22:09.600558 2026] [security2:error] [pid 915741:tid 915939] [client 103.153.183.69:22108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..\\xef\\xbc\\x8f../etc/passwd"] [unique_id "al4S8a-615n1P-attmywkgAAAdM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:22:09.622985 2026] [security2:error] [pid 915741:tid 915768] [remote 192.241.143.148:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4S8a-615n1P-attmywlAABoRo"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:22:09.693420 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.97:54245] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/js/1.php7"] [unique_id "al4S8RKaHUf6J8d3elJoNAAAAME"]
[Mon Jul 20 06:22:09.693534 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.97:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/1.php7"] [unique_id "al4S8RKaHUf6J8d3elJoNAAAAME"]
[Mon Jul 20 06:22:09.737549 2026] [core:error] [pid 915741:tid 915916] [client 103.153.183.69:22108] AH10244: invalid URI path (/.%2e/etc/passwd?_=xefuj0ft&v=366l3), referer: https://t.co/euaya6jspt
[Mon Jul 20 06:22:09.740781 2026] [security2:error] [pid 915741:tid 915918] [client 127.0.0.1:15548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4S8a-615n1P-attmywmQAAAb4"], referer: https://t.co/euaya6jspt
[Mon Jul 20 06:22:09.948273 2026] [security2:error] [pid 884009:tid 884248] [client 13.201.64.214:37414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4S8RKaHUf6J8d3elJoPwAAAPA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:10.337349 2026] [security2:error] [pid 915741:tid 915803] [remote 192.241.143.148:37730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4S8q-615n1P-attmywpQAB0T0"]
[Mon Jul 20 06:22:10.364551 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.102:29900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7a-615n1P-attmyv3QAB5BQ"]
[Mon Jul 20 06:22:10.408641 2026] [security2:error] [pid 884009:tid 884182] [client 34.73.38.214:61847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S8hKaHUf6J8d3elJoXAAAAK4"]
[Mon Jul 20 06:22:10.530237 2026] [security2:error] [pid 915741:tid 915778] [remote 192.241.143.148:37730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4S8q-615n1P-attmywrAABpiQ"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 06:22:10.530773 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S8q-615n1P-attmywogAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:10.576359 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:61688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoYAAAAJo"], referer: http://processorstudio.com/Wp
[Mon Jul 20 06:22:10.627027 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:59952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoWwAAAKk"], referer: http://savilerowtravel.com/Wp
[Mon Jul 20 06:22:10.687120 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S8q-615n1P-attmywsgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:10.687248 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:61185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S8q-615n1P-attmywsgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:10.741596 2026] [security2:error] [pid 915741:tid 915878] [client 34.73.38.214:63273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S8q-615n1P-attmywtgAAAZY"]
[Mon Jul 20 06:22:11.368992 2026] [security2:error] [pid 884009:tid 884038] [remote 156.59.198.136:22472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsafety.ca"] [uri "/wp-content/uploads/2025/08/KSS-Sustainability-Policy.docx-1.pdf"] [unique_id "al4S8xKaHUf6J8d3elJogwAAkxs"]
[Mon Jul 20 06:22:11.430041 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:52547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4S86-615n1P-attmyw1QAAAdI"], referer: https://processorstudio.com/Wp
[Mon Jul 20 06:22:11.500864 2026] [security2:error] [pid 884009:tid 884193] [client 185.132.186.90:36211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/install.php"] [unique_id "al4S8xKaHUf6J8d3elJoiQAAALk"]
[Mon Jul 20 06:22:11.650193 2026] [security2:error] [pid 915741:tid 915987] [client 14.225.17.146:52216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4S86-615n1P-attmyw1gAAAgM"], referer: https://savilerowtravel.com/Wp
[Mon Jul 20 06:22:11.739402 2026] [security2:error] [pid 915741:tid 915877] [client 68.235.52.68:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4S86-615n1P-attmyw3AAAAZU"]
[Mon Jul 20 06:22:11.739548 2026] [security2:error] [pid 915741:tid 915877] [client 68.235.52.68:50564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4S86-615n1P-attmyw3AAAAZU"]
[Mon Jul 20 06:22:11.777668 2026] [security2:error] [pid 915741:tid 915969] [client 14.225.17.146:61707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4S86-615n1P-attmyw2QAAAfE"], referer: http://thefriendlyspreadsheet.com/Wp
[Mon Jul 20 06:22:11.880151 2026] [security2:error] [pid 884009:tid 884060] [remote 152.228.213.32:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4S8xKaHUf6J8d3elJongAA5jE"]
[Mon Jul 20 06:22:11.992451 2026] [security2:error] [pid 884009:tid 884144] [client 41.173.37.102:10121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S8xKaHUf6J8d3elJoowAAAIk"]
[Mon Jul 20 06:22:11.992569 2026] [security2:error] [pid 884009:tid 884144] [client 41.173.37.102:10121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S8xKaHUf6J8d3elJoowAAAIk"]
[Mon Jul 20 06:22:12.082462 2026] [security2:error] [pid 884009:tid 884048] [remote 152.228.213.32:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4S9BKaHUf6J8d3elJopQAA6CU"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:22:12.265120 2026] [security2:error] [pid 884009:tid 884216] [client 57.141.18.38:58338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7xKaHUf6J8d3elJn5gAA0BI"]
[Mon Jul 20 06:22:12.354164 2026] [security2:error] [pid 915741:tid 915923] [client 57.141.18.88:40484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywRQABwwQ"]
[Mon Jul 20 06:22:12.379810 2026] [security2:error] [pid 884009:tid 884174] [client 14.225.17.146:50999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoWgAAAKY"], referer: http://mollycahill.com/Wp
[Mon Jul 20 06:22:12.488143 2026] [security2:error] [pid 915741:tid 915991] [client 57.141.18.37:26120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywRgACByk"]
[Mon Jul 20 06:22:12.624810 2026] [security2:error] [pid 884009:tid 884115] [remote 188.166.241.141:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S9BKaHUf6J8d3elJotwAA0mg"]
[Mon Jul 20 06:22:12.680520 2026] [security2:error] [pid 915741:tid 915919] [client 51.91.255.78:36234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyxAQAAAb8"]
[Mon Jul 20 06:22:12.827483 2026] [security2:error] [pid 915741:tid 915985] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyw_AAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:12.836185 2026] [security2:error] [pid 884009:tid 884266] [client 57.141.18.49:64770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8BKaHUf6J8d3elJn_AABAm0"]
[Mon Jul 20 06:22:12.872943 2026] [security2:error] [pid 915741:tid 915824] [remote 5.223.65.249:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9K-615n1P-attmyxFAAB9lI"]
[Mon Jul 20 06:22:13.000024 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:52558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyxEwAAAfU"], referer: http://alexsandbergmusic.com/Wp
[Mon Jul 20 06:22:13.056242 2026] [security2:error] [pid 884009:tid 884043] [remote 188.166.241.141:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S9RKaHUf6J8d3elJoxQAA4yA"], referer: https://mail.ait.afz.mybluehost.me/wp-login.php
[Mon Jul 20 06:22:13.103812 2026] [security2:error] [pid 884009:tid 884094] [remote 202.51.202.242:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4S9RKaHUf6J8d3elJoxgAA21M"]
[Mon Jul 20 06:22:13.278094 2026] [security2:error] [pid 915741:tid 915828] [remote 5.223.65.249:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9a-615n1P-attmyxJgAB3lY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:13.291815 2026] [security2:error] [pid 915741:tid 915884] [client 171.61.165.146:19630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9a-615n1P-attmyxJwAAAZw"]
[Mon Jul 20 06:22:13.291924 2026] [security2:error] [pid 915741:tid 915884] [client 171.61.165.146:19630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9a-615n1P-attmyxJwAAAZw"]
[Mon Jul 20 06:22:13.320722 2026] [security2:error] [pid 884009:tid 884179] [client 14.225.17.146:61723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4S8xKaHUf6J8d3elJooAAAAKs"], referer: http://alchemygroup.ca/Wp
[Mon Jul 20 06:22:13.324893 2026] [security2:error] [pid 915741:tid 915982] [client 185.132.186.90:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/min.php"] [unique_id "al4S9a-615n1P-attmyxKgAAAf4"]
[Mon Jul 20 06:22:13.372970 2026] [security2:error] [pid 915741:tid 915835] [remote 192.241.143.148:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9a-615n1P-attmyxLQACBF0"]
[Mon Jul 20 06:22:13.432703 2026] [security2:error] [pid 915741:tid 915920] [client 14.225.17.146:58631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyw-QAAAcA"], referer: http://alrowad-hub.net/Wp
[Mon Jul 20 06:22:13.558510 2026] [security2:error] [pid 915741:tid 915836] [remote 192.241.143.148:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9a-615n1P-attmyxMgABnl4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:13.759734 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S9a-615n1P-attmyxNgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:13.759845 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S9a-615n1P-attmyxNgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:13.792490 2026] [security2:error] [pid 884009:tid 884241] [client 57.141.18.21:30066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8RKaHUf6J8d3elJoJAAA6TI"]
[Mon Jul 20 06:22:13.797063 2026] [security2:error] [pid 915741:tid 915951] [client 57.141.18.95:27808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8a-615n1P-attmywgQAB3zU"]
[Mon Jul 20 06:22:14.462062 2026] [security2:error] [pid 884009:tid 884110] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9hKaHUf6J8d3elJpBgAAzmM"]
[Mon Jul 20 06:22:14.462181 2026] [security2:error] [pid 884009:tid 884214] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9hKaHUf6J8d3elJpBgAAzmM"]
[Mon Jul 20 06:22:14.564692 2026] [security2:error] [pid 915741:tid 915929] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxRAAAAck"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:14.570933 2026] [security2:error] [pid 915741:tid 915883] [client 103.153.183.69:18642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../var/www/html/.env"] [unique_id "al4S9q-615n1P-attmyxSgAAAZs"], referer: https://twitter.com/
[Mon Jul 20 06:22:14.773966 2026] [security2:error] [pid 915741:tid 915998] [client 103.153.183.69:18642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../var/www/.env"] [unique_id "al4S9q-615n1P-attmyxUQAAAg4"], referer: https://t.co/01esdha803
[Mon Jul 20 06:22:14.803977 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.90:29620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoXQAA93U"]
[Mon Jul 20 06:22:14.912640 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.78:39372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8q-615n1P-attmywqgAB-j8"]
[Mon Jul 20 06:22:14.988480 2026] [security2:error] [pid 915741:tid 915992] [client 103.153.183.69:18642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//var/www/html/wp-config.php"] [unique_id "al4S9q-615n1P-attmyxXAAAAgg"], referer: https://twitter.com/
[Mon Jul 20 06:22:15.012743 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.3:54888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoZgAAtjc"]
[Mon Jul 20 06:22:15.021836 2026] [security2:error] [pid 915741:tid 915857] [remote 57.141.18.60:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5017581"] [unique_id "al4S96-615n1P-attmyxXgAB-3M"]
[Mon Jul 20 06:22:15.062395 2026] [security2:error] [pid 915741:tid 915934] [client 50.116.65.227:46964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4S96-615n1P-attmyxYQAAAc4"]
[Mon Jul 20 06:22:15.066120 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:52108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxUwAAAds"], referer: http://recruitinginsight.us/Wp
[Mon Jul 20 06:22:15.123679 2026] [security2:error] [pid 915741:tid 915894] [client 185.132.186.97:47321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al4S96-615n1P-attmyxZQAAAaY"]
[Mon Jul 20 06:22:15.245483 2026] [security2:error] [pid 884009:tid 884123] [remote 202.51.202.242:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4S9xKaHUf6J8d3elJpIQAAv3A"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:22:15.854536 2026] [security2:error] [pid 915741:tid 915930] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S96-615n1P-attmyxfAAAAco"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:15.938325 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.85:59704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8xKaHUf6J8d3elJokgAA0yo"]
[Mon Jul 20 06:22:16.698775 2026] [security2:error] [pid 884009:tid 884171] [client 158.173.89.95:20103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S-BKaHUf6J8d3elJpZAAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:16.795673 2026] [security2:error] [pid 915741:tid 915957] [client 134.19.178.167:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.178.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4S-K-615n1P-attmyxmAAAAeU"]
[Mon Jul 20 06:22:16.795820 2026] [security2:error] [pid 915741:tid 915957] [client 134.19.178.167:34068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4S-K-615n1P-attmyxmAAAAeU"]
[Mon Jul 20 06:22:16.948628 2026] [security2:error] [pid 915741:tid 915903] [client 14.225.17.146:52435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4S-K-615n1P-attmyxngAAAa8"], referer: http://walkingandtalking.net/Wp
[Mon Jul 20 06:22:16.953138 2026] [security2:error] [pid 915741:tid 915970] [client 185.132.186.93:37609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/backup/autoload_classmap.php"] [unique_id "al4S-K-615n1P-attmyxowAAAfI"]
[Mon Jul 20 06:22:17.731785 2026] [security2:error] [pid 915741:tid 915961] [client 50.116.65.227:26144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4S-a-615n1P-attmyxwAAAAek"]
[Mon Jul 20 06:22:17.745275 2026] [security2:error] [pid 884009:tid 884207] [client 50.116.65.227:47002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4S-RKaHUf6J8d3elJpjQAAAMc"]
[Mon Jul 20 06:22:17.765868 2026] [security2:error] [pid 915741:tid 915889] [client 171.60.139.123:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S-a-615n1P-attmyxxgAAAaE"]
[Mon Jul 20 06:22:17.765993 2026] [security2:error] [pid 915741:tid 915889] [client 171.60.139.123:61975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S-a-615n1P-attmyxxgAAAaE"]
[Mon Jul 20 06:22:17.826474 2026] [security2:error] [pid 915741:tid 915948] [client 14.225.17.146:52516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4S-a-615n1P-attmyxxwAAAdw"], referer: https://walkingandtalking.net/Wp
[Mon Jul 20 06:22:17.883458 2026] [security2:error] [pid 915741:tid 915874] [client 14.225.17.146:52478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4S-a-615n1P-attmyxvQAAAZI"], referer: http://ksands.co.uk/Wp
[Mon Jul 20 06:22:18.271697 2026] [security2:error] [pid 884009:tid 884155] [client 77.110.127.138:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S-hKaHUf6J8d3elJppAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:18.271820 2026] [security2:error] [pid 884009:tid 884155] [client 77.110.127.138:61215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S-hKaHUf6J8d3elJppAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:18.287435 2026] [security2:error] [pid 884009:tid 884261] [client 158.173.166.181:54029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S-hKaHUf6J8d3elJppgAAAP0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:18.293575 2026] [security2:error] [pid 915741:tid 915995] [client 50.116.65.227:47008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S-q-615n1P-attmyx4wAAAgs"]
[Mon Jul 20 06:22:18.306899 2026] [security2:error] [pid 915741:tid 915873] [client 50.116.65.227:47024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S-q-615n1P-attmyx5AAAAZE"]
[Mon Jul 20 06:22:18.411559 2026] [core:error] [pid 915741:tid 915956] [client 198.235.24.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:18.411579 2026] [core:error] [pid 915741:tid 915956] [client 198.235.24.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:18.585500 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.107:42486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxRQABtXc"]
[Mon Jul 20 06:22:18.648844 2026] [security2:error] [pid 915741:tid 915890] [client 57.141.18.83:25914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxSAABomA"]
[Mon Jul 20 06:22:18.722007 2026] [security2:error] [pid 915741:tid 915868] [remote 81.173.115.7:36486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S-q-615n1P-attmyx8wAB3X4"]
[Mon Jul 20 06:22:18.774862 2026] [security2:error] [pid 915741:tid 915920] [client 185.132.186.103:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/uploads.php"] [unique_id "al4S-q-615n1P-attmyx9QAAAcA"]
[Mon Jul 20 06:22:18.799452 2026] [security2:error] [pid 884009:tid 884174] [client 45.116.69.230:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S-hKaHUf6J8d3elJpugAAAKY"]
[Mon Jul 20 06:22:18.799579 2026] [security2:error] [pid 884009:tid 884174] [client 45.116.69.230:54054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S-hKaHUf6J8d3elJpugAAAKY"]
[Mon Jul 20 06:22:18.951145 2026] [security2:error] [pid 915741:tid 915744] [remote 81.173.115.7:36486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S-q-615n1P-attmyx9wAB1AI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:22:19.019843 2026] [security2:error] [pid 915741:tid 915918] [client 57.141.18.124:53962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxUAABvnQ"]
[Mon Jul 20 06:22:19.025009 2026] [security2:error] [pid 884009:tid 884229] [client 14.225.17.146:52084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4S-BKaHUf6J8d3elJpYwAAAN0"], referer: http://talknutritionwithlesley.com/Wp
[Mon Jul 20 06:22:19.307094 2026] [security2:error] [pid 884009:tid 884237] [client 103.141.108.143:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S-xKaHUf6J8d3elJpywAAAOU"]
[Mon Jul 20 06:22:19.307234 2026] [security2:error] [pid 884009:tid 884237] [client 103.141.108.143:54654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S-xKaHUf6J8d3elJpywAAAOU"]
[Mon Jul 20 06:22:19.350026 2026] [security2:error] [pid 915741:tid 915987] [client 14.225.17.146:52432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4S-6-615n1P-attmyx_gAAAgM"], referer: http://jvcmotorsports.com/Wp
[Mon Jul 20 06:22:19.387982 2026] [security2:error] [pid 915741:tid 915819] [remote 162.19.86.63:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S-6-615n1P-attmyyDgABlE0"]
[Mon Jul 20 06:22:19.544268 2026] [security2:error] [pid 915741:tid 915892] [client 57.141.18.83:25926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S96-615n1P-attmyxbgABpG8"]
[Mon Jul 20 06:22:19.600315 2026] [security2:error] [pid 915741:tid 915751] [remote 162.19.86.63:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S-6-615n1P-attmyyFgAB-Ak"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:22:20.100556 2026] [core:error] [pid 915741:tid 915907] [client 14.225.17.146:60898] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:20.100594 2026] [core:error] [pid 915741:tid 915907] [client 14.225.17.146:60898] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:20.158681 2026] [security2:error] [pid 884009:tid 884205] [client 178.152.178.232:37193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S_BKaHUf6J8d3elJp8AAAAMU"]
[Mon Jul 20 06:22:20.158836 2026] [security2:error] [pid 884009:tid 884205] [client 178.152.178.232:37193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S_BKaHUf6J8d3elJp8AAAAMU"]
[Mon Jul 20 06:22:20.329980 2026] [security2:error] [pid 884009:tid 884164] [client 57.141.18.38:48142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9xKaHUf6J8d3elJpQAAAnUE"]
[Mon Jul 20 06:22:20.603137 2026] [security2:error] [pid 915741:tid 915992] [client 185.132.186.64:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/file.php"] [unique_id "al4S_K-615n1P-attmyyPAAAAgg"]
[Mon Jul 20 06:22:20.637022 2026] [security2:error] [pid 915741:tid 915981] [client 57.141.18.48:22192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-K-615n1P-attmyxjwAB_WY"]
[Mon Jul 20 06:22:20.806526 2026] [security2:error] [pid 915741:tid 915905] [client 14.225.17.146:61389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4S-6-615n1P-attmyyDwAAAbE"], referer: http://momheadquarters.com/Wp
[Mon Jul 20 06:22:21.172331 2026] [security2:error] [pid 884009:tid 884258] [client 54.244.177.189:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4S_RKaHUf6J8d3elJqFAAAAPo"]
[Mon Jul 20 06:22:21.250643 2026] [security2:error] [pid 884009:tid 884252] [client 77.110.127.138:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_RKaHUf6J8d3elJqGgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:21.250729 2026] [security2:error] [pid 884009:tid 884252] [client 77.110.127.138:61226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_RKaHUf6J8d3elJqGgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:21.335382 2026] [security2:error] [pid 884009:tid 884238] [client 74.7.227.179:33688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4S_RKaHUf6J8d3elJqFQAA5ks"], referer: https://tejasenvironmental.com/p=110265
[Mon Jul 20 06:22:21.484690 2026] [security2:error] [pid 884009:tid 884175] [client 57.141.18.48:22200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-RKaHUf6J8d3elJpdwAApws"]
[Mon Jul 20 06:22:21.866876 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S_a-615n1P-attmyyXgAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:22.015380 2026] [security2:error] [pid 915741:tid 915913] [client 27.96.94.195:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyyeQAAAbk"]
[Mon Jul 20 06:22:22.015541 2026] [security2:error] [pid 915741:tid 915913] [client 27.96.94.195:37906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyyeQAAAbk"]
[Mon Jul 20 06:22:22.041671 2026] [security2:error] [pid 915741:tid 915910] [client 74.208.214.194:40714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4S_q-615n1P-attmyyegAAAbY"]
[Mon Jul 20 06:22:22.116151 2026] [security2:error] [pid 915741:tid 915950] [client 57.141.18.48:22212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-a-615n1P-attmyxuwAB3nY"]
[Mon Jul 20 06:22:22.135166 2026] [security2:error] [pid 915741:tid 915772] [remote 57.141.18.114:34902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6035871"] [unique_id "al4S_q-615n1P-attmyyfgACDB4"]
[Mon Jul 20 06:22:22.436779 2026] [security2:error] [pid 915741:tid 915918] [client 185.132.186.63:60055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes.php"] [unique_id "al4S_q-615n1P-attmyykwAAAb4"]
[Mon Jul 20 06:22:22.613779 2026] [security2:error] [pid 915741:tid 915940] [client 41.173.37.102:10536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyymwAAAdQ"]
[Mon Jul 20 06:22:22.613928 2026] [security2:error] [pid 915741:tid 915940] [client 41.173.37.102:10536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyymwAAAdQ"]
[Mon Jul 20 06:22:22.634105 2026] [security2:error] [pid 915741:tid 915774] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S_q-615n1P-attmyynAABpyA"]
[Mon Jul 20 06:22:22.907614 2026] [security2:error] [pid 915741:tid 915927] [client 14.225.17.146:61770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4S_a-615n1P-attmyyUgAAAcc"], referer: https://north-woods-engineering.com/Wp
[Mon Jul 20 06:22:23.086492 2026] [security2:error] [pid 915741:tid 915976] [client 14.225.17.146:51835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4S_q-615n1P-attmyyjAAAAfg"], referer: http://idigress.studio/Wp
[Mon Jul 20 06:22:23.173565 2026] [security2:error] [pid 915741:tid 915808] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S_6-615n1P-attmyytAAB9UI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:23.240532 2026] [security2:error] [pid 884009:tid 884234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S_hKaHUf6J8d3elJqVgAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:23.553674 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S_xKaHUf6J8d3elJqfAAAANg"]
[Mon Jul 20 06:22:23.553786 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S_xKaHUf6J8d3elJqfAAAANg"]
[Mon Jul 20 06:22:23.852589 2026] [security2:error] [pid 884009:tid 884265] [client 77.110.127.138:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_xKaHUf6J8d3elJqjQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:23.852689 2026] [security2:error] [pid 884009:tid 884265] [client 77.110.127.138:61252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_xKaHUf6J8d3elJqjQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:23.895778 2026] [security2:error] [pid 915741:tid 915945] [client 14.225.17.146:51687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4S_q-615n1P-attmyynQAAAdk"], referer: http://collectingrealestate.com/Wp
[Mon Jul 20 06:22:23.985816 2026] [security2:error] [pid 884009:tid 884242] [client 57.141.18.89:31364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-xKaHUf6J8d3elJpzAAA6ho"]
[Mon Jul 20 06:22:24.141274 2026] [security2:error] [pid 915741:tid 915879] [client 50.116.65.227:26408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4TAK-615n1P-attmyy0wAAAZc"]
[Mon Jul 20 06:22:24.143274 2026] [security2:error] [pid 884009:tid 884229] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S_xKaHUf6J8d3elJqhwAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:24.152507 2026] [security2:error] [pid 915741:tid 915949] [client 50.116.65.227:48912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4TAK-615n1P-attmyy1AAAAaw"]
[Mon Jul 20 06:22:24.221361 2026] [security2:error] [pid 884009:tid 884217] [client 171.61.165.146:10040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqmwAAANE"]
[Mon Jul 20 06:22:24.221563 2026] [security2:error] [pid 884009:tid 884217] [client 171.61.165.146:10040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqmwAAANE"]
[Mon Jul 20 06:22:24.353031 2026] [security2:error] [pid 915741:tid 915930] [client 103.59.160.95:63580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy2AAAAco"]
[Mon Jul 20 06:22:24.381190 2026] [security2:error] [pid 884009:tid 884020] [remote 20.153.140.50:58614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqpAAAzQk"]
[Mon Jul 20 06:22:24.381419 2026] [security2:error] [pid 884009:tid 884213] [client 20.153.140.50:58614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqpAAAzQk"]
[Mon Jul 20 06:22:24.454616 2026] [security2:error] [pid 884009:tid 884148] [client 103.59.160.95:63589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4TABKaHUf6J8d3elJqqAAAAI0"]
[Mon Jul 20 06:22:24.566788 2026] [security2:error] [pid 915741:tid 915934] [client 103.59.160.95:63580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.160.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/xmlrpc.php"] [unique_id "al4TAK-615n1P-attmyy4wAAAc4"]
[Mon Jul 20 06:22:24.668627 2026] [security2:error] [pid 884009:tid 884236] [client 103.59.160.95:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.160.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqtQAAAOQ"]
[Mon Jul 20 06:22:25.004965 2026] [security2:error] [pid 915741:tid 915994] [client 14.225.17.146:62957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4S_6-615n1P-attmyysQAAAgo"], referer: http://narv.co/Wp
[Mon Jul 20 06:22:25.045632 2026] [security2:error] [pid 884009:tid 884107] [remote 93.177.75.10:51354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.75.177.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4TABKaHUf6J8d3elJqvwAAqmA"], referer: https://aviationsynergy.aero/
[Mon Jul 20 06:22:25.052691 2026] [security2:error] [pid 884009:tid 884172] [client 57.141.18.37:30304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_BKaHUf6J8d3elJp-wAApDA"]
[Mon Jul 20 06:22:25.113974 2026] [security2:error] [pid 915741:tid 915923] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy8QABwys"], referer: http://aleishapenny.ca/Wp
[Mon Jul 20 06:22:25.131588 2026] [security2:error] [pid 915741:tid 915792] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TAa-615n1P-attmyy-QAB2TI"]
[Mon Jul 20 06:22:25.132283 2026] [security2:error] [pid 915741:tid 915945] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TAa-615n1P-attmyy-QAB2TI"]
[Mon Jul 20 06:22:25.202147 2026] [security2:error] [pid 915741:tid 915878] [client 103.153.183.69:49412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4TAa-615n1P-attmyy_wAAAZY"], referer: https://www.google.com/search?q=9mhjo7
[Mon Jul 20 06:22:25.266808 2026] [security2:error] [pid 884009:tid 884185] [client 119.74.54.159:38826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4TARKaHUf6J8d3elJqyAAAALE"]
[Mon Jul 20 06:22:25.300546 2026] [security2:error] [pid 915741:tid 915973] [client 185.132.186.68:40855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "al4TAa-615n1P-attmyzCQAAAfU"]
[Mon Jul 20 06:22:25.306313 2026] [lsapi:warn] [pid 915741:tid 915954] [client 14.225.17.146:62965] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:25.306342 2026] [lsapi:warn] [pid 915741:tid 915954] [client 14.225.17.146:62965] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:25.315100 2026] [security2:error] [pid 915741:tid 915764] [remote 117.0.21.154:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4TAa-615n1P-attmyzCAAB2hY"]
[Mon Jul 20 06:22:25.440852 2026] [security2:error] [pid 915741:tid 915911] [client 103.59.160.95:64116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TAa-615n1P-attmyzFwAAAbc"]
[Mon Jul 20 06:22:25.522668 2026] [security2:error] [pid 915741:tid 915883] [client 74.7.228.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4TAa-615n1P-attmyzIAAAAZs"]
[Mon Jul 20 06:22:25.532939 2026] [security2:error] [pid 915741:tid 915974] [client 74.7.228.53:45914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/robots.txt"] [unique_id "al4TAa-615n1P-attmyzGAAB9jc"]
[Mon Jul 20 06:22:25.563225 2026] [security2:error] [pid 915741:tid 915871] [client 113.169.53.224:51360] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4TAa-615n1P-attmyzJQAAAY8"]
[Mon Jul 20 06:22:25.617448 2026] [security2:error] [pid 884009:tid 884184] [client 103.59.160.95:64131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TARKaHUf6J8d3elJq3AAAALA"]
[Mon Jul 20 06:22:25.657148 2026] [security2:error] [pid 915741:tid 915938] [client 45.13.6.125:54376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4TAa-615n1P-attmyzKQAAAdI"]
[Mon Jul 20 06:22:25.717500 2026] [security2:error] [pid 915741:tid 915909] [client 82.39.10.58:44278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4TAa-615n1P-attmyzKwAAAbU"]
[Mon Jul 20 06:22:25.725865 2026] [security2:error] [pid 884009:tid 884200] [client 84.70.126.40:48114] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4TARKaHUf6J8d3elJq4QAAAMA"]
[Mon Jul 20 06:22:25.764561 2026] [security2:error] [pid 915741:tid 915969] [client 66.131.17.83:57504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4TAa-615n1P-attmyzLQAAAfE"]
[Mon Jul 20 06:22:25.792958 2026] [security2:error] [pid 884009:tid 884240] [client 14.225.17.146:63063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4TABKaHUf6J8d3elJqoAAAAOg"], referer: http://chestermonty.com/Wp
[Mon Jul 20 06:22:25.859776 2026] [security2:error] [pid 915741:tid 915900] [client 86.202.104.235:59434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4TAa-615n1P-attmyzMAAAAaw"]
[Mon Jul 20 06:22:25.880994 2026] [lsapi:warn] [pid 915741:tid 915985] [client 50.116.65.227:48938] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:22:25.881016 2026] [lsapi:warn] [pid 915741:tid 915985] [client 50.116.65.227:48938] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:22:25.896633 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:62965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy7AAAAeI"], referer: http://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:25.949024 2026] [security2:error] [pid 915741:tid 915889] [client 76.70.92.140:48536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4TAa-615n1P-attmyzOQAAAaE"]
[Mon Jul 20 06:22:25.985564 2026] [security2:error] [pid 915741:tid 915970] [client 187.136.224.75:4697] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4TAa-615n1P-attmyzPwAAAfI"]
[Mon Jul 20 06:22:25.992258 2026] [security2:error] [pid 884009:tid 884246] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TARKaHUf6J8d3elJq5QAA7nY"], referer: https://aleishapenny.ca/Wp
[Mon Jul 20 06:22:26.043400 2026] [security2:error] [pid 884009:tid 884168] [client 79.16.35.47:45772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4TAhKaHUf6J8d3elJq8gAAAKE"]
[Mon Jul 20 06:22:26.048236 2026] [security2:error] [pid 915741:tid 915956] [client 14.225.17.146:63292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4TAa-615n1P-attmyzMgAAAeQ"], referer: https://narv.co/Wp
[Mon Jul 20 06:22:26.115782 2026] [security2:error] [pid 915741:tid 915958] [client 57.141.18.40:65440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_a-615n1P-attmyyYwAB5hc"]
[Mon Jul 20 06:22:26.202205 2026] [security2:error] [pid 915741:tid 915876] [client 3.75.183.99:40144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TAq-615n1P-attmyzSAAAAZQ"]
[Mon Jul 20 06:22:26.202369 2026] [security2:error] [pid 915741:tid 915876] [client 3.75.183.99:40144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TAq-615n1P-attmyzSAAAAZQ"]
[Mon Jul 20 06:22:26.235662 2026] [security2:error] [pid 915741:tid 915804] [remote 117.0.21.154:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4TAq-615n1P-attmyzSQABkT4"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 06:22:26.284616 2026] [security2:error] [pid 915741:tid 915882] [client 2.82.223.226:41422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4TAq-615n1P-attmyzTQAAAZo"]
[Mon Jul 20 06:22:26.293394 2026] [security2:error] [pid 884009:tid 884165] [client 47.128.114.143:26400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.allergyantidotes.com"] [uri "/robots.txt"] [unique_id "al4TAhKaHUf6J8d3elJq-wAAAJ4"]
[Mon Jul 20 06:22:26.407857 2026] [security2:error] [pid 884009:tid 884143] [client 103.59.160.95:64513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TAhKaHUf6J8d3elJrAgAAAIg"]
[Mon Jul 20 06:22:26.504785 2026] [security2:error] [pid 915741:tid 915979] [client 103.59.160.95:64588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TAq-615n1P-attmyzWQAAAfs"]
[Mon Jul 20 06:22:26.700587 2026] [lsapi:warn] [pid 915741:tid 915982] [client 14.225.17.146:60959] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:26.700609 2026] [lsapi:warn] [pid 915741:tid 915982] [client 14.225.17.146:60959] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:26.712009 2026] [security2:error] [pid 915741:tid 915968] [client 14.225.17.146:63151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4TAq-615n1P-attmyzXgAAAfA"], referer: https://chestermonty.com/Wp
[Mon Jul 20 06:22:26.753705 2026] [security2:error] [pid 915741:tid 915982] [client 14.225.17.146:60959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4TAq-615n1P-attmyzYQAAAf4"], referer: https://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:26.790337 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:54485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4TAhKaHUf6J8d3elJrDAAAAJo"], referer: http://friendlyspreadsheet.com/Wp
[Mon Jul 20 06:22:26.827049 2026] [security2:error] [pid 915741:tid 915947] [client 50.116.65.227:26422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Feature-Image.jpg"] [unique_id "al4TAq-615n1P-attmyzZwAAAds"]
[Mon Jul 20 06:22:26.840854 2026] [security2:error] [pid 915741:tid 915902] [client 50.116.65.227:48954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Feature-Image.jpg"] [unique_id "al4TAq-615n1P-attmyzaAAAAa4"]
[Mon Jul 20 06:22:26.869066 2026] [fcgid:warn] [pid 915741:tid 915930] (70014)End of file found: [client 66.132.172.201:22056] mod_fcgid: can't get data from http client
[Mon Jul 20 06:22:27.185867 2026] [security2:error] [pid 915741:tid 915906] [client 14.225.17.146:49901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4TAq-615n1P-attmyzbQAAAbI"], referer: http://maxenengineering.com/Wp
[Mon Jul 20 06:22:27.235676 2026] [security2:error] [pid 915741:tid 915883] [client 38.159.162.81:34952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4TA6-615n1P-attmyzewAAAZs"]
[Mon Jul 20 06:22:27.259303 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.109:29924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_q-615n1P-attmyymgAB-iU"]
[Mon Jul 20 06:22:27.272178 2026] [security2:error] [pid 915741:tid 915911] [client 103.59.160.95:64992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TA6-615n1P-attmyzfAAAAbc"]
[Mon Jul 20 06:22:27.345139 2026] [security2:error] [pid 915741:tid 915992] [client 103.59.160.95:65034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TA6-615n1P-attmyzggAAAgg"]
[Mon Jul 20 06:22:27.458431 2026] [lsapi:warn] [pid 915741:tid 915806] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 06:22:27.524327 2026] [lsapi:warn] [pid 915741:tid 915778] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 06:22:27.546816 2026] [lsapi:warn] [pid 915741:tid 915807] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 06:22:27.685231 2026] [security2:error] [pid 915741:tid 915962] [client 14.225.17.146:63061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyziwAAAeo"], referer: https://friendlyspreadsheet.com/Wp
[Mon Jul 20 06:22:27.690301 2026] [security2:error] [pid 915741:tid 915828] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rzj.zfx.mybluehost.me"] [uri "/.env.old"] [unique_id "al4TA6-615n1P-attmyzkQABkFY"]
[Mon Jul 20 06:22:27.947542 2026] [security2:error] [pid 915741:tid 915771] [remote 154.61.75.100:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4TA6-615n1P-attmyzoQAB_x0"]
[Mon Jul 20 06:22:28.040740 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:60775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyzmAAAAfU"], referer: http://mezzacraft.com/Wp
[Mon Jul 20 06:22:28.051066 2026] [security2:error] [pid 915741:tid 915982] [client 14.225.17.146:63279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyzngAAAf4"], referer: http://taskidsvirginia.com/Wp
[Mon Jul 20 06:22:28.124276 2026] [security2:error] [pid 915741:tid 915945] [client 185.132.186.68:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/load.php"] [unique_id "al4TBK-615n1P-attmyzqwAAAdk"]
[Mon Jul 20 06:22:28.144689 2026] [security2:error] [pid 884009:tid 884246] [client 103.59.160.95:65355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TBBKaHUf6J8d3elJrRAAAAO4"]
[Mon Jul 20 06:22:28.146922 2026] [security2:error] [pid 884009:tid 884202] [client 57.141.18.101:54914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_xKaHUf6J8d3elJqbQAAwhw"]
[Mon Jul 20 06:22:28.159642 2026] [security2:error] [pid 915741:tid 915937] [client 14.225.17.146:63346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4TBK-615n1P-attmyzpQAAAdE"], referer: https://maxenengineering.com/Wp
[Mon Jul 20 06:22:28.204358 2026] [security2:error] [pid 915741:tid 915995] [client 103.59.160.95:65376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TBK-615n1P-attmyzrQAAAgs"]
[Mon Jul 20 06:22:28.450088 2026] [security2:error] [pid 915741:tid 915842] [remote 154.61.75.100:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4TBK-615n1P-attmyzuQABnmQ"], referer: https://grndl.com/wp-login.php
[Mon Jul 20 06:22:28.470717 2026] [security2:error] [pid 915741:tid 915906] [client 77.110.127.138:61271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TBK-615n1P-attmyzrwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.584832 2026] [security2:error] [pid 884009:tid 884156] [client 171.60.139.123:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TBBKaHUf6J8d3elJrUQAAAJU"]
[Mon Jul 20 06:22:28.584968 2026] [security2:error] [pid 884009:tid 884156] [client 171.60.139.123:62489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TBBKaHUf6J8d3elJrUQAAAJU"]
[Mon Jul 20 06:22:28.751325 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4TBK-615n1P-attmyzwgAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.909285 2026] [security2:error] [pid 884009:tid 884264] [client 77.110.127.138:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TBBKaHUf6J8d3elJrZQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.909400 2026] [security2:error] [pid 884009:tid 884264] [client 77.110.127.138:61280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TBBKaHUf6J8d3elJrZQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.968821 2026] [security2:error] [pid 915741:tid 915903] [client 57.141.18.54:48446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy1QABryw"]
[Mon Jul 20 06:22:29.042897 2026] [security2:error] [pid 915741:tid 915882] [client 103.153.183.69:23704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//var/www/html/config.php"] [unique_id "al4TBa-615n1P-attmyz1AAAAZo"], referer: https://t.co/wkz1vkhiqw
[Mon Jul 20 06:22:29.053909 2026] [security2:error] [pid 884009:tid 884199] [client 103.59.160.95:49385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrbQAAAL8"]
[Mon Jul 20 06:22:29.082046 2026] [security2:error] [pid 884009:tid 884225] [client 103.59.160.95:49421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrbwAAANk"]
[Mon Jul 20 06:22:29.457625 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:63268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyznQAAAeI"], referer: http://guidehunting.com/Wp
[Mon Jul 20 06:22:29.475852 2026] [security2:error] [pid 915741:tid 915935] [client 57.141.18.76:47154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy6QABzy0"]
[Mon Jul 20 06:22:29.499622 2026] [security2:error] [pid 915741:tid 915937] [client 45.116.69.230:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TBa-615n1P-attmyz7AAAAdE"]
[Mon Jul 20 06:22:29.500242 2026] [security2:error] [pid 915741:tid 915937] [client 45.116.69.230:54599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TBa-615n1P-attmyz7AAAAdE"]
[Mon Jul 20 06:22:29.527076 2026] [security2:error] [pid 915741:tid 915890] [client 14.225.17.146:63081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyzjAAAAaI"], referer: http://partnerselectricalllc.com/Wp
[Mon Jul 20 06:22:29.578021 2026] [lsapi:warn] [pid 915741:tid 915857] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:22:29.716048 2026] [lsapi:warn] [pid 915741:tid 915813] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:22:29.723917 2026] [lsapi:warn] [pid 915741:tid 915748] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:22:29.876703 2026] [core:error] [pid 884009:tid 884144] [client 198.235.24.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:29.876726 2026] [core:error] [pid 884009:tid 884144] [client 198.235.24.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:29.889011 2026] [security2:error] [pid 884009:tid 884220] [client 103.59.160.95:49785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrvgAAANQ"]
[Mon Jul 20 06:22:29.938973 2026] [security2:error] [pid 884009:tid 884261] [client 185.132.186.80:32499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/chosen.php"] [unique_id "al4TBRKaHUf6J8d3elJrwAAAAP0"]
[Mon Jul 20 06:22:29.939676 2026] [security2:error] [pid 884009:tid 884149] [client 103.59.160.95:49786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrwgAAAI4"]
[Mon Jul 20 06:22:30.063383 2026] [security2:error] [pid 915741:tid 915930] [client 103.141.108.143:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmyz_gAAAco"]
[Mon Jul 20 06:22:30.063490 2026] [security2:error] [pid 915741:tid 915930] [client 103.141.108.143:55122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmyz_gAAAco"]
[Mon Jul 20 06:22:30.094202 2026] [security2:error] [pid 915741:tid 915947] [client 77.110.127.138:61288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TBa-615n1P-attmyz9QAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:30.164166 2026] [core:error] [pid 915741:tid 915938] [client 103.153.183.69:35200] AH10244: invalid URI path (/%2e./etc/passwd?_=1mr0sxrq&v=re4ov), referer: https://www.google.com/
[Mon Jul 20 06:22:30.167087 2026] [security2:error] [pid 915741:tid 915990] [client 127.0.0.1:25270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TBq-615n1P-attmy0BAAAAgY"], referer: https://www.google.com/
[Mon Jul 20 06:22:30.431682 2026] [core:error] [pid 915741:tid 915957] [client 103.153.183.69:35216] AH10244: invalid URI path (/../../../etc/passwd?_=mkjq29j9&v=9u3sq), referer: https://www.bing.com/search?q=j4tdfc
[Mon Jul 20 06:22:30.434913 2026] [security2:error] [pid 884009:tid 884268] [client 127.0.0.1:25276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TBhKaHUf6J8d3elJr5wAAAQQ"], referer: https://www.bing.com/search?q=j4tdfc
[Mon Jul 20 06:22:30.579960 2026] [security2:error] [pid 915741:tid 915900] [client 178.152.178.232:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmy0HgAAAaw"]
[Mon Jul 20 06:22:30.580112 2026] [security2:error] [pid 915741:tid 915900] [client 178.152.178.232:35983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmy0HgAAAaw"]
[Mon Jul 20 06:22:30.628300 2026] [security2:error] [pid 915741:tid 915891] [client 14.225.17.146:61314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4TBq-615n1P-attmy0DgAAAaM"], referer: https://guidehunting.com/Wp
[Mon Jul 20 06:22:30.676525 2026] [security2:error] [pid 915741:tid 915942] [client 154.29.87.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vtv.zzt.mybluehost.me"] [uri "/index.php"] [unique_id "al4TBq-615n1P-attmy0GgAAAdY"]
[Mon Jul 20 06:22:30.798701 2026] [security2:error] [pid 915741:tid 915935] [client 103.59.160.95:50136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TBq-615n1P-attmy0JwAAAc8"]
[Mon Jul 20 06:22:30.798722 2026] [security2:error] [pid 915741:tid 915985] [client 103.59.160.95:50178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TBq-615n1P-attmy0KAAAAgE"]
[Mon Jul 20 06:22:30.846433 2026] [security2:error] [pid 915741:tid 915906] [client 14.225.17.146:49944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4TBq-615n1P-attmy0GwAAAbI"], referer: http://healthylifegourmet.org/Wp
[Mon Jul 20 06:22:31.536209 2026] [security2:error] [pid 915741:tid 915969] [client 168.144.240.66:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "prontomc.co.uk"] [uri "/license.txt"] [unique_id "al4TB6-615n1P-attmy0RAAAAfE"]
[Mon Jul 20 06:22:31.691386 2026] [security2:error] [pid 915741:tid 915987] [client 103.59.160.95:50680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TB6-615n1P-attmy0SgAAAgM"]
[Mon Jul 20 06:22:31.765700 2026] [security2:error] [pid 884009:tid 884200] [client 185.132.186.67:58287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-theme-float.php"] [unique_id "al4TBxKaHUf6J8d3elJsGgAAAMA"]
[Mon Jul 20 06:22:31.785797 2026] [security2:error] [pid 884009:tid 884190] [client 103.153.183.69:23720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//var/www/html/configuration.php"] [unique_id "al4TBxKaHUf6J8d3elJsHAAAALY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:22:31.822894 2026] [security2:error] [pid 884009:tid 884258] [client 66.249.73.66:63920] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "w.saphansiam.org"] [uri "/robots.txt"] [unique_id "al4TBxKaHUf6J8d3elJsHgAAAPo"]
[Mon Jul 20 06:22:32.059789 2026] [core:error] [pid 915741:tid 915933] [client 103.153.183.69:35218] AH10244: invalid URI path (/../../../../etc/passwd?_=bcs5jg30&v=ki7zf), referer: https://www.reddit.com/
[Mon Jul 20 06:22:32.063001 2026] [security2:error] [pid 915741:tid 915902] [client 127.0.0.1:25280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TCK-615n1P-attmy0WwAAAa4"], referer: https://www.reddit.com/
[Mon Jul 20 06:22:32.082848 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.48:40324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TAq-615n1P-attmyzbgABqEg"]
[Mon Jul 20 06:22:32.189418 2026] [security2:error] [pid 915741:tid 915921] [client 103.59.160.95:50695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TCK-615n1P-attmy0XQAAAcE"]
[Mon Jul 20 06:22:32.209350 2026] [security2:error] [pid 915741:tid 915915] [client 103.153.183.69:23722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../app/.env"] [unique_id "al4TCK-615n1P-attmy0XgAAAbs"], referer: https://t.co/00fyu8er5x
[Mon Jul 20 06:22:32.380547 2026] [fcgid:warn] [pid 915741:tid 915946] (70014)End of file found: [client 66.132.172.201:22062] mod_fcgid: can't get data from http client
[Mon Jul 20 06:22:32.449094 2026] [core:error] [pid 915741:tid 915874] [client 103.153.183.69:35230] AH10244: invalid URI path (/../.env?_=35dq137n&v=c1my6), referer: https://www.google.com/search?q=ypld9y
[Mon Jul 20 06:22:32.552150 2026] [security2:error] [pid 884009:tid 884205] [client 103.59.160.95:51110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TCBKaHUf6J8d3elJsRQAAAMU"]
[Mon Jul 20 06:22:32.656496 2026] [security2:error] [pid 915741:tid 915750] [remote 182.77.62.24:34466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TCK-615n1P-attmy0cgAB1Qg"]
[Mon Jul 20 06:22:32.656703 2026] [security2:error] [pid 915741:tid 915941] [client 182.77.62.24:34466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TCK-615n1P-attmy0cgAB1Qg"]
[Mon Jul 20 06:22:32.665256 2026] [security2:error] [pid 915741:tid 915755] [remote 100.42.189.89:44502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4TCK-615n1P-attmy0cwACCg0"]
[Mon Jul 20 06:22:32.777361 2026] [security2:error] [pid 884009:tid 884213] [client 103.153.183.69:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/.env"] [unique_id "al4TCBKaHUf6J8d3elJsSwAAAM0"], referer: https://www.reddit.com/
[Mon Jul 20 06:22:32.833893 2026] [security2:error] [pid 884009:tid 884179] [client 77.110.127.138:61303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TCBKaHUf6J8d3elJsSAAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:32.868917 2026] [security2:error] [pid 884009:tid 884264] [client 103.153.183.69:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4TCBKaHUf6J8d3elJsUQAAAQA"], referer: https://duckduckgo.com/?q=rnkcp
[Mon Jul 20 06:22:32.975495 2026] [security2:error] [pid 884009:tid 884266] [client 103.153.183.69:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4TCBKaHUf6J8d3elJsWgAAAQI"], referer: https://www.google.com/
[Mon Jul 20 06:22:33.017312 2026] [security2:error] [pid 884009:tid 884255] [client 77.110.127.138:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4TCRKaHUf6J8d3elJsXAAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:33.063887 2026] [security2:error] [pid 884009:tid 884194] [client 103.59.160.95:51275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TCRKaHUf6J8d3elJsXgAAALo"]
[Mon Jul 20 06:22:33.095932 2026] [security2:error] [pid 915741:tid 915972] [client 14.225.17.146:61128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4TB6-615n1P-attmy0RwAAAfQ"], referer: http://reosportsboats.com/Wp
[Mon Jul 20 06:22:33.222772 2026] [security2:error] [pid 915741:tid 915757] [remote 100.42.189.89:44502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4TCa-615n1P-attmy0igABug8"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 06:22:33.266930 2026] [security2:error] [pid 884009:tid 884190] [client 77.110.127.138:61307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TCRKaHUf6J8d3elJsYgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:33.267091 2026] [security2:error] [pid 884009:tid 884190] [client 77.110.127.138:61307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TCRKaHUf6J8d3elJsYgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:33.296509 2026] [security2:error] [pid 915741:tid 915876] [client 41.173.37.102:10957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TCa-615n1P-attmy0iwAAAZQ"]
[Mon Jul 20 06:22:33.296599 2026] [security2:error] [pid 915741:tid 915876] [client 41.173.37.102:10957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TCa-615n1P-attmy0iwAAAZQ"]
[Mon Jul 20 06:22:33.503721 2026] [security2:error] [pid 884009:tid 884250] [client 103.59.160.95:51385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TCRKaHUf6J8d3elJsbwAAAPI"]
[Mon Jul 20 06:22:33.568822 2026] [security2:error] [pid 915741:tid 915884] [client 57.141.18.106:24024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBK-615n1P-attmyzugABnGk"]
[Mon Jul 20 06:22:33.570837 2026] [security2:error] [pid 915741:tid 915955] [client 185.132.186.64:34417] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TCa-615n1P-attmy0mAAAAeM"]
[Mon Jul 20 06:22:33.905376 2026] [security2:error] [pid 915741:tid 915899] [client 57.141.18.49:63862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBK-615n1P-attmyzxQABq1Q"]
[Mon Jul 20 06:22:33.905629 2026] [security2:error] [pid 915741:tid 915967] [client 103.59.160.95:51686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TCa-615n1P-attmy0pQAAAe8"]
[Mon Jul 20 06:22:33.973179 2026] [core:error] [pid 915741:tid 915879] [client 14.225.17.146:63168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:33.973209 2026] [core:error] [pid 915741:tid 915879] [client 14.225.17.146:63168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:34.053793 2026] [security2:error] [pid 915741:tid 915990] [client 14.225.17.146:61674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4TCa-615n1P-attmy0qQAAAgY"], referer: https://reosportsboats.com/Wp
[Mon Jul 20 06:22:34.296346 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:49951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4TCa-615n1P-attmy0iAAAAeI"]
[Mon Jul 20 06:22:34.412921 2026] [security2:error] [pid 915741:tid 915980] [client 103.59.160.95:51846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TCq-615n1P-attmy0xQAAAfw"]
[Mon Jul 20 06:22:34.543054 2026] [security2:error] [pid 915741:tid 915959] [client 57.141.18.43:32262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBa-615n1P-attmyz6wAB5wc"]
[Mon Jul 20 06:22:34.704648 2026] [security2:error] [pid 915741:tid 915916] [client 77.110.127.138:61318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TCq-615n1P-attmy0xgAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:34.787027 2026] [security2:error] [pid 915741:tid 915941] [client 103.59.160.95:52012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TCq-615n1P-attmy01QAAAdU"]
[Mon Jul 20 06:22:34.882911 2026] [proxy:error] [pid 871012:tid 871116] (70007)The timeout specified has expired: [remote 80.210.17.232:52592] AH01095: prefetch request body failed to 127.0.0.1:8443 (127.0.0.1) from 80.210.17.232 (), referer: https://jenfarley.com/about/
[Mon Jul 20 06:22:34.903857 2026] [security2:error] [pid 915741:tid 915785] [remote 162.19.86.63:32814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TCq-615n1P-attmy02gAB3is"]
[Mon Jul 20 06:22:34.910033 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.98:24608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBa-615n1P-attmyz8QAB3HI"]
[Mon Jul 20 06:22:34.918649 2026] [security2:error] [pid 915741:tid 915944] [client 50.116.65.227:47568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TCq-615n1P-attmy02wAAAdg"]
[Mon Jul 20 06:22:34.930933 2026] [security2:error] [pid 915741:tid 915947] [client 50.116.65.227:26362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TCq-615n1P-attmy03AAAAes"]
[Mon Jul 20 06:22:34.944144 2026] [security2:error] [pid 915741:tid 915986] [client 27.96.94.195:37655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TCq-615n1P-attmy03gAAAgI"]
[Mon Jul 20 06:22:34.944271 2026] [security2:error] [pid 915741:tid 915986] [client 27.96.94.195:37655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TCq-615n1P-attmy03gAAAgI"]
[Mon Jul 20 06:22:35.076653 2026] [security2:error] [pid 915741:tid 915930] [client 198.98.59.181:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.59.98.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.coachpops.org"] [uri "/wp-login.php"] [unique_id "al4TC6-615n1P-attmy04gAAAco"]
[Mon Jul 20 06:22:35.110424 2026] [security2:error] [pid 915741:tid 915792] [remote 162.19.86.63:32814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TC6-615n1P-attmy05AAB4TI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:22:35.120803 2026] [security2:error] [pid 884009:tid 884261] [client 171.61.165.146:21734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJstQAAAP0"]
[Mon Jul 20 06:22:35.120929 2026] [security2:error] [pid 884009:tid 884261] [client 171.61.165.146:21734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJstQAAAP0"]
[Mon Jul 20 06:22:35.311473 2026] [security2:error] [pid 915741:tid 915937] [client 98.159.234.160:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TC6-615n1P-attmy07QAAAdE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:35.383967 2026] [security2:error] [pid 884009:tid 884151] [client 103.59.160.95:52223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TCxKaHUf6J8d3elJswQAAAJA"]
[Mon Jul 20 06:22:35.412203 2026] [security2:error] [pid 915741:tid 915918] [client 185.132.186.86:64061] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TC6-615n1P-attmy09gAAAb4"]
[Mon Jul 20 06:22:35.487758 2026] [security2:error] [pid 884009:tid 884048] [remote 47.86.33.52:11598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TCxKaHUf6J8d3elJsxgAAjSU"]
[Mon Jul 20 06:22:35.806984 2026] [security2:error] [pid 884009:tid 884039] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJs1QAA3Bw"]
[Mon Jul 20 06:22:35.807147 2026] [security2:error] [pid 884009:tid 884228] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJs1QAA3Bw"]
[Mon Jul 20 06:22:35.986140 2026] [security2:error] [pid 884009:tid 884127] [remote 47.86.33.52:11598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TCxKaHUf6J8d3elJs4AAAiXQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:36.013852 2026] [security2:error] [pid 884009:tid 884253] [client 77.110.127.138:61323] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4TDBKaHUf6J8d3elJs5wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:36.125717 2026] [security2:error] [pid 915741:tid 915875] [client 14.225.17.146:54631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4TCq-615n1P-attmy0ywAAAZM"], referer: http://eframiproperties.com/Wp
[Mon Jul 20 06:22:36.171549 2026] [security2:error] [pid 915741:tid 915898] [client 77.110.127.138:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDK-615n1P-attmy1AgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:36.171694 2026] [security2:error] [pid 915741:tid 915898] [client 77.110.127.138:61328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDK-615n1P-attmy1AgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:36.503079 2026] [security2:error] [pid 915741:tid 915983] [client 57.141.18.13:59718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TB6-615n1P-attmy0PAAB_3Q"]
[Mon Jul 20 06:22:36.579718 2026] [security2:error] [pid 915741:tid 915793] [remote 47.86.33.52:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4TDK-615n1P-attmy1HQABvzM"]
[Mon Jul 20 06:22:36.613861 2026] [security2:error] [pid 915741:tid 915888] [client 104.234.53.63:57987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TDK-615n1P-attmy1FgAAAaA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:37.149020 2026] [security2:error] [pid 915741:tid 915928] [client 57.141.18.106:59066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TCK-615n1P-attmy0XwAByAs"]
[Mon Jul 20 06:22:37.167472 2026] [security2:error] [pid 884009:tid 884178] [client 77.110.127.138:61301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TDBKaHUf6J8d3elJtCgAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:37.261891 2026] [security2:error] [pid 915741:tid 915876] [client 185.132.186.64:25553] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TDa-615n1P-attmy1PAAAAZQ"]
[Mon Jul 20 06:22:37.351141 2026] [security2:error] [pid 915741:tid 915991] [client 104.28.159.66:49960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santabear.space"] [uri "/wp-login.php"] [unique_id "al4TDa-615n1P-attmy1PQAAAgc"]
[Mon Jul 20 06:22:37.738448 2026] [security2:error] [pid 915741:tid 915901] [client 50.116.65.227:26398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TDa-615n1P-attmy1UQAAAa0"]
[Mon Jul 20 06:22:37.750062 2026] [security2:error] [pid 915741:tid 915931] [client 50.116.65.227:26402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TDa-615n1P-attmy1UgAAAcs"]
[Mon Jul 20 06:22:37.772015 2026] [security2:error] [pid 915741:tid 915911] [client 112.208.70.94:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TDa-615n1P-attmy1VgAAAbc"]
[Mon Jul 20 06:22:37.772144 2026] [security2:error] [pid 915741:tid 915911] [client 112.208.70.94:45967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TDa-615n1P-attmy1VgAAAbc"]
[Mon Jul 20 06:22:37.785515 2026] [security2:error] [pid 915741:tid 915958] [client 166.88.169.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tgs.lfg.mybluehost.me"] [uri "/index.php"] [unique_id "al4TDa-615n1P-attmy1QwAAAeY"]
[Mon Jul 20 06:22:37.849187 2026] [security2:error] [pid 915741:tid 915783] [remote 154.66.198.148:22794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TDa-615n1P-attmy1WAAB_Sk"]
[Mon Jul 20 06:22:37.911458 2026] [security2:error] [pid 884009:tid 884213] [client 93.177.75.10:65497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4TDRKaHUf6J8d3elJtPQAAAM0"], referer: https://aviationsynergy.aero/
[Mon Jul 20 06:22:38.074922 2026] [security2:error] [pid 884009:tid 884233] [client 77.110.127.138:61337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDhKaHUf6J8d3elJtRwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:38.075037 2026] [security2:error] [pid 884009:tid 884233] [client 77.110.127.138:61337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDhKaHUf6J8d3elJtRwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:38.128495 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:55448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4TDa-615n1P-attmy1OwAAAd0"], referer: http://mobilesurvsolutions.com/Wp
[Mon Jul 20 06:22:38.315262 2026] [security2:error] [pid 884009:tid 884166] [client 50.116.65.227:26436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TDhKaHUf6J8d3elJtSgAAAJ8"]
[Mon Jul 20 06:22:38.451571 2026] [security2:error] [pid 915741:tid 915823] [remote 47.86.33.52:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4TDq-615n1P-attmy1cQABwlE"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:22:38.494695 2026] [security2:error] [pid 884009:tid 884172] [client 50.116.65.227:26450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TDhKaHUf6J8d3elJtVwAAAKQ"]
[Mon Jul 20 06:22:38.505349 2026] [security2:error] [pid 915741:tid 915807] [remote 154.66.198.148:22794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TDq-615n1P-attmy1cwABnEE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:22:38.535043 2026] [security2:error] [pid 915741:tid 915994] [client 57.141.18.96:47462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TCa-615n1P-attmy0lgACCnY"]
[Mon Jul 20 06:22:38.761175 2026] [security2:error] [pid 884009:tid 884248] [client 14.225.17.146:61778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4TDhKaHUf6J8d3elJtZAAAAPA"], referer: http://dereckcastellon.com/Wp
[Mon Jul 20 06:22:38.799832 2026] [security2:error] [pid 915741:tid 915983] [client 13.201.64.214:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TDq-615n1P-attmy1gwAAAf8"]
[Mon Jul 20 06:22:38.916466 2026] [security2:error] [pid 884009:tid 884176] [client 57.141.18.121:25682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TCRKaHUf6J8d3elJseQAAqDk"]
[Mon Jul 20 06:22:39.002682 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:61313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TDq-615n1P-attmy1ggAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:39.124630 2026] [security2:error] [pid 915741:tid 915929] [client 185.132.186.87:41643] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TD6-615n1P-attmy1jAAAAck"]
[Mon Jul 20 06:22:39.164278 2026] [security2:error] [pid 915741:tid 915883] [client 35.162.140.124:49167] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thecreole.com"] [uri "/index.cgi"] [unique_id "al4TD6-615n1P-attmy1iwAAAZs"]
[Mon Jul 20 06:22:39.280985 2026] [security2:error] [pid 915741:tid 915886] [client 13.201.64.214:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1kwAAAZ4"]
[Mon Jul 20 06:22:39.281091 2026] [security2:error] [pid 915741:tid 915886] [client 13.201.64.214:51764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1kwAAAZ4"]
[Mon Jul 20 06:22:39.349572 2026] [security2:error] [pid 915741:tid 915981] [client 171.60.139.123:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1mAAAAf0"]
[Mon Jul 20 06:22:39.349707 2026] [security2:error] [pid 915741:tid 915981] [client 171.60.139.123:63007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1mAAAAf0"]
[Mon Jul 20 06:22:39.483792 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TD6-615n1P-attmy1oAAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:39.483892 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TD6-615n1P-attmy1oAAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:39.570855 2026] [security2:error] [pid 884009:tid 884268] [client 57.141.18.12:58186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TChKaHUf6J8d3elJslwABBEs"]
[Mon Jul 20 06:22:39.681161 2026] [security2:error] [pid 884009:tid 884220] [client 57.141.18.33:36902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TChKaHUf6J8d3elJsoAAA1Bs"]
[Mon Jul 20 06:22:39.880677 2026] [security2:error] [pid 915741:tid 915994] [client 43.205.139.3:21282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TD6-615n1P-attmy1qQAAAgo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:39.971839 2026] [security2:error] [pid 915741:tid 915967] [client 74.208.214.194:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TD6-615n1P-attmy1rgAAAe8"]
[Mon Jul 20 06:22:39.979447 2026] [security2:error] [pid 915741:tid 915919] [client 77.110.127.138:61319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TD6-615n1P-attmy1pwAAAb8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:40.167040 2026] [security2:error] [pid 884009:tid 884218] [client 114.119.157.124:40857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "russianlanguagetutor.com"] [uri "/mistakes-to-avoid-when-choosing-a-russian-language-teacher-online"] [unique_id "al4TEBKaHUf6J8d3elJtmQAAANI"], referer: https://russianlanguagetutor.com/mistakes-to-avoid-when-choosing-a-russian-language-teacher-online
[Mon Jul 20 06:22:40.250994 2026] [security2:error] [pid 915741:tid 915872] [client 45.116.69.230:55117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy1xAAAAZA"]
[Mon Jul 20 06:22:40.251151 2026] [security2:error] [pid 915741:tid 915872] [client 45.116.69.230:55117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy1xAAAAZA"]
[Mon Jul 20 06:22:40.353481 2026] [security2:error] [pid 915741:tid 915908] [client 57.141.18.98:37970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TC6-615n1P-attmy06QABtBY"]
[Mon Jul 20 06:22:40.470416 2026] [security2:error] [pid 915741:tid 915874] [client 50.116.65.227:34496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TEK-615n1P-attmy10gAAAZI"]
[Mon Jul 20 06:22:40.480843 2026] [security2:error] [pid 915741:tid 915903] [client 50.116.65.227:23598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TEK-615n1P-attmy11AAAAeg"]
[Mon Jul 20 06:22:40.785821 2026] [security2:error] [pid 915741:tid 915975] [client 178.152.178.232:37415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy13wAAAfc"]
[Mon Jul 20 06:22:40.785917 2026] [security2:error] [pid 915741:tid 915975] [client 178.152.178.232:37415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy13wAAAfc"]
[Mon Jul 20 06:22:40.815331 2026] [security2:error] [pid 915741:tid 915893] [client 57.141.18.75:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TC6-615n1P-attmy0_QABpVw"]
[Mon Jul 20 06:22:40.945908 2026] [security2:error] [pid 915741:tid 915994] [client 103.141.108.143:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy15wAAAgo"]
[Mon Jul 20 06:22:40.946550 2026] [security2:error] [pid 915741:tid 915994] [client 103.141.108.143:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy15wAAAgo"]
[Mon Jul 20 06:22:41.437179 2026] [security2:error] [pid 884009:tid 884240] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJtxgAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:41.467287 2026] [security2:error] [pid 915741:tid 915943] [client 14.225.17.146:63124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4TEK-615n1P-attmy1sgAAAdc"]
[Mon Jul 20 06:22:41.536026 2026] [security2:error] [pid 915741:tid 915911] [client 114.119.149.232:30087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4TEa-615n1P-attmy2CAAAAbc"], referer: https://newstral.com/en/article/en/1151935704/la-rice-crop-off-to-good-start-prices-up
[Mon Jul 20 06:22:41.696113 2026] [security2:error] [pid 884009:tid 884189] [client 14.225.17.146:63682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJt2wAAALU"], referer: http://nextlevelpressurewashing.com/Wp
[Mon Jul 20 06:22:41.928364 2026] [security2:error] [pid 915741:tid 915945] [client 57.141.18.50:52660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDK-615n1P-attmy1KgAB2U4"]
[Mon Jul 20 06:22:41.976559 2026] [security2:error] [pid 915741:tid 915921] [client 77.110.127.138:61362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TEa-615n1P-attmy2FAAAAcE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.097375 2026] [security2:error] [pid 884009:tid 884224] [client 77.110.127.138:61364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEhKaHUf6J8d3elJt7wAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.097503 2026] [security2:error] [pid 884009:tid 884224] [client 77.110.127.138:61364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEhKaHUf6J8d3elJt7wAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.147507 2026] [security2:error] [pid 884009:tid 884244] [client 14.225.17.146:63689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJt3wAAAOw"], referer: http://waterproofgoods.com/Wp
[Mon Jul 20 06:22:42.246772 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEq-615n1P-attmy2IgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.246882 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEq-615n1P-attmy2IgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.599729 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.38:51796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDa-615n1P-attmy1QgABnUM"]
[Mon Jul 20 06:22:42.618038 2026] [security2:error] [pid 884009:tid 884200] [client 66.249.66.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4TEhKaHUf6J8d3elJt_wAAAMA"]
[Mon Jul 20 06:22:42.759691 2026] [security2:error] [pid 884009:tid 884206] [client 77.110.127.138:61369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TEhKaHUf6J8d3elJt-wAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.885287 2026] [security2:error] [pid 915741:tid 915906] [client 14.225.17.146:63242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4TEq-615n1P-attmy2NwAAAbI"], referer: http://dasmarque.com/Wp
[Mon Jul 20 06:22:43.307949 2026] [security2:error] [pid 915741:tid 915922] [client 50.116.65.227:34518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4TE6-615n1P-attmy2WAAAAcI"]
[Mon Jul 20 06:22:43.319209 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.50:52662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDq-615n1P-attmy1aQACBCo"]
[Mon Jul 20 06:22:43.320266 2026] [security2:error] [pid 915741:tid 915981] [client 50.116.65.227:23644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4TE6-615n1P-attmy2WQAAAZM"]
[Mon Jul 20 06:22:43.499160 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2VwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:43.547393 2026] [security2:error] [pid 915741:tid 915913] [client 57.141.18.92:29042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDq-615n1P-attmy1bQABuUA"]
[Mon Jul 20 06:22:43.591522 2026] [security2:error] [pid 915741:tid 915925] [client 34.74.185.202:51841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4TE6-615n1P-attmy2YgAAAcU"]
[Mon Jul 20 06:22:43.676459 2026] [security2:error] [pid 915741:tid 915900] [client 77.110.127.138:61372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2XAAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:43.863885 2026] [security2:error] [pid 915741:tid 915813] [remote 162.19.86.63:41171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4TE6-615n1P-attmy2aQAB60c"]
[Mon Jul 20 06:22:43.942293 2026] [security2:error] [pid 915741:tid 915926] [client 77.110.127.138:61313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2YwAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:43.965805 2026] [security2:error] [pid 884009:tid 884229] [client 41.173.37.102:11382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TExKaHUf6J8d3elJuLgAAAN0"]
[Mon Jul 20 06:22:43.965901 2026] [security2:error] [pid 884009:tid 884229] [client 41.173.37.102:11382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TExKaHUf6J8d3elJuLgAAAN0"]
[Mon Jul 20 06:22:43.972007 2026] [security2:error] [pid 915741:tid 915923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2ZgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:44.076197 2026] [security2:error] [pid 915741:tid 915869] [remote 162.19.86.63:41171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4TFK-615n1P-attmy2cgABwH8"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 06:22:44.197596 2026] [security2:error] [pid 915741:tid 915996] [client 34.74.185.202:52247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TFK-615n1P-attmy2dAAAAgw"]
[Mon Jul 20 06:22:44.231033 2026] [security2:error] [pid 884009:tid 884217] [client 57.141.18.22:29842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDxKaHUf6J8d3elJtdgAA0Uo"]
[Mon Jul 20 06:22:44.523466 2026] [security2:error] [pid 884009:tid 884176] [client 14.225.17.146:61204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4TFBKaHUf6J8d3elJuMwAAAKg"], referer: http://hilltopnurseryinc.com/Wp
[Mon Jul 20 06:22:44.628082 2026] [security2:error] [pid 915741:tid 915865] [remote 81.173.115.7:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TFK-615n1P-attmy2kwACCXs"]
[Mon Jul 20 06:22:44.669333 2026] [security2:error] [pid 884009:tid 884263] [client 77.110.127.138:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TFBKaHUf6J8d3elJuRQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:44.669461 2026] [security2:error] [pid 884009:tid 884263] [client 77.110.127.138:61379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TFBKaHUf6J8d3elJuRQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:44.800401 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:58649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2RwAAAds"], referer: http://ccsdifference.com/Wp
[Mon Jul 20 06:22:44.817872 2026] [security2:error] [pid 915741:tid 915744] [remote 81.173.115.7:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TFK-615n1P-attmy2nAABvAI"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:22:44.874507 2026] [security2:error] [pid 915741:tid 915924] [client 34.74.185.202:54586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TFK-615n1P-attmy2oAAAAcQ"]
[Mon Jul 20 06:22:45.113516 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:61319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TFK-615n1P-attmy2mAAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:45.316272 2026] [security2:error] [pid 915741:tid 915969] [client 216.73.217.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy2sQAAAfE"]
[Mon Jul 20 06:22:45.353013 2026] [security2:error] [pid 915741:tid 915955] [client 27.96.94.195:37898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TFa-615n1P-attmy2tQAAAeM"]
[Mon Jul 20 06:22:45.353158 2026] [security2:error] [pid 915741:tid 915955] [client 27.96.94.195:37898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TFa-615n1P-attmy2tQAAAeM"]
[Mon Jul 20 06:22:45.443552 2026] [security2:error] [pid 884009:tid 884189] [client 216.73.217.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4TFRKaHUf6J8d3elJuVgAAALU"], referer: https://processorstudio.com/sitemap.xml
[Mon Jul 20 06:22:45.491255 2026] [security2:error] [pid 915741:tid 915957] [client 57.141.18.12:58188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TEK-615n1P-attmy1zwAB5QA"]
[Mon Jul 20 06:22:45.679621 2026] [security2:error] [pid 915741:tid 915932] [client 34.74.185.202:56477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TFa-615n1P-attmy2zgAAAcw"]
[Mon Jul 20 06:22:45.680627 2026] [security2:error] [pid 915741:tid 915884] [client 14.225.17.146:60782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4TFK-615n1P-attmy2bgAAAZw"], referer: http://nwcarvingacademy.com/Wp
[Mon Jul 20 06:22:45.774612 2026] [security2:error] [pid 884009:tid 884178] [client 57.141.18.78:26874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TEBKaHUf6J8d3elJtsQAAqiA"]
[Mon Jul 20 06:22:45.841717 2026] [security2:error] [pid 915741:tid 915929] [client 14.225.17.146:62836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy2yQAAAck"], referer: https://ccsdifference.com/Wp
[Mon Jul 20 06:22:45.992153 2026] [security2:error] [pid 915741:tid 915959] [client 34.74.185.202:51456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TFa-615n1P-attmy22wAAAec"]
[Mon Jul 20 06:22:46.018573 2026] [security2:error] [pid 884009:tid 884158] [client 171.61.165.146:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuaQAAAJc"]
[Mon Jul 20 06:22:46.018697 2026] [security2:error] [pid 884009:tid 884158] [client 171.61.165.146:26608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuaQAAAJc"]
[Mon Jul 20 06:22:46.159590 2026] [ssl:error] [pid 884009:tid 884220] [client 199.45.154.150:53418] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.poopscoopmarketing.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:22:46.160015 2026] [security2:error] [pid 884009:tid 884171] [client 45.157.112.60:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TFhKaHUf6J8d3elJubAAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:46.162362 2026] [security2:error] [pid 915741:tid 915908] [client 50.116.65.227:34522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TFq-615n1P-attmy25wAAAbQ"]
[Mon Jul 20 06:22:46.172190 2026] [security2:error] [pid 884009:tid 884211] [client 50.116.65.227:23712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TFhKaHUf6J8d3elJubQAAAI4"]
[Mon Jul 20 06:22:46.270801 2026] [security2:error] [pid 915741:tid 915990] [client 14.225.17.146:51445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy25QAAAgY"], referer: http://adirondackengineering.com/Wp
[Mon Jul 20 06:22:46.402929 2026] [security2:error] [pid 884009:tid 884260] [client 57.141.18.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TFhKaHUf6J8d3elJudAAAAPw"]
[Mon Jul 20 06:22:46.582917 2026] [security2:error] [pid 884009:tid 884067] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuggAA9zg"]
[Mon Jul 20 06:22:46.583066 2026] [security2:error] [pid 884009:tid 884255] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuggAA9zg"]
[Mon Jul 20 06:22:46.637846 2026] [security2:error] [pid 915741:tid 915915] [client 103.153.183.69:39968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..\\xe0\\x80\\xaf../etc/passwd"] [unique_id "al4TFq-615n1P-attmy2_gAAAbs"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:22:46.639417 2026] [security2:error] [pid 915741:tid 915897] [client 14.224.227.113:54413] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4TFq-615n1P-attmy2_wAAAak"]
[Mon Jul 20 06:22:46.699507 2026] [security2:error] [pid 884009:tid 884197] [client 57.141.18.40:22940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJt3QAAvQ4"]
[Mon Jul 20 06:22:46.739220 2026] [security2:error] [pid 884009:tid 884175] [client 14.225.17.146:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4TFhKaHUf6J8d3elJufgAAAKc"], referer: https://nwcarvingacademy.com/Wp
[Mon Jul 20 06:22:46.822264 2026] [security2:error] [pid 915741:tid 915931] [client 34.74.185.202:59389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TFq-615n1P-attmy3CgAAAcs"]
[Mon Jul 20 06:22:47.073007 2026] [security2:error] [pid 884009:tid 884170] [client 34.74.185.202:63024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TFxKaHUf6J8d3elJunAAAAKI"]
[Mon Jul 20 06:22:47.084706 2026] [core:error] [pid 884009:tid 884140] [client 103.153.183.69:23236] AH10244: invalid URI path (/../../.env?_=iprphgyb&v=8awcg), referer: https://duckduckgo.com/?q=iehr5
[Mon Jul 20 06:22:47.368636 2026] [security2:error] [pid 884009:tid 884151] [client 14.225.17.146:51349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4TFRKaHUf6J8d3elJuZgAAAJA"], referer: http://solkeetw.com/Wp
[Mon Jul 20 06:22:47.405780 2026] [security2:error] [pid 884009:tid 884171] [client 50.116.65.227:23740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TFxKaHUf6J8d3elJuqQAAAKM"]
[Mon Jul 20 06:22:47.416129 2026] [security2:error] [pid 915741:tid 915911] [client 50.116.65.227:23752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TF6-615n1P-attmy3IgAAAbc"]
[Mon Jul 20 06:22:47.721118 2026] [security2:error] [pid 915741:tid 915808] [remote 45.90.123.233:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TF6-615n1P-attmy3LQAByUI"]
[Mon Jul 20 06:22:47.721412 2026] [security2:error] [pid 915741:tid 915929] [client 45.90.123.233:42096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TF6-615n1P-attmy3LQAByUI"]
[Mon Jul 20 06:22:47.730989 2026] [core:error] [pid 915741:tid 915878] [client 103.153.183.69:23240] AH10244: invalid URI path (/../../.env?_=bor5t3vg&v=9bztk), referer: https://www.bing.com/search?q=zkwjx8
[Mon Jul 20 06:22:47.742188 2026] [security2:error] [pid 915741:tid 915934] [client 57.141.18.76:35678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TEq-615n1P-attmy2LwABzmM"]
[Mon Jul 20 06:22:48.011729 2026] [security2:error] [pid 884009:tid 884259] [client 34.74.185.202:63024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TGBKaHUf6J8d3elJuvgAAAPs"]
[Mon Jul 20 06:22:48.028179 2026] [security2:error] [pid 915741:tid 915995] [client 14.225.17.146:51385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy26QAAAgs"], referer: http://according2plant.com/Wp
[Mon Jul 20 06:22:48.184039 2026] [security2:error] [pid 915741:tid 915882] [client 104.234.53.94:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TGK-615n1P-attmy3SQAAAZo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:48.367307 2026] [security2:error] [pid 915741:tid 915992] [client 57.141.18.126:60156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2TQACCHA"]
[Mon Jul 20 06:22:48.408767 2026] [security2:error] [pid 884009:tid 884243] [client 77.110.127.138:61381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TGBKaHUf6J8d3elJuwwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:48.442546 2026] [security2:error] [pid 884009:tid 884037] [remote 20.153.140.50:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4TGBKaHUf6J8d3elJuyQAA_Ro"]
[Mon Jul 20 06:22:48.538586 2026] [security2:error] [pid 884009:tid 884142] [client 57.141.18.115:44602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TExKaHUf6J8d3elJuGwAAh34"]
[Mon Jul 20 06:22:48.570304 2026] [security2:error] [pid 884009:tid 884163] [client 74.125.213.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4TFhKaHUf6J8d3elJugAAAAJw"]
[Mon Jul 20 06:22:48.583342 2026] [security2:error] [pid 915741:tid 915880] [client 14.225.17.146:56276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy3FQAAAZg"], referer: http://mtlegnews.gov/Wp
[Mon Jul 20 06:22:48.599359 2026] [security2:error] [pid 884009:tid 884092] [remote 8.217.108.67:54822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4TGBKaHUf6J8d3elJu0AAAuFE"]
[Mon Jul 20 06:22:48.874927 2026] [security2:error] [pid 884009:tid 884224] [client 57.141.18.111:61286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TExKaHUf6J8d3elJuKwAA2EA"]
[Mon Jul 20 06:22:48.904094 2026] [security2:error] [pid 884009:tid 884117] [remote 20.153.140.50:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4TGBKaHUf6J8d3elJu4AAApWo"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 06:22:48.991290 2026] [security2:error] [pid 915741:tid 915919] [client 34.73.38.214:61427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TGK-615n1P-attmy3YgAAAb8"]
[Mon Jul 20 06:22:49.232031 2026] [security2:error] [pid 915741:tid 915925] [client 14.225.17.146:51525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy3EgAAAcU"], referer: http://latiendadejorge.com.gt/Wp
[Mon Jul 20 06:22:49.244977 2026] [security2:error] [pid 884009:tid 884165] [client 34.74.185.202:65439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TGRKaHUf6J8d3elJu9QAAAJ4"]
[Mon Jul 20 06:22:49.265062 2026] [security2:error] [pid 915741:tid 915791] [remote 192.241.143.148:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TGa-615n1P-attmy3bwABxzE"]
[Mon Jul 20 06:22:49.367276 2026] [security2:error] [pid 884009:tid 884238] [client 68.235.52.68:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TGRKaHUf6J8d3elJu-wAAAOY"]
[Mon Jul 20 06:22:49.367383 2026] [security2:error] [pid 884009:tid 884238] [client 68.235.52.68:46192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TGRKaHUf6J8d3elJu-wAAAOY"]
[Mon Jul 20 06:22:49.458132 2026] [security2:error] [pid 915741:tid 915754] [remote 192.241.143.148:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TGa-615n1P-attmy3fAABsQw"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:22:49.580595 2026] [security2:error] [pid 884009:tid 884240] [client 57.141.18.22:29864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFBKaHUf6J8d3elJuQwAA6CQ"]
[Mon Jul 20 06:22:49.678058 2026] [security2:error] [pid 915741:tid 915957] [client 14.225.17.146:50676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4TGK-615n1P-attmy3UQAAAeU"], referer: http://whiteoutcb.com/Wp
[Mon Jul 20 06:22:49.842530 2026] [security2:error] [pid 915741:tid 915968] [client 57.141.18.23:54742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFK-615n1P-attmy2oQAB8H4"]
[Mon Jul 20 06:22:49.911947 2026] [security2:error] [pid 884009:tid 884191] [client 103.153.183.69:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/.env"] [unique_id "al4TGRKaHUf6J8d3elJvCQAAALc"], referer: https://www.facebook.com/
[Mon Jul 20 06:22:50.131175 2026] [security2:error] [pid 915741:tid 915955] [client 34.74.185.202:63622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TGq-615n1P-attmy3ngAAAeM"]
[Mon Jul 20 06:22:50.207086 2026] [security2:error] [pid 915741:tid 915905] [client 34.73.38.214:54500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TGq-615n1P-attmy3owAAAbE"]
[Mon Jul 20 06:22:50.240660 2026] [security2:error] [pid 884009:tid 884174] [client 171.60.139.123:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TGhKaHUf6J8d3elJvEAAAAKY"]
[Mon Jul 20 06:22:50.240843 2026] [security2:error] [pid 884009:tid 884174] [client 171.60.139.123:63524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TGhKaHUf6J8d3elJvEAAAAKY"]
[Mon Jul 20 06:22:50.363325 2026] [security2:error] [pid 915741:tid 915874] [client 57.141.18.56:47760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy2vgABkgg"]
[Mon Jul 20 06:22:50.597074 2026] [security2:error] [pid 915741:tid 915879] [client 14.225.17.146:50651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4TGq-615n1P-attmy3qQAAAZc"], referer: http://grecruit.online/Wp
[Mon Jul 20 06:22:50.716276 2026] [security2:error] [pid 915741:tid 915951] [client 3.75.183.99:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TGq-615n1P-attmy3vgAAAd8"]
[Mon Jul 20 06:22:50.814381 2026] [security2:error] [pid 915741:tid 915971] [client 57.141.18.98:27778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy21QAB824"]
[Mon Jul 20 06:22:50.968205 2026] [security2:error] [pid 915741:tid 915954] [client 57.141.18.100:50818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy23QAB4l0"]
[Mon Jul 20 06:22:51.058532 2026] [security2:error] [pid 884009:tid 884221] [client 45.116.69.230:55660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TGxKaHUf6J8d3elJvLgAAANU"]
[Mon Jul 20 06:22:51.058661 2026] [security2:error] [pid 884009:tid 884221] [client 45.116.69.230:55660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TGxKaHUf6J8d3elJvLgAAANU"]
[Mon Jul 20 06:22:51.066902 2026] [security2:error] [pid 915741:tid 915923] [client 34.74.185.202:53176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TG6-615n1P-attmy3zQAAAcM"]
[Mon Jul 20 06:22:51.135059 2026] [security2:error] [pid 915741:tid 915897] [client 50.116.65.227:36842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4TG6-615n1P-attmy3zgAAAak"]
[Mon Jul 20 06:22:51.146524 2026] [security2:error] [pid 915741:tid 915950] [client 50.116.65.227:26234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4TG6-615n1P-attmy3zwAAAd4"]
[Mon Jul 20 06:22:51.278422 2026] [security2:error] [pid 915741:tid 915874] [client 34.73.38.214:54552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TG6-615n1P-attmy30QAAAZI"]
[Mon Jul 20 06:22:51.332907 2026] [security2:error] [pid 915741:tid 915891] [client 57.141.18.25:52494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy27wABow8"]
[Mon Jul 20 06:22:51.521648 2026] [security2:error] [pid 915741:tid 915995] [client 104.234.53.54:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TG6-615n1P-attmy33wAAAgs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:51.605058 2026] [security2:error] [pid 915741:tid 915913] [client 103.141.108.143:56061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TG6-615n1P-attmy35wAAAbk"]
[Mon Jul 20 06:22:51.605236 2026] [security2:error] [pid 915741:tid 915913] [client 103.141.108.143:56061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TG6-615n1P-attmy35wAAAbk"]
[Mon Jul 20 06:22:51.614057 2026] [security2:error] [pid 915741:tid 915904] [client 108.59.114.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy33AAAAbA"]
[Mon Jul 20 06:22:51.734974 2026] [security2:error] [pid 915741:tid 915875] [client 54.169.146.187:64916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TG6-615n1P-attmy37AAAAZM"]
[Mon Jul 20 06:22:51.821648 2026] [security2:error] [pid 884009:tid 884205] [client 63.179.149.246:19882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TGxKaHUf6J8d3elJvSgAAAMU"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:52.110903 2026] [security2:error] [pid 884009:tid 884201] [client 34.73.38.214:52911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4THBKaHUf6J8d3elJvWgAAAME"]
[Mon Jul 20 06:22:52.274530 2026] [security2:error] [pid 884009:tid 884067] [remote 8.217.108.67:54822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4THBKaHUf6J8d3elJvaAABAjg"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:22:52.397161 2026] [security2:error] [pid 884009:tid 884077] [remote 72.167.132.114:38530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4THBKaHUf6J8d3elJvbQAAhUI"]
[Mon Jul 20 06:22:52.439354 2026] [security2:error] [pid 915741:tid 915929] [client 34.73.38.214:58255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4THK-615n1P-attmy3_gAAAck"]
[Mon Jul 20 06:22:52.446992 2026] [security2:error] [pid 915741:tid 915931] [client 34.74.185.202:53195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4THK-615n1P-attmy3_wAAAcs"]
[Mon Jul 20 06:22:52.532430 2026] [security2:error] [pid 915741:tid 915993] [client 66.249.68.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mzsassy.com"] [uri "/index.php"] [unique_id "al4TGq-615n1P-attmy3rwACCRI"]
[Mon Jul 20 06:22:52.562186 2026] [security2:error] [pid 884009:tid 884176] [client 57.141.18.120:43242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFxKaHUf6J8d3elJutgAAqAI"]
[Mon Jul 20 06:22:52.567971 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:42375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4THK-615n1P-attmy4CgAAAeI"]
[Mon Jul 20 06:22:52.568122 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:42375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4THK-615n1P-attmy4CgAAAeI"]
[Mon Jul 20 06:22:52.600869 2026] [security2:error] [pid 915741:tid 915943] [client 47.129.222.11:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4THK-615n1P-attmy4DQAAAdc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:52.635710 2026] [security2:error] [pid 915741:tid 915983] [client 78.46.190.63:62588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4THK-615n1P-attmy4CQAAAf8"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:22:52.731033 2026] [security2:error] [pid 884009:tid 884234] [client 77.110.127.138:61388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THBKaHUf6J8d3elJvWQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:52.766249 2026] [security2:error] [pid 884009:tid 884087] [remote 72.167.132.114:38530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4THBKaHUf6J8d3elJvhQAA4Uw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:22:52.775299 2026] [security2:error] [pid 884009:tid 884224] [client 77.110.127.138:61394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THBKaHUf6J8d3elJvYgAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:52.897181 2026] [security2:error] [pid 884009:tid 884259] [client 77.110.127.138:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THBKaHUf6J8d3elJvhwAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:52.897276 2026] [security2:error] [pid 884009:tid 884259] [client 77.110.127.138:61397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THBKaHUf6J8d3elJvhwAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:53.235526 2026] [security2:error] [pid 884009:tid 884257] [client 34.73.38.214:49437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4THRKaHUf6J8d3elJvlgAAAPk"]
[Mon Jul 20 06:22:53.317098 2026] [security2:error] [pid 884009:tid 884240] [client 77.110.127.138:61399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THRKaHUf6J8d3elJvkgAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:53.379967 2026] [security2:error] [pid 884009:tid 884252] [client 34.74.185.202:59817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4THRKaHUf6J8d3elJvnQAAAPQ"]
[Mon Jul 20 06:22:53.699765 2026] [security2:error] [pid 915741:tid 915964] [client 34.73.38.214:57543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4THa-615n1P-attmy4LwAAAew"]
[Mon Jul 20 06:22:53.888251 2026] [security2:error] [pid 884009:tid 884244] [client 104.234.53.63:37805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4THRKaHUf6J8d3elJvtAAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:54.015004 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THa-615n1P-attmy4MQAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.093788 2026] [security2:error] [pid 915741:tid 915924] [client 34.73.38.214:56987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4PgAAAcQ"]
[Mon Jul 20 06:22:54.106995 2026] [security2:error] [pid 884009:tid 884149] [client 77.110.127.138:61403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THRKaHUf6J8d3elJvugAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.182220 2026] [security2:error] [pid 915741:tid 915818] [remote 152.228.213.32:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4THq-615n1P-attmy4PwACB0w"]
[Mon Jul 20 06:22:54.240083 2026] [security2:error] [pid 915741:tid 915912] [client 34.73.38.214:51811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4RgAAAbg"]
[Mon Jul 20 06:22:54.285999 2026] [security2:error] [pid 915741:tid 915876] [client 77.110.127.138:61405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THq-615n1P-attmy4PQAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.316190 2026] [security2:error] [pid 915741:tid 915965] [client 178.152.178.232:36934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4TAAAAe0"]
[Mon Jul 20 06:22:54.323101 2026] [security2:error] [pid 915741:tid 915965] [client 178.152.178.232:36934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4TAAAAe0"]
[Mon Jul 20 06:22:54.387958 2026] [security2:error] [pid 884009:tid 884255] [client 34.73.38.214:53194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4THhKaHUf6J8d3elJvygAAAPc"]
[Mon Jul 20 06:22:54.413489 2026] [security2:error] [pid 915741:tid 915998] [client 57.141.18.26:27770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TGa-615n1P-attmy3hQACDjY"]
[Mon Jul 20 06:22:54.520022 2026] [security2:error] [pid 884009:tid 884239] [client 34.73.38.214:58807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4THhKaHUf6J8d3elJv0AAAAOc"]
[Mon Jul 20 06:22:54.573651 2026] [security2:error] [pid 915741:tid 915884] [client 41.173.37.102:11810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4WAAAAZw"]
[Mon Jul 20 06:22:54.573737 2026] [security2:error] [pid 915741:tid 915884] [client 41.173.37.102:11810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4WAAAAZw"]
[Mon Jul 20 06:22:54.585176 2026] [security2:error] [pid 915741:tid 915910] [client 77.110.127.138:61407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THq-615n1P-attmy4TgAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.612403 2026] [security2:error] [pid 915741:tid 915780] [remote 152.228.213.32:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4THq-615n1P-attmy4WwAB-CY"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:22:54.672143 2026] [security2:error] [pid 915741:tid 915890] [client 34.73.38.214:63490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4YAAAAaI"]
[Mon Jul 20 06:22:54.790000 2026] [security2:error] [pid 915741:tid 915929] [client 34.73.38.214:57724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4ZgAAAck"]
[Mon Jul 20 06:22:54.887926 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.12:53236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TGq-615n1P-attmy3oAABqBQ"]
[Mon Jul 20 06:22:54.905450 2026] [security2:error] [pid 915741:tid 915948] [client 34.73.38.214:63490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4agAAAdw"]
[Mon Jul 20 06:22:54.995349 2026] [security2:error] [pid 915741:tid 915843] [remote 72.167.132.114:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4THq-615n1P-attmy4bQABo2U"]
[Mon Jul 20 06:22:55.050926 2026] [security2:error] [pid 884009:tid 884225] [client 77.110.127.138:61413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THhKaHUf6J8d3elJv2gAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.082841 2026] [security2:error] [pid 884009:tid 884252] [client 34.73.38.214:57842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4THxKaHUf6J8d3elJv4gAAAPQ"]
[Mon Jul 20 06:22:55.155769 2026] [security2:error] [pid 884009:tid 884236] [client 104.234.53.63:37805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4THxKaHUf6J8d3elJv5wAAAOQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:55.222917 2026] [security2:error] [pid 915741:tid 915867] [remote 72.167.132.114:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TH6-615n1P-attmy4egABuH0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:22:55.230971 2026] [security2:error] [pid 915741:tid 915978] [client 34.73.38.214:57063] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TH6-615n1P-attmy4ewAAAfo"]
[Mon Jul 20 06:22:55.319323 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TH6-615n1P-attmy4fwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.319410 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TH6-615n1P-attmy4fwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.383461 2026] [security2:error] [pid 915741:tid 915923] [client 34.73.38.214:56175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TH6-615n1P-attmy4hAAAAcM"]
[Mon Jul 20 06:22:55.531427 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THxKaHUf6J8d3elJv-wAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.531545 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THxKaHUf6J8d3elJv-wAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.548266 2026] [security2:error] [pid 915741:tid 915950] [client 34.73.38.214:49196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TH6-615n1P-attmy4jwAAAd4"]
[Mon Jul 20 06:22:55.601030 2026] [security2:error] [pid 884009:tid 884254] [client 77.110.127.138:61416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THxKaHUf6J8d3elJv9AAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.700946 2026] [security2:error] [pid 884009:tid 884159] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THxKaHUf6J8d3elJv-gAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.751036 2026] [security2:error] [pid 915741:tid 915987] [client 57.141.18.32:51598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy3ywACAyU"]
[Mon Jul 20 06:22:55.766884 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:61117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4THxKaHUf6J8d3elJwBAAAAQQ"]
[Mon Jul 20 06:22:55.984511 2026] [security2:error] [pid 884009:tid 884186] [client 34.73.38.214:62882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4THxKaHUf6J8d3elJwDwAAALI"]
[Mon Jul 20 06:22:56.047885 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4lAAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:56.142212 2026] [security2:error] [pid 915741:tid 915916] [client 34.73.38.214:52946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TIK-615n1P-attmy4qgAAAbw"]
[Mon Jul 20 06:22:56.165170 2026] [security2:error] [pid 915741:tid 915932] [client 57.141.18.8:60262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy30wABzCk"]
[Mon Jul 20 06:22:56.348198 2026] [security2:error] [pid 915741:tid 915971] [client 34.73.38.214:59273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TIK-615n1P-attmy4sQAAAfM"]
[Mon Jul 20 06:22:56.372548 2026] [security2:error] [pid 915741:tid 915889] [client 57.141.18.87:28300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy33gABoRk"]
[Mon Jul 20 06:22:56.536215 2026] [security2:error] [pid 915741:tid 915984] [client 77.110.127.138:61423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4rQAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:56.739255 2026] [security2:error] [pid 915741:tid 915831] [remote 91.142.222.105:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4TIK-615n1P-attmy4wgABlVk"]
[Mon Jul 20 06:22:56.816680 2026] [security2:error] [pid 915741:tid 915886] [client 14.225.17.146:64474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4wwAAAZ4"], referer: http://katsklar.com/Wp
[Mon Jul 20 06:22:56.855144 2026] [security2:error] [pid 915741:tid 915817] [remote 188.166.241.141:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4TIK-615n1P-attmy4xQABlEs"]
[Mon Jul 20 06:22:57.035479 2026] [security2:error] [pid 915741:tid 915819] [remote 91.142.222.105:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4TIa-615n1P-attmy4zQAB100"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:22:57.198172 2026] [security2:error] [pid 884009:tid 884021] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwRQAArgo"]
[Mon Jul 20 06:22:57.198388 2026] [security2:error] [pid 884009:tid 884182] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwRQAArgo"]
[Mon Jul 20 06:22:57.253880 2026] [security2:error] [pid 884009:tid 884200] [client 57.141.18.37:60506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4THBKaHUf6J8d3elJvgwAAwEU"]
[Mon Jul 20 06:22:57.294727 2026] [security2:error] [pid 915741:tid 915822] [remote 188.166.241.141:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4TIa-615n1P-attmy41gAB7lA"], referer: https://rtkenergypartners.com/wp-login.php
[Mon Jul 20 06:22:57.358356 2026] [security2:error] [pid 915741:tid 915902] [client 77.110.127.138:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy41wAAAa4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.358553 2026] [security2:error] [pid 915741:tid 915902] [client 77.110.127.138:61398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy41wAAAa4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.523211 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy44wAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.523365 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy44wAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.549057 2026] [security2:error] [pid 915741:tid 915891] [client 50.116.65.227:26246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TIa-615n1P-attmy45QAAAaM"]
[Mon Jul 20 06:22:57.559734 2026] [security2:error] [pid 915741:tid 915945] [client 50.116.65.227:26258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TIa-615n1P-attmy45gAAAdk"]
[Mon Jul 20 06:22:57.585196 2026] [security2:error] [pid 915741:tid 915940] [client 77.110.127.138:61432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4TIa-615n1P-attmy46QAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.660736 2026] [security2:error] [pid 884009:tid 884029] [remote 151.240.255.102:43331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwRAAA1BI"], referer: https://www.thewelloiledlife.com/free-shipping-on-young-livings-premium-starter-kit/
[Mon Jul 20 06:22:57.894642 2026] [security2:error] [pid 915741:tid 915884] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4uwAAAZw"]
[Mon Jul 20 06:22:57.946984 2026] [security2:error] [pid 884009:tid 884160] [client 57.141.18.85:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4THRKaHUf6J8d3elJvogAAmR4"]
[Mon Jul 20 06:22:57.977669 2026] [security2:error] [pid 884009:tid 884246] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwXAAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:58.000169 2026] [security2:error] [pid 884009:tid 884236] [client 171.61.165.146:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwYwAAAOQ"]
[Mon Jul 20 06:22:58.000302 2026] [security2:error] [pid 884009:tid 884236] [client 171.61.165.146:14016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwYwAAAOQ"]
[Mon Jul 20 06:22:58.234843 2026] [security2:error] [pid 915741:tid 915993] [client 14.225.17.146:64416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4rAAAAgk"], referer: http://www.justinagrayman.com/Wp
[Mon Jul 20 06:22:58.430516 2026] [security2:error] [pid 915741:tid 915933] [client 50.116.65.227:36850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TIq-615n1P-attmy5DQAAAc0"]
[Mon Jul 20 06:22:58.440670 2026] [security2:error] [pid 915741:tid 915997] [client 50.116.65.227:26286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TIq-615n1P-attmy5DwAAAcQ"]
[Mon Jul 20 06:22:58.818804 2026] [security2:error] [pid 884009:tid 884180] [client 14.225.17.146:64415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwXgAAAKw"]
[Mon Jul 20 06:22:58.945035 2026] [security2:error] [pid 884009:tid 884015] [remote 81.173.115.7:45474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TIhKaHUf6J8d3elJwgwAAyQQ"]
[Mon Jul 20 06:22:58.945290 2026] [security2:error] [pid 884009:tid 884209] [client 81.173.115.7:45474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TIhKaHUf6J8d3elJwgwAAyQQ"]
[Mon Jul 20 06:22:59.025003 2026] [security2:error] [pid 915741:tid 915961] [client 57.141.18.16:62890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4THq-615n1P-attmy4YwAB6Uc"]
[Mon Jul 20 06:22:59.201428 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TI6-615n1P-attmy5OAAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.201531 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TI6-615n1P-attmy5OAAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.361562 2026] [security2:error] [pid 884009:tid 884239] [client 77.110.127.138:61437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TIxKaHUf6J8d3elJwiwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.375959 2026] [security2:error] [pid 915741:tid 915947] [client 47.128.30.14:63668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hollinbankfarm.com"] [uri "/robots.txt"] [unique_id "al4TI6-615n1P-attmy5QwAAAds"]
[Mon Jul 20 06:22:59.397414 2026] [security2:error] [pid 915741:tid 915946] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TI6-615n1P-attmy5NgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.469029 2026] [security2:error] [pid 884009:tid 884163] [client 77.110.127.138:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4TIxKaHUf6J8d3elJwlgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.512437 2026] [security2:error] [pid 915741:tid 915994] [client 57.141.18.97:35576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4cgACCn8"]
[Mon Jul 20 06:22:59.718769 2026] [security2:error] [pid 884009:tid 884176] [client 27.96.94.195:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TIxKaHUf6J8d3elJwnQAAAKg"]
[Mon Jul 20 06:22:59.718966 2026] [security2:error] [pid 884009:tid 884176] [client 27.96.94.195:37826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TIxKaHUf6J8d3elJwnQAAAKg"]
[Mon Jul 20 06:23:00.177195 2026] [security2:error] [pid 915741:tid 915964] [client 57.141.18.61:53396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4mQAB7AI"]
[Mon Jul 20 06:23:00.196134 2026] [security2:error] [pid 915741:tid 915874] [client 57.141.18.73:53992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4nAABkkU"]
[Mon Jul 20 06:23:00.277725 2026] [security2:error] [pid 884009:tid 884244] [client 104.234.53.84:45115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TJBKaHUf6J8d3elJwrwAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:00.797353 2026] [security2:error] [pid 915741:tid 915905] [client 171.60.139.123:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TJK-615n1P-attmy5hQAAAbE"]
[Mon Jul 20 06:23:00.797493 2026] [security2:error] [pid 915741:tid 915905] [client 171.60.139.123:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TJK-615n1P-attmy5hQAAAbE"]
[Mon Jul 20 06:23:00.891886 2026] [security2:error] [pid 915741:tid 915970] [client 14.225.17.146:62494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4TI6-615n1P-attmy5NwAAAfI"], referer: http://vinovinhowine.com/Wp
[Mon Jul 20 06:23:01.179862 2026] [security2:error] [pid 884009:tid 884264] [client 57.141.18.5:61178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIBKaHUf6J8d3elJwNAABAAc"]
[Mon Jul 20 06:23:01.610712 2026] [security2:error] [pid 884009:tid 884161] [client 57.141.18.117:20252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwSwAAmjQ"]
[Mon Jul 20 06:23:01.648465 2026] [security2:error] [pid 915741:tid 915899] [client 57.141.18.42:36564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIa-615n1P-attmy42QABqyw"]
[Mon Jul 20 06:23:01.793254 2026] [security2:error] [pid 884009:tid 884249] [client 104.234.53.69:42243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TJRKaHUf6J8d3elJw3wAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:01.907412 2026] [security2:error] [pid 915741:tid 915923] [client 178.152.178.232:36325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TJa-615n1P-attmy5twAAAcM"]
[Mon Jul 20 06:23:01.907538 2026] [security2:error] [pid 915741:tid 915923] [client 178.152.178.232:36325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TJa-615n1P-attmy5twAAAcM"]
[Mon Jul 20 06:23:02.110954 2026] [security2:error] [pid 884009:tid 884150] [client 104.234.53.69:42243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TJhKaHUf6J8d3elJw8wAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:02.262607 2026] [security2:error] [pid 884009:tid 884043] [remote 57.141.18.100:57492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3520689"] [unique_id "al4TJhKaHUf6J8d3elJw9QAAzSA"]
[Mon Jul 20 06:23:02.352054 2026] [security2:error] [pid 915741:tid 915952] [client 103.141.108.143:56535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TJq-615n1P-attmy5zQAAAeA"]
[Mon Jul 20 06:23:02.352555 2026] [security2:error] [pid 915741:tid 915952] [client 103.141.108.143:56535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TJq-615n1P-attmy5zQAAAeA"]
[Mon Jul 20 06:23:02.413884 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.39:47153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIq-615n1P-attmy4_wAB3Go"]
[Mon Jul 20 06:23:02.430531 2026] [security2:error] [pid 915741:tid 915895] [client 57.141.18.9:51728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIq-615n1P-attmy4_AABpyE"]
[Mon Jul 20 06:23:03.174937 2026] [security2:error] [pid 915741:tid 915829] [remote 152.228.213.32:38794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TJ6-615n1P-attmy5_gAB_lc"]
[Mon Jul 20 06:23:03.175135 2026] [security2:error] [pid 915741:tid 915982] [client 152.228.213.32:38794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TJ6-615n1P-attmy5_gAB_lc"]
[Mon Jul 20 06:23:03.258777 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.26:22582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIhKaHUf6J8d3elJwhwAA9yE"]
[Mon Jul 20 06:23:04.093664 2026] [security2:error] [pid 915741:tid 915965] [client 45.116.69.230:56191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6XAAAAe0"]
[Mon Jul 20 06:23:04.093782 2026] [security2:error] [pid 915741:tid 915965] [client 45.116.69.230:56191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6XAAAAe0"]
[Mon Jul 20 06:23:04.346030 2026] [security2:error] [pid 915741:tid 915942] [client 158.173.166.181:50473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TKK-615n1P-attmy6ZAAAAdY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:04.502975 2026] [security2:error] [pid 884009:tid 884115] [remote 217.113.60.80:38192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4TKBKaHUf6J8d3elJxMwAAv2g"]
[Mon Jul 20 06:23:04.595669 2026] [security2:error] [pid 915741:tid 915954] [client 57.141.18.124:42464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TJK-615n1P-attmy5dgAB4nc"]
[Mon Jul 20 06:23:04.632584 2026] [proxy:error] [pid 884009:tid 884150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:04.632638 2026] [proxy_http:error] [pid 884009:tid 884150] [client 20.74.45.95:60574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:04.633772 2026] [proxy:error] [pid 884009:tid 884150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:04.633821 2026] [proxy_http:error] [pid 884009:tid 884150] [client 20.74.45.95:60574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:04.861403 2026] [security2:error] [pid 915741:tid 915854] [remote 130.185.118.215:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6hgACDnA"]
[Mon Jul 20 06:23:04.861633 2026] [security2:error] [pid 915741:tid 915998] [client 130.185.118.215:41948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6hgACDnA"]
[Mon Jul 20 06:23:04.938095 2026] [security2:error] [pid 884009:tid 884017] [remote 217.113.60.80:38192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4TKBKaHUf6J8d3elJxRgAA8AY"], referer: https://mail.factsandminds.com/wp-login.php
[Mon Jul 20 06:23:05.242443 2026] [security2:error] [pid 915741:tid 915924] [client 41.173.37.102:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TKa-615n1P-attmy6mQAAAcQ"]
[Mon Jul 20 06:23:05.242722 2026] [security2:error] [pid 915741:tid 915924] [client 41.173.37.102:12241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TKa-615n1P-attmy6mQAAAcQ"]
[Mon Jul 20 06:23:05.982592 2026] [security2:error] [pid 915741:tid 915897] [client 104.234.53.69:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TKa-615n1P-attmy6vwAAAak"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:06.111218 2026] [security2:error] [pid 884009:tid 884142] [client 50.116.65.227:52540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TKhKaHUf6J8d3elJxawAAAIc"]
[Mon Jul 20 06:23:06.121699 2026] [security2:error] [pid 884009:tid 884201] [client 50.116.65.227:59112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TKhKaHUf6J8d3elJxbQAAAME"]
[Mon Jul 20 06:23:06.265536 2026] [autoindex:error] [pid 884009:tid 884241] [client 147.93.171.187:59822] AH01276: Cannot serve directory /home4/vnluelmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:23:06.278469 2026] [security2:error] [pid 915741:tid 915905] [client 77.110.127.138:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TKq-615n1P-attmy6ygAAAbE"]
[Mon Jul 20 06:23:06.278556 2026] [security2:error] [pid 915741:tid 915905] [client 77.110.127.138:61444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TKq-615n1P-attmy6ygAAAbE"]
[Mon Jul 20 06:23:06.300774 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TKq-615n1P-attmy6zQAAAaA"]
[Mon Jul 20 06:23:06.300929 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TKq-615n1P-attmy6zQAAAaA"]
[Mon Jul 20 06:23:06.320104 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4TKq-615n1P-attmy6zwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:06.407053 2026] [security2:error] [pid 915741:tid 915954] [client 103.153.183.69:8858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e%2f%2e%2e%2fetc%2fpasswd"] [unique_id "al4TKq-615n1P-attmy62gAAAeI"], referer: https://twitter.com/
[Mon Jul 20 06:23:06.435052 2026] [security2:error] [pid 915741:tid 915916] [client 103.153.183.69:8858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/etc/passwd"] [unique_id "al4TKq-615n1P-attmy63AAAAbw"], referer: https://t.co/3aa6qah2aa
[Mon Jul 20 06:23:06.676893 2026] [security2:error] [pid 915741:tid 915955] [client 50.116.65.227:59116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TKq-615n1P-attmy65wAAAeM"]
[Mon Jul 20 06:23:06.679302 2026] [security2:error] [pid 915741:tid 915876] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy6zgAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:06.687739 2026] [security2:error] [pid 915741:tid 915956] [client 50.116.65.227:59124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TKq-615n1P-attmy66AAAAeQ"]
[Mon Jul 20 06:23:06.871599 2026] [security2:error] [pid 915741:tid 915977] [client 14.225.17.146:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4TKa-615n1P-attmy6sgAAAfk"], referer: http://ravmike.com/Wp
[Mon Jul 20 06:23:06.889613 2026] [autoindex:error] [pid 884009:tid 884248] [client 143.244.47.86:9829] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:06.977074 2026] [security2:error] [pid 884009:tid 884138] [remote 217.61.143.92:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4TKhKaHUf6J8d3elJxkwAApX8"]
[Mon Jul 20 06:23:07.021601 2026] [security2:error] [pid 884009:tid 884171] [client 14.225.17.146:65489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4TKhKaHUf6J8d3elJxkAAAAKM"]
[Mon Jul 20 06:23:07.166568 2026] [security2:error] [pid 915741:tid 915908] [client 77.110.127.138:61460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy63gAAAbQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:07.209724 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TK6-615n1P-attmy6_gAAAZc"]
[Mon Jul 20 06:23:07.209885 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:61461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TK6-615n1P-attmy6_gAAAZc"]
[Mon Jul 20 06:23:07.287413 2026] [security2:error] [pid 884009:tid 884222] [client 158.173.89.95:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TKxKaHUf6J8d3elJxowAAANY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:07.315817 2026] [security2:error] [pid 915741:tid 915906] [client 74.208.214.194:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TK6-615n1P-attmy7BAAAAbI"]
[Mon Jul 20 06:23:07.448720 2026] [security2:error] [pid 915741:tid 915903] [client 14.225.17.146:62650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy6xwAAAa8"], referer: http://cloudspacesgroup.com/Wp
[Mon Jul 20 06:23:07.450870 2026] [security2:error] [pid 915741:tid 915888] [client 20.245.75.247:14976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TK6-615n1P-attmy7BgAAAaA"]
[Mon Jul 20 06:23:07.466665 2026] [security2:error] [pid 884009:tid 884226] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TKxKaHUf6J8d3elJxnwAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:07.470557 2026] [security2:error] [pid 915741:tid 915939] [client 20.245.75.247:14976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TK6-615n1P-attmy7CgAAAdM"]
[Mon Jul 20 06:23:07.528111 2026] [security2:error] [pid 884009:tid 884230] [client 57.141.18.109:43166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TJxKaHUf6J8d3elJxFwAA3hI"]
[Mon Jul 20 06:23:07.792543 2026] [security2:error] [pid 915741:tid 915801] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HAABoTs"]
[Mon Jul 20 06:23:07.792742 2026] [security2:error] [pid 915741:tid 915889] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HAABoTs"]
[Mon Jul 20 06:23:07.795891 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:49403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4TKxKaHUf6J8d3elJxtwAAAKk"], referer: https://ravmike.com/Wp
[Mon Jul 20 06:23:07.801563 2026] [security2:error] [pid 915741:tid 915971] [client 57.141.18.100:45280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TJ6-615n1P-attmy6RwAB81I"]
[Mon Jul 20 06:23:07.855268 2026] [security2:error] [pid 915741:tid 915907] [client 171.61.165.146:19032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HgAAAbM"]
[Mon Jul 20 06:23:07.856295 2026] [security2:error] [pid 915741:tid 915907] [client 171.61.165.146:19032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HgAAAbM"]
[Mon Jul 20 06:23:07.951198 2026] [security2:error] [pid 915741:tid 915952] [client 103.153.183.69:8858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/.env"] [unique_id "al4TK6-615n1P-attmy7IQAAAeA"], referer: https://www.bing.com/search?q=9iz5lx
[Mon Jul 20 06:23:08.004092 2026] [security2:error] [pid 884009:tid 884228] [client 27.96.94.195:37468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TLBKaHUf6J8d3elJxxgAAANw"]
[Mon Jul 20 06:23:08.004199 2026] [security2:error] [pid 884009:tid 884228] [client 27.96.94.195:37468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TLBKaHUf6J8d3elJxxgAAANw"]
[Mon Jul 20 06:23:08.017999 2026] [security2:error] [pid 884009:tid 884231] [client 104.234.53.52:27635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TLBKaHUf6J8d3elJxxwAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:08.067688 2026] [security2:error] [pid 915741:tid 915848] [remote 188.166.241.141:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7LwAB6mo"]
[Mon Jul 20 06:23:08.127147 2026] [security2:error] [pid 884009:tid 884074] [remote 217.61.143.92:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4TLBKaHUf6J8d3elJxyQAAqz8"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:23:08.298756 2026] [security2:error] [pid 884009:tid 884236] [client 57.141.18.5:56362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKBKaHUf6J8d3elJxKwAA5Fw"]
[Mon Jul 20 06:23:08.301596 2026] [security2:error] [pid 884009:tid 884243] [client 52.109.4.7:22082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TLBKaHUf6J8d3elJx1gAAAOs"]
[Mon Jul 20 06:23:08.371106 2026] [security2:error] [pid 884009:tid 884151] [client 52.109.4.7:22082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TLBKaHUf6J8d3elJx2gAAAJA"]
[Mon Jul 20 06:23:08.436708 2026] [security2:error] [pid 915741:tid 915775] [remote 188.166.241.141:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7OAABwCE"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 06:23:08.463337 2026] [security2:error] [pid 915741:tid 915845] [remote 82.223.97.42:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7OQABy2c"]
[Mon Jul 20 06:23:08.672947 2026] [security2:error] [pid 915741:tid 915773] [remote 82.223.97.42:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7QgAB9B8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:08.865394 2026] [security2:error] [pid 915741:tid 915953] [client 14.225.17.146:59489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy66QAAAeE"], referer: http://younutrition.gr/Wp
[Mon Jul 20 06:23:08.874990 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:08.875030 2026] [proxy_http:error] [pid 884009:tid 884208] [client 143.244.47.86:33076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:08.875650 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:08.875675 2026] [proxy_http:error] [pid 884009:tid 884208] [client 143.244.47.86:33076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:09.014335 2026] [security2:error] [pid 915741:tid 915795] [remote 199.189.225.40:34605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TLa-615n1P-attmy7VwAByjU"]
[Mon Jul 20 06:23:09.211165 2026] [security2:error] [pid 915741:tid 915821] [remote 199.189.225.40:34605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TLa-615n1P-attmy7XQABl08"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:23:09.346355 2026] [proxy:error] [pid 915741:tid 915937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:09.346404 2026] [proxy_http:error] [pid 915741:tid 915937] [client 143.244.47.86:63849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:09.347235 2026] [proxy:error] [pid 915741:tid 915937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:09.347278 2026] [proxy_http:error] [pid 915741:tid 915937] [client 143.244.47.86:63849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:09.587719 2026] [security2:error] [pid 884009:tid 884203] [client 14.225.17.146:49400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4TLRKaHUf6J8d3elJx-AAAAMM"], referer: http://aljosour-alarabia.com/Wp
[Mon Jul 20 06:23:09.642268 2026] [security2:error] [pid 884009:tid 884228] [client 104.234.53.91:46261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TLRKaHUf6J8d3elJyEAAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:09.869173 2026] [autoindex:error] [pid 915741:tid 915970] [client 143.244.47.86:22118] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:10.147942 2026] [security2:error] [pid 915741:tid 915976] [client 34.73.38.214:53305] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TLq-615n1P-attmy7jgAAAfg"]
[Mon Jul 20 06:23:10.346944 2026] [security2:error] [pid 915741:tid 915981] [client 57.141.18.113:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy6wwAB_RU"]
[Mon Jul 20 06:23:10.347464 2026] [security2:error] [pid 915741:tid 915942] [client 34.73.38.214:51612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TLq-615n1P-attmy7mAAAAdY"]
[Mon Jul 20 06:23:10.467756 2026] [security2:error] [pid 915741:tid 915879] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.amagicbutton.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7lAAAAZc"]
[Mon Jul 20 06:23:10.936736 2026] [security2:error] [pid 915741:tid 915877] [client 104.234.53.57:25455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TLq-615n1P-attmy7xQAAAZU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:10.937703 2026] [security2:error] [pid 915741:tid 915929] [client 34.73.38.214:62301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TLq-615n1P-attmy7xgAAAck"]
[Mon Jul 20 06:23:11.035504 2026] [security2:error] [pid 884009:tid 884167] [client 57.141.18.118:41534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKhKaHUf6J8d3elJxgQAAoFo"]
[Mon Jul 20 06:23:11.139108 2026] [security2:error] [pid 915741:tid 915940] [client 57.141.18.46:37946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy66gAB1Ag"]
[Mon Jul 20 06:23:11.196842 2026] [security2:error] [pid 915741:tid 915779] [remote 217.113.60.80:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy70QAB-CU"]
[Mon Jul 20 06:23:11.224060 2026] [security2:error] [pid 915741:tid 915783] [remote 167.233.114.32:53652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy70wAB5ik"]
[Mon Jul 20 06:23:11.261573 2026] [security2:error] [pid 884009:tid 884154] [client 57.141.18.107:53634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKhKaHUf6J8d3elJxjwAAk3U"]
[Mon Jul 20 06:23:11.401295 2026] [security2:error] [pid 915741:tid 915767] [remote 167.233.114.32:53652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy73gABlxk"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:23:11.438905 2026] [security2:error] [pid 915741:tid 915938] [client 34.73.38.214:57380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TL6-615n1P-attmy73wAAAdI"]
[Mon Jul 20 06:23:11.462355 2026] [security2:error] [pid 915741:tid 915865] [remote 217.113.60.80:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy74AABrXs"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:23:11.510925 2026] [autoindex:error] [pid 884009:tid 884229] [client 143.244.47.86:10949] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:11.516630 2026] [security2:error] [pid 915741:tid 915908] [client 171.60.139.123:64548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TL6-615n1P-attmy75AAAAbQ"]
[Mon Jul 20 06:23:11.516718 2026] [security2:error] [pid 915741:tid 915908] [client 171.60.139.123:64548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TL6-615n1P-attmy75AAAAbQ"]
[Mon Jul 20 06:23:11.528254 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.119:63982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy68QAB3G0"]
[Mon Jul 20 06:23:11.681063 2026] [security2:error] [pid 915741:tid 915973] [client 116.179.33.12:53754] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4TL6-615n1P-attmy77gAAAfU"]
[Mon Jul 20 06:23:11.689849 2026] [security2:error] [pid 915741:tid 915894] [client 34.73.38.214:53166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TL6-615n1P-attmy78AAAAaY"]
[Mon Jul 20 06:23:11.835886 2026] [security2:error] [pid 884009:tid 884180] [client 104.234.53.88:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TLxKaHUf6J8d3elJyYAAAAKw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:11.909426 2026] [security2:error] [pid 915741:tid 915974] [client 14.225.17.146:49173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7kAAAAfY"], referer: http://bigwormfishing.com/Wp
[Mon Jul 20 06:23:12.194149 2026] [security2:error] [pid 915741:tid 915901] [client 34.73.38.214:60484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TMK-615n1P-attmy8DgAAAa0"]
[Mon Jul 20 06:23:12.266834 2026] [core:error] [pid 915741:tid 915890] [client 31.40.204.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:12.266860 2026] [core:error] [pid 915741:tid 915890] [client 31.40.204.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:12.550201 2026] [security2:error] [pid 915741:tid 915912] [client 178.152.178.232:37327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8JgAAAbg"]
[Mon Jul 20 06:23:12.557063 2026] [security2:error] [pid 915741:tid 915912] [client 178.152.178.232:37327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8JgAAAbg"]
[Mon Jul 20 06:23:12.569281 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TMBKaHUf6J8d3elJyfQAAAPI"]
[Mon Jul 20 06:23:12.569379 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:56723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TMBKaHUf6J8d3elJyfQAAAPI"]
[Mon Jul 20 06:23:12.692908 2026] [security2:error] [pid 915741:tid 915883] [client 34.73.38.214:63922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TMK-615n1P-attmy8LQAAAZs"]
[Mon Jul 20 06:23:12.781895 2026] [security2:error] [pid 915741:tid 915946] [client 14.225.17.146:63601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TMK-615n1P-attmy8JwAAAdo"], referer: http://secretkeynumerology.com/Wp
[Mon Jul 20 06:23:12.866874 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:63696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4TMK-615n1P-attmy8LwAAAfU"], referer: https://bigwormfishing.com/Wp
[Mon Jul 20 06:23:12.908799 2026] [security2:error] [pid 915741:tid 915992] [client 57.141.18.107:53636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLK-615n1P-attmy7QQACCHY"]
[Mon Jul 20 06:23:12.978719 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8OQAAAZA"]
[Mon Jul 20 06:23:12.980002 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:56999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8OQAAAZA"]
[Mon Jul 20 06:23:13.041862 2026] [security2:error] [pid 915741:tid 915959] [client 104.234.53.91:48687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TMa-615n1P-attmy8PQAAAec"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:13.091445 2026] [security2:error] [pid 915741:tid 915926] [client 34.73.38.214:65373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TMa-615n1P-attmy8QQAAAcY"]
[Mon Jul 20 06:23:13.334180 2026] [security2:error] [pid 915741:tid 915879] [client 34.73.38.214:55730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TMa-615n1P-attmy8RgAAAZc"]
[Mon Jul 20 06:23:13.571552 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:63313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TMRKaHUf6J8d3elJymQAAAQQ"]
[Mon Jul 20 06:23:13.658868 2026] [security2:error] [pid 915741:tid 915963] [client 50.116.65.227:11464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TMa-615n1P-attmy8WgAAAes"]
[Mon Jul 20 06:23:13.666558 2026] [security2:error] [pid 915741:tid 915980] [client 14.225.17.146:65478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4TL6-615n1P-attmy77AAAAfw"], referer: http://tntcatholic.com/Wp
[Mon Jul 20 06:23:13.670558 2026] [security2:error] [pid 915741:tid 915968] [client 50.116.65.227:25840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TMa-615n1P-attmy8WwAAAc0"]
[Mon Jul 20 06:23:13.713951 2026] [security2:error] [pid 915741:tid 915882] [client 104.234.53.55:47909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TMa-615n1P-attmy8YAAAAZo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:13.753536 2026] [security2:error] [pid 915741:tid 915964] [client 57.141.18.113:53494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLa-615n1P-attmy7dAAB7Bo"]
[Mon Jul 20 06:23:13.781742 2026] [security2:error] [pid 915741:tid 915992] [client 34.73.38.214:55295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TMa-615n1P-attmy8YwAAAgg"]
[Mon Jul 20 06:23:13.786492 2026] [security2:error] [pid 915741:tid 915895] [client 77.110.127.138:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4TMa-615n1P-attmy8ZAAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:13.882940 2026] [security2:error] [pid 915741:tid 915914] [client 14.225.17.146:56229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TMa-615n1P-attmy8YQAAAbo"], referer: https://secretkeynumerology.com/Wp
[Mon Jul 20 06:23:13.918656 2026] [security2:error] [pid 884009:tid 884206] [client 34.73.38.214:56514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TMRKaHUf6J8d3elJyrAAAAMY"]
[Mon Jul 20 06:23:13.927440 2026] [security2:error] [pid 915741:tid 915916] [client 103.169.209.130:52952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4TMa-615n1P-attmy8awAAAbw"]
[Mon Jul 20 06:23:14.089161 2026] [security2:error] [pid 915741:tid 915850] [remote 100.42.189.89:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8bwACBmw"]
[Mon Jul 20 06:23:14.286037 2026] [security2:error] [pid 915741:tid 915957] [client 54.169.146.187:31220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8cQAAAeU"]
[Mon Jul 20 06:23:14.324891 2026] [security2:error] [pid 884009:tid 884239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TMRKaHUf6J8d3elJypwAAAOc"]
[Mon Jul 20 06:23:14.429065 2026] [security2:error] [pid 915741:tid 915776] [remote 100.42.189.89:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8dAABuSI"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:23:14.752049 2026] [security2:error] [pid 915741:tid 915936] [client 57.141.18.112:54170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7tAAB0EY"]
[Mon Jul 20 06:23:14.967588 2026] [security2:error] [pid 915741:tid 915991] [client 57.141.18.87:62552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7wQACBxs"]
[Mon Jul 20 06:23:15.006413 2026] [security2:error] [pid 915741:tid 915790] [remote 98.156.100.191:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8lAABpTA"]
[Mon Jul 20 06:23:15.225657 2026] [security2:error] [pid 915741:tid 915913] [client 77.110.127.138:61516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TM6-615n1P-attmy8qgAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:15.225770 2026] [security2:error] [pid 915741:tid 915913] [client 77.110.127.138:61516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TM6-615n1P-attmy8qgAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:15.374073 2026] [security2:error] [pid 915741:tid 915759] [remote 57.141.18.63:28442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3520689"] [unique_id "al4TM6-615n1P-attmy8sgAB0xE"]
[Mon Jul 20 06:23:15.467080 2026] [security2:error] [pid 915741:tid 915950] [client 67.1.105.214:43520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4TM6-615n1P-attmy8vQAAAd4"]
[Mon Jul 20 06:23:15.476095 2026] [security2:error] [pid 915741:tid 915933] [client 54.204.158.117:15978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.158.204.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TM6-615n1P-attmy8vAAAAc0"]
[Mon Jul 20 06:23:15.644087 2026] [security2:error] [pid 915741:tid 915984] [client 68.151.204.91:58744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4TM6-615n1P-attmy8ygAAAgA"]
[Mon Jul 20 06:23:15.651575 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TM6-615n1P-attmy8ugAAAZM"]
[Mon Jul 20 06:23:15.727922 2026] [security2:error] [pid 915741:tid 915937] [client 57.141.18.39:46779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TL6-615n1P-attmy75QAB0QU"]
[Mon Jul 20 06:23:15.784393 2026] [security2:error] [pid 884009:tid 884109] [remote 110.249.202.234:37040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/wp-content/uploads/2025/09/Aosta-Drinks-Menu.pdf"] [unique_id "al4TMxKaHUf6J8d3elJy7AAAm2I"]
[Mon Jul 20 06:23:15.810036 2026] [security2:error] [pid 915741:tid 915896] [client 50.116.65.227:25870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TM6-615n1P-attmy8zgAAAag"]
[Mon Jul 20 06:23:15.819979 2026] [security2:error] [pid 915741:tid 915981] [client 50.116.65.227:25892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TM6-615n1P-attmy80QAAAf0"]
[Mon Jul 20 06:23:15.861096 2026] [security2:error] [pid 915741:tid 915936] [client 184.161.128.34:33714] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4TM6-615n1P-attmy81AAAAdA"]
[Mon Jul 20 06:23:15.900551 2026] [security2:error] [pid 915741:tid 915902] [client 129.222.247.80:6519] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4TM6-615n1P-attmy81wAAAa4"]
[Mon Jul 20 06:23:15.914429 2026] [security2:error] [pid 915741:tid 915894] [client 41.173.37.102:12675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TM6-615n1P-attmy82AAAAaY"]
[Mon Jul 20 06:23:15.914513 2026] [security2:error] [pid 915741:tid 915894] [client 41.173.37.102:12675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TM6-615n1P-attmy82AAAAaY"]
[Mon Jul 20 06:23:16.033157 2026] [security2:error] [pid 915741:tid 915905] [client 177.253.131.51:51990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4TNK-615n1P-attmy85gAAAbE"]
[Mon Jul 20 06:23:16.042854 2026] [security2:error] [pid 915741:tid 915920] [client 147.12.209.239:57116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4TNK-615n1P-attmy86AAAAcA"]
[Mon Jul 20 06:23:16.183859 2026] [security2:error] [pid 884009:tid 884247] [client 141.98.143.70:13761] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff"] [unique_id "al4TNBKaHUf6J8d3elJy_gAAAO8"]
[Mon Jul 20 06:23:16.206524 2026] [security2:error] [pid 915741:tid 915915] [client 112.201.205.242:37636] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4TNK-615n1P-attmy88gAAAbs"]
[Mon Jul 20 06:23:16.232430 2026] [security2:error] [pid 915741:tid 915876] [client 179.6.57.59:15831] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4TNK-615n1P-attmy89QAAAZQ"]
[Mon Jul 20 06:23:16.305784 2026] [security2:error] [pid 915741:tid 915877] [client 181.94.227.115:25479] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4TNK-615n1P-attmy8-wAAAZU"]
[Mon Jul 20 06:23:16.332364 2026] [security2:error] [pid 915741:tid 915883] [client 170.79.52.73:24817] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamawcubgee.woff2"] [unique_id "al4TNK-615n1P-attmy8_AAAAZs"]
[Mon Jul 20 06:23:16.349018 2026] [security2:error] [pid 884009:tid 884230] [client 104.234.53.83:54657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TNBKaHUf6J8d3elJzAQAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:16.357370 2026] [security2:error] [pid 884009:tid 884220] [client 196.234.134.214:50058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4TNBKaHUf6J8d3elJzAwAAANQ"]
[Mon Jul 20 06:23:16.374809 2026] [security2:error] [pid 915741:tid 915908] [client 200.53.206.216:56982] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4TNK-615n1P-attmy8_wAAAbQ"]
[Mon Jul 20 06:23:16.404854 2026] [security2:error] [pid 884009:tid 884226] [client 18.141.57.241:39152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TNBKaHUf6J8d3elJzAgAAANo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:23:16.431641 2026] [security2:error] [pid 884009:tid 884259] [client 171.250.160.8:3387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4TNBKaHUf6J8d3elJzCAAAAPs"]
[Mon Jul 20 06:23:16.482825 2026] [security2:error] [pid 915741:tid 915944] [client 77.110.127.138:61521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpAIAEPg2A'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4TNK-615n1P-attmy9BgAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.500778 2026] [security2:error] [pid 915741:tid 915931] [client 185.18.224.125:36286] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4TNK-615n1P-attmy9CAAAAcs"]
[Mon Jul 20 06:23:16.527704 2026] [security2:error] [pid 884009:tid 884176] [client 188.26.194.222:33208] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4TNBKaHUf6J8d3elJzEQAAAKg"]
[Mon Jul 20 06:23:16.544635 2026] [security2:error] [pid 915741:tid 915970] [client 91.182.175.182:35426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4TNK-615n1P-attmy9DgAAAfI"]
[Mon Jul 20 06:23:16.564540 2026] [security2:error] [pid 915741:tid 915871] [client 57.141.18.84:25292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMK-615n1P-attmy8HwABj2k"]
[Mon Jul 20 06:23:16.572556 2026] [security2:error] [pid 915741:tid 915946] [client 103.113.194.63:55298] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4TNK-615n1P-attmy9EQAAAdo"]
[Mon Jul 20 06:23:16.636629 2026] [security2:error] [pid 915741:tid 915880] [client 77.110.127.138:61522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNK-615n1P-attmy9FQAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.636734 2026] [security2:error] [pid 915741:tid 915880] [client 77.110.127.138:61522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNK-615n1P-attmy9FQAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.642964 2026] [security2:error] [pid 915741:tid 915918] [client 138.97.119.106:39698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4TNK-615n1P-attmy9FwAAAb4"]
[Mon Jul 20 06:23:16.726623 2026] [security2:error] [pid 915741:tid 915934] [client 86.108.23.14:49566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4TNK-615n1P-attmy9GQAAAc4"]
[Mon Jul 20 06:23:16.757208 2026] [security2:error] [pid 884009:tid 884146] [client 200.149.47.32:39701] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4TNBKaHUf6J8d3elJzFQAAAIs"]
[Mon Jul 20 06:23:16.760542 2026] [security2:error] [pid 884009:tid 884229] [client 116.204.140.26:37834] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4TNBKaHUf6J8d3elJzFgAAAN0"]
[Mon Jul 20 06:23:16.780139 2026] [security2:error] [pid 884009:tid 884209] [client 14.225.17.146:65269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4TMxKaHUf6J8d3elJy4AAAAMk"], referer: http://headachescarpaltunnelfibromyalgia.com/Wp
[Mon Jul 20 06:23:16.787573 2026] [security2:error] [pid 884009:tid 884167] [client 77.110.127.138:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php8zEBHZM7'%20OR%2051=(SELECT%2051%20FROM%20PG_SLEEP(15))--"] [unique_id "al4TNBKaHUf6J8d3elJzGAAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.813254 2026] [security2:error] [pid 884009:tid 884257] [client 203.20.108.16:58806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4TNBKaHUf6J8d3elJzGQAAAPk"]
[Mon Jul 20 06:23:16.872417 2026] [security2:error] [pid 884009:tid 884267] [client 203.9.211.159:14580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4TNBKaHUf6J8d3elJzHAAAAQM"]
[Mon Jul 20 06:23:16.940794 2026] [security2:error] [pid 915741:tid 915917] [client 180.191.16.119:35467] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4TNK-615n1P-attmy9JwAAAb0"]
[Mon Jul 20 06:23:16.942615 2026] [security2:error] [pid 884009:tid 884198] [client 185.244.152.34:61621] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4TNBKaHUf6J8d3elJzHwAAAL4"]
[Mon Jul 20 06:23:16.949920 2026] [security2:error] [pid 915741:tid 915835] [remote 98.156.100.191:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TNK-615n1P-attmy9JAAByF0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:16.973248 2026] [security2:error] [pid 915741:tid 915962] [client 77.137.23.14:41858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4TNK-615n1P-attmy9KwAAAeo"]
[Mon Jul 20 06:23:17.085776 2026] [security2:error] [pid 915741:tid 915963] [client 197.38.175.37:36594] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4TNa-615n1P-attmy9NAAAAes"]
[Mon Jul 20 06:23:17.103532 2026] [security2:error] [pid 884009:tid 884268] [client 77.110.127.138:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNRKaHUf6J8d3elJzJwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:17.103660 2026] [security2:error] [pid 884009:tid 884268] [client 77.110.127.138:61528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNRKaHUf6J8d3elJzJwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:17.112628 2026] [security2:error] [pid 884009:tid 884264] [client 136.158.50.9:7284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4TNRKaHUf6J8d3elJzKAAAAQA"]
[Mon Jul 20 06:23:17.145087 2026] [core:error] [pid 884009:tid 884216] [client 103.153.183.69:59766] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=0py8g0oi&v=qjscu), referer: https://www.reddit.com/
[Mon Jul 20 06:23:17.147485 2026] [security2:error] [pid 884009:tid 884149] [client 127.0.0.1:52978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TNRKaHUf6J8d3elJzKwAAAI4"], referer: https://www.reddit.com/
[Mon Jul 20 06:23:17.163377 2026] [security2:error] [pid 915741:tid 915986] [client 103.157.10.91:27115] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbnka.woff2"] [unique_id "al4TNa-615n1P-attmy9OgAAAgI"]
[Mon Jul 20 06:23:17.270817 2026] [security2:error] [pid 915741:tid 915971] [client 185.117.151.113:61553] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4TNa-615n1P-attmy9QAAAAfM"]
[Mon Jul 20 06:23:17.305619 2026] [security2:error] [pid 884009:tid 884251] [client 65.1.132.125:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TNRKaHUf6J8d3elJzMQAAAPM"]
[Mon Jul 20 06:23:17.305721 2026] [security2:error] [pid 884009:tid 884251] [client 65.1.132.125:57436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TNRKaHUf6J8d3elJzMQAAAPM"]
[Mon Jul 20 06:23:17.375866 2026] [security2:error] [pid 884009:tid 884233] [client 51.39.233.148:3404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf"] [unique_id "al4TNRKaHUf6J8d3elJzNQAAAOE"]
[Mon Jul 20 06:23:17.379992 2026] [security2:error] [pid 915741:tid 915929] [client 152.58.200.19:53366] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4TNa-615n1P-attmy9RgAAAck"]
[Mon Jul 20 06:23:17.384960 2026] [security2:error] [pid 915741:tid 915950] [client 176.236.235.14:6892] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4TNa-615n1P-attmy9RwAAAd4"]
[Mon Jul 20 06:23:17.487497 2026] [security2:error] [pid 915741:tid 915969] [client 27.96.94.195:36935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TNa-615n1P-attmy9TgAAAfE"]
[Mon Jul 20 06:23:17.487612 2026] [security2:error] [pid 915741:tid 915969] [client 27.96.94.195:36935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TNa-615n1P-attmy9TgAAAfE"]
[Mon Jul 20 06:23:17.537586 2026] [security2:error] [pid 915741:tid 915924] [client 84.54.66.146:4381] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4TNa-615n1P-attmy9UgAAAcQ"]
[Mon Jul 20 06:23:17.551181 2026] [security2:error] [pid 915741:tid 915891] [client 34.90.66.217:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.olearyplumbingllc.com"] [uri "/"] [unique_id "al4TNa-615n1P-attmy9VQAAAaM"]
[Mon Jul 20 06:23:17.551266 2026] [security2:error] [pid 915741:tid 915891] [client 34.90.66.217:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.olearyplumbingllc.com"] [uri "/"] [unique_id "al4TNa-615n1P-attmy9VQAAAaM"]
[Mon Jul 20 06:23:17.573305 2026] [security2:error] [pid 915741:tid 915928] [client 77.110.127.138:61536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpW65qqIxh')%20OR%20826=(SELECT%20826%20FROM%20PG_SLEEP(15))--"] [unique_id "al4TNa-615n1P-attmy9WAAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:17.696993 2026] [security2:error] [pid 915741:tid 915892] [client 102.67.231.58:41526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4TNa-615n1P-attmy9WwAAAaQ"]
[Mon Jul 20 06:23:17.800775 2026] [security2:error] [pid 884009:tid 884166] [client 156.221.146.9:50118] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4TNRKaHUf6J8d3elJzRAAAAJ8"]
[Mon Jul 20 06:23:17.855862 2026] [security2:error] [pid 884009:tid 884232] [client 180.149.232.175:37932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4TNRKaHUf6J8d3elJzRQAAAOA"]
[Mon Jul 20 06:23:17.914618 2026] [security2:error] [pid 915741:tid 915872] [client 103.130.239.219:16518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4TNa-615n1P-attmy9XwAAAZA"]
[Mon Jul 20 06:23:17.942236 2026] [core:error] [pid 915741:tid 915966] [client 103.153.183.69:59772] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.env?_=90etvjgf&v=3k2va), referer: https://news.ycombinator.com/
[Mon Jul 20 06:23:17.973366 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.22:46600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMa-615n1P-attmy8VgABln8"]
[Mon Jul 20 06:23:18.019820 2026] [security2:error] [pid 915741:tid 915961] [client 115.135.199.52:40263] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufc5qw54a.woff2"] [unique_id "al4TNq-615n1P-attmy9aAAAAek"]
[Mon Jul 20 06:23:18.043519 2026] [security2:error] [pid 915741:tid 915954] [client 82.215.111.155:14548] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4TNq-615n1P-attmy9bAAAAeI"]
[Mon Jul 20 06:23:18.103042 2026] [security2:error] [pid 915741:tid 915996] [client 197.70.51.105:50660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4TNq-615n1P-attmy9cgAAAgw"]
[Mon Jul 20 06:23:18.217255 2026] [security2:error] [pid 915741:tid 915925] [client 91.188.149.75:60296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4TNq-615n1P-attmy9dwAAAcU"]
[Mon Jul 20 06:23:18.388660 2026] [security2:error] [pid 884009:tid 884181] [client 77.110.127.138:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNhKaHUf6J8d3elJzWQAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:18.388762 2026] [security2:error] [pid 884009:tid 884181] [client 77.110.127.138:61541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNhKaHUf6J8d3elJzWQAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:18.428289 2026] [security2:error] [pid 884009:tid 884083] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzWwAA4kg"]
[Mon Jul 20 06:23:18.428775 2026] [security2:error] [pid 884009:tid 884234] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzWwAA4kg"]
[Mon Jul 20 06:23:18.666885 2026] [security2:error] [pid 884009:tid 884257] [client 171.61.165.146:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzaAAAAPk"]
[Mon Jul 20 06:23:18.667019 2026] [security2:error] [pid 884009:tid 884257] [client 171.61.165.146:18157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzaAAAAPk"]
[Mon Jul 20 06:23:18.763797 2026] [security2:error] [pid 915741:tid 915785] [remote 57.141.18.17:32164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4TNq-615n1P-attmy9lgAB3ys"]
[Mon Jul 20 06:23:18.773357 2026] [security2:error] [pid 915741:tid 915979] [client 139.135.192.36:27089] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4TNq-615n1P-attmy9lwAAAfs"]
[Mon Jul 20 06:23:18.802806 2026] [security2:error] [pid 884009:tid 884241] [client 103.6.123.207:46132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4TNhKaHUf6J8d3elJzawAAAOk"]
[Mon Jul 20 06:23:18.809186 2026] [security2:error] [pid 915741:tid 915949] [client 192.236.168.43:41002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.narulatrucking.com"] [uri "/"] [unique_id "al4TNq-615n1P-attmy9mAAAAd0"]
[Mon Jul 20 06:23:18.810364 2026] [security2:error] [pid 884009:tid 884158] [client 57.141.18.89:60786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMhKaHUf6J8d3elJyvAAAlwQ"]
[Mon Jul 20 06:23:18.862604 2026] [security2:error] [pid 915741:tid 915837] [remote 72.167.132.114:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TNq-615n1P-attmy9mgABmV8"]
[Mon Jul 20 06:23:18.888020 2026] [security2:error] [pid 915741:tid 915922] [client 77.110.127.138:61550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNq-615n1P-attmy9nQAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:18.888114 2026] [security2:error] [pid 915741:tid 915922] [client 77.110.127.138:61550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNq-615n1P-attmy9nQAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:19.033868 2026] [security2:error] [pid 915741:tid 915997] [client 103.91.129.66:36890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4TN6-615n1P-attmy9qwAAAg0"]
[Mon Jul 20 06:23:19.072262 2026] [security2:error] [pid 915741:tid 915913] [client 14.225.17.146:57865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4TNq-615n1P-attmy9hAAAAbk"]
[Mon Jul 20 06:23:19.082772 2026] [security2:error] [pid 915741:tid 915862] [remote 72.167.132.114:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TN6-615n1P-attmy9rwAB7Hg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:19.117828 2026] [security2:error] [pid 915741:tid 915956] [client 112.208.70.94:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TN6-615n1P-attmy9sQAAAeQ"]
[Mon Jul 20 06:23:19.117947 2026] [security2:error] [pid 915741:tid 915956] [client 112.208.70.94:43213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TN6-615n1P-attmy9sQAAAeQ"]
[Mon Jul 20 06:23:19.268109 2026] [security2:error] [pid 884009:tid 884242] [client 104.168.114.154:55120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "narulatrucking.com"] [uri "/"] [unique_id "al4TNxKaHUf6J8d3elJzeQAAAOo"]
[Mon Jul 20 06:23:19.303930 2026] [security2:error] [pid 915741:tid 915873] [client 103.238.110.113:5332] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4TN6-615n1P-attmy9ugAAAZE"]
[Mon Jul 20 06:23:19.358514 2026] [security2:error] [pid 884009:tid 884252] [client 104.168.114.154:55144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.narulatrucking.com"] [uri "/"] [unique_id "al4TNxKaHUf6J8d3elJzfwAAAPQ"]
[Mon Jul 20 06:23:19.404508 2026] [security2:error] [pid 915741:tid 915917] [client 45.115.42.85:60392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4TN6-615n1P-attmy9wgAAAb0"]
[Mon Jul 20 06:23:19.701716 2026] [security2:error] [pid 915741:tid 915980] [client 98.159.234.160:30479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TN6-615n1P-attmy9zAAAAfw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:19.774131 2026] [security2:error] [pid 884009:tid 884153] [client 57.141.18.91:42778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMxKaHUf6J8d3elJy6QAAkgg"]
[Mon Jul 20 06:23:19.975638 2026] [security2:error] [pid 915741:tid 915910] [client 104.234.53.74:59791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TN6-615n1P-attmy92gAAAbY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:20.073227 2026] [security2:error] [pid 915741:tid 915904] [client 32.198.12.77:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TOK-615n1P-attmy93gAAAbA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:23:20.370278 2026] [security2:error] [pid 915741:tid 915882] [client 57.141.18.48:39722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNK-615n1P-attmy89wABmjM"]
[Mon Jul 20 06:23:20.452505 2026] [security2:error] [pid 884009:tid 884192] [client 160.177.31.32:50346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4TOBKaHUf6J8d3elJzogAAALg"]
[Mon Jul 20 06:23:20.689294 2026] [security2:error] [pid 915741:tid 915905] [client 57.141.18.104:37328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNK-615n1P-attmy9EwABsXU"]
[Mon Jul 20 06:23:20.816977 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.37:24620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNK-615n1P-attmy9GgAB3F4"]
[Mon Jul 20 06:23:21.241923 2026] [security2:error] [pid 915741:tid 915964] [client 52.47.76.32:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TOa-615n1P-attmy-FwAAAew"]
[Mon Jul 20 06:23:21.242045 2026] [security2:error] [pid 915741:tid 915964] [client 52.47.76.32:54044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TOa-615n1P-attmy-FwAAAew"]
[Mon Jul 20 06:23:21.315085 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TOa-615n1P-attmy-HQAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.315216 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TOa-615n1P-attmy-HQAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.613019 2026] [security2:error] [pid 915741:tid 915914] [client 34.74.185.202:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4TOa-615n1P-attmy-KgAAAbo"]
[Mon Jul 20 06:23:21.635189 2026] [security2:error] [pid 915741:tid 915895] [client 57.141.18.44:54200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNa-615n1P-attmy9SAABp1E"]
[Mon Jul 20 06:23:21.689560 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TORKaHUf6J8d3elJzygAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.689691 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:61561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TORKaHUf6J8d3elJzygAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.799417 2026] [autoindex:error] [pid 884009:tid 884054] [remote 143.244.47.86:43591] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:21.824934 2026] [security2:error] [pid 884009:tid 884109] [remote 152.228.213.32:39614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4TORKaHUf6J8d3elJz1AAA2mI"]
[Mon Jul 20 06:23:21.871419 2026] [security2:error] [pid 915741:tid 915992] [client 14.225.17.146:57916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4TN6-615n1P-attmy90gAAAgg"], referer: http://webgardensbypaula.com/Wp
[Mon Jul 20 06:23:21.937432 2026] [security2:error] [pid 915741:tid 915970] [client 50.116.65.227:33046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TOa-615n1P-attmy-OQAAAfI"]
[Mon Jul 20 06:23:21.948086 2026] [security2:error] [pid 884009:tid 884181] [client 50.116.65.227:31156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TORKaHUf6J8d3elJz3AAAAL8"]
[Mon Jul 20 06:23:21.996503 2026] [security2:error] [pid 884009:tid 884266] [client 74.7.227.179:54008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4TORKaHUf6J8d3elJz1gABAkk"], referer: https://tejasenvironmental.com/p=539057
[Mon Jul 20 06:23:22.096229 2026] [security2:error] [pid 884009:tid 884137] [remote 152.228.213.32:39614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4TOhKaHUf6J8d3elJz4gAAvn4"], referer: https://bigwormfishing.com/wp-login.php
[Mon Jul 20 06:23:22.174064 2026] [security2:error] [pid 915741:tid 915896] [client 104.234.53.58:32395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TOq-615n1P-attmy-RwAAAag"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:22.195330 2026] [security2:error] [pid 915741:tid 915930] [client 77.110.127.138:61563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phput023jUN'))%20OR%20175=(SELECT%20175%20FROM%20PG_SLEEP(15))--"] [unique_id "al4TOq-615n1P-attmy-SAAAAco"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:22.200045 2026] [security2:error] [pid 884009:tid 884012] [remote 98.156.100.191:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TOhKaHUf6J8d3elJz5QAAnQE"]
[Mon Jul 20 06:23:22.219862 2026] [security2:error] [pid 915741:tid 915928] [client 34.74.185.202:49207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TOq-615n1P-attmy-SgAAAcg"]
[Mon Jul 20 06:23:22.251230 2026] [security2:error] [pid 915741:tid 915876] [client 171.60.139.123:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TOq-615n1P-attmy-TAAAAZQ"]
[Mon Jul 20 06:23:22.251373 2026] [security2:error] [pid 915741:tid 915876] [client 171.60.139.123:65064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TOq-615n1P-attmy-TAAAAZQ"]
[Mon Jul 20 06:23:22.317800 2026] [security2:error] [pid 915741:tid 915993] [client 57.141.18.78:27430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNq-615n1P-attmy9cQACCR0"]
[Mon Jul 20 06:23:22.463019 2026] [security2:error] [pid 884009:tid 884128] [remote 98.156.100.191:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TOhKaHUf6J8d3elJz8wAA6XU"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:23:22.604515 2026] [security2:error] [pid 915741:tid 915941] [client 66.102.122.221:34470] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4TOq-615n1P-attmy-XAAAAdU"]
[Mon Jul 20 06:23:23.154868 2026] [security2:error] [pid 915741:tid 915918] [client 114.119.150.215:43775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dasmarque.com"] [uri "/"] [unique_id "al4TO6-615n1P-attmy-ewAAAb4"], referer: https://kriesi.at/support/topic/product-zoom-available-for-propulsion
[Mon Jul 20 06:23:23.209552 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TO6-615n1P-attmy-fAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:23.209736 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:61569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TO6-615n1P-attmy-fAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:23.221056 2026] [security2:error] [pid 915741:tid 915919] [client 45.116.69.230:57272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-fQAAAb8"]
[Mon Jul 20 06:23:23.221184 2026] [security2:error] [pid 915741:tid 915919] [client 45.116.69.230:57272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-fQAAAb8"]
[Mon Jul 20 06:23:23.307021 2026] [security2:error] [pid 915741:tid 915928] [client 34.74.185.202:65419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TO6-615n1P-attmy-iAAAAcg"]
[Mon Jul 20 06:23:23.336614 2026] [security2:error] [pid 915741:tid 915880] [client 57.141.18.111:56190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TN6-615n1P-attmy9tAABmGE"]
[Mon Jul 20 06:23:23.371955 2026] [security2:error] [pid 915741:tid 915960] [client 14.225.17.146:57907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4TOK-615n1P-attmy-AwAAAeg"], referer: http://drewsasburyparkbeachhouse.com/Wp
[Mon Jul 20 06:23:23.465047 2026] [security2:error] [pid 915741:tid 915925] [client 14.225.17.146:58205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4TOa-615n1P-attmy-PQAAAcU"], referer: http://inspirespublishing.com/Wp
[Mon Jul 20 06:23:23.514775 2026] [security2:error] [pid 884009:tid 884228] [client 178.152.178.232:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TOxKaHUf6J8d3elJ0GAAAANw"]
[Mon Jul 20 06:23:23.521290 2026] [security2:error] [pid 884009:tid 884228] [client 178.152.178.232:36454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TOxKaHUf6J8d3elJ0GAAAANw"]
[Mon Jul 20 06:23:23.607316 2026] [security2:error] [pid 915741:tid 915979] [client 14.182.195.220:52151] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4TO6-615n1P-attmy-lAAAAfs"]
[Mon Jul 20 06:23:23.700906 2026] [security2:error] [pid 915741:tid 915962] [client 103.141.108.143:57474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-mgAAAeo"]
[Mon Jul 20 06:23:23.701010 2026] [security2:error] [pid 915741:tid 915962] [client 103.141.108.143:57474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-mgAAAeo"]
[Mon Jul 20 06:23:23.889775 2026] [security2:error] [pid 915741:tid 915942] [client 57.141.18.114:56168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TN6-615n1P-attmy90QAB1kE"]
[Mon Jul 20 06:23:24.412908 2026] [security2:error] [pid 915741:tid 915898] [client 45.56.185.237:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4TPK-615n1P-attmy-rQABqhM"]
[Mon Jul 20 06:23:24.453214 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:65404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4TOq-615n1P-attmy-XwAAAd0"], referer: http://fineartsfactory.net/Wp
[Mon Jul 20 06:23:24.526034 2026] [security2:error] [pid 884009:tid 884263] [client 50.116.65.227:31216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TPBKaHUf6J8d3elJ0QgAAAP8"]
[Mon Jul 20 06:23:24.533082 2026] [security2:error] [pid 915741:tid 915899] [client 34.74.185.202:62424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TPK-615n1P-attmy-wAAAAas"]
[Mon Jul 20 06:23:24.536432 2026] [security2:error] [pid 884009:tid 884249] [client 50.116.65.227:31226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TPBKaHUf6J8d3elJ0RAAAAPE"]
[Mon Jul 20 06:23:24.587624 2026] [security2:error] [pid 915741:tid 915790] [remote 20.153.140.50:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TPK-615n1P-attmy-wgAB5jA"]
[Mon Jul 20 06:23:24.687823 2026] [security2:error] [pid 915741:tid 915922] [client 57.141.18.78:27438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TOK-615n1P-attmy99gABwjQ"]
[Mon Jul 20 06:23:24.958328 2026] [security2:error] [pid 884009:tid 884153] [client 77.110.127.138:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4TPBKaHUf6J8d3elJ0VAAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:24.983115 2026] [security2:error] [pid 915741:tid 915797] [remote 20.153.140.50:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TPK-615n1P-attmy-0QABmjc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:23:25.111437 2026] [security2:error] [pid 915741:tid 915963] [client 77.110.127.138:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy-2wAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:25.111542 2026] [security2:error] [pid 915741:tid 915963] [client 77.110.127.138:61584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy-2wAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:25.443302 2026] [security2:error] [pid 915741:tid 915903] [client 34.74.185.202:51947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TPa-615n1P-attmy-6gAAAa8"]
[Mon Jul 20 06:23:25.665791 2026] [security2:error] [pid 884009:tid 884254] [client 57.141.18.124:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TORKaHUf6J8d3elJz1QAA9gY"]
[Mon Jul 20 06:23:25.950055 2026] [security2:error] [pid 884009:tid 884185] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4TPRKaHUf6J8d3elJ0bQAAALE"]
[Mon Jul 20 06:23:25.980125 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy_CAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:25.980268 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy_CAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:26.178209 2026] [security2:error] [pid 915741:tid 915991] [client 77.110.127.138:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4TPq-615n1P-attmy_FQAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:26.529485 2026] [security2:error] [pid 915741:tid 915965] [client 104.234.53.70:36307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TPq-615n1P-attmy_IwAAAe0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:26.568376 2026] [security2:error] [pid 884009:tid 884238] [client 41.173.37.102:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TPhKaHUf6J8d3elJ0igAAAOY"]
[Mon Jul 20 06:23:26.568472 2026] [security2:error] [pid 884009:tid 884238] [client 41.173.37.102:13078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TPhKaHUf6J8d3elJ0igAAAOY"]
[Mon Jul 20 06:23:26.673672 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:62274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TPq-615n1P-attmy_LAAAAbc"]
[Mon Jul 20 06:23:26.744076 2026] [core:error] [pid 884009:tid 884235] [client 103.153.183.69:59782] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.env?_=fme9a9hf&v=w088g), referer: https://twitter.com/
[Mon Jul 20 06:23:27.466220 2026] [security2:error] [pid 884009:tid 884198] [client 57.141.18.7:32918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TOxKaHUf6J8d3elJ0JwAAvjM"]
[Mon Jul 20 06:23:27.629220 2026] [security2:error] [pid 915741:tid 915956] [client 34.74.185.202:62277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TP6-615n1P-attmy_WQAAAeQ"]
[Mon Jul 20 06:23:27.950522 2026] [security2:error] [pid 915741:tid 915880] [client 57.141.18.108:40256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPK-615n1P-attmy-tgABmBA"]
[Mon Jul 20 06:23:27.957980 2026] [security2:error] [pid 915741:tid 915810] [remote 103.255.134.61:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4TP6-615n1P-attmy_YgABvUQ"]
[Mon Jul 20 06:23:28.095157 2026] [security2:error] [pid 915741:tid 915984] [client 34.74.185.202:60231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TQK-615n1P-attmy_ZgAAAgA"]
[Mon Jul 20 06:23:28.303663 2026] [security2:error] [pid 915741:tid 915841] [remote 57.141.18.105:48706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/2529028"] [unique_id "al4TQK-615n1P-attmy_bQABsmM"]
[Mon Jul 20 06:23:28.362674 2026] [security2:error] [pid 915741:tid 915883] [client 77.110.127.138:61592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4TQK-615n1P-attmy_bgAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:28.377707 2026] [security2:error] [pid 915741:tid 915962] [client 57.141.18.72:48630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPK-615n1P-attmy-xgAB6jk"]
[Mon Jul 20 06:23:28.457393 2026] [security2:error] [pid 915741:tid 915985] [client 27.96.94.195:37654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TQK-615n1P-attmy_dwAAAgE"]
[Mon Jul 20 06:23:28.457536 2026] [security2:error] [pid 915741:tid 915985] [client 27.96.94.195:37654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TQK-615n1P-attmy_dwAAAgE"]
[Mon Jul 20 06:23:28.559312 2026] [security2:error] [pid 884009:tid 884176] [client 34.74.185.202:59388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TQBKaHUf6J8d3elJ03wAAAKg"]
[Mon Jul 20 06:23:28.600038 2026] [security2:error] [pid 915741:tid 915873] [client 104.234.53.67:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TQK-615n1P-attmy_fQAAAZE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:28.645220 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.76:52758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPa-615n1P-attmy-1QABqBE"]
[Mon Jul 20 06:23:28.804494 2026] [security2:error] [pid 915741:tid 915882] [client 14.225.17.146:57637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4TP6-615n1P-attmy_QwAAAZo"], referer: http://expertcultures.com/Wp
[Mon Jul 20 06:23:28.860422 2026] [security2:error] [pid 915741:tid 915837] [remote 103.124.95.115:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4TQK-615n1P-attmy_iwABpV8"]
[Mon Jul 20 06:23:28.875080 2026] [security2:error] [pid 915741:tid 915877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_cwAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:28.898617 2026] [security2:error] [pid 915741:tid 915778] [remote 103.255.134.61:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4TQK-615n1P-attmy_kAABliQ"], referer: https://swafforddetailing.com/wp-login.php
[Mon Jul 20 06:23:28.951396 2026] [security2:error] [pid 915741:tid 915908] [client 34.74.185.202:51802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TQK-615n1P-attmy_kwAAAbQ"]
[Mon Jul 20 06:23:29.094993 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:61597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TQa-615n1P-attmy_mgAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:29.095127 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:61597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TQa-615n1P-attmy_mgAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:29.112411 2026] [security2:error] [pid 915741:tid 915950] [client 57.141.18.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_gQAAAd4"]
[Mon Jul 20 06:23:29.124566 2026] [security2:error] [pid 915741:tid 915818] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_nAAB0Uw"]
[Mon Jul 20 06:23:29.124708 2026] [security2:error] [pid 915741:tid 915937] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_nAAB0Uw"]
[Mon Jul 20 06:23:29.321898 2026] [security2:error] [pid 915741:tid 915765] [remote 103.124.95.115:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4TQa-615n1P-attmy_pAABuxc"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:23:29.326961 2026] [security2:error] [pid 915741:tid 915905] [client 14.225.17.146:58613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4TP6-615n1P-attmy_TQAAAbE"], referer: http://sarahsnyder.net/Wp
[Mon Jul 20 06:23:29.412108 2026] [security2:error] [pid 915741:tid 915896] [client 34.74.185.202:49532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TQa-615n1P-attmy_rAAAAag"]
[Mon Jul 20 06:23:29.420645 2026] [security2:error] [pid 915741:tid 915883] [client 77.110.127.138:61598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQa-615n1P-attmy_ngAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:29.491982 2026] [security2:error] [pid 915741:tid 915990] [client 171.61.165.146:31883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_swAAAgY"]
[Mon Jul 20 06:23:29.492172 2026] [security2:error] [pid 915741:tid 915990] [client 171.61.165.146:31883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_swAAAgY"]
[Mon Jul 20 06:23:29.613015 2026] [security2:error] [pid 915741:tid 915748] [remote 47.86.33.52:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TQa-615n1P-attmy_tQAB7AY"]
[Mon Jul 20 06:23:29.773478 2026] [security2:error] [pid 884009:tid 884207] [client 34.74.185.202:53935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TQRKaHUf6J8d3elJ1DQAAAMc"]
[Mon Jul 20 06:23:29.841232 2026] [security2:error] [pid 915741:tid 915980] [client 57.141.18.94:21602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPq-615n1P-attmy_GgAB_Cw"]
[Mon Jul 20 06:23:29.863349 2026] [security2:error] [pid 884009:tid 884263] [client 77.110.127.138:61602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQRKaHUf6J8d3elJ1BwAAAP8"]
[Mon Jul 20 06:23:29.969924 2026] [ssl:error] [pid 915741:tid 915902] [client 104.48.69.105:49142] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:23:30.053185 2026] [security2:error] [pid 884009:tid 884161] [client 34.74.185.202:57329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TQhKaHUf6J8d3elJ1GQAAAJo"]
[Mon Jul 20 06:23:30.128365 2026] [security2:error] [pid 915741:tid 915787] [remote 47.86.33.52:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TQq-615n1P-attmy_xwABsC0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:30.204198 2026] [security2:error] [pid 915741:tid 915992] [client 74.208.214.194:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TQq-615n1P-attmy_ywAAAgg"]
[Mon Jul 20 06:23:30.271443 2026] [security2:error] [pid 884009:tid 884237] [client 158.173.241.141:30587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TQhKaHUf6J8d3elJ1GgAAAOU"], referer: http://sesamegreenbeans.com/nine-days-south-africa-v/
[Mon Jul 20 06:23:30.293728 2026] [security2:error] [pid 915741:tid 915959] [client 14.225.17.146:57812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_yAAAAec"], referer: https://sarahsnyder.net/Wp
[Mon Jul 20 06:23:30.429958 2026] [security2:error] [pid 915741:tid 915892] [client 77.110.127.138:61612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_xgAAAaQ"]
[Mon Jul 20 06:23:30.439247 2026] [security2:error] [pid 915741:tid 915940] [client 57.141.18.0:20582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPq-615n1P-attmy_OQAB1Dg"]
[Mon Jul 20 06:23:30.452962 2026] [security2:error] [pid 915741:tid 915884] [client 14.225.17.146:58476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_hAAAAZw"], referer: http://cheesewithjam.com/Wp
[Mon Jul 20 06:23:30.629063 2026] [security2:error] [pid 915741:tid 915942] [client 57.141.18.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_zwAAAdY"]
[Mon Jul 20 06:23:30.940053 2026] [security2:error] [pid 915741:tid 915962] [client 50.116.65.227:47238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TQq-615n1P-attmy_8QAAAeo"]
[Mon Jul 20 06:23:30.952217 2026] [security2:error] [pid 884009:tid 884168] [client 50.116.65.227:59900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TQhKaHUf6J8d3elJ1PQAAAKE"]
[Mon Jul 20 06:23:31.167271 2026] [security2:error] [pid 915741:tid 915987] [client 57.141.18.28:38518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TP6-615n1P-attmy_VAACAzw"]
[Mon Jul 20 06:23:31.392229 2026] [security2:error] [pid 884009:tid 884158] [client 14.225.17.146:59162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4TQxKaHUf6J8d3elJ1RAAAAJc"], referer: http://thesoloceos.com/Wp
[Mon Jul 20 06:23:31.567044 2026] [security2:error] [pid 915741:tid 915982] [client 209.87.169.176:42009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "querenciapartners.com"] [uri "/"] [unique_id "al4TQ6-615n1P-attmzACgAAAf4"], referer: http://qpcanada.com/
[Mon Jul 20 06:23:31.786760 2026] [security2:error] [pid 915741:tid 915889] [client 14.225.17.146:58491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4TQ6-615n1P-attmzAGgAAAaE"], referer: http://adultdaycarereno.com/Wp
[Mon Jul 20 06:23:31.800025 2026] [security2:error] [pid 915741:tid 915929] [client 14.225.17.146:57533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_3QAAAck"]
[Mon Jul 20 06:23:31.946911 2026] [security2:error] [pid 915741:tid 915984] [client 50.116.65.227:47256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TQ6-615n1P-attmzAJAAAAgA"]
[Mon Jul 20 06:23:31.958070 2026] [security2:error] [pid 915741:tid 915885] [client 50.116.65.227:59948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TQ6-615n1P-attmzAJQAAAZ0"]
[Mon Jul 20 06:23:32.005107 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzAJwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.005200 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzAJwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.084252 2026] [security2:error] [pid 915741:tid 915872] [client 57.141.18.68:48598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_fwABkFY"]
[Mon Jul 20 06:23:32.155931 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:61618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzALQAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.156038 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:61618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzALQAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.342780 2026] [security2:error] [pid 915741:tid 915996] [client 57.141.18.33:32590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_jwACDE8"]
[Mon Jul 20 06:23:32.374250 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:58464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzAMQAAAeI"], referer: https://thesoloceos.com/Wp
[Mon Jul 20 06:23:32.527652 2026] [security2:error] [pid 915741:tid 915941] [client 185.198.240.141:52337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "querenciapartners.com"] [uri "/"] [unique_id "al4TRK-615n1P-attmzARgAAAdU"], referer: http://qpcanada.com/wp-includes/css/buttons.css
[Mon Jul 20 06:23:32.694463 2026] [security2:error] [pid 915741:tid 915968] [client 14.225.17.146:58181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzATQAAAfA"], referer: https://adultdaycarereno.com/Wp
[Mon Jul 20 06:23:32.850674 2026] [security2:error] [pid 915741:tid 915963] [client 171.60.139.123:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TRK-615n1P-attmzAUgAAAes"]
[Mon Jul 20 06:23:32.850786 2026] [security2:error] [pid 915741:tid 915963] [client 171.60.139.123:49193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TRK-615n1P-attmzAUgAAAes"]
[Mon Jul 20 06:23:32.853676 2026] [security2:error] [pid 884009:tid 884234] [client 112.208.70.94:43637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TRBKaHUf6J8d3elJ1hAAAAOI"]
[Mon Jul 20 06:23:32.853768 2026] [security2:error] [pid 884009:tid 884234] [client 112.208.70.94:43637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TRBKaHUf6J8d3elJ1hAAAAOI"]
[Mon Jul 20 06:23:33.265797 2026] [security2:error] [pid 915741:tid 915936] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAWQAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:33.274742 2026] [security2:error] [pid 884009:tid 884155] [client 45.157.112.60:24885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TRRKaHUf6J8d3elJ1mAAAAJQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:33.365454 2026] [security2:error] [pid 915741:tid 915938] [client 173.239.214.12:61985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "querenciapartners.com"] [uri "/"] [unique_id "al4TRa-615n1P-attmzAZgAAAdI"], referer: http://qpcanada.com/media/system/js/core.js
[Mon Jul 20 06:23:33.408051 2026] [security2:error] [pid 915741:tid 915970] [client 57.141.18.35:20468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQa-615n1P-attmy_uwAB8kA"]
[Mon Jul 20 06:23:33.443164 2026] [security2:error] [pid 884009:tid 884091] [remote 162.19.86.63:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TRRKaHUf6J8d3elJ1nQAAoFA"]
[Mon Jul 20 06:23:33.443304 2026] [security2:error] [pid 884009:tid 884167] [client 162.19.86.63:50479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TRRKaHUf6J8d3elJ1nQAAoFA"]
[Mon Jul 20 06:23:34.043595 2026] [security2:error] [pid 915741:tid 915939] [client 57.141.18.76:52768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_3AAB014"]
[Mon Jul 20 06:23:34.055354 2026] [security2:error] [pid 915741:tid 915809] [remote 192.241.143.148:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TRq-615n1P-attmzAmgABuEM"]
[Mon Jul 20 06:23:34.165059 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:61630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAowAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.165172 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:61630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAowAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.249010 2026] [security2:error] [pid 915741:tid 915850] [remote 192.241.143.148:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TRq-615n1P-attmzApAABqGw"], referer: https://friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:34.285834 2026] [security2:error] [pid 915741:tid 915989] [client 103.141.108.143:58014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzApgAAAgU"]
[Mon Jul 20 06:23:34.285938 2026] [security2:error] [pid 915741:tid 915989] [client 103.141.108.143:58014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzApgAAAgU"]
[Mon Jul 20 06:23:34.322586 2026] [security2:error] [pid 915741:tid 915974] [client 77.110.127.138:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAqwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.322685 2026] [security2:error] [pid 915741:tid 915974] [client 77.110.127.138:61631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAqwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.349255 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:61598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArAAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.349400 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:61598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArAAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.401718 2026] [security2:error] [pid 915741:tid 915946] [client 77.110.127.138:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.401867 2026] [security2:error] [pid 915741:tid 915946] [client 77.110.127.138:61600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.466675 2026] [security2:error] [pid 884009:tid 884212] [client 77.110.127.138:61602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1vgAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.466790 2026] [security2:error] [pid 884009:tid 884212] [client 77.110.127.138:61602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1vgAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.518059 2026] [security2:error] [pid 915741:tid 915917] [client 77.110.127.138:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAsgAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.518245 2026] [security2:error] [pid 915741:tid 915917] [client 77.110.127.138:61601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAsgAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.528948 2026] [security2:error] [pid 915741:tid 915978] [client 14.225.17.146:57727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAZAAAAfo"], referer: http://sarahholyfield.com/Wp
[Mon Jul 20 06:23:34.571099 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:61609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1xwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.571244 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:61609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1xwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.632658 2026] [security2:error] [pid 915741:tid 915938] [client 77.110.127.138:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAuAAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.632852 2026] [security2:error] [pid 915741:tid 915938] [client 77.110.127.138:61610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAuAAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.667530 2026] [security2:error] [pid 915741:tid 915914] [client 178.152.178.232:37463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAugAAAbo"]
[Mon Jul 20 06:23:34.667629 2026] [security2:error] [pid 915741:tid 915914] [client 178.152.178.232:37463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAugAAAbo"]
[Mon Jul 20 06:23:34.702167 2026] [security2:error] [pid 915741:tid 915994] [client 45.116.69.230:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAvAAAAgo"]
[Mon Jul 20 06:23:34.702330 2026] [security2:error] [pid 915741:tid 915994] [client 45.116.69.230:58056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAvAAAAgo"]
[Mon Jul 20 06:23:35.015993 2026] [security2:error] [pid 915741:tid 915977] [client 57.141.18.7:59902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQ6-615n1P-attmzABgAB-Qc"]
[Mon Jul 20 06:23:35.186966 2026] [security2:error] [pid 884009:tid 884155] [client 46.110.96.34:17733] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4TRxKaHUf6J8d3elJ13AAAAJQ"]
[Mon Jul 20 06:23:35.339957 2026] [security2:error] [pid 884009:tid 884240] [client 104.234.53.52:50953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TRxKaHUf6J8d3elJ14gAAAOg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:35.509453 2026] [security2:error] [pid 915741:tid 915987] [client 14.225.17.146:58844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAYAAAAgM"]
[Mon Jul 20 06:23:35.527754 2026] [security2:error] [pid 915741:tid 915743] [remote 20.153.140.50:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4TR6-615n1P-attmzA2gAB9gE"]
[Mon Jul 20 06:23:35.790820 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TR6-615n1P-attmzA2wAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:35.832092 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.23:34478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzANQAB5D8"]
[Mon Jul 20 06:23:35.852075 2026] [security2:error] [pid 915741:tid 915933] [client 77.110.127.138:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TR6-615n1P-attmzA7QAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:35.852209 2026] [security2:error] [pid 915741:tid 915933] [client 77.110.127.138:61633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TR6-615n1P-attmzA7QAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:35.925274 2026] [security2:error] [pid 915741:tid 915747] [remote 20.153.140.50:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4TR6-615n1P-attmzA8QABkwU"], referer: https://superiorcopywriting.com/wp-login.php
[Mon Jul 20 06:23:35.927563 2026] [security2:error] [pid 915741:tid 915990] [client 57.141.18.41:47726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzAQQACBhw"]
[Mon Jul 20 06:23:36.384300 2026] [security2:error] [pid 915741:tid 915981] [client 114.119.128.23:56669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thierry-henry.fr"] [uri "/wed-2019/amp/"] [unique_id "al4TSK-615n1P-attmzBDAAAAf0"], referer: https://thierry-henry.fr/episode28-laplace/amp/
[Mon Jul 20 06:23:36.397283 2026] [security2:error] [pid 884009:tid 884268] [client 14.224.227.113:55726] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4TSBKaHUf6J8d3elJ2DAAAAQQ"]
[Mon Jul 20 06:23:36.573923 2026] [ssl:error] [pid 884009:tid 884165] [client 104.48.69.105:49146] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:23:36.670433 2026] [security2:error] [pid 884009:tid 884043] [remote 45.90.123.233:46558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4TSBKaHUf6J8d3elJ2GwAAwyA"]
[Mon Jul 20 06:23:36.719028 2026] [security2:error] [pid 915741:tid 915881] [client 14.225.17.146:57089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBEQAAAZk"], referer: http://falconarrowshop.com/Wp
[Mon Jul 20 06:23:36.776958 2026] [security2:error] [pid 915741:tid 915995] [client 14.225.17.146:57361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBEwAAAgs"]
[Mon Jul 20 06:23:36.873741 2026] [security2:error] [pid 884009:tid 884019] [remote 45.90.123.233:46558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4TSBKaHUf6J8d3elJ2IwAAwQg"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 06:23:37.026822 2026] [security2:error] [pid 915741:tid 915961] [client 77.110.127.138:61620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TSa-615n1P-attmzBJAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:37.026929 2026] [security2:error] [pid 915741:tid 915961] [client 77.110.127.138:61620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TSa-615n1P-attmzBJAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:37.035315 2026] [security2:error] [pid 915741:tid 915946] [client 14.225.17.146:58422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4TR6-615n1P-attmzA4QAAAdo"], referer: http://goyalsatyam.com/Wp
[Mon Jul 20 06:23:37.147722 2026] [security2:error] [pid 884009:tid 884219] [client 41.173.37.102:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TSRKaHUf6J8d3elJ2MwAAANM"]
[Mon Jul 20 06:23:37.147869 2026] [security2:error] [pid 884009:tid 884219] [client 41.173.37.102:13704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TSRKaHUf6J8d3elJ2MwAAANM"]
[Mon Jul 20 06:23:37.276262 2026] [security2:error] [pid 915741:tid 915892] [client 57.141.18.20:59220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAagABpHY"]
[Mon Jul 20 06:23:37.293854 2026] [security2:error] [pid 915741:tid 915962] [client 127.0.0.1:20602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TSa-615n1P-attmzBNAAAAeo"], referer: https://t.co/5st0lvavmo
[Mon Jul 20 06:23:37.379488 2026] [security2:error] [pid 915741:tid 915768] [remote 85.204.69.248:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBNgABqxo"]
[Mon Jul 20 06:23:37.611550 2026] [security2:error] [pid 915741:tid 915810] [remote 188.166.241.141:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBSQABzkQ"]
[Mon Jul 20 06:23:37.625703 2026] [security2:error] [pid 915741:tid 915804] [remote 85.204.69.248:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBSwAB_D4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:37.649827 2026] [ssl:error] [pid 915741:tid 915924] [client 104.48.69.105:49162] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:23:37.761088 2026] [security2:error] [pid 884009:tid 884077] [remote 57.141.18.25:59418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3579229"] [unique_id "al4TSRKaHUf6J8d3elJ2SgAA7UI"]
[Mon Jul 20 06:23:37.881936 2026] [security2:error] [pid 915741:tid 915950] [client 216.38.230.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBRQAB3n8"]
[Mon Jul 20 06:23:37.883032 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.95:48434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRq-615n1P-attmzAlQAB3CM"]
[Mon Jul 20 06:23:37.978589 2026] [security2:error] [pid 915741:tid 915759] [remote 188.166.241.141:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBWAAB5BE"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:23:38.366870 2026] [security2:error] [pid 915741:tid 915947] [client 57.141.18.38:33286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRq-615n1P-attmzAtAAB2yI"]
[Mon Jul 20 06:23:38.389960 2026] [security2:error] [pid 915741:tid 915936] [client 14.225.17.146:49780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBNwAAAdA"], referer: http://entuvy.com/Wp
[Mon Jul 20 06:23:38.885265 2026] [security2:error] [pid 915741:tid 915894] [client 14.225.17.146:53062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBOQAAAaY"], referer: http://kromosenergy.com/Wp
[Mon Jul 20 06:23:38.932247 2026] [security2:error] [pid 884009:tid 884183] [client 113.160.97.242:57665] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4TShKaHUf6J8d3elJ2cAAAAK8"]
[Mon Jul 20 06:23:39.026830 2026] [security2:error] [pid 915741:tid 915968] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.cel.bdi.mybluehost.me"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBAQAAAfA"]
[Mon Jul 20 06:23:39.680339 2026] [security2:error] [pid 915741:tid 915896] [client 14.225.17.146:49541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4TS6-615n1P-attmzBmQAAAag"], referer: http://bruceledewitz.com/Wp
[Mon Jul 20 06:23:39.739471 2026] [security2:error] [pid 884009:tid 884134] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2kwAAtXs"]
[Mon Jul 20 06:23:39.739661 2026] [security2:error] [pid 884009:tid 884189] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2kwAAtXs"]
[Mon Jul 20 06:23:39.937058 2026] [security2:error] [pid 884009:tid 884237] [client 143.244.48.150:59934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2lgAAAOU"], referer: https://recruitinginsight.us/2020/03/24/protect-your-recruiting-infrastructure/
[Mon Jul 20 06:23:39.937108 2026] [security2:error] [pid 884009:tid 884237] [client 143.244.48.150:59934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2lgAAAOU"], referer: https://recruitinginsight.us/2020/03/24/protect-your-recruiting-infrastructure/
[Mon Jul 20 06:23:39.976356 2026] [security2:error] [pid 884009:tid 884196] [client 82.102.18.116:11170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TSxKaHUf6J8d3elJ2mQAAALw"]
[Mon Jul 20 06:23:39.986736 2026] [security2:error] [pid 915741:tid 915904] [client 57.141.18.39:25269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBBgABsBI"]
[Mon Jul 20 06:23:40.204710 2026] [security2:error] [pid 915741:tid 915780] [remote 45.90.123.233:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TTK-615n1P-attmzBxAACBSY"]
[Mon Jul 20 06:23:40.257458 2026] [security2:error] [pid 915741:tid 915877] [client 50.116.65.227:21080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4TTK-615n1P-attmzByQAAAZU"]
[Mon Jul 20 06:23:40.267699 2026] [security2:error] [pid 915741:tid 915890] [client 50.116.65.227:58916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4TTK-615n1P-attmzBygAAAaI"]
[Mon Jul 20 06:23:40.399557 2026] [security2:error] [pid 915741:tid 915851] [remote 45.90.123.233:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TTK-615n1P-attmzBzwABpW0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:23:40.537729 2026] [security2:error] [pid 884009:tid 884030] [remote 117.0.21.154:60024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TTBKaHUf6J8d3elJ2rQAA8hM"]
[Mon Jul 20 06:23:40.577411 2026] [security2:error] [pid 915741:tid 915891] [client 171.61.165.146:32960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TTK-615n1P-attmzB2gAAAaM"]
[Mon Jul 20 06:23:40.577565 2026] [security2:error] [pid 915741:tid 915891] [client 171.61.165.146:32960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TTK-615n1P-attmzB2gAAAaM"]
[Mon Jul 20 06:23:40.650063 2026] [security2:error] [pid 884009:tid 884194] [client 82.102.18.116:38870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TTBKaHUf6J8d3elJ2tQAAALo"]
[Mon Jul 20 06:23:40.684769 2026] [security2:error] [pid 884009:tid 884220] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TTBKaHUf6J8d3elJ2qwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:40.693212 2026] [security2:error] [pid 915741:tid 915888] [client 14.225.17.146:53207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzB1gAAAaA"], referer: http://samdothan.org/Wp
[Mon Jul 20 06:23:41.017589 2026] [security2:error] [pid 884009:tid 884066] [remote 117.0.21.154:60024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TTRKaHUf6J8d3elJ2wQABAjc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:41.248923 2026] [security2:error] [pid 915741:tid 915881] [client 57.141.18.61:43856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBTgABmVo"]
[Mon Jul 20 06:23:41.492389 2026] [security2:error] [pid 915741:tid 915855] [remote 20.153.140.50:58664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TTa-615n1P-attmzB-QAB4XE"]
[Mon Jul 20 06:23:41.492644 2026] [security2:error] [pid 915741:tid 915953] [client 20.153.140.50:58664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TTa-615n1P-attmzB-QAB4XE"]
[Mon Jul 20 06:23:41.649145 2026] [security2:error] [pid 915741:tid 915984] [client 14.225.17.146:49710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzB6wAAAgA"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/Wp
[Mon Jul 20 06:23:41.792591 2026] [autoindex:error] [pid 884009:tid 884249] [client 64.227.107.201:39922] AH01276: Cannot serve directory /home2/bzmppvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:42.108227 2026] [security2:error] [pid 915741:tid 915981] [client 57.141.18.22:55238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSq-615n1P-attmzBcQAB_Xg"]
[Mon Jul 20 06:23:42.478097 2026] [security2:error] [pid 884009:tid 884157] [client 57.141.18.1:23400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TShKaHUf6J8d3elJ2cQAAlh0"]
[Mon Jul 20 06:23:42.520362 2026] [security2:error] [pid 884009:tid 884227] [client 103.153.183.69:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../root/.bash_history"] [unique_id "al4TThKaHUf6J8d3elJ3DgAAANs"], referer: https://www.reddit.com/
[Mon Jul 20 06:23:42.562373 2026] [security2:error] [pid 884009:tid 884205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TThKaHUf6J8d3elJ3CAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:42.623832 2026] [security2:error] [pid 884009:tid 884122] [remote 72.167.132.114:33244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4TThKaHUf6J8d3elJ3EQAA528"]
[Mon Jul 20 06:23:42.680828 2026] [security2:error] [pid 915741:tid 915827] [remote 20.153.140.50:58678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4TTq-615n1P-attmzCLAAB6lU"]
[Mon Jul 20 06:23:42.711362 2026] [security2:error] [pid 884009:tid 884189] [client 50.116.65.227:58952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TThKaHUf6J8d3elJ3FgAAALU"]
[Mon Jul 20 06:23:42.722578 2026] [security2:error] [pid 884009:tid 884175] [client 50.116.65.227:58956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TThKaHUf6J8d3elJ3GAAAAKc"]
[Mon Jul 20 06:23:42.749499 2026] [security2:error] [pid 884009:tid 884142] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4TThKaHUf6J8d3elJ3AQAAhzQ"], referer: http://ali-alghanim.net/Wp
[Mon Jul 20 06:23:42.870620 2026] [security2:error] [pid 884009:tid 884019] [remote 72.167.132.114:33244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4TThKaHUf6J8d3elJ3HwAAtgg"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:23:42.932506 2026] [security2:error] [pid 915741:tid 915939] [client 57.141.18.97:37770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TS6-615n1P-attmzBqwAB02U"]
[Mon Jul 20 06:23:43.019297 2026] [security2:error] [pid 884009:tid 884216] [client 57.141.18.37:37948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSxKaHUf6J8d3elJ2kgAA0EQ"]
[Mon Jul 20 06:23:43.021375 2026] [security2:error] [pid 884009:tid 884150] [client 77.110.127.138:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TTxKaHUf6J8d3elJ3JAAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:43.021475 2026] [security2:error] [pid 884009:tid 884150] [client 77.110.127.138:61652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TTxKaHUf6J8d3elJ3JAAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:43.065725 2026] [security2:error] [pid 915741:tid 915809] [remote 20.153.140.50:58678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4TT6-615n1P-attmzCOQACAUM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:23:43.201814 2026] [security2:error] [pid 915741:tid 915952] [client 57.141.18.96:58156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TS6-615n1P-attmzBtgAB4HU"]
[Mon Jul 20 06:23:43.339994 2026] [security2:error] [pid 884009:tid 884263] [client 82.102.18.116:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TTxKaHUf6J8d3elJ3LwAAAP8"]
[Mon Jul 20 06:23:43.340148 2026] [security2:error] [pid 884009:tid 884263] [client 82.102.18.116:38882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TTxKaHUf6J8d3elJ3LwAAAP8"]
[Mon Jul 20 06:23:43.391337 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TT6-615n1P-attmzCQQAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:43.453252 2026] [security2:error] [pid 915741:tid 915918] [client 57.141.18.111:62226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzBwAABvgg"]
[Mon Jul 20 06:23:43.603265 2026] [security2:error] [pid 884009:tid 884195] [client 171.60.139.123:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TTxKaHUf6J8d3elJ3MwAAALs"]
[Mon Jul 20 06:23:43.603401 2026] [security2:error] [pid 884009:tid 884195] [client 171.60.139.123:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TTxKaHUf6J8d3elJ3MwAAALs"]
[Mon Jul 20 06:23:43.650706 2026] [security2:error] [pid 915741:tid 915972] [client 57.141.18.1:23420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzByAAB9Dw"]
[Mon Jul 20 06:23:44.243413 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUK-615n1P-attmzCfwAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:44.243528 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:61662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUK-615n1P-attmzCfwAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:44.421301 2026] [security2:error] [pid 915741:tid 915966] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TUK-615n1P-attmzCfQAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:44.845598 2026] [security2:error] [pid 915741:tid 915919] [client 14.225.17.146:52944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4TT6-615n1P-attmzCXgAAAb8"], referer: http://betterbonddogtraining.com/Wp
[Mon Jul 20 06:23:44.967496 2026] [security2:error] [pid 884009:tid 884033] [remote 167.233.114.32:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TUBKaHUf6J8d3elJ3VQAAsxY"]
[Mon Jul 20 06:23:44.978335 2026] [security2:error] [pid 915741:tid 915896] [client 103.141.108.143:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TUK-615n1P-attmzCqwAAAag"]
[Mon Jul 20 06:23:44.978658 2026] [security2:error] [pid 915741:tid 915896] [client 103.141.108.143:58702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TUK-615n1P-attmzCqwAAAag"]
[Mon Jul 20 06:23:45.157807 2026] [security2:error] [pid 884009:tid 884080] [remote 167.233.114.32:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TURKaHUf6J8d3elJ3XAAA4kU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:45.665154 2026] [security2:error] [pid 915741:tid 915908] [client 104.234.53.86:54673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TUa-615n1P-attmzCzAAAAbQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:45.690167 2026] [security2:error] [pid 884009:tid 884163] [client 45.116.69.230:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TURKaHUf6J8d3elJ3bAAAAJw"]
[Mon Jul 20 06:23:45.690286 2026] [security2:error] [pid 884009:tid 884163] [client 45.116.69.230:58714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TURKaHUf6J8d3elJ3bAAAAJw"]
[Mon Jul 20 06:23:45.890799 2026] [security2:error] [pid 884009:tid 884183] [client 103.153.183.69:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/nginx/nginx.conf"] [unique_id "al4TURKaHUf6J8d3elJ3bwAAAK8"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:23:46.103206 2026] [security2:error] [pid 884009:tid 884207] [client 103.153.183.69:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/apache2/apache2.conf"] [unique_id "al4TUhKaHUf6J8d3elJ3cwAAAMc"], referer: https://t.co/321boh8yal
[Mon Jul 20 06:23:46.172654 2026] [security2:error] [pid 915741:tid 915895] [client 77.110.127.138:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUq-615n1P-attmzC7AAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:46.172801 2026] [security2:error] [pid 915741:tid 915895] [client 77.110.127.138:61669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUq-615n1P-attmzC7AAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:46.229858 2026] [security2:error] [pid 884009:tid 884148] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4TUBKaHUf6J8d3elJ3RwAAAI0"]
[Mon Jul 20 06:23:46.337613 2026] [security2:error] [pid 915741:tid 915928] [client 18.140.64.130:65138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TUq-615n1P-attmzC9gAAAcg"]
[Mon Jul 20 06:23:46.337715 2026] [security2:error] [pid 915741:tid 915928] [client 18.140.64.130:65138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TUq-615n1P-attmzC9gAAAcg"]
[Mon Jul 20 06:23:46.492533 2026] [security2:error] [pid 915741:tid 915955] [client 52.109.124.141:23937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TUq-615n1P-attmzC_wAAAeM"]
[Mon Jul 20 06:23:46.555733 2026] [security2:error] [pid 915741:tid 915933] [client 57.141.18.100:54152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TTq-615n1P-attmzCMQABzSc"]
[Mon Jul 20 06:23:46.556038 2026] [security2:error] [pid 884009:tid 884257] [client 57.141.18.75:20948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TThKaHUf6J8d3elJ3IAAA-Wg"]
[Mon Jul 20 06:23:46.558422 2026] [security2:error] [pid 884009:tid 884200] [client 77.110.127.138:61670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TUhKaHUf6J8d3elJ3dwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:46.590986 2026] [security2:error] [pid 884009:tid 884216] [client 14.225.17.146:55570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4TURKaHUf6J8d3elJ3ZQAAANA"], referer: http://nikkidesigns.net/Wp
[Mon Jul 20 06:23:46.673035 2026] [security2:error] [pid 915741:tid 915973] [client 52.109.124.141:23937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TUq-615n1P-attmzDCgAAAfU"]
[Mon Jul 20 06:23:47.137816 2026] [security2:error] [pid 915741:tid 915987] [client 57.141.18.107:25582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TT6-615n1P-attmzCVwACAzA"]
[Mon Jul 20 06:23:47.199442 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TUq-615n1P-attmzDGgAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:47.308485 2026] [proxy:error] [pid 915741:tid 915929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:47.308545 2026] [proxy_http:error] [pid 915741:tid 915929] [client 205.210.31.50:63080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:47.309045 2026] [proxy:error] [pid 915741:tid 915929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:47.309093 2026] [proxy_http:error] [pid 915741:tid 915929] [client 205.210.31.50:63080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:47.359807 2026] [security2:error] [pid 915741:tid 915924] [client 50.116.65.227:21094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4TU6-615n1P-attmzDMwAAAcQ"]
[Mon Jul 20 06:23:47.452534 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TU6-615n1P-attmzDOgAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:47.452654 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TU6-615n1P-attmzDOgAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:47.580553 2026] [security2:error] [pid 915741:tid 915948] [client 14.225.17.146:60419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4TU6-615n1P-attmzDNgAAAdw"], referer: http://ivetstrategies.com/Wp
[Mon Jul 20 06:23:47.709820 2026] [security2:error] [pid 915741:tid 915846] [remote 57.141.18.75:33206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4TU6-615n1P-attmzDVQABuGg"]
[Mon Jul 20 06:23:47.816176 2026] [security2:error] [pid 915741:tid 915901] [client 41.173.37.102:14124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TU6-615n1P-attmzDWAAAAa0"]
[Mon Jul 20 06:23:47.816302 2026] [security2:error] [pid 915741:tid 915901] [client 41.173.37.102:14124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TU6-615n1P-attmzDWAAAAa0"]
[Mon Jul 20 06:23:47.857129 2026] [security2:error] [pid 915741:tid 915902] [client 50.116.65.227:21096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TU6-615n1P-attmzDWwAAAa4"]
[Mon Jul 20 06:23:47.868104 2026] [security2:error] [pid 915741:tid 915980] [client 50.116.65.227:59018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TU6-615n1P-attmzDXAAAAfw"]
[Mon Jul 20 06:23:48.057251 2026] [core:error] [pid 915741:tid 915966] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.057275 2026] [core:error] [pid 915741:tid 915966] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.105326 2026] [core:error] [pid 915741:tid 915927] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.105354 2026] [core:error] [pid 915741:tid 915927] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.135681 2026] [security2:error] [pid 915741:tid 915963] [client 52.109.108.111:20420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TVK-615n1P-attmzDcgAAAes"]
[Mon Jul 20 06:23:48.160626 2026] [core:error] [pid 915741:tid 915992] [client 103.153.183.69:45564] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=9z8y2wxa&v=rwo8n), referer: https://www.reddit.com/
[Mon Jul 20 06:23:48.164033 2026] [security2:error] [pid 915741:tid 915974] [client 127.0.0.1:42028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TVK-615n1P-attmzDdwAAAfY"], referer: https://www.reddit.com/
[Mon Jul 20 06:23:48.206528 2026] [security2:error] [pid 884009:tid 884123] [remote 192.241.143.148:45028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nAAAjnA"]
[Mon Jul 20 06:23:48.206737 2026] [security2:error] [pid 884009:tid 884149] [client 192.241.143.148:45028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nAAAjnA"]
[Mon Jul 20 06:23:48.244912 2026] [security2:error] [pid 884009:tid 884221] [client 77.110.127.138:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.245031 2026] [security2:error] [pid 884009:tid 884221] [client 77.110.127.138:61679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.294166 2026] [security2:error] [pid 915741:tid 915996] [client 52.109.108.111:20420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TVK-615n1P-attmzDfQAAAgw"]
[Mon Jul 20 06:23:48.458049 2026] [lsapi:warn] [pid 915741:tid 915742] [remote 20.169.78.128:0] [host ali-alghanim.com] Backend log: PHP Warning: getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:23:48.510257 2026] [security2:error] [pid 915741:tid 915934] [client 34.162.230.222:1376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDhgAAAc4"]
[Mon Jul 20 06:23:48.522026 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDgAAAAbo"]
[Mon Jul 20 06:23:48.522227 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDgAAAAbo"]
[Mon Jul 20 06:23:48.522262 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDgAAAAbo"]
[Mon Jul 20 06:23:48.628128 2026] [security2:error] [pid 915741:tid 915861] [remote 217.61.143.92:33988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TVK-615n1P-attmzDlwACBXc"]
[Mon Jul 20 06:23:48.864729 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDrQAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.864845 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDrQAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.882391 2026] [security2:error] [pid 915741:tid 915802] [remote 57.141.18.116:31530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4TVK-615n1P-attmzDqgABvTw"]
[Mon Jul 20 06:23:48.922888 2026] [security2:error] [pid 915741:tid 915783] [remote 217.61.143.92:33988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TVK-615n1P-attmzDtgACByk"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:48.954839 2026] [security2:error] [pid 884009:tid 884151] [client 57.141.18.80:27936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TURKaHUf6J8d3elJ3XgAAkBs"]
[Mon Jul 20 06:23:49.189273 2026] [security2:error] [pid 915741:tid 915929] [client 14.225.17.146:50186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDdQAAAck"], referer: http://ancestralidadytrance.space/Wp
[Mon Jul 20 06:23:49.191114 2026] [security2:error] [pid 884009:tid 884140] [client 57.141.18.80:27950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TURKaHUf6J8d3elJ3awAAhUI"]
[Mon Jul 20 06:23:49.239447 2026] [security2:error] [pid 915741:tid 915926] [client 14.225.17.146:50129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDfgAAAcY"], referer: http://techtradeinc.com/Wp
[Mon Jul 20 06:23:49.465728 2026] [security2:error] [pid 915741:tid 915944] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVa-615n1P-attmzDvgAAAdg"]
[Mon Jul 20 06:23:49.465947 2026] [security2:error] [pid 915741:tid 915944] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVa-615n1P-attmzDvgAAAdg"]
[Mon Jul 20 06:23:49.465985 2026] [security2:error] [pid 915741:tid 915944] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVa-615n1P-attmzDvgAAAdg"]
[Mon Jul 20 06:23:49.481702 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.107:25590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TUa-615n1P-attmzC2wACBA4"]
[Mon Jul 20 06:23:49.639781 2026] [security2:error] [pid 915741:tid 915849] [remote 173.212.252.15:35024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TVa-615n1P-attmzDzgAB42s"]
[Mon Jul 20 06:23:49.789845 2026] [security2:error] [pid 884009:tid 884262] [client 112.208.70.94:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TVRKaHUf6J8d3elJ3vwAAAP4"]
[Mon Jul 20 06:23:49.789956 2026] [security2:error] [pid 884009:tid 884262] [client 112.208.70.94:44012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TVRKaHUf6J8d3elJ3vwAAAP4"]
[Mon Jul 20 06:23:49.838883 2026] [security2:error] [pid 915741:tid 915844] [remote 173.212.252.15:35024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TVa-615n1P-attmzD1QAB9mY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:23:49.876529 2026] [security2:error] [pid 884009:tid 884198] [client 57.141.18.106:22104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TUhKaHUf6J8d3elJ3dgAAvnM"]
[Mon Jul 20 06:23:50.057465 2026] [security2:error] [pid 915741:tid 915953] [client 14.225.17.146:60403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDpAAAAeE"], referer: http://mazzucelli.com/Wp
[Mon Jul 20 06:23:50.349167 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD_AAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.349268 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD_AAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.363474 2026] [security2:error] [pid 915741:tid 915774] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVq-615n1P-attmzD_QAB_iA"]
[Mon Jul 20 06:23:50.363699 2026] [security2:error] [pid 915741:tid 915982] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVq-615n1P-attmzD_QAB_iA"]
[Mon Jul 20 06:23:50.374210 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD8gAAAbo"]
[Mon Jul 20 06:23:50.374393 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD8gAAAbo"]
[Mon Jul 20 06:23:50.374427 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD8gAAAbo"]
[Mon Jul 20 06:23:50.511530 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzECwAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.511639 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzECwAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.623275 2026] [security2:error] [pid 915741:tid 915976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TVq-615n1P-attmzEAwAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.639183 2026] [security2:error] [pid 915741:tid 915944] [client 158.173.166.181:42867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TVq-615n1P-attmzEEAAAAdg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:50.699456 2026] [security2:error] [pid 915741:tid 915986] [client 14.225.17.146:60465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDnQAAAgI"], referer: http://floorsourcestock.com/Wp
[Mon Jul 20 06:23:51.214368 2026] [security2:error] [pid 915741:tid 915763] [remote 173.212.252.15:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TV6-615n1P-attmzELgABoBU"]
[Mon Jul 20 06:23:51.363582 2026] [security2:error] [pid 884009:tid 884243] [client 171.61.165.146:25152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVxKaHUf6J8d3elJ37wAAAOs"]
[Mon Jul 20 06:23:51.363738 2026] [security2:error] [pid 884009:tid 884243] [client 171.61.165.146:25152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVxKaHUf6J8d3elJ37wAAAOs"]
[Mon Jul 20 06:23:51.403975 2026] [security2:error] [pid 915741:tid 915866] [remote 173.212.252.15:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TV6-615n1P-attmzEPQABknw"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:23:51.404368 2026] [security2:error] [pid 915741:tid 915889] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEKgAAAaE"]
[Mon Jul 20 06:23:51.404509 2026] [security2:error] [pid 915741:tid 915889] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEKgAAAaE"]
[Mon Jul 20 06:23:51.404542 2026] [security2:error] [pid 915741:tid 915889] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEKgAAAaE"]
[Mon Jul 20 06:23:51.955614 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEWQAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:51.955707 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEWQAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:52.055733 2026] [security2:error] [pid 915741:tid 915954] [client 50.116.65.227:60128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TWK-615n1P-attmzEXwAAAeI"]
[Mon Jul 20 06:23:52.066897 2026] [security2:error] [pid 915741:tid 915933] [client 50.116.65.227:60132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TWK-615n1P-attmzEYgAAAc0"]
[Mon Jul 20 06:23:52.348716 2026] [security2:error] [pid 915741:tid 915995] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWK-615n1P-attmzEaAAAAgs"]
[Mon Jul 20 06:23:52.348921 2026] [security2:error] [pid 915741:tid 915995] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWK-615n1P-attmzEaAAAAgs"]
[Mon Jul 20 06:23:52.348956 2026] [security2:error] [pid 915741:tid 915995] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWK-615n1P-attmzEaAAAAgs"]
[Mon Jul 20 06:23:52.436854 2026] [fcgid:warn] [pid 915741:tid 915968] (70014)End of file found: [client 66.132.172.216:49484] mod_fcgid: can't get data from http client
[Mon Jul 20 06:23:52.458157 2026] [security2:error] [pid 884009:tid 884191] [client 57.141.18.91:20964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVRKaHUf6J8d3elJ3rQAAtxw"]
[Mon Jul 20 06:23:52.497325 2026] [security2:error] [pid 915741:tid 915927] [client 14.225.17.146:49855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4TVq-615n1P-attmzEEwAAAcc"], referer: http://tacticaltreeoperations.com/Wp
[Mon Jul 20 06:23:52.667800 2026] [security2:error] [pid 915741:tid 915986] [client 50.116.65.227:60150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TWK-615n1P-attmzEewAAAgI"]
[Mon Jul 20 06:23:52.750435 2026] [security2:error] [pid 884009:tid 884263] [client 14.225.17.146:55583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4TVxKaHUf6J8d3elJ37QAAAP8"], referer: http://bnb-engineering.com/Wp
[Mon Jul 20 06:23:52.835946 2026] [security2:error] [pid 915741:tid 915967] [client 104.234.53.90:25543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TWK-615n1P-attmzEiAAAAe8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:52.856990 2026] [security2:error] [pid 884009:tid 884144] [client 50.116.65.227:60164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TWBKaHUf6J8d3elJ4FQAAAIk"]
[Mon Jul 20 06:23:53.120994 2026] [security2:error] [pid 884009:tid 884195] [client 77.110.127.138:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWRKaHUf6J8d3elJ4HQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:53.121161 2026] [security2:error] [pid 884009:tid 884195] [client 77.110.127.138:61695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWRKaHUf6J8d3elJ4HQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:53.264392 2026] [security2:error] [pid 884009:tid 884121] [remote 147.50.252.213:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4TWRKaHUf6J8d3elJ4HwAA824"]
[Mon Jul 20 06:23:53.280806 2026] [security2:error] [pid 915741:tid 915997] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWa-615n1P-attmzElAAAAg0"]
[Mon Jul 20 06:23:53.280969 2026] [security2:error] [pid 915741:tid 915997] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWa-615n1P-attmzElAAAAg0"]
[Mon Jul 20 06:23:53.281004 2026] [security2:error] [pid 915741:tid 915997] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWa-615n1P-attmzElAAAAg0"]
[Mon Jul 20 06:23:53.521870 2026] [security2:error] [pid 915741:tid 915767] [remote 81.173.115.7:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4TWa-615n1P-attmzEsgABkRk"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:23:53.632461 2026] [security2:error] [pid 915741:tid 915813] [remote 152.228.213.32:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4TWa-615n1P-attmzEtAAB7Uc"]
[Mon Jul 20 06:23:53.769598 2026] [security2:error] [pid 915741:tid 915943] [client 104.234.53.49:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TWa-615n1P-attmzEwAAAAdc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:53.773534 2026] [security2:error] [pid 884009:tid 884034] [remote 147.50.252.213:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4TWRKaHUf6J8d3elJ4KAAArxc"], referer: https://supportinghands22.org/wp-login.php
[Mon Jul 20 06:23:54.030120 2026] [security2:error] [pid 915741:tid 915937] [client 57.141.18.89:41516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVq-615n1P-attmzEDAAB0RE"]
[Mon Jul 20 06:23:54.309204 2026] [security2:error] [pid 915741:tid 915996] [client 171.60.139.123:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TWq-615n1P-attmzE4wAAAgw"]
[Mon Jul 20 06:23:54.309322 2026] [security2:error] [pid 915741:tid 915996] [client 171.60.139.123:50235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TWq-615n1P-attmzE4wAAAgw"]
[Mon Jul 20 06:23:54.324170 2026] [security2:error] [pid 915741:tid 915970] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWq-615n1P-attmzE1AAAAfI"]
[Mon Jul 20 06:23:54.324326 2026] [security2:error] [pid 915741:tid 915970] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWq-615n1P-attmzE1AAAAfI"]
[Mon Jul 20 06:23:54.324358 2026] [security2:error] [pid 915741:tid 915970] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWq-615n1P-attmzE1AAAAfI"]
[Mon Jul 20 06:23:54.367791 2026] [security2:error] [pid 884009:tid 884186] [client 57.141.18.2:40598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVhKaHUf6J8d3elJ34QAAsnU"]
[Mon Jul 20 06:23:54.484048 2026] [security2:error] [pid 915741:tid 915859] [remote 81.173.115.7:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4TWq-615n1P-attmzE8QAB3nU"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:23:54.584634 2026] [security2:error] [pid 884009:tid 884187] [client 77.110.127.138:61699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWhKaHUf6J8d3elJ4OgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:54.584728 2026] [security2:error] [pid 884009:tid 884187] [client 77.110.127.138:61699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWhKaHUf6J8d3elJ4OgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:54.654662 2026] [security2:error] [pid 915741:tid 915864] [remote 152.228.213.32:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4TWq-615n1P-attmzE9QABxno"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:23:55.001213 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWxKaHUf6J8d3elJ4TAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:55.001317 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWxKaHUf6J8d3elJ4TAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:55.510244 2026] [security2:error] [pid 884009:tid 884175] [client 57.141.18.70:24868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVxKaHUf6J8d3elJ4BQAApwo"]
[Mon Jul 20 06:23:55.666218 2026] [security2:error] [pid 915741:tid 915874] [client 103.141.108.143:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TW6-615n1P-attmzFIgAAAZI"]
[Mon Jul 20 06:23:55.666336 2026] [security2:error] [pid 915741:tid 915874] [client 103.141.108.143:59264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TW6-615n1P-attmzFIgAAAZI"]
[Mon Jul 20 06:23:55.669341 2026] [security2:error] [pid 915741:tid 915979] [client 57.141.18.37:54954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWK-615n1P-attmzEbgAB-2Q"]
[Mon Jul 20 06:23:55.861896 2026] [security2:error] [pid 884009:tid 884103] [remote 100.42.189.89:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TWxKaHUf6J8d3elJ4ZQAAr1w"]
[Mon Jul 20 06:23:56.071364 2026] [security2:error] [pid 884009:tid 884045] [remote 100.42.189.89:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TXBKaHUf6J8d3elJ4aAAAwSI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:23:56.294943 2026] [security2:error] [pid 915741:tid 915975] [client 45.116.69.230:59229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFSwAAAfc"]
[Mon Jul 20 06:23:56.295047 2026] [security2:error] [pid 915741:tid 915975] [client 45.116.69.230:59229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFSwAAAfc"]
[Mon Jul 20 06:23:56.454966 2026] [security2:error] [pid 915741:tid 915956] [client 178.152.178.232:35955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFUwAAAeQ"]
[Mon Jul 20 06:23:56.455088 2026] [security2:error] [pid 915741:tid 915956] [client 178.152.178.232:35955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFUwAAAeQ"]
[Mon Jul 20 06:23:57.031628 2026] [security2:error] [pid 915741:tid 915898] [client 57.141.18.23:28370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWa-615n1P-attmzEsQABqkM"]
[Mon Jul 20 06:23:57.268254 2026] [security2:error] [pid 915741:tid 915955] [client 14.225.17.146:50478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4TW6-615n1P-attmzFLwAAAeM"], referer: http://omrobuildingcenter.com/Wp
[Mon Jul 20 06:23:57.342774 2026] [security2:error] [pid 884009:tid 884096] [remote 57.141.18.74:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4TXRKaHUf6J8d3elJ4iwAAvVU"]
[Mon Jul 20 06:23:57.437810 2026] [security2:error] [pid 884009:tid 884258] [client 14.225.17.146:50465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4TWxKaHUf6J8d3elJ4YwAAAPo"], referer: http://careysheatingandcooling.com/Wp
[Mon Jul 20 06:23:57.564855 2026] [security2:error] [pid 915741:tid 915912] [client 57.141.18.96:62746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWq-615n1P-attmzE1wABuAg"]
[Mon Jul 20 06:23:57.784856 2026] [security2:error] [pid 915741:tid 915922] [client 50.116.65.227:50364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TXa-615n1P-attmzFnAAAAcI"]
[Mon Jul 20 06:23:57.794606 2026] [security2:error] [pid 915741:tid 915876] [client 50.116.65.227:60210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TXa-615n1P-attmzFnQAAAZQ"]
[Mon Jul 20 06:23:57.828396 2026] [security2:error] [pid 915741:tid 915916] [client 50.116.65.227:60226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/09/IMG_7359-1-scaled.jpeg"] [unique_id "al4TXa-615n1P-attmzFoAAAAbw"]
[Mon Jul 20 06:23:57.940410 2026] [security2:error] [pid 884009:tid 884204] [client 57.141.18.28:44258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWhKaHUf6J8d3elJ4OQAAxHo"]
[Mon Jul 20 06:23:58.116882 2026] [security2:error] [pid 884009:tid 884191] [client 57.141.18.22:48574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWhKaHUf6J8d3elJ4QgAAtx0"]
[Mon Jul 20 06:23:58.179474 2026] [security2:error] [pid 884009:tid 884244] [client 158.173.89.95:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TXhKaHUf6J8d3elJ4mAAAAOw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:58.464502 2026] [security2:error] [pid 915741:tid 915944] [client 41.173.37.102:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TXq-615n1P-attmzFvwAAAdg"]
[Mon Jul 20 06:23:58.464609 2026] [security2:error] [pid 915741:tid 915944] [client 41.173.37.102:14555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TXq-615n1P-attmzFvwAAAdg"]
[Mon Jul 20 06:23:58.611016 2026] [security2:error] [pid 884009:tid 884150] [client 104.234.53.69:59111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TXhKaHUf6J8d3elJ4oQAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:58.678853 2026] [security2:error] [pid 915741:tid 915898] [client 14.224.227.113:55729] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4TXq-615n1P-attmzF0QAAAao"]
[Mon Jul 20 06:23:59.153399 2026] [security2:error] [pid 884009:tid 884257] [client 57.141.18.113:50636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWxKaHUf6J8d3elJ4YQAA-UY"]
[Mon Jul 20 06:23:59.451957 2026] [security2:error] [pid 915741:tid 915966] [client 14.225.17.146:56810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4TX6-615n1P-attmzF6wAAAe4"], referer: http://myspineworld.com/Wp
[Mon Jul 20 06:23:59.542488 2026] [security2:error] [pid 915741:tid 915897] [client 14.225.17.146:56762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFrwAAAak"], referer: http://colinkeyphotography.com/Wp
[Mon Jul 20 06:23:59.619791 2026] [security2:error] [pid 884009:tid 884203] [client 104.234.53.69:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TXxKaHUf6J8d3elJ4uwAAAMM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:59.831724 2026] [security2:error] [pid 915741:tid 915910] [client 57.141.18.16:28518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXK-615n1P-attmzFUQABtl0"]
[Mon Jul 20 06:23:59.861875 2026] [security2:error] [pid 915741:tid 915988] [client 14.225.17.146:54162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFuAAAAgQ"], referer: http://709fx.com/Wp
[Mon Jul 20 06:23:59.969405 2026] [security2:error] [pid 884009:tid 884172] [client 77.110.127.138:61711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TXxKaHUf6J8d3elJ4yAAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:59.969508 2026] [security2:error] [pid 884009:tid 884172] [client 77.110.127.138:61711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TXxKaHUf6J8d3elJ4yAAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.229710 2026] [autoindex:error] [pid 915741:tid 915965] [client 185.132.186.76:45851] AH01276: Cannot serve directory /var/www/html/.well-known/acme-challenge/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:00.327668 2026] [security2:error] [pid 915741:tid 915905] [client 57.141.18.110:25928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXK-615n1P-attmzFaAABsXM"]
[Mon Jul 20 06:24:00.384478 2026] [security2:error] [pid 884009:tid 884149] [client 14.225.17.146:54226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ40QAAAI4"], referer: http://lelandumc.org/Wp
[Mon Jul 20 06:24:00.449666 2026] [security2:error] [pid 884009:tid 884197] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ4ywAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.555395 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.48:20282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXa-615n1P-attmzFgwAB-iQ"]
[Mon Jul 20 06:24:00.635372 2026] [security2:error] [pid 884009:tid 884210] [client 14.225.17.146:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ40wAAAMo"], referer: https://myspineworld.com/Wp
[Mon Jul 20 06:24:00.851669 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TYK-615n1P-attmzGQwAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.851805 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TYK-615n1P-attmzGQwAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.969133 2026] [security2:error] [pid 915741:tid 915833] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TYK-615n1P-attmzGRwACBFs"]
[Mon Jul 20 06:24:00.969715 2026] [security2:error] [pid 915741:tid 915988] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TYK-615n1P-attmzGRwACBFs"]
[Mon Jul 20 06:24:00.976928 2026] [security2:error] [pid 884009:tid 884146] [client 186.14.157.105:33354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ44AAAAIs"]
[Mon Jul 20 06:24:01.302499 2026] [security2:error] [pid 915741:tid 915941] [client 57.141.18.116:24492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFrAAB1XI"]
[Mon Jul 20 06:24:01.320998 2026] [core:error] [pid 915741:tid 915918] [client 103.153.183.69:8928] AH10244: invalid URI path (/%2e./%2e./.env?_=y4j0cls5&v=7oqmy), referer: https://t.co/tryd7mbc7q
[Mon Jul 20 06:24:01.579909 2026] [security2:error] [pid 915741:tid 915768] [remote 193.70.112.205:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4TYa-615n1P-attmzGagABuxo"]
[Mon Jul 20 06:24:01.673698 2026] [security2:error] [pid 884009:tid 884260] [client 50.116.65.227:54548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TYRKaHUf6J8d3elJ49wAAAPw"]
[Mon Jul 20 06:24:01.684406 2026] [security2:error] [pid 884009:tid 884142] [client 50.116.65.227:54550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TYRKaHUf6J8d3elJ4-AAAAIc"]
[Mon Jul 20 06:24:01.733433 2026] [security2:error] [pid 884009:tid 884177] [client 57.141.18.80:20572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXhKaHUf6J8d3elJ4ngAAqUw"]
[Mon Jul 20 06:24:01.733565 2026] [security2:error] [pid 915741:tid 915931] [client 57.141.18.24:32276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFwAAByzM"]
[Mon Jul 20 06:24:01.799810 2026] [security2:error] [pid 884009:tid 884173] [client 57.141.18.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TYRKaHUf6J8d3elJ49QAAAKU"]
[Mon Jul 20 06:24:01.822830 2026] [security2:error] [pid 915741:tid 915804] [remote 193.70.112.205:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4TYa-615n1P-attmzGcAABmD4"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:24:02.417802 2026] [security2:error] [pid 915741:tid 915935] [client 57.141.18.60:25710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TX6-615n1P-attmzF7QABz2g"]
[Mon Jul 20 06:24:02.615280 2026] [security2:error] [pid 915741:tid 915950] [client 14.225.17.146:54321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4TYa-615n1P-attmzGTQAAAd4"], referer: http://amalia-capital.com/Wp
[Mon Jul 20 06:24:02.855715 2026] [security2:error] [pid 884009:tid 884089] [remote 72.167.132.114:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TYhKaHUf6J8d3elJ5IQAA1E4"]
[Mon Jul 20 06:24:03.065154 2026] [security2:error] [pid 884009:tid 884092] [remote 72.167.132.114:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TYxKaHUf6J8d3elJ5JwAAvlE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:03.149007 2026] [security2:error] [pid 915741:tid 915986] [client 104.234.53.69:59749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TY6-615n1P-attmzGqQAAAgI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:03.493322 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGwAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.493401 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGwAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.646574 2026] [security2:error] [pid 884009:tid 884194] [client 77.110.127.138:61761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/charity/"] [unique_id "al4TYxKaHUf6J8d3elJ5NAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.766348 2026] [security2:error] [pid 915741:tid 915889] [client 57.141.18.124:60992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYK-615n1P-attmzGNgABoT8"]
[Mon Jul 20 06:24:03.806827 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGzQAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.806936 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGzQAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.813373 2026] [security2:error] [pid 915741:tid 915964] [client 114.119.140.113:60039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nextbit.mx"] [uri "/robots.txt"] [unique_id "al4TY6-615n1P-attmzGzgAAAew"], referer: https://www.nextbit.mx/robots.txt
[Mon Jul 20 06:24:03.896341 2026] [autoindex:error] [pid 915741:tid 915936] [client 199.45.155.104:48698] AH01276: Cannot serve directory /home4/gpmvvomy/funnels.allandbeckson.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:04.075279 2026] [security2:error] [pid 915741:tid 915898] [client 171.61.165.146:18147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TZK-615n1P-attmzG5AAAAao"]
[Mon Jul 20 06:24:04.075405 2026] [security2:error] [pid 915741:tid 915898] [client 171.61.165.146:18147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TZK-615n1P-attmzG5AAAAao"]
[Mon Jul 20 06:24:04.157154 2026] [security2:error] [pid 915741:tid 915990] [client 104.234.53.69:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TZK-615n1P-attmzG5gAAAgY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:04.441328 2026] [security2:error] [pid 915741:tid 915937] [client 57.141.18.7:50840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYa-615n1P-attmzGWQAB0WA"]
[Mon Jul 20 06:24:04.742417 2026] [security2:error] [pid 884009:tid 884192] [client 57.141.18.69:49796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYRKaHUf6J8d3elJ47wAAuGw"]
[Mon Jul 20 06:24:05.107351 2026] [security2:error] [pid 915741:tid 915927] [client 171.60.139.123:50879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHGwAAAcc"]
[Mon Jul 20 06:24:05.107503 2026] [security2:error] [pid 915741:tid 915927] [client 171.60.139.123:50879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHGwAAAcc"]
[Mon Jul 20 06:24:05.122976 2026] [security2:error] [pid 915741:tid 915853] [remote 95.217.78.234:48816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4TZa-615n1P-attmzHHAABu28"]
[Mon Jul 20 06:24:05.282578 2026] [security2:error] [pid 884009:tid 884161] [client 50.116.65.227:32758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4TZRKaHUf6J8d3elJ5WwAAAJo"]
[Mon Jul 20 06:24:05.292984 2026] [security2:error] [pid 884009:tid 884251] [client 50.116.65.227:54610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4TZRKaHUf6J8d3elJ5XAAAAMg"]
[Mon Jul 20 06:24:05.429632 2026] [security2:error] [pid 915741:tid 915843] [remote 113.160.142.119:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4TZa-615n1P-attmzHLQAB92U"]
[Mon Jul 20 06:24:05.760937 2026] [security2:error] [pid 915741:tid 915752] [remote 95.217.78.234:48816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4TZa-615n1P-attmzHPAACCQo"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:24:05.769979 2026] [security2:error] [pid 884009:tid 884074] [remote 162.19.86.63:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZRKaHUf6J8d3elJ5awAArj8"]
[Mon Jul 20 06:24:05.770155 2026] [security2:error] [pid 884009:tid 884182] [client 162.19.86.63:37816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZRKaHUf6J8d3elJ5awAArj8"]
[Mon Jul 20 06:24:05.823797 2026] [security2:error] [pid 915741:tid 915994] [client 50.116.65.227:32766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TZa-615n1P-attmzHQgAAAgo"]
[Mon Jul 20 06:24:05.833942 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.59:45862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYq-615n1P-attmzGkAAB7VU"]
[Mon Jul 20 06:24:05.834687 2026] [security2:error] [pid 915741:tid 915990] [client 50.116.65.227:54634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TZa-615n1P-attmzHQwAAAbM"]
[Mon Jul 20 06:24:05.900599 2026] [security2:error] [pid 915741:tid 915897] [client 57.141.18.45:53300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYq-615n1P-attmzGlQABqR8"]
[Mon Jul 20 06:24:05.902482 2026] [security2:error] [pid 884009:tid 884211] [client 57.141.18.108:25608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYhKaHUf6J8d3elJ5FwAAyxA"]
[Mon Jul 20 06:24:05.966896 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:44431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHTAAAAeI"]
[Mon Jul 20 06:24:05.967048 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:44431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHTAAAAeI"]
[Mon Jul 20 06:24:06.034697 2026] [security2:error] [pid 915741:tid 915794] [remote 113.160.142.119:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4TZq-615n1P-attmzHUwABsTQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:24:06.300700 2026] [security2:error] [pid 915741:tid 915892] [client 103.141.108.143:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TZq-615n1P-attmzHYwAAAaQ"]
[Mon Jul 20 06:24:06.300890 2026] [security2:error] [pid 915741:tid 915892] [client 103.141.108.143:59741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TZq-615n1P-attmzHYwAAAaQ"]
[Mon Jul 20 06:24:06.767642 2026] [security2:error] [pid 884009:tid 884165] [client 178.152.178.232:36725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hAAAAJ4"]
[Mon Jul 20 06:24:06.767791 2026] [security2:error] [pid 884009:tid 884165] [client 178.152.178.232:36725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hAAAAJ4"]
[Mon Jul 20 06:24:06.832807 2026] [security2:error] [pid 884009:tid 884174] [client 77.110.127.138:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:06.832940 2026] [security2:error] [pid 884009:tid 884174] [client 77.110.127.138:61797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:06.985015 2026] [security2:error] [pid 915741:tid 915988] [client 77.110.127.138:61798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/charity/"] [unique_id "al4TZq-615n1P-attmzHfQAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:07.044286 2026] [security2:error] [pid 915741:tid 915976] [client 57.141.18.105:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TY6-615n1P-attmzG3AAB-DY"]
[Mon Jul 20 06:24:07.131851 2026] [security2:error] [pid 915741:tid 915967] [client 57.141.18.13:33466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TY6-615n1P-attmzG4gAB730"]
[Mon Jul 20 06:24:07.136432 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZ6-615n1P-attmzHiAAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:07.136545 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZ6-615n1P-attmzHiAAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:07.286284 2026] [security2:error] [pid 915741:tid 915840] [remote 47.86.33.52:32160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TZ6-615n1P-attmzHkgAB2WI"]
[Mon Jul 20 06:24:07.701543 2026] [security2:error] [pid 884009:tid 884202] [client 68.235.52.68:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TZxKaHUf6J8d3elJ5mgAAAMI"]
[Mon Jul 20 06:24:07.701685 2026] [security2:error] [pid 884009:tid 884202] [client 68.235.52.68:43800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TZxKaHUf6J8d3elJ5mgAAAMI"]
[Mon Jul 20 06:24:07.739432 2026] [security2:error] [pid 915741:tid 915871] [client 104.234.53.93:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TZ6-615n1P-attmzHpQAAAY8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:07.858279 2026] [security2:error] [pid 915741:tid 915952] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4TZ6-615n1P-attmzHpwAAAeA"]
[Mon Jul 20 06:24:07.859254 2026] [security2:error] [pid 915741:tid 915757] [remote 100.42.189.89:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHrAABoA8"]
[Mon Jul 20 06:24:07.859438 2026] [security2:error] [pid 915741:tid 915888] [client 100.42.189.89:45596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHrAABoA8"]
[Mon Jul 20 06:24:07.954137 2026] [security2:error] [pid 915741:tid 915928] [client 45.116.69.230:59770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHswAAAcg"]
[Mon Jul 20 06:24:07.954260 2026] [security2:error] [pid 915741:tid 915928] [client 45.116.69.230:59770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHswAAAcg"]
[Mon Jul 20 06:24:08.316149 2026] [security2:error] [pid 915741:tid 915987] [client 190.114.42.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4TaK-615n1P-attmzHuwAAAgM"]
[Mon Jul 20 06:24:08.544625 2026] [security2:error] [pid 915741:tid 915998] [client 163.172.166.82:50320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4TaK-615n1P-attmzHyQAAAg4"]
[Mon Jul 20 06:24:08.659735 2026] [security2:error] [pid 915741:tid 915992] [client 57.141.18.20:57998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZa-615n1P-attmzHOQACCEc"]
[Mon Jul 20 06:24:08.734990 2026] [security2:error] [pid 915741:tid 915995] [client 47.128.47.111:43426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/robots.txt"] [unique_id "al4TaK-615n1P-attmzH2wAAAgs"]
[Mon Jul 20 06:24:08.996440 2026] [security2:error] [pid 884009:tid 884236] [client 57.141.18.81:38444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZhKaHUf6J8d3elJ5dQAA5Dk"]
[Mon Jul 20 06:24:09.024276 2026] [autoindex:error] [pid 915741:tid 915954] [client 104.168.28.15:40074] AH01276: Cannot serve directory /home2/hsdrromy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:09.032926 2026] [security2:error] [pid 884009:tid 884164] [client 41.173.37.102:14984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TaRKaHUf6J8d3elJ5vgAAAJ0"]
[Mon Jul 20 06:24:09.033080 2026] [security2:error] [pid 884009:tid 884164] [client 41.173.37.102:14984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TaRKaHUf6J8d3elJ5vgAAAJ0"]
[Mon Jul 20 06:24:09.093981 2026] [security2:error] [pid 884009:tid 884219] [client 114.119.134.106:64127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musichaven.info"] [uri "/category/research/"] [unique_id "al4TaRKaHUf6J8d3elJ5wAAAANM"], referer: https://www.musichaven.info/how-music-therapy-helps-women-suffering-from-domestic-violence/
[Mon Jul 20 06:24:09.094591 2026] [security2:error] [pid 915741:tid 915754] [remote 103.255.134.61:55604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4Taa-615n1P-attmzH6AABvQw"]
[Mon Jul 20 06:24:09.252083 2026] [security2:error] [pid 915741:tid 915943] [client 57.141.18.48:44292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZq-615n1P-attmzHZgAB13s"]
[Mon Jul 20 06:24:09.332401 2026] [security2:error] [pid 915741:tid 915938] [client 103.175.18.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Taa-615n1P-attmzH6QAB0kM"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91iron-knight-studio-escala-1-6-kamado-nezuko/
[Mon Jul 20 06:24:09.915953 2026] [security2:error] [pid 915741:tid 915834] [remote 47.86.33.52:32160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Taa-615n1P-attmzIEwABrlw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:10.363470 2026] [security2:error] [pid 884009:tid 884153] [client 57.141.18.116:30192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZxKaHUf6J8d3elJ5kgAAkhE"]
[Mon Jul 20 06:24:10.704502 2026] [security2:error] [pid 915741:tid 915927] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.epu.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4TZa-615n1P-attmzHTwAAAcc"]
[Mon Jul 20 06:24:10.734702 2026] [security2:error] [pid 884009:tid 884211] [client 77.110.127.138:61840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TahKaHUf6J8d3elJ57wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:10.734805 2026] [security2:error] [pid 884009:tid 884211] [client 77.110.127.138:61840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TahKaHUf6J8d3elJ57wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:10.736414 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.17:36076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZ6-615n1P-attmzHsgAB-jM"]
[Mon Jul 20 06:24:10.793673 2026] [security2:error] [pid 915741:tid 915910] [client 98.159.234.160:25997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Taq-615n1P-attmzIRgAAAbY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:10.807626 2026] [security2:error] [pid 915741:tid 915975] [client 57.141.18.19:34988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZ6-615n1P-attmzHtAAB9zI"]
[Mon Jul 20 06:24:10.896032 2026] [security2:error] [pid 915741:tid 915971] [client 77.110.127.138:61842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Taq-615n1P-attmzISAAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:10.896143 2026] [security2:error] [pid 915741:tid 915971] [client 77.110.127.138:61842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Taq-615n1P-attmzISAAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:11.048527 2026] [security2:error] [pid 915741:tid 915912] [client 77.110.127.138:61843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/charity/"] [unique_id "al4Ta6-615n1P-attmzITAAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:11.336823 2026] [security2:error] [pid 915741:tid 915872] [client 66.249.89.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Ta6-615n1P-attmzIUgABkE8"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91kawaii-studio-escala-1-6-fern-2/
[Mon Jul 20 06:24:11.582302 2026] [security2:error] [pid 884009:tid 884134] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TaxKaHUf6J8d3elJ5_wAA8ns"]
[Mon Jul 20 06:24:11.582458 2026] [security2:error] [pid 884009:tid 884250] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TaxKaHUf6J8d3elJ5_wAA8ns"]
[Mon Jul 20 06:24:11.862474 2026] [security2:error] [pid 915741:tid 915949] [client 57.141.18.26:47406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taa-615n1P-attmzH4wAB3UA"]
[Mon Jul 20 06:24:11.914564 2026] [security2:error] [pid 915741:tid 915876] [client 104.234.53.71:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Ta6-615n1P-attmzIiAAAAZQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:11.917158 2026] [security2:error] [pid 884009:tid 884087] [remote 152.228.213.32:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TaxKaHUf6J8d3elJ6FQAApUw"]
[Mon Jul 20 06:24:12.115559 2026] [security2:error] [pid 884009:tid 884031] [remote 152.228.213.32:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TbBKaHUf6J8d3elJ6HgAArxQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:12.262608 2026] [security2:error] [pid 915741:tid 915913] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.factsandminds.com"] [uri "/index.php"] [unique_id "al4Taq-615n1P-attmzIMAAAAbk"]
[Mon Jul 20 06:24:12.313539 2026] [security2:error] [pid 884009:tid 884181] [client 50.116.65.227:24306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TbBKaHUf6J8d3elJ6JQAAAK0"]
[Mon Jul 20 06:24:12.323799 2026] [security2:error] [pid 915741:tid 915976] [client 50.116.65.227:24312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TbK-615n1P-attmzImQAAAfg"]
[Mon Jul 20 06:24:12.463239 2026] [security2:error] [pid 915741:tid 915857] [remote 20.153.140.50:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzIowAB4HM"]
[Mon Jul 20 06:24:12.669898 2026] [security2:error] [pid 915741:tid 915931] [client 57.141.18.54:21132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taa-615n1P-attmzIEAAByz8"]
[Mon Jul 20 06:24:12.748116 2026] [security2:error] [pid 915741:tid 915744] [remote 100.42.189.89:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzItwAB5QI"]
[Mon Jul 20 06:24:12.871870 2026] [security2:error] [pid 915741:tid 915840] [remote 20.153.140.50:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzIwwABp2I"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:12.960678 2026] [security2:error] [pid 915741:tid 915803] [remote 100.42.189.89:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzIzAACAz0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:13.109595 2026] [security2:error] [pid 915741:tid 915920] [client 57.141.18.123:30486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taq-615n1P-attmzILAABwBs"]
[Mon Jul 20 06:24:13.215435 2026] [security2:error] [pid 915741:tid 915915] [client 50.116.65.227:41990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Tba-615n1P-attmzI3QAAAbs"]
[Mon Jul 20 06:24:13.226445 2026] [security2:error] [pid 915741:tid 915952] [client 50.116.65.227:24348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Tba-615n1P-attmzI3gAAAgY"]
[Mon Jul 20 06:24:13.360907 2026] [security2:error] [pid 915741:tid 915908] [client 34.74.185.202:49190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tba-615n1P-attmzI6AAAAbQ"]
[Mon Jul 20 06:24:13.539624 2026] [security2:error] [pid 915741:tid 915912] [client 192.236.168.43:52562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "webgardensbypaula.com"] [uri "/"] [unique_id "al4Tba-615n1P-attmzI8QAAAbg"]
[Mon Jul 20 06:24:13.614869 2026] [security2:error] [pid 884009:tid 884238] [client 171.61.165.146:9391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TbRKaHUf6J8d3elJ6SgAAAOY"]
[Mon Jul 20 06:24:13.614999 2026] [security2:error] [pid 884009:tid 884238] [client 171.61.165.146:9391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TbRKaHUf6J8d3elJ6SgAAAOY"]
[Mon Jul 20 06:24:13.686265 2026] [security2:error] [pid 915741:tid 915892] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "undefeatedthe.com"] [uri "/.well-known/about.php"] [unique_id "al4Tba-615n1P-attmzI-AAAAaQ"]
[Mon Jul 20 06:24:13.686334 2026] [security2:error] [pid 915741:tid 915892] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "undefeatedthe.com"] [uri "/.well-known/about.php"] [unique_id "al4Tba-615n1P-attmzI-AAAAaQ"]
[Mon Jul 20 06:24:13.687241 2026] [security2:error] [pid 915741:tid 915959] [client 57.141.18.60:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taq-615n1P-attmzIQgAB52c"]
[Mon Jul 20 06:24:13.864378 2026] [security2:error] [pid 915741:tid 915960] [client 34.74.185.202:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tba-615n1P-attmzJBQAAAeg"]
[Mon Jul 20 06:24:14.250230 2026] [security2:error] [pid 915741:tid 915918] [client 34.74.185.202:50992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tbq-615n1P-attmzJFAAAAb4"]
[Mon Jul 20 06:24:14.307209 2026] [security2:error] [pid 915741:tid 915917] [client 104.168.114.154:38918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.webgardensbypaula.com"] [uri "/"] [unique_id "al4Tbq-615n1P-attmzJFgAAAb0"]
[Mon Jul 20 06:24:14.699804 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tbq-615n1P-attmzJKQAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:14.699927 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tbq-615n1P-attmzJKQAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:14.793204 2026] [security2:error] [pid 915741:tid 915891] [client 34.74.185.202:57763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tbq-615n1P-attmzJKwAAAaM"]
[Mon Jul 20 06:24:15.000328 2026] [security2:error] [pid 884009:tid 884209] [client 77.110.127.138:61872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbhKaHUf6J8d3elJ6dAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.000427 2026] [security2:error] [pid 884009:tid 884209] [client 77.110.127.138:61872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbhKaHUf6J8d3elJ6dAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.105455 2026] [security2:error] [pid 915741:tid 915900] [client 34.74.185.202:62745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tb6-615n1P-attmzJOwAAAaw"]
[Mon Jul 20 06:24:15.215456 2026] [security2:error] [pid 915741:tid 915981] [client 77.110.127.138:61873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJQQAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.216103 2026] [security2:error] [pid 915741:tid 915981] [client 77.110.127.138:61873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJQQAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.249044 2026] [security2:error] [pid 915741:tid 915972] [client 104.168.59.36:44872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-be93471d.zanjan-fromer.com"] [uri "/"] [unique_id "al4Tb6-615n1P-attmzJQgAAAfQ"]
[Mon Jul 20 06:24:15.445301 2026] [security2:error] [pid 884009:tid 884257] [client 77.110.127.138:61874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6fQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.445403 2026] [security2:error] [pid 884009:tid 884257] [client 77.110.127.138:61874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6fQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.493146 2026] [security2:error] [pid 915741:tid 915986] [client 77.110.127.138:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJTAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.493246 2026] [security2:error] [pid 915741:tid 915986] [client 77.110.127.138:61875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJTAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.603711 2026] [security2:error] [pid 884009:tid 884144] [client 77.110.127.138:61876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6hAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.603831 2026] [security2:error] [pid 884009:tid 884144] [client 77.110.127.138:61876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6hAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.651290 2026] [security2:error] [pid 915741:tid 915929] [client 34.74.185.202:59932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tb6-615n1P-attmzJVQAAAck"]
[Mon Jul 20 06:24:15.767979 2026] [security2:error] [pid 915741:tid 915893] [client 171.60.139.123:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tb6-615n1P-attmzJWgAAAaU"]
[Mon Jul 20 06:24:15.768095 2026] [security2:error] [pid 915741:tid 915893] [client 171.60.139.123:51631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tb6-615n1P-attmzJWgAAAaU"]
[Mon Jul 20 06:24:15.781168 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJXAAAAaY"]
[Mon Jul 20 06:24:15.781309 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJXAAAAaY"]
[Mon Jul 20 06:24:15.891381 2026] [security2:error] [pid 915741:tid 915788] [remote 154.66.198.148:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tb6-615n1P-attmzJZwAB7y4"]
[Mon Jul 20 06:24:15.939812 2026] [security2:error] [pid 915741:tid 915982] [client 77.110.127.138:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJbAAAAf4"]
[Mon Jul 20 06:24:15.939948 2026] [security2:error] [pid 915741:tid 915982] [client 77.110.127.138:61881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJbAAAAf4"]
[Mon Jul 20 06:24:15.968746 2026] [security2:error] [pid 915741:tid 915874] [client 34.74.185.202:65447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tb6-615n1P-attmzJbwAAAZI"]
[Mon Jul 20 06:24:16.275087 2026] [security2:error] [pid 915741:tid 915889] [client 104.234.53.51:22655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TcK-615n1P-attmzJfwAAAaE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:16.297466 2026] [security2:error] [pid 915741:tid 915917] [client 34.74.185.202:55767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TcK-615n1P-attmzJgQAAAb0"]
[Mon Jul 20 06:24:16.416625 2026] [security2:error] [pid 915741:tid 915922] [client 57.141.18.96:61190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tba-615n1P-attmzI6QABwho"]
[Mon Jul 20 06:24:16.447227 2026] [security2:error] [pid 915741:tid 915779] [remote 154.66.198.148:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TcK-615n1P-attmzJiQABsCU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:16.538288 2026] [security2:error] [pid 884009:tid 884147] [client 84.233.195.150:64726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4TcBKaHUf6J8d3elJ6nQAAAIw"]
[Mon Jul 20 06:24:16.665125 2026] [security2:error] [pid 915741:tid 915963] [client 34.74.185.202:55375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TcK-615n1P-attmzJlAAAAes"]
[Mon Jul 20 06:24:16.976570 2026] [security2:error] [pid 884009:tid 884262] [client 57.141.18.8:54974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TbRKaHUf6J8d3elJ6XAAA_jI"]
[Mon Jul 20 06:24:17.000879 2026] [security2:error] [pid 915741:tid 915885] [client 84.233.195.157:53442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4Tca-615n1P-attmzJpAAAAZ0"]
[Mon Jul 20 06:24:17.037538 2026] [security2:error] [pid 884009:tid 884231] [client 57.141.18.125:20432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TbhKaHUf6J8d3elJ6YAAA33U"]
[Mon Jul 20 06:24:17.081013 2026] [security2:error] [pid 915741:tid 915968] [client 34.74.185.202:52867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tca-615n1P-attmzJqwAAAfA"]
[Mon Jul 20 06:24:17.310961 2026] [security2:error] [pid 915741:tid 915920] [client 103.141.108.143:60203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tca-615n1P-attmzJtAAAAcA"]
[Mon Jul 20 06:24:17.311045 2026] [security2:error] [pid 915741:tid 915920] [client 103.141.108.143:60203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tca-615n1P-attmzJtAAAAcA"]
[Mon Jul 20 06:24:17.475665 2026] [security2:error] [pid 915741:tid 915940] [client 84.233.195.153:54978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4Tca-615n1P-attmzJtwAAAdQ"]
[Mon Jul 20 06:24:17.601947 2026] [security2:error] [pid 915741:tid 915904] [client 34.74.185.202:58750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tca-615n1P-attmzJxQAAAbA"]
[Mon Jul 20 06:24:17.672433 2026] [security2:error] [pid 915741:tid 915996] [client 57.141.18.114:51182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tbq-615n1P-attmzJJgACDGg"]
[Mon Jul 20 06:24:17.733092 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:60300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TcRKaHUf6J8d3elJ6ugAAAPk"]
[Mon Jul 20 06:24:17.733251 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:60300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TcRKaHUf6J8d3elJ6ugAAAPk"]
[Mon Jul 20 06:24:17.741651 2026] [security2:error] [pid 915741:tid 915981] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJsgAB_U8"], referer: http://ardhalwafaa.com/WP
[Mon Jul 20 06:24:17.805816 2026] [security2:error] [pid 915741:tid 915922] [client 14.225.17.146:53755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJygAAAcI"], referer: http://thefriendlyspreadsheet.com/WP
[Mon Jul 20 06:24:17.819304 2026] [security2:error] [pid 884009:tid 884141] [client 114.119.137.95:49477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2023/02/postdeadline-dac-comments-february-10-2023.pdf"] [unique_id "al4TcRKaHUf6J8d3elJ6vAAAAIY"], referer: https://mtredistricting.gov/document-library/
[Mon Jul 20 06:24:17.956085 2026] [security2:error] [pid 915741:tid 915971] [client 84.233.195.151:52599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4Tca-615n1P-attmzJ2AAAAfM"]
[Mon Jul 20 06:24:17.988634 2026] [security2:error] [pid 915741:tid 915967] [client 14.225.17.146:59625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJ1QAAAe8"], referer: http://nikkidesigns.net/WP
[Mon Jul 20 06:24:18.003801 2026] [security2:error] [pid 915741:tid 915966] [client 34.74.185.202:51018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tcq-615n1P-attmzJ2wAAAe4"]
[Mon Jul 20 06:24:18.132795 2026] [security2:error] [pid 915741:tid 915902] [client 14.225.17.146:59675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJ2QAAAa4"], referer: http://ksands.co.uk/WP
[Mon Jul 20 06:24:18.393444 2026] [security2:error] [pid 915741:tid 915965] [client 104.234.53.66:37557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Tcq-615n1P-attmzJ7QAAAe0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:18.539989 2026] [security2:error] [pid 884009:tid 884165] [client 57.141.18.31:30612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TbxKaHUf6J8d3elJ6ggAAnjQ"]
[Mon Jul 20 06:24:18.614778 2026] [security2:error] [pid 915741:tid 915988] [client 104.168.59.36:45840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.website-be93471d.zanjan-fromer.com"] [uri "/"] [unique_id "al4Tcq-615n1P-attmzJ_gAAAgQ"]
[Mon Jul 20 06:24:18.634615 2026] [security2:error] [pid 915741:tid 915970] [client 57.141.18.71:50482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tb6-615n1P-attmzJUQAB8jc"]
[Mon Jul 20 06:24:18.705142 2026] [security2:error] [pid 915741:tid 915943] [client 37.139.53.21:59547] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.21" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tcq-615n1P-attmzKAQAAAdc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:18.705246 2026] [security2:error] [pid 915741:tid 915943] [client 37.139.53.21:59547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tcq-615n1P-attmzKAQAAAdc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:18.731797 2026] [security2:error] [pid 915741:tid 915940] [client 14.225.17.146:59979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4Tcq-615n1P-attmzJ-wAAAdQ"], referer: http://alexsandbergmusic.com/WP
[Mon Jul 20 06:24:19.194244 2026] [security2:error] [pid 915741:tid 915908] [client 18.140.64.130:17938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Tc6-615n1P-attmzKGAAAAbQ"]
[Mon Jul 20 06:24:19.715376 2026] [security2:error] [pid 915741:tid 915965] [client 41.173.37.102:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKLAAAAe0"]
[Mon Jul 20 06:24:19.715501 2026] [security2:error] [pid 915741:tid 915965] [client 41.173.37.102:1448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKLAAAAe0"]
[Mon Jul 20 06:24:19.828198 2026] [security2:error] [pid 915741:tid 915987] [client 149.20.243.159:58675] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKLQAAAgM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:19.857693 2026] [security2:error] [pid 915741:tid 915872] [client 112.208.70.94:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKMQAAAZA"]
[Mon Jul 20 06:24:19.857852 2026] [security2:error] [pid 915741:tid 915872] [client 112.208.70.94:44838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKMQAAAZA"]
[Mon Jul 20 06:24:19.882902 2026] [security2:error] [pid 915741:tid 915935] [client 77.110.127.138:61892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKMwAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:19.883014 2026] [security2:error] [pid 915741:tid 915935] [client 77.110.127.138:61892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKMwAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.126397 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.3:57080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJpQABqCg"]
[Mon Jul 20 06:24:20.165812 2026] [security2:error] [pid 884009:tid 884227] [client 18.140.64.130:17950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TdBKaHUf6J8d3elJ6_QAAANs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:24:20.274772 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TdK-615n1P-attmzKOwAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.491922 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TdK-615n1P-attmzKWwAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.492056 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TdK-615n1P-attmzKWwAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.829242 2026] [security2:error] [pid 915741:tid 915804] [remote 51.158.61.221:35626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4TdK-615n1P-attmzKcwAB_j4"]
[Mon Jul 20 06:24:20.829530 2026] [security2:error] [pid 915741:tid 915982] [client 51.158.61.221:35626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4TdK-615n1P-attmzKcwAB_j4"]
[Mon Jul 20 06:24:20.904785 2026] [security2:error] [pid 884009:tid 884118] [remote 57.141.18.32:30642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TcRKaHUf6J8d3elJ6twAA42s"]
[Mon Jul 20 06:24:20.975664 2026] [security2:error] [pid 915741:tid 915973] [client 50.116.65.227:16302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TdK-615n1P-attmzKeQAAAfU"]
[Mon Jul 20 06:24:20.987012 2026] [security2:error] [pid 915741:tid 915895] [client 50.116.65.227:59814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TdK-615n1P-attmzKegAAAac"]
[Mon Jul 20 06:24:21.014310 2026] [security2:error] [pid 915741:tid 915956] [client 114.119.132.58:21313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jennylouraya.com"] [uri "/gepettos-and-whole-foods-flower-hill"] [unique_id "al4Tda-615n1P-attmzKewAAAeQ"], referer: https://www.jennylouraya.com/2013/page/7
[Mon Jul 20 06:24:21.151372 2026] [security2:error] [pid 915741:tid 915955] [client 57.141.18.63:22256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJ1wAB4wo"]
[Mon Jul 20 06:24:21.302979 2026] [security2:error] [pid 915741:tid 915917] [client 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzKlwAAAb0"]
[Mon Jul 20 06:24:21.635793 2026] [security2:error] [pid 915741:tid 915980] [client 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzKuAAAAfw"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:24:21.908175 2026] [security2:error] [pid 915741:tid 915881] [client 50.116.65.227:59826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Tda-615n1P-attmzKzQAAAZk"]
[Mon Jul 20 06:24:21.910037 2026] [security2:error] [pid 915741:tid 915837] [remote 152.228.213.32:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzKzAAB4V8"]
[Mon Jul 20 06:24:21.918451 2026] [security2:error] [pid 915741:tid 915945] [client 50.116.65.227:59834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Tda-615n1P-attmzKzwAAAdk"]
[Mon Jul 20 06:24:21.933442 2026] [security2:error] [pid 915741:tid 915892] [client 216.73.217.138:44922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Tda-615n1P-attmzKyQABpFw"]
[Mon Jul 20 06:24:21.993918 2026] [security2:error] [pid 915741:tid 915788] [remote 84.247.172.23:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzK0wABky4"]
[Mon Jul 20 06:24:22.064949 2026] [security2:error] [pid 915741:tid 915941] [client 57.141.18.82:54570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tcq-615n1P-attmzJ_wAB1TQ"]
[Mon Jul 20 06:24:22.137461 2026] [security2:error] [pid 915741:tid 915768] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tdq-615n1P-attmzK5AABnRo"]
[Mon Jul 20 06:24:22.137599 2026] [security2:error] [pid 915741:tid 915885] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tdq-615n1P-attmzK5AABnRo"]
[Mon Jul 20 06:24:22.150895 2026] [security2:error] [pid 915741:tid 915838] [remote 152.228.213.32:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tdq-615n1P-attmzK5QAB9mA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:24:22.174338 2026] [security2:error] [pid 915741:tid 915964] [client 74.7.227.179:52498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK3QAB7G0"], referer: https://tejasenvironmental.com/p=2588833
[Mon Jul 20 06:24:22.233280 2026] [security2:error] [pid 915741:tid 915954] [client 104.234.53.92:28857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Tdq-615n1P-attmzK4wAAAeI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:22.262077 2026] [security2:error] [pid 915741:tid 915790] [remote 84.247.172.23:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tdq-615n1P-attmzK8AAB5DA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:24:22.615998 2026] [security2:error] [pid 915741:tid 915987] [client 149.20.243.159:58675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKLQAAAgM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:22.616057 2026] [security2:error] [pid 915741:tid 915987] [client 149.20.243.159:58675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKLQAAAgM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:22.647714 2026] [security2:error] [pid 915741:tid 915950] [client 74.7.241.180:39618] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "teresaharding.com"] [uri "/cgi-sys/404.html"] [unique_id "al4Tdq-615n1P-attmzLEAAAAd4"]
[Mon Jul 20 06:24:22.674095 2026] [security2:error] [pid 915741:tid 915915] [client 104.234.53.92:28857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tdq-615n1P-attmzLFAAAAbs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:22.738855 2026] [security2:error] [pid 915741:tid 915936] [client 14.225.17.146:59810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK-QAAAdA"], referer: http://mollycahill.com/WP
[Mon Jul 20 06:24:23.186865 2026] [security2:error] [pid 915741:tid 915900] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzLMgAAAaw"]
[Mon Jul 20 06:24:23.189036 2026] [security2:error] [pid 915741:tid 915892] [client 189.175.47.15:33006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLOAAAAaQ"]
[Mon Jul 20 06:24:23.272923 2026] [security2:error] [pid 884009:tid 884081] [remote 57.141.18.110:50298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TcxKaHUf6J8d3elJ68AAAmkY"]
[Mon Jul 20 06:24:23.307400 2026] [security2:error] [pid 915741:tid 915926] [client 158.173.241.141:58503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLOgABxnA"]
[Mon Jul 20 06:24:23.400181 2026] [security2:error] [pid 915741:tid 915791] [remote 124.55.178.99:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Td6-615n1P-attmzLSwABvjE"]
[Mon Jul 20 06:24:23.612901 2026] [security2:error] [pid 915741:tid 915916] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLXgAAAbw"], referer: http://adultdaycarereno.com/WP
[Mon Jul 20 06:24:23.827349 2026] [security2:error] [pid 915741:tid 915831] [remote 124.55.178.99:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Td6-615n1P-attmzLdAABzlk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:24.088080 2026] [security2:error] [pid 915741:tid 915877] [client 57.141.18.113:49758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TdK-615n1P-attmzKUwABlQE"]
[Mon Jul 20 06:24:24.316532 2026] [core:error] [pid 915741:tid 915971] [client 14.225.17.146:52429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:24.316550 2026] [core:error] [pid 915741:tid 915971] [client 14.225.17.146:52429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:24.493087 2026] [security2:error] [pid 915741:tid 915966] [client 138.199.60.178:56834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLnAAAAe4"], referer: https://lifeisbetterlakeside.com
[Mon Jul 20 06:24:24.568290 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:51769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLrwAAAd0"], referer: https://adultdaycarereno.com/WP
[Mon Jul 20 06:24:24.570442 2026] [security2:error] [pid 915741:tid 915978] [client 171.61.165.146:18948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TeK-615n1P-attmzLtgAAAfo"]
[Mon Jul 20 06:24:24.570536 2026] [security2:error] [pid 915741:tid 915978] [client 171.61.165.146:18948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TeK-615n1P-attmzLtgAAAfo"]
[Mon Jul 20 06:24:24.631148 2026] [security2:error] [pid 915741:tid 915939] [client 57.141.18.83:35090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TdK-615n1P-attmzKdAAB0w0"]
[Mon Jul 20 06:24:24.719795 2026] [security2:error] [pid 915741:tid 915905] [client 45.157.112.60:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TeK-615n1P-attmzLvAAAAbE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:24.789814 2026] [security2:error] [pid 915741:tid 915907] [client 43.134.44.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLpwAAAbM"], referer: https://www.savilerowtravel.com/hotels/austria/the-elizabeth-arthotel-2/me-02-hotel-elisabeth-2011
[Mon Jul 20 06:24:24.849267 2026] [security2:error] [pid 915741:tid 915942] [client 114.119.166.95:60709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "new-menus.com"] [uri "/robots.txt"] [unique_id "al4TeK-615n1P-attmzLyAAAAdY"], referer: http://new-menus.com/robots.txt
[Mon Jul 20 06:24:24.994124 2026] [security2:error] [pid 915741:tid 915980] [client 50.116.65.227:16312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4TeK-615n1P-attmzL2wAAAfw"]
[Mon Jul 20 06:24:25.005627 2026] [security2:error] [pid 915741:tid 915924] [client 50.116.65.227:59848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4Tea-615n1P-attmzL3AAAAcQ"]
[Mon Jul 20 06:24:25.051460 2026] [security2:error] [pid 915741:tid 915785] [remote 100.42.189.89:45752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Tea-615n1P-attmzL3gABmys"]
[Mon Jul 20 06:24:25.091865 2026] [security2:error] [pid 915741:tid 915943] [client 77.110.127.138:61920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzL5gAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.092012 2026] [security2:error] [pid 915741:tid 915943] [client 77.110.127.138:61920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzL5gAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.256709 2026] [security2:error] [pid 915741:tid 915807] [remote 100.42.189.89:45752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Tea-615n1P-attmzL6wAB6kE"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:24:25.375320 2026] [security2:error] [pid 915741:tid 915935] [client 57.141.18.101:42670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tda-615n1P-attmzKnQABzxM"]
[Mon Jul 20 06:24:25.652397 2026] [security2:error] [pid 915741:tid 915992] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tea-615n1P-attmzL7wAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.885110 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzMHgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.885192 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzMHgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.980492 2026] [security2:error] [pid 915741:tid 915897] [client 57.141.18.46:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tda-615n1P-attmzKygABqS0"]
[Mon Jul 20 06:24:26.001911 2026] [security2:error] [pid 915741:tid 915994] [client 104.234.53.90:28653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Teq-615n1P-attmzMJAAAAgo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:26.055082 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMKgAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.055187 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:61932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMKgAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.176432 2026] [security2:error] [pid 915741:tid 915930] [client 57.141.18.42:48426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK1AABygY"]
[Mon Jul 20 06:24:26.213543 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMPwAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.213919 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMPwAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.389955 2026] [security2:error] [pid 915741:tid 915967] [client 171.60.139.123:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Teq-615n1P-attmzMSwAAAe8"]
[Mon Jul 20 06:24:26.390112 2026] [security2:error] [pid 915741:tid 915967] [client 171.60.139.123:52198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Teq-615n1P-attmzMSwAAAe8"]
[Mon Jul 20 06:24:26.398990 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMTAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.399113 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMTAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.569980 2026] [authz_core:error] [pid 915741:tid 915907] [client 66.132.195.57:41114] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:24:26.578382 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.31:37616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK_QABtQU"]
[Mon Jul 20 06:24:26.737365 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:61904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMawAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.737525 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:61904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMawAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.795732 2026] [security2:error] [pid 915741:tid 915888] [client 77.110.127.138:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMbwAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.795846 2026] [security2:error] [pid 915741:tid 915888] [client 77.110.127.138:61903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMbwAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.820448 2026] [security2:error] [pid 915741:tid 915941] [client 57.141.18.14:23998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzLDgAB1V0"]
[Mon Jul 20 06:24:26.849328 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:61905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMdAAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.849448 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:61905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMdAAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.858874 2026] [security2:error] [pid 915741:tid 915911] [client 104.234.53.68:56445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Teq-615n1P-attmzMbgAAAbc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:27.019157 2026] [security2:error] [pid 915741:tid 915891] [client 34.74.185.202:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Te6-615n1P-attmzMggAAAaM"]
[Mon Jul 20 06:24:27.316223 2026] [autoindex:error] [pid 915741:tid 915815] [remote 2a06:98c0:3600::103:0] AH01276: Cannot serve directory /home2/rzsjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:24:27.719838 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Te6-615n1P-attmzMxwAAAZ4"]
[Mon Jul 20 06:24:27.719964 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:60674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Te6-615n1P-attmzMxwAAAZ4"]
[Mon Jul 20 06:24:27.789461 2026] [proxy:error] [pid 915741:tid 915895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:27.789539 2026] [proxy_http:error] [pid 915741:tid 915895] [client 34.73.38.214:60675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:27.790023 2026] [proxy:error] [pid 915741:tid 915895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:27.790055 2026] [proxy_http:error] [pid 915741:tid 915895] [client 34.73.38.214:60675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:27.841853 2026] [core:error] [pid 915741:tid 915942] [client 66.132.195.57:41132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:27.841880 2026] [core:error] [pid 915741:tid 915942] [client 66.132.195.57:41132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:27.925093 2026] [security2:error] [pid 915741:tid 915959] [client 34.74.185.202:50117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Te6-615n1P-attmzM1wAAAec"]
[Mon Jul 20 06:24:27.926859 2026] [security2:error] [pid 915741:tid 915898] [client 104.234.53.68:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Te6-615n1P-attmzM1QAAAao"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:27.954782 2026] [security2:error] [pid 915741:tid 915921] [client 57.141.18.72:47138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLdwABwT0"]
[Mon Jul 20 06:24:27.984939 2026] [security2:error] [pid 915741:tid 915825] [remote 47.86.33.52:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Te6-615n1P-attmzM4wAB6FM"]
[Mon Jul 20 06:24:28.024182 2026] [security2:error] [pid 915741:tid 915887] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4Te6-615n1P-attmzMqQABnwM"], referer: http://ali-alghanim.net/WP
[Mon Jul 20 06:24:28.103883 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:60996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Teq-615n1P-attmzMRAAAAdI"], referer: http://windowtx.com/WP
[Mon Jul 20 06:24:28.163185 2026] [security2:error] [pid 915741:tid 915845] [remote 160.187.68.132:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TfK-615n1P-attmzM9gAB9Gc"]
[Mon Jul 20 06:24:28.417888 2026] [security2:error] [pid 915741:tid 915881] [client 45.116.69.230:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TfK-615n1P-attmzM_gAAAZk"]
[Mon Jul 20 06:24:28.417990 2026] [security2:error] [pid 915741:tid 915881] [client 45.116.69.230:60824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TfK-615n1P-attmzM_gAAAZk"]
[Mon Jul 20 06:24:28.639512 2026] [security2:error] [pid 915741:tid 915771] [remote 160.187.68.132:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TfK-615n1P-attmzNFAAByR0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:28.716888 2026] [security2:error] [pid 915741:tid 915994] [client 186.87.10.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzM-wAAAgo"]
[Mon Jul 20 06:24:28.736158 2026] [security2:error] [pid 915741:tid 915915] [client 57.141.18.106:35282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLrQABuz4"]
[Mon Jul 20 06:24:28.863894 2026] [security2:error] [pid 915741:tid 915940] [client 77.110.127.138:61943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TfK-615n1P-attmzNKAAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:28.863994 2026] [security2:error] [pid 915741:tid 915940] [client 77.110.127.138:61943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TfK-615n1P-attmzNKAAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:28.952401 2026] [core:error] [pid 915741:tid 915899] [client 103.153.183.69:8686] AH10244: invalid URI path (/%2e./%2e./etc/passwd?_=ap77v5fg&v=bsjfe), referer: https://twitter.com/
[Mon Jul 20 06:24:28.955467 2026] [security2:error] [pid 915741:tid 915952] [client 127.0.0.1:15840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TfK-615n1P-attmzNOAAAAeA"], referer: https://twitter.com/
[Mon Jul 20 06:24:29.045385 2026] [security2:error] [pid 915741:tid 915962] [client 104.234.53.54:58217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tfa-615n1P-attmzNQQAAAeo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:29.067142 2026] [proxy:error] [pid 915741:tid 915893] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:29.067205 2026] [proxy_http:error] [pid 915741:tid 915893] [client 34.73.38.214:52122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:29.067768 2026] [proxy:error] [pid 915741:tid 915893] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:29.067796 2026] [proxy_http:error] [pid 915741:tid 915893] [client 34.73.38.214:52122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:29.163614 2026] [security2:error] [pid 915741:tid 915875] [client 148.251.126.195:44466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzNOwAAAZM"]
[Mon Jul 20 06:24:29.180845 2026] [security2:error] [pid 915741:tid 915979] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzNNAAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:29.345508 2026] [security2:error] [pid 915741:tid 915996] [client 34.74.185.202:62566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tfa-615n1P-attmzNXQAAAgw"]
[Mon Jul 20 06:24:29.362845 2026] [security2:error] [pid 915741:tid 915995] [client 34.74.185.202:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tfa-615n1P-attmzNXwAAAgs"]
[Mon Jul 20 06:24:29.462738 2026] [security2:error] [pid 915741:tid 915945] [client 57.141.18.61:53224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tea-615n1P-attmzL6AAB2Qw"]
[Mon Jul 20 06:24:29.656575 2026] [security2:error] [pid 915741:tid 915753] [remote 47.86.33.52:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Tfa-615n1P-attmzNdgAByQs"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:24:29.802416 2026] [security2:error] [pid 915741:tid 915916] [client 77.110.127.138:61944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tfa-615n1P-attmzNfwAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:29.802557 2026] [security2:error] [pid 915741:tid 915916] [client 77.110.127.138:61944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tfa-615n1P-attmzNfwAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:29.858085 2026] [security2:error] [pid 915741:tid 915924] [client 103.153.183.69:23540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/ubuntu/.ssh/id_rsa"] [unique_id "al4Tfa-615n1P-attmzNggAAAcQ"], referer: https://www.bing.com/search?q=qyqejj
[Mon Jul 20 06:24:29.863109 2026] [security2:error] [pid 915741:tid 915955] [client 57.141.18.18:43346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tea-615n1P-attmzMEQAB4zQ"]
[Mon Jul 20 06:24:30.357683 2026] [security2:error] [pid 915741:tid 915880] [client 41.173.37.102:1887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tfq-615n1P-attmzNuAAAAZg"]
[Mon Jul 20 06:24:30.357822 2026] [security2:error] [pid 915741:tid 915880] [client 41.173.37.102:1887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tfq-615n1P-attmzNuAAAAZg"]
[Mon Jul 20 06:24:30.494998 2026] [security2:error] [pid 915741:tid 915900] [client 14.225.17.146:53706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzNIgAAAaw"]
[Mon Jul 20 06:24:30.726492 2026] [core:error] [pid 915741:tid 915911] [client 103.153.183.69:8694] AH10244: invalid URI path (/.%2e/.%2e/etc/passwd?_=legur6y1&v=1lgco), referer: https://www.facebook.com/
[Mon Jul 20 06:24:30.729737 2026] [security2:error] [pid 915741:tid 915973] [client 127.0.0.1:15858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4Tfq-615n1P-attmzN4AAAAfU"], referer: https://www.facebook.com/
[Mon Jul 20 06:24:30.731826 2026] [security2:error] [pid 915741:tid 915966] [client 34.74.185.202:58226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tfq-615n1P-attmzN4gAAAe4"]
[Mon Jul 20 06:24:30.734016 2026] [security2:error] [pid 915741:tid 915885] [client 34.74.185.202:58194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tfq-615n1P-attmzN5AAAAZ0"]
[Mon Jul 20 06:24:30.824717 2026] [security2:error] [pid 915741:tid 915877] [client 14.225.17.146:51818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4Tfa-615n1P-attmzNbQAAAZU"], referer: http://lutheranphilosopher.com/WP
[Mon Jul 20 06:24:30.882192 2026] [proxy:error] [pid 915741:tid 915992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:30.882285 2026] [proxy_http:error] [pid 915741:tid 915992] [client 34.73.38.214:63840] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:30.883552 2026] [proxy:error] [pid 915741:tid 915992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:30.883605 2026] [proxy_http:error] [pid 915741:tid 915992] [client 34.73.38.214:63840] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:30.927847 2026] [security2:error] [pid 915741:tid 915941] [client 72.63.213.42:11844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4Tfq-615n1P-attmzNwQAB1R8"], referer: https://www.thewelloiledlife.com/tag/sleepessence/
[Mon Jul 20 06:24:31.031383 2026] [security2:error] [pid 915741:tid 915786] [remote 192.241.143.148:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tf6-615n1P-attmzN8QAB9Cw"]
[Mon Jul 20 06:24:31.052746 2026] [security2:error] [pid 915741:tid 915988] [client 77.110.127.138:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzN8wAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.052901 2026] [security2:error] [pid 915741:tid 915988] [client 77.110.127.138:61947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzN8wAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.058430 2026] [security2:error] [pid 915741:tid 915915] [client 148.251.126.195:44478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Tfq-615n1P-attmzN7AAAAbs"]
[Mon Jul 20 06:24:31.225684 2026] [security2:error] [pid 915741:tid 915867] [remote 192.241.143.148:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tf6-615n1P-attmzOBQABlH0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:31.336394 2026] [security2:error] [pid 915741:tid 915966] [client 77.110.127.138:61948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzODAAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.336516 2026] [security2:error] [pid 915741:tid 915966] [client 77.110.127.138:61948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzODAAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.434869 2026] [security2:error] [pid 915741:tid 915910] [client 50.116.65.227:41940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Tf6-615n1P-attmzOEgAAAbY"]
[Mon Jul 20 06:24:31.444886 2026] [security2:error] [pid 915741:tid 915974] [client 50.116.65.227:41954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Tf6-615n1P-attmzOEwAAAfY"]
[Mon Jul 20 06:24:31.628566 2026] [security2:error] [pid 915741:tid 915988] [client 34.74.185.202:56505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tf6-615n1P-attmzOJQAAAgQ"]
[Mon Jul 20 06:24:31.674939 2026] [security2:error] [pid 915741:tid 915989] [client 14.225.17.146:61371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Tf6-615n1P-attmzOFAAAAgU"], referer: http://according2plant.com/WP
[Mon Jul 20 06:24:31.737317 2026] [security2:error] [pid 915741:tid 915918] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tf6-615n1P-attmzOGgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.986500 2026] [security2:error] [pid 915741:tid 915979] [client 34.74.185.202:61855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tf6-615n1P-attmzORgAAAfs"]
[Mon Jul 20 06:24:31.994985 2026] [security2:error] [pid 915741:tid 915884] [client 57.141.18.49:44788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Te6-615n1P-attmzM0AABnCQ"]
[Mon Jul 20 06:24:32.132569 2026] [security2:error] [pid 915741:tid 915818] [remote 152.228.213.32:34760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOTQACCUw"]
[Mon Jul 20 06:24:32.218388 2026] [security2:error] [pid 915741:tid 915995] [client 34.74.185.202:50025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TgK-615n1P-attmzOXAAAAgs"]
[Mon Jul 20 06:24:32.312331 2026] [security2:error] [pid 915741:tid 915752] [remote 152.228.213.32:34760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOagABkgo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:32.519624 2026] [security2:error] [pid 915741:tid 915978] [client 148.251.126.195:44494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzObQAAAfo"]
[Mon Jul 20 06:24:32.543095 2026] [security2:error] [pid 915741:tid 915765] [remote 78.46.157.202:35780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOeQAB9hc"]
[Mon Jul 20 06:24:32.623581 2026] [security2:error] [pid 915741:tid 915866] [remote 47.86.33.52:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOgAAB2Hw"]
[Mon Jul 20 06:24:32.637430 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:32.637517 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:55028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:32.638542 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:32.638575 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:55028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:32.720604 2026] [security2:error] [pid 915741:tid 915957] [client 68.235.52.68:43162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOigAAAeU"]
[Mon Jul 20 06:24:32.720710 2026] [security2:error] [pid 915741:tid 915957] [client 68.235.52.68:43162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOigAAAeU"]
[Mon Jul 20 06:24:32.728332 2026] [security2:error] [pid 915741:tid 915886] [client 68.235.52.68:43160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOjAAAAZ4"]
[Mon Jul 20 06:24:32.728430 2026] [security2:error] [pid 915741:tid 915886] [client 68.235.52.68:43160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOjAAAAZ4"]
[Mon Jul 20 06:24:32.729226 2026] [security2:error] [pid 915741:tid 915760] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOiwACChI"]
[Mon Jul 20 06:24:32.729426 2026] [security2:error] [pid 915741:tid 915994] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOiwACChI"]
[Mon Jul 20 06:24:32.760765 2026] [security2:error] [pid 915741:tid 915829] [remote 78.46.157.202:35780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOkAABkVc"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:24:32.814934 2026] [security2:error] [pid 915741:tid 915920] [client 112.208.70.94:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOmAAAAcA"]
[Mon Jul 20 06:24:32.815158 2026] [security2:error] [pid 915741:tid 915920] [client 112.208.70.94:45228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOmAAAAcA"]
[Mon Jul 20 06:24:32.853636 2026] [security2:error] [pid 915741:tid 915750] [remote 103.255.134.61:39908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOmQAB-Qg"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:24:32.947472 2026] [security2:error] [pid 915741:tid 915927] [client 34.74.185.202:65143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TgK-615n1P-attmzOmwAAAcc"]
[Mon Jul 20 06:24:33.101045 2026] [security2:error] [pid 915741:tid 915877] [client 14.225.17.146:62900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOegAAAZU"], referer: http://drewsasburyparkbeachhouse.com/WP
[Mon Jul 20 06:24:33.131967 2026] [security2:error] [pid 915741:tid 915871] [client 57.141.18.109:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tfa-615n1P-attmzNRQABj3k"]
[Mon Jul 20 06:24:33.187927 2026] [security2:error] [pid 915741:tid 915958] [client 148.251.126.195:44502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOnAAAAeY"]
[Mon Jul 20 06:24:33.294385 2026] [security2:error] [pid 915741:tid 915787] [remote 147.50.252.213:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tga-615n1P-attmzOtQACBi0"]
[Mon Jul 20 06:24:33.294539 2026] [security2:error] [pid 915741:tid 915990] [client 147.50.252.213:34716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tga-615n1P-attmzOtQACBi0"]
[Mon Jul 20 06:24:33.567412 2026] [security2:error] [pid 915741:tid 915900] [client 34.74.185.202:55475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tga-615n1P-attmzOxQAAAaw"]
[Mon Jul 20 06:24:33.776981 2026] [security2:error] [pid 915741:tid 915969] [client 57.141.18.100:25802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tfa-615n1P-attmzNdwAB8TU"]
[Mon Jul 20 06:24:33.875139 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO3AAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:33.875236 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO3AAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:33.948603 2026] [security2:error] [pid 915741:tid 915950] [client 77.110.127.138:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO4gAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:33.948698 2026] [security2:error] [pid 915741:tid 915950] [client 77.110.127.138:61956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO4gAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.026262 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzO6wAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.026359 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzO6wAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.030238 2026] [security2:error] [pid 915741:tid 915881] [client 34.74.185.202:58086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tgq-615n1P-attmzO7AAAAZk"]
[Mon Jul 20 06:24:34.277775 2026] [security2:error] [pid 915741:tid 915971] [client 14.225.17.146:62899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOewAAAfM"], referer: http://outlookturf.com/WP
[Mon Jul 20 06:24:34.443738 2026] [security2:error] [pid 915741:tid 915944] [client 77.83.36.161:29860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4Tgq-615n1P-attmzPCQAAAdg"]
[Mon Jul 20 06:24:34.465902 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPDAAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.466000 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPDAAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.485778 2026] [security2:error] [pid 915741:tid 915890] [client 34.74.185.202:55340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tgq-615n1P-attmzPDQAAAaI"]
[Mon Jul 20 06:24:34.652020 2026] [security2:error] [pid 915741:tid 915978] [client 34.74.185.202:58100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tgq-615n1P-attmzPGQAAAfo"]
[Mon Jul 20 06:24:34.666441 2026] [security2:error] [pid 915741:tid 915891] [client 77.110.127.138:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPGgAAAaM"]
[Mon Jul 20 06:24:34.666537 2026] [security2:error] [pid 915741:tid 915891] [client 77.110.127.138:61962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPGgAAAaM"]
[Mon Jul 20 06:24:34.825347 2026] [security2:error] [pid 915741:tid 915934] [client 77.110.127.138:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPKgAAAc4"]
[Mon Jul 20 06:24:34.825488 2026] [security2:error] [pid 915741:tid 915934] [client 77.110.127.138:61964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPKgAAAc4"]
[Mon Jul 20 06:24:35.006085 2026] [core:error] [pid 915741:tid 915892] [client 14.225.17.146:61373] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WP
[Mon Jul 20 06:24:35.006115 2026] [core:error] [pid 915741:tid 915892] [client 14.225.17.146:61373] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WP
[Mon Jul 20 06:24:35.095317 2026] [security2:error] [pid 915741:tid 915982] [client 77.83.36.161:30230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4Tg6-615n1P-attmzPRwAAAf4"]
[Mon Jul 20 06:24:35.392611 2026] [core:error] [pid 915741:tid 915924] [client 14.225.17.146:63358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:35.392631 2026] [core:error] [pid 915741:tid 915924] [client 14.225.17.146:63358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:35.413425 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.25:27638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tf6-615n1P-attmzOCgABnU0"]
[Mon Jul 20 06:24:35.610015 2026] [security2:error] [pid 915741:tid 915945] [client 34.74.185.202:49866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tg6-615n1P-attmzPbwAAAdk"]
[Mon Jul 20 06:24:35.640641 2026] [security2:error] [pid 915741:tid 915877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tg6-615n1P-attmzPXQAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:35.747251 2026] [security2:error] [pid 915741:tid 915965] [client 77.83.36.161:30579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4Tg6-615n1P-attmzPdwAAAe0"]
[Mon Jul 20 06:24:35.812047 2026] [security2:error] [pid 915741:tid 915901] [client 34.74.185.202:54398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tg6-615n1P-attmzPfgAAAa0"]
[Mon Jul 20 06:24:35.973652 2026] [security2:error] [pid 915741:tid 915962] [client 171.61.165.146:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tg6-615n1P-attmzPlAAAAeo"]
[Mon Jul 20 06:24:35.973765 2026] [security2:error] [pid 915741:tid 915962] [client 171.61.165.146:22150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tg6-615n1P-attmzPlAAAAeo"]
[Mon Jul 20 06:24:35.990243 2026] [security2:error] [pid 915741:tid 915926] [client 34.73.38.214:57900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tg6-615n1P-attmzPlQAAAcY"]
[Mon Jul 20 06:24:36.078604 2026] [security2:error] [pid 915741:tid 915937] [client 34.74.185.202:51868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ThK-615n1P-attmzPmwAAAdE"]
[Mon Jul 20 06:24:36.431765 2026] [security2:error] [pid 915741:tid 915926] [client 74.208.214.194:44708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ThK-615n1P-attmzPtwAAAcY"]
[Mon Jul 20 06:24:36.469305 2026] [security2:error] [pid 915741:tid 915902] [client 14.225.17.146:61477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4ThK-615n1P-attmzPrQAAAa4"], referer: http://eframiproperties.com/WP
[Mon Jul 20 06:24:36.573308 2026] [security2:error] [pid 915741:tid 915969] [client 34.74.185.202:50949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ThK-615n1P-attmzPywAAAfE"]
[Mon Jul 20 06:24:36.962033 2026] [security2:error] [pid 915741:tid 915998] [client 171.60.139.123:52722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ThK-615n1P-attmzP6wAAAg4"]
[Mon Jul 20 06:24:36.962174 2026] [security2:error] [pid 915741:tid 915998] [client 171.60.139.123:52722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ThK-615n1P-attmzP6wAAAg4"]
[Mon Jul 20 06:24:37.099240 2026] [security2:error] [pid 915741:tid 915876] [client 14.225.17.146:63388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4Tg6-615n1P-attmzPcwAAAZQ"], referer: http://slutilities.com/WP
[Mon Jul 20 06:24:37.109351 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.114:20500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOiAABtWM"]
[Mon Jul 20 06:24:37.197050 2026] [security2:error] [pid 915741:tid 915753] [remote 47.86.33.52:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4Tha-615n1P-attmzP_gABsAs"], referer: https://hammadownenterprises.com/wp-login.php
[Mon Jul 20 06:24:37.234092 2026] [security2:error] [pid 915741:tid 915905] [client 34.74.185.202:50483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQBQAAAbE"]
[Mon Jul 20 06:24:37.366090 2026] [security2:error] [pid 915741:tid 915898] [client 14.225.17.146:55117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzP-AAAAao"], referer: http://guidehunting.com/WP
[Mon Jul 20 06:24:37.436856 2026] [security2:error] [pid 915741:tid 915896] [client 34.74.185.202:50591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQHQAAAag"]
[Mon Jul 20 06:24:37.598110 2026] [security2:error] [pid 915741:tid 915871] [client 65.1.132.125:10782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Tha-615n1P-attmzQLQAAAY8"]
[Mon Jul 20 06:24:37.677854 2026] [security2:error] [pid 915741:tid 915943] [client 34.73.38.214:58960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQPAAAAdc"]
[Mon Jul 20 06:24:37.764524 2026] [security2:error] [pid 915741:tid 915977] [client 14.225.17.146:55586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzQMgAAAfk"], referer: http://fluidtemple.org/WP
[Mon Jul 20 06:24:37.768815 2026] [security2:error] [pid 915741:tid 915878] [client 34.74.185.202:50585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQQgAAAZY"]
[Mon Jul 20 06:24:37.917237 2026] [security2:error] [pid 915741:tid 915799] [remote 104.244.79.40:60074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Tha-615n1P-attmzQSwABpjk"]
[Mon Jul 20 06:24:38.083384 2026] [security2:error] [pid 915741:tid 915921] [client 57.141.18.48:33656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tga-615n1P-attmzO1QABwSo"]
[Mon Jul 20 06:24:38.084182 2026] [security2:error] [pid 915741:tid 915914] [client 77.110.127.138:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Thq-615n1P-attmzQWgAAAbo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:38.084313 2026] [security2:error] [pid 915741:tid 915914] [client 77.110.127.138:61988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Thq-615n1P-attmzQWgAAAbo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:38.130318 2026] [security2:error] [pid 915741:tid 915767] [remote 104.244.79.40:60074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Thq-615n1P-attmzQYQAB1hk"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:24:38.219690 2026] [security2:error] [pid 915741:tid 915905] [client 34.74.185.202:49600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Thq-615n1P-attmzQbgAAAbE"]
[Mon Jul 20 06:24:38.415143 2026] [security2:error] [pid 915741:tid 915909] [client 14.225.17.146:55348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQagAAAbU"], referer: http://floorsourcestock.com/WP
[Mon Jul 20 06:24:38.432561 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Thq-615n1P-attmzQggAAAZA"]
[Mon Jul 20 06:24:38.433466 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:61140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Thq-615n1P-attmzQggAAAZA"]
[Mon Jul 20 06:24:38.468252 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:54967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQawAAAdI"], referer: https://guidehunting.com/WP
[Mon Jul 20 06:24:38.704643 2026] [security2:error] [pid 915741:tid 915894] [client 34.73.38.214:60582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Thq-615n1P-attmzQngAAAaY"]
[Mon Jul 20 06:24:38.758976 2026] [security2:error] [pid 915741:tid 915984] [client 14.225.17.146:55428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzQDwAAAgA"], referer: http://detroitcsc.com/WP
[Mon Jul 20 06:24:38.917289 2026] [security2:error] [pid 915741:tid 915962] [client 34.74.185.202:58372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Thq-615n1P-attmzQqAAAAeo"]
[Mon Jul 20 06:24:38.968316 2026] [security2:error] [pid 915741:tid 915862] [remote 57.141.18.22:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2937685"] [unique_id "al4Thq-615n1P-attmzQrQABkXg"]
[Mon Jul 20 06:24:39.120119 2026] [security2:error] [pid 915741:tid 915871] [client 45.116.69.230:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Th6-615n1P-attmzQvQAAAY8"]
[Mon Jul 20 06:24:39.120199 2026] [security2:error] [pid 915741:tid 915871] [client 45.116.69.230:61345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Th6-615n1P-attmzQvQAAAY8"]
[Mon Jul 20 06:24:39.289617 2026] [authz_core:error] [pid 915741:tid 915918] [client 66.132.195.57:50170] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:24:39.418680 2026] [security2:error] [pid 915741:tid 915924] [client 34.74.185.202:63220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Th6-615n1P-attmzQ0wAAAcQ"]
[Mon Jul 20 06:24:39.533575 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Th6-615n1P-attmzQ2AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:39.533689 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Th6-615n1P-attmzQ2AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:39.941574 2026] [security2:error] [pid 915741:tid 915952] [client 65.1.132.125:10798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Th6-615n1P-attmzQ9gAAAeA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:24:40.168715 2026] [security2:error] [pid 915741:tid 915901] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Th6-615n1P-attmzQ7wAAAa0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:40.201253 2026] [security2:error] [pid 915741:tid 915804] [remote 18.61.192.253:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TiK-615n1P-attmzRDwAB_j4"]
[Mon Jul 20 06:24:40.220075 2026] [security2:error] [pid 915741:tid 915994] [client 57.141.18.89:56180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tg6-615n1P-attmzPeQACCmc"]
[Mon Jul 20 06:24:40.311552 2026] [core:error] [pid 915741:tid 915911] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.311570 2026] [core:error] [pid 915741:tid 915911] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.336312 2026] [core:error] [pid 915741:tid 915943] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.336349 2026] [core:error] [pid 915741:tid 915943] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.441853 2026] [security2:error] [pid 915741:tid 915962] [client 14.225.17.146:54854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRMAAAAeo"], referer: http://eduardsales.com/WP
[Mon Jul 20 06:24:40.476773 2026] [security2:error] [pid 915741:tid 915939] [client 34.74.185.202:65129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TiK-615n1P-attmzRNwAAAdM"]
[Mon Jul 20 06:24:40.520987 2026] [security2:error] [pid 915741:tid 915880] [client 34.73.38.214:63936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TiK-615n1P-attmzRPgAAAZg"]
[Mon Jul 20 06:24:40.698896 2026] [security2:error] [pid 915741:tid 915774] [remote 18.61.192.253:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TiK-615n1P-attmzRVgABqyA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:40.904479 2026] [security2:error] [pid 915741:tid 915962] [client 50.116.65.227:57388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TiK-615n1P-attmzRYwAAAeo"]
[Mon Jul 20 06:24:40.916089 2026] [security2:error] [pid 915741:tid 915939] [client 50.116.65.227:57394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TiK-615n1P-attmzRZAAAAdM"]
[Mon Jul 20 06:24:41.009102 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:2325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tia-615n1P-attmzRagAAAfU"]
[Mon Jul 20 06:24:41.009213 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:2325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tia-615n1P-attmzRagAAAfU"]
[Mon Jul 20 06:24:41.048716 2026] [security2:error] [pid 915741:tid 915878] [client 14.225.17.146:55077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRXQAAAZY"], referer: http://soloceos.com/WP
[Mon Jul 20 06:24:41.154580 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:62005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tia-615n1P-attmzRfwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:41.154739 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:62005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tia-615n1P-attmzRfwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:41.160601 2026] [security2:error] [pid 915741:tid 915976] [client 14.225.17.146:61839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4Tia-615n1P-attmzRbgAAAfg"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WP
[Mon Jul 20 06:24:41.311136 2026] [security2:error] [pid 915741:tid 915832] [remote 173.212.252.15:46264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Tia-615n1P-attmzRkgAB61o"]
[Mon Jul 20 06:24:41.317694 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRaQAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:41.525008 2026] [security2:error] [pid 915741:tid 915747] [remote 173.212.252.15:46264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Tia-615n1P-attmzRoAABzgU"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 06:24:41.560271 2026] [security2:error] [pid 915741:tid 915956] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4Tia-615n1P-attmzRpAAAAeQ"], referer: https://duckduckgo.com/?q=ptse6
[Mon Jul 20 06:24:41.624955 2026] [autoindex:error] [pid 915741:tid 915890] [client 159.89.124.33:52868] AH01276: Cannot serve directory /home2/jworalmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:41.642274 2026] [security2:error] [pid 915741:tid 915908] [client 14.225.17.146:54968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Tia-615n1P-attmzRngAAAbQ"], referer: http://colinkeyphotography.com/WP
[Mon Jul 20 06:24:41.718243 2026] [security2:error] [pid 915741:tid 915880] [client 158.173.166.181:41499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tia-615n1P-attmzRtwAAAZg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:41.851369 2026] [security2:error] [pid 915741:tid 915945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tia-615n1P-attmzRrAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.026772 2026] [security2:error] [pid 915741:tid 915933] [client 57.141.18.48:65532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzQOwABzVE"]
[Mon Jul 20 06:24:42.491133 2026] [security2:error] [pid 915741:tid 915996] [client 57.141.18.92:56950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQXwACDFU"]
[Mon Jul 20 06:24:42.556864 2026] [security2:error] [pid 915741:tid 915961] [client 57.141.18.78:54520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQbQAB6UY"]
[Mon Jul 20 06:24:42.594000 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSAQAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.594125 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:62017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSAQAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.621475 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tiq-615n1P-attmzR8QAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.763599 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:62019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSEgAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.763716 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:62019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSEgAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.787023 2026] [security2:error] [pid 915741:tid 915937] [client 34.73.38.214:56130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tiq-615n1P-attmzSFAAAAdE"]
[Mon Jul 20 06:24:42.857594 2026] [security2:error] [pid 915741:tid 915801] [remote 81.173.115.7:38736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tiq-615n1P-attmzSGgAByTs"]
[Mon Jul 20 06:24:42.903901 2026] [security2:error] [pid 915741:tid 915963] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4Tiq-615n1P-attmzSHAAAAes"], referer: https://twitter.com/
[Mon Jul 20 06:24:42.934302 2026] [security2:error] [pid 915741:tid 915942] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4Tiq-615n1P-attmzSHgAAAdY"], referer: https://www.bing.com/search?q=1tsvvy
[Mon Jul 20 06:24:43.010395 2026] [core:error] [pid 915741:tid 915934] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:43.010423 2026] [core:error] [pid 915741:tid 915934] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:43.042306 2026] [security2:error] [pid 915741:tid 915995] [client 14.225.17.146:63482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4Tiq-615n1P-attmzSJgAAAgs"], referer: http://daseighty.net/WP
[Mon Jul 20 06:24:43.053323 2026] [security2:error] [pid 915741:tid 915830] [remote 81.173.115.7:38736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Ti6-615n1P-attmzSLAACA1g"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:43.076399 2026] [security2:error] [pid 915741:tid 915900] [client 35.221.62.63:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.62.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/xmlrpc.php"] [unique_id "al4Ti6-615n1P-attmzSLgAAAaw"]
[Mon Jul 20 06:24:43.319156 2026] [security2:error] [pid 915741:tid 915813] [remote 78.46.157.202:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Ti6-615n1P-attmzSSgABk0c"]
[Mon Jul 20 06:24:43.336832 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSTgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.336967 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSTgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.341205 2026] [security2:error] [pid 915741:tid 915877] [client 35.221.62.63:64939] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSTwAAAZU"]
[Mon Jul 20 06:24:43.356987 2026] [security2:error] [pid 915741:tid 915742] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ti6-615n1P-attmzSUgAB_gA"]
[Mon Jul 20 06:24:43.357150 2026] [security2:error] [pid 915741:tid 915982] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ti6-615n1P-attmzSUgAB_gA"]
[Mon Jul 20 06:24:43.458148 2026] [security2:error] [pid 915741:tid 915913] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSRAAAAbk"]
[Mon Jul 20 06:24:43.529924 2026] [security2:error] [pid 915741:tid 915845] [remote 78.46.157.202:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Ti6-615n1P-attmzSYwAB5Gc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:43.570059 2026] [security2:error] [pid 915741:tid 915936] [client 34.198.201.66:45116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSZAAAAdA"], referer: https://windowtx.com
[Mon Jul 20 06:24:43.582966 2026] [security2:error] [pid 915741:tid 915884] [client 35.221.62.63:56511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSZgAAAZw"]
[Mon Jul 20 06:24:43.653329 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:62025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSbwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.653438 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:62025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSbwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.814447 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.23:34502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Th6-615n1P-attmzQ0gABtQ0"]
[Mon Jul 20 06:24:43.870095 2026] [security2:error] [pid 915741:tid 915949] [client 35.221.62.63:52530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSjAAAAd0"]
[Mon Jul 20 06:24:43.891838 2026] [security2:error] [pid 915741:tid 915892] [client 34.73.38.214:52564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSjwAAAaQ"]
[Mon Jul 20 06:24:43.926236 2026] [security2:error] [pid 915741:tid 915964] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSdAAAAew"]
[Mon Jul 20 06:24:43.980851 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSngAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.980996 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSngAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.050549 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSogAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.050697 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSogAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.183204 2026] [security2:error] [pid 915741:tid 915929] [client 104.234.53.49:45515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TjK-615n1P-attmzSqwAAAck"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:44.184525 2026] [security2:error] [pid 915741:tid 915918] [client 35.221.62.63:56595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzSrAAAAb4"]
[Mon Jul 20 06:24:44.358303 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:62029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSwwAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.358386 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:62029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSwwAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.432442 2026] [security2:error] [pid 915741:tid 915905] [client 35.221.62.63:52469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzSyQAAAbE"]
[Mon Jul 20 06:24:44.558049 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.22:49102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzSvwABnS0"]
[Mon Jul 20 06:24:44.563099 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:62031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzS1gAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.564781 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:62031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzS1gAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.675074 2026] [security2:error] [pid 915741:tid 915880] [client 35.221.62.63:52707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzS3wAAAZg"]
[Mon Jul 20 06:24:44.725277 2026] [security2:error] [pid 915741:tid 915933] [client 14.225.17.146:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzSyAAAAc0"], referer: http://transparentservices.online/WP
[Mon Jul 20 06:24:44.815332 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.86:51050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRHgACBBc"]
[Mon Jul 20 06:24:44.939044 2026] [security2:error] [pid 915741:tid 915955] [client 35.221.62.63:58000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzS8wAAAeM"]
[Mon Jul 20 06:24:44.977146 2026] [security2:error] [pid 915741:tid 915942] [client 104.234.53.77:52467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TjK-615n1P-attmzS-QAAAdY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:45.106658 2026] [security2:error] [pid 915741:tid 915897] [client 65.1.132.125:10814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4Tja-615n1P-attmzTBwAAAak"]
[Mon Jul 20 06:24:45.163457 2026] [security2:error] [pid 915741:tid 915893] [client 14.225.17.146:63314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4TjK-615n1P-attmzS-gAAAaU"], referer: http://dereckcastellon.com/WP
[Mon Jul 20 06:24:45.239777 2026] [security2:error] [pid 915741:tid 915892] [client 35.221.62.63:64219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTEwAAAaQ"]
[Mon Jul 20 06:24:45.507944 2026] [security2:error] [pid 915741:tid 915964] [client 35.221.62.63:55386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTLQAAAew"]
[Mon Jul 20 06:24:45.533455 2026] [security2:error] [pid 915741:tid 915991] [client 34.73.38.214:54691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTLwAAAgc"]
[Mon Jul 20 06:24:45.843287 2026] [security2:error] [pid 915741:tid 915966] [client 35.221.62.63:52824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTRgAAAe4"]
[Mon Jul 20 06:24:46.085776 2026] [security2:error] [pid 915741:tid 915981] [client 104.234.53.84:53047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Tjq-615n1P-attmzTWgAAAf0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:46.143783 2026] [security2:error] [pid 915741:tid 915907] [client 65.1.132.125:10826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4Tjq-615n1P-attmzTXQAAAbM"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:24:46.144303 2026] [security2:error] [pid 915741:tid 915912] [client 35.221.62.63:49329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tjq-615n1P-attmzTXAAAAbg"]
[Mon Jul 20 06:24:46.221679 2026] [security2:error] [pid 915741:tid 915901] [client 14.225.17.146:51614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4Tjq-615n1P-attmzTYgAAAa0"], referer: http://dasmarque.com/WP
[Mon Jul 20 06:24:46.254141 2026] [security2:error] [pid 915741:tid 915984] [client 77.110.127.138:62037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTaAAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.254256 2026] [security2:error] [pid 915741:tid 915984] [client 77.110.127.138:62037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTaAAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.404690 2026] [security2:error] [pid 915741:tid 915956] [client 35.221.62.63:58370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tjq-615n1P-attmzTdQAAAeQ"]
[Mon Jul 20 06:24:46.409686 2026] [security2:error] [pid 915741:tid 915947] [client 77.110.127.138:62038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTdgAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.409781 2026] [security2:error] [pid 915741:tid 915947] [client 77.110.127.138:62038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTdgAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.425126 2026] [security2:error] [pid 915741:tid 915979] [client 57.141.18.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4Tjq-615n1P-attmzTaQAAAfs"]
[Mon Jul 20 06:24:46.961684 2026] [security2:error] [pid 915741:tid 915977] [client 8.228.127.164:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.127.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardsales.com"] [uri "/xmlrpc.php"] [unique_id "al4Tjq-615n1P-attmzTmgAAAfk"]
[Mon Jul 20 06:24:46.961804 2026] [security2:error] [pid 915741:tid 915977] [client 8.228.127.164:61049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eduardsales.com"] [uri "/xmlrpc.php"] [unique_id "al4Tjq-615n1P-attmzTmgAAAfk"]
[Mon Jul 20 06:24:46.984159 2026] [security2:error] [pid 915741:tid 915919] [client 50.116.65.227:57506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4Tjq-615n1P-attmzTnQAAAb8"]
[Mon Jul 20 06:24:46.985340 2026] [security2:error] [pid 915741:tid 915950] [client 14.225.17.146:63904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4Tjq-615n1P-attmzTWQAAAd4"], referer: http://dnsplumbing.com/WP
[Mon Jul 20 06:24:47.052651 2026] [security2:error] [pid 915741:tid 915873] [client 34.73.38.214:58403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tj6-615n1P-attmzTqQAAAZE"]
[Mon Jul 20 06:24:47.203934 2026] [security2:error] [pid 915741:tid 915941] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/git/.ssh/id_rsa"] [unique_id "al4Tj6-615n1P-attmzTtgAAAdU"], referer: https://www.google.com/search?q=nxafjw
[Mon Jul 20 06:24:47.244599 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.54:42124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSMAABliQ"]
[Mon Jul 20 06:24:47.284947 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:62043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tj6-615n1P-attmzTuwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:47.285081 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:62043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tj6-615n1P-attmzTuwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:47.482231 2026] [security2:error] [pid 915741:tid 915943] [client 14.225.17.146:54384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Tj6-615n1P-attmzTwwAAAdc"], referer: http://northbrookcpa.ca/WP
[Mon Jul 20 06:24:47.614472 2026] [security2:error] [pid 915741:tid 915906] [client 171.60.139.123:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT0gAAAbI"]
[Mon Jul 20 06:24:47.614580 2026] [security2:error] [pid 915741:tid 915906] [client 171.60.139.123:53246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT0gAAAbI"]
[Mon Jul 20 06:24:47.620648 2026] [security2:error] [pid 915741:tid 915910] [client 50.116.65.227:57508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Tj6-615n1P-attmzTuQAAAbY"]
[Mon Jul 20 06:24:47.949845 2026] [security2:error] [pid 915741:tid 915871] [client 50.116.65.227:57524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Tj6-615n1P-attmzT1AAAAY8"]
[Mon Jul 20 06:24:47.962338 2026] [security2:error] [pid 915741:tid 915993] [client 57.141.18.14:21692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSbgACCR0"]
[Mon Jul 20 06:24:47.977849 2026] [security2:error] [pid 915741:tid 915947] [client 112.208.70.94:45637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT8gAAAds"]
[Mon Jul 20 06:24:47.978029 2026] [security2:error] [pid 915741:tid 915947] [client 112.208.70.94:45637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT8gAAAds"]
[Mon Jul 20 06:24:48.095618 2026] [security2:error] [pid 915741:tid 915922] [client 34.73.38.214:58081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TkK-615n1P-attmzUAQAAAcI"]
[Mon Jul 20 06:24:48.397184 2026] [security2:error] [pid 915741:tid 915953] [client 57.141.18.15:51720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzSsAAB4SI"]
[Mon Jul 20 06:24:48.772859 2026] [security2:error] [pid 915741:tid 915903] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/admin/.ssh/id_rsa"] [unique_id "al4TkK-615n1P-attmzUPgAAAa8"], referer: https://duckduckgo.com/?q=fz9pz
[Mon Jul 20 06:24:48.922403 2026] [security2:error] [pid 915741:tid 915962] [client 57.141.18.35:61396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzS5AAB6jc"]
[Mon Jul 20 06:24:49.087681 2026] [security2:error] [pid 915741:tid 915924] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/passwd"] [unique_id "al4Tka-615n1P-attmzUXgAAAcQ"], referer: https://www.google.com/search?q=jx5j8x
[Mon Jul 20 06:24:49.185186 2026] [security2:error] [pid 915741:tid 915922] [client 103.141.108.143:61614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUbAAAAcI"]
[Mon Jul 20 06:24:49.185310 2026] [security2:error] [pid 915741:tid 915922] [client 103.141.108.143:61614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUbAAAAcI"]
[Mon Jul 20 06:24:49.265129 2026] [security2:error] [pid 915741:tid 915840] [remote 81.173.115.7:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4Tka-615n1P-attmzUdQABtWI"]
[Mon Jul 20 06:24:49.278328 2026] [security2:error] [pid 915741:tid 915953] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/shadow"] [unique_id "al4Tka-615n1P-attmzUdgAAAeE"], referer: https://t.co/npoa030pbs
[Mon Jul 20 06:24:49.457365 2026] [security2:error] [pid 915741:tid 915880] [client 34.73.38.214:58579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tka-615n1P-attmzUgQAAAZg"]
[Mon Jul 20 06:24:49.470100 2026] [security2:error] [pid 915741:tid 915803] [remote 81.173.115.7:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4Tka-615n1P-attmzUggABxj0"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 06:24:49.481768 2026] [security2:error] [pid 915741:tid 915950] [client 158.173.89.95:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tka-615n1P-attmzUgwAAAd4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:49.625288 2026] [security2:error] [pid 915741:tid 915968] [client 57.141.18.22:65024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tja-615n1P-attmzTJgAB8Ek"]
[Mon Jul 20 06:24:49.702420 2026] [security2:error] [pid 915741:tid 915945] [client 45.116.69.230:61862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUmwAAAdk"]
[Mon Jul 20 06:24:49.702525 2026] [security2:error] [pid 915741:tid 915945] [client 45.116.69.230:61862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUmwAAAdk"]
[Mon Jul 20 06:24:49.834991 2026] [security2:error] [pid 915741:tid 915951] [client 34.74.185.202:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUpAAAAd8"]
[Mon Jul 20 06:24:50.030770 2026] [security2:error] [pid 915741:tid 915942] [client 14.225.17.146:51364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUTQAAAdY"], referer: http://travelbyfire.com/WP
[Mon Jul 20 06:24:50.107125 2026] [security2:error] [pid 915741:tid 915990] [client 57.141.18.85:51990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tja-615n1P-attmzTTAACBjw"]
[Mon Jul 20 06:24:50.157224 2026] [security2:error] [pid 915741:tid 915957] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzT_QAAAeU"]
[Mon Jul 20 06:24:50.271639 2026] [security2:error] [pid 915741:tid 915876] [client 34.74.185.202:60849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tkq-615n1P-attmzUyQAAAZQ"]
[Mon Jul 20 06:24:50.377919 2026] [security2:error] [pid 915741:tid 915910] [client 77.110.127.138:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU0QAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.378034 2026] [security2:error] [pid 915741:tid 915910] [client 77.110.127.138:62056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU0QAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.405765 2026] [security2:error] [pid 915741:tid 915989] [client 34.74.185.202:58381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tkq-615n1P-attmzU1AAAAgU"]
[Mon Jul 20 06:24:50.531454 2026] [security2:error] [pid 915741:tid 915896] [client 34.74.185.202:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tkq-615n1P-attmzU5AAAAag"]
[Mon Jul 20 06:24:50.550381 2026] [security2:error] [pid 915741:tid 915745] [remote 57.141.18.22:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4Tkq-615n1P-attmzU6AAB0wM"]
[Mon Jul 20 06:24:50.558612 2026] [security2:error] [pid 915741:tid 915956] [client 77.110.127.138:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU6wAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.558687 2026] [security2:error] [pid 915741:tid 915956] [client 77.110.127.138:62057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU6wAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.834425 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:54432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUOQAAAds"], referer: http://jvcmotorsports.com/WP
[Mon Jul 20 06:24:50.899417 2026] [security2:error] [pid 915741:tid 915973] [client 34.74.185.202:57674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tkq-615n1P-attmzVEAAAAfU"]
[Mon Jul 20 06:24:50.921156 2026] [security2:error] [pid 915741:tid 915927] [client 14.225.17.146:51512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4Tkq-615n1P-attmzVDgAAAcc"], referer: https://travelbyfire.com/WP
[Mon Jul 20 06:24:50.966489 2026] [security2:error] [pid 915741:tid 915838] [remote 57.141.18.115:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4Tkq-615n1P-attmzVFQABkmA"]
[Mon Jul 20 06:24:50.983778 2026] [security2:error] [pid 915741:tid 915970] [client 34.73.38.214:58880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tkq-615n1P-attmzVFwAAAfI"]
[Mon Jul 20 06:24:51.036274 2026] [security2:error] [pid 915741:tid 915943] [client 34.74.185.202:62688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVHgAAAdc"]
[Mon Jul 20 06:24:51.196537 2026] [security2:error] [pid 915741:tid 915976] [client 77.110.127.138:62060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tk6-615n1P-attmzVKgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:51.196634 2026] [security2:error] [pid 915741:tid 915976] [client 77.110.127.138:62060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tk6-615n1P-attmzVKgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:51.248677 2026] [security2:error] [pid 915741:tid 915974] [client 34.74.185.202:60251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVMAAAAfY"]
[Mon Jul 20 06:24:51.455932 2026] [security2:error] [pid 915741:tid 915919] [client 104.234.53.90:41199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tk6-615n1P-attmzVQAAAAb8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:51.552107 2026] [security2:error] [pid 915741:tid 915945] [client 46.110.96.34:8554] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4Tk6-615n1P-attmzVUQAAAdk"]
[Mon Jul 20 06:24:51.618034 2026] [security2:error] [pid 915741:tid 915896] [client 41.173.37.102:2752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tk6-615n1P-attmzVWQAAAag"]
[Mon Jul 20 06:24:51.618123 2026] [security2:error] [pid 915741:tid 915896] [client 41.173.37.102:2752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tk6-615n1P-attmzVWQAAAag"]
[Mon Jul 20 06:24:51.728861 2026] [security2:error] [pid 915741:tid 915976] [client 34.74.185.202:50889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVcgAAAfg"]
[Mon Jul 20 06:24:51.952233 2026] [security2:error] [pid 915741:tid 915996] [client 34.74.185.202:55026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVgwAAAgw"]
[Mon Jul 20 06:24:52.087177 2026] [security2:error] [pid 915741:tid 915947] [client 34.74.185.202:52364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzVmQAAAds"]
[Mon Jul 20 06:24:52.122319 2026] [security2:error] [pid 915741:tid 915773] [remote 91.142.222.105:39808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4TlK-615n1P-attmzVnwAB1R8"]
[Mon Jul 20 06:24:52.138600 2026] [security2:error] [pid 915741:tid 915927] [client 34.74.185.202:58889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzVoQAAAcc"]
[Mon Jul 20 06:24:52.370607 2026] [security2:error] [pid 915741:tid 915745] [remote 91.142.222.105:39808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4TlK-615n1P-attmzVygABwQM"], referer: https://joulecommunications.com/wp-login.php
[Mon Jul 20 06:24:52.421452 2026] [security2:error] [pid 915741:tid 915942] [client 34.74.185.202:63149] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzV0gAAAdY"]
[Mon Jul 20 06:24:52.539385 2026] [security2:error] [pid 915741:tid 915995] [client 57.141.18.91:24236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUJgACC1Q"]
[Mon Jul 20 06:24:52.569350 2026] [security2:error] [pid 915741:tid 915957] [client 34.74.185.202:51617] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzV4wAAAeU"]
[Mon Jul 20 06:24:52.608423 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:62479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4TlK-615n1P-attmzVuAAAAfU"], referer: http://hilltopnurseryinc.com/WP
[Mon Jul 20 06:24:52.716635 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TlK-615n1P-attmzV9wAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:52.716733 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TlK-615n1P-attmzV9wAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:52.718043 2026] [security2:error] [pid 915741:tid 915936] [client 57.141.18.60:59736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUOgAB0Bk"]
[Mon Jul 20 06:24:52.761160 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:52.761245 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:61439] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:52.761834 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:52.761872 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:61439] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:52.881336 2026] [security2:error] [pid 915741:tid 915931] [client 34.74.185.202:64895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzWDwAAAcs"]
[Mon Jul 20 06:24:52.964869 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.115:30076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUUgABlgI"]
[Mon Jul 20 06:24:53.121497 2026] [security2:error] [pid 915741:tid 915916] [client 34.74.185.202:52634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWIAAAAbw"]
[Mon Jul 20 06:24:53.265099 2026] [security2:error] [pid 915741:tid 915971] [client 77.110.127.138:62067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TlK-615n1P-attmzWEQAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:53.270309 2026] [security2:error] [pid 915741:tid 915920] [client 57.141.18.8:34500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUewABwDs"]
[Mon Jul 20 06:24:53.307232 2026] [security2:error] [pid 915741:tid 915979] [client 34.74.185.202:49958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWLwAAAfs"]
[Mon Jul 20 06:24:53.333311 2026] [security2:error] [pid 915741:tid 915886] [client 77.110.127.138:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tla-615n1P-attmzWNQAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:53.333412 2026] [security2:error] [pid 915741:tid 915886] [client 77.110.127.138:62069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tla-615n1P-attmzWNQAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:53.654606 2026] [security2:error] [pid 915741:tid 915989] [client 34.74.185.202:61971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWRwAAAgU"]
[Mon Jul 20 06:24:53.670303 2026] [security2:error] [pid 915741:tid 915993] [client 57.141.18.66:28472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUrAACCUc"]
[Mon Jul 20 06:24:53.689709 2026] [security2:error] [pid 915741:tid 915881] [client 34.74.185.202:54582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWSgAAAZk"]
[Mon Jul 20 06:24:53.805951 2026] [security2:error] [pid 915741:tid 915873] [client 57.141.18.53:58234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUrwABkUw"]
[Mon Jul 20 06:24:53.968142 2026] [security2:error] [pid 915741:tid 915823] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tla-615n1P-attmzWWgAB5lE"]
[Mon Jul 20 06:24:53.968326 2026] [security2:error] [pid 915741:tid 915958] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tla-615n1P-attmzWWgAB5lE"]
[Mon Jul 20 06:24:54.163400 2026] [security2:error] [pid 915741:tid 915934] [client 34.74.185.202:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWZQAAAc4"]
[Mon Jul 20 06:24:54.214141 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tlq-615n1P-attmzWagAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:54.214228 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tlq-615n1P-attmzWagAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:54.295819 2026] [security2:error] [pid 915741:tid 915914] [client 57.141.18.56:46618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tkq-615n1P-attmzVAgABul4"]
[Mon Jul 20 06:24:54.371818 2026] [security2:error] [pid 915741:tid 915905] [client 34.74.185.202:64849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWgAAAAbE"]
[Mon Jul 20 06:24:54.545546 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:50863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4TlK-615n1P-attmzVmAAAAdI"], referer: http://aandarealtygroup.com/WP
[Mon Jul 20 06:24:54.662403 2026] [security2:error] [pid 915741:tid 915969] [client 77.110.127.138:62076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tlq-615n1P-attmzWcwAAAfE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:54.689607 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.96:56888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tk6-615n1P-attmzVJAACBBo"]
[Mon Jul 20 06:24:54.809541 2026] [security2:error] [pid 915741:tid 915992] [client 34.74.185.202:50201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWngAAAgg"]
[Mon Jul 20 06:24:54.858101 2026] [security2:error] [pid 915741:tid 915984] [client 14.251.3.155:55742] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Tlq-615n1P-attmzWpAAAAgA"]
[Mon Jul 20 06:24:54.893638 2026] [security2:error] [pid 915741:tid 915940] [client 34.74.185.202:54062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWqQAAAdQ"]
[Mon Jul 20 06:24:55.062975 2026] [proxy:error] [pid 915741:tid 915892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:55.063076 2026] [proxy_http:error] [pid 915741:tid 915892] [client 34.73.38.214:64888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:55.063857 2026] [proxy:error] [pid 915741:tid 915892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:55.063909 2026] [proxy_http:error] [pid 915741:tid 915892] [client 34.73.38.214:64888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:55.204347 2026] [security2:error] [pid 915741:tid 915882] [client 34.74.185.202:62591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tl6-615n1P-attmzWvAAAAZo"]
[Mon Jul 20 06:24:55.489415 2026] [core:error] [pid 915741:tid 915946] [client 14.225.17.146:62264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WP
[Mon Jul 20 06:24:55.489442 2026] [core:error] [pid 915741:tid 915946] [client 14.225.17.146:62264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WP
[Mon Jul 20 06:24:55.528393 2026] [security2:error] [pid 915741:tid 915973] [client 93.152.221.118:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Tl6-615n1P-attmzW1QAAAfU"], referer: https://www.facebook.com/
[Mon Jul 20 06:24:55.638974 2026] [security2:error] [pid 915741:tid 915757] [remote 160.187.68.132:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tl6-615n1P-attmzW5AAB6A8"]
[Mon Jul 20 06:24:55.744656 2026] [security2:error] [pid 915741:tid 915782] [remote 17.241.219.182:55794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.219.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tl6-615n1P-attmzW6QAB7ig"], referer: https://mezzacraft.com/mosaic-crochet-course-walton-on-thames-monday-daytimes-4-11-24/
[Mon Jul 20 06:24:55.787056 2026] [lsapi:warn] [pid 915741:tid 915903] [client 14.225.17.146:56453] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WP
[Mon Jul 20 06:24:55.787086 2026] [lsapi:warn] [pid 915741:tid 915903] [client 14.225.17.146:56453] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WP
[Mon Jul 20 06:24:55.824935 2026] [security2:error] [pid 915741:tid 915907] [client 93.152.221.118:62397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Tl6-615n1P-attmzW8QAAAbM"]
[Mon Jul 20 06:24:56.136218 2026] [proxy:error] [pid 915741:tid 915917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:56.136294 2026] [proxy_http:error] [pid 915741:tid 915917] [client 34.73.38.214:52740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:56.136933 2026] [proxy:error] [pid 915741:tid 915917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:56.136961 2026] [proxy_http:error] [pid 915741:tid 915917] [client 34.73.38.214:52740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:56.165295 2026] [security2:error] [pid 915741:tid 915984] [client 34.74.185.202:62778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TmK-615n1P-attmzXDwAAAgA"]
[Mon Jul 20 06:24:56.225940 2026] [security2:error] [pid 915741:tid 915961] [client 14.225.17.146:56452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXDAAAAek"], referer: http://inspirespublishing.com/WP
[Mon Jul 20 06:24:56.313724 2026] [lsapi:warn] [pid 915741:tid 915991] [client 50.116.65.227:50532] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:56.313757 2026] [lsapi:warn] [pid 915741:tid 915991] [client 50.116.65.227:50532] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:56.329684 2026] [security2:error] [pid 915741:tid 915903] [client 14.225.17.146:56453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Tl6-615n1P-attmzWvwAAAa8"], referer: http://oswegooperatheater.com/WP
[Mon Jul 20 06:24:56.448310 2026] [security2:error] [pid 915741:tid 915749] [remote 160.187.68.132:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TmK-615n1P-attmzXKwACCwc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:56.511314 2026] [security2:error] [pid 915741:tid 915905] [client 74.7.228.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "zzzwillowzzz.com"] [uri "/robots.txt"] [unique_id "al4TmK-615n1P-attmzXMAAAAbE"]
[Mon Jul 20 06:24:56.531676 2026] [security2:error] [pid 915741:tid 915889] [client 14.225.17.146:64379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4Tlq-615n1P-attmzWrgAAAaE"], referer: http://xp-design.co/WP
[Mon Jul 20 06:24:56.631178 2026] [security2:error] [pid 915741:tid 915949] [client 34.74.185.202:57535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TmK-615n1P-attmzXOQAAAd0"]
[Mon Jul 20 06:24:56.654730 2026] [security2:error] [pid 915741:tid 915896] [client 104.234.53.85:30031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TmK-615n1P-attmzXOwAAAag"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:56.792552 2026] [security2:error] [pid 915741:tid 915915] [client 57.141.18.105:30092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tla-615n1P-attmzWRgABuzg"]
[Mon Jul 20 06:24:57.085455 2026] [security2:error] [pid 915741:tid 915935] [client 34.74.185.202:55110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tma-615n1P-attmzXVgAAAc8"]
[Mon Jul 20 06:24:57.190302 2026] [lsapi:warn] [pid 915741:tid 915884] [client 14.225.17.146:56623] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WP
[Mon Jul 20 06:24:57.190325 2026] [lsapi:warn] [pid 915741:tid 915884] [client 14.225.17.146:56623] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WP
[Mon Jul 20 06:24:57.250535 2026] [security2:error] [pid 915741:tid 915884] [client 14.225.17.146:56623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXWwAAAZw"], referer: https://oswegooperatheater.com/WP
[Mon Jul 20 06:24:57.558642 2026] [security2:error] [pid 915741:tid 915993] [client 14.225.17.146:62429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXEgAAAgk"], referer: http://phillipbloch.com/WP
[Mon Jul 20 06:24:57.625869 2026] [security2:error] [pid 915741:tid 915929] [client 34.74.185.202:52812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tma-615n1P-attmzXdgAAAck"]
[Mon Jul 20 06:24:57.684830 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:62465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tma-615n1P-attmzXeQAAAbc"]
[Mon Jul 20 06:24:57.790363 2026] [security2:error] [pid 915741:tid 915944] [client 14.225.17.146:56017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXdQAAAdg"], referer: http://careysheatingandcooling.com/WP
[Mon Jul 20 06:24:57.942401 2026] [security2:error] [pid 915741:tid 915806] [remote 103.82.22.235:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tma-615n1P-attmzXkQACA0A"]
[Mon Jul 20 06:24:57.994915 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:57.994960 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:56270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:57.995402 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:57.995425 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:56270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:58.296838 2026] [security2:error] [pid 915741:tid 915902] [client 171.60.139.123:53791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tmq-615n1P-attmzXuwAAAa4"]
[Mon Jul 20 06:24:58.296947 2026] [security2:error] [pid 915741:tid 915902] [client 171.60.139.123:53791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tmq-615n1P-attmzXuwAAAa4"]
[Mon Jul 20 06:24:58.335142 2026] [security2:error] [pid 915741:tid 915957] [client 93.152.221.118:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzXvwAAAeU"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:24:58.341073 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:62088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzXqQAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:58.383368 2026] [security2:error] [pid 915741:tid 915932] [client 104.234.53.53:42835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Tmq-615n1P-attmzXugAAAcw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:58.422319 2026] [security2:error] [pid 915741:tid 915987] [client 34.74.185.202:52448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tmq-615n1P-attmzXxAAAAgM"]
[Mon Jul 20 06:24:58.451878 2026] [security2:error] [pid 915741:tid 915827] [remote 103.82.22.235:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzXxgABnVU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:58.590849 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:54456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tmq-615n1P-attmzX1AAAAbc"]
[Mon Jul 20 06:24:58.641808 2026] [security2:error] [pid 915741:tid 915872] [client 57.141.18.35:51378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tl6-615n1P-attmzW3gABkH0"]
[Mon Jul 20 06:24:58.693872 2026] [security2:error] [pid 915741:tid 915917] [client 104.234.53.53:42835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzX2wAAAb0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:58.789575 2026] [lsapi:warn] [pid 915741:tid 915945] [client 35.233.110.193:56364] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:58.789593 2026] [lsapi:warn] [pid 915741:tid 915945] [client 35.233.110.193:56364] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:58.796817 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tmq-615n1P-attmzX3wAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:58.796905 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:62090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tmq-615n1P-attmzX3wAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:58.848113 2026] [security2:error] [pid 915741:tid 915945] [client 35.233.110.193:56364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzX3gAAAdk"]
[Mon Jul 20 06:24:58.948993 2026] [security2:error] [pid 915741:tid 915845] [remote 72.167.132.114:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzX7AABpWc"]
[Mon Jul 20 06:24:59.140694 2026] [security2:error] [pid 915741:tid 915966] [client 35.233.110.193:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.110.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/xmlrpc.php"] [unique_id "al4Tm6-615n1P-attmzX_wAAAe4"]
[Mon Jul 20 06:24:59.182913 2026] [security2:error] [pid 915741:tid 915990] [client 57.141.18.91:24280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tl6-615n1P-attmzW-gACBn8"]
[Mon Jul 20 06:24:59.246158 2026] [security2:error] [pid 915741:tid 915837] [remote 72.167.132.114:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tm6-615n1P-attmzYBQABsl8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:59.264713 2026] [security2:error] [pid 915741:tid 915916] [client 34.74.185.202:51660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYBwAAAbw"]
[Mon Jul 20 06:24:59.326515 2026] [security2:error] [pid 915741:tid 915900] [client 34.74.185.202:51289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYDAAAAaw"]
[Mon Jul 20 06:24:59.389394 2026] [security2:error] [pid 915741:tid 915905] [client 34.73.38.214:59279] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYFgAAAbE"]
[Mon Jul 20 06:24:59.475481 2026] [security2:error] [pid 915741:tid 915920] [client 14.225.17.146:62496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4Tm6-615n1P-attmzYBgAAAcA"], referer: http://amalia-capital.com/WP
[Mon Jul 20 06:24:59.536025 2026] [security2:error] [pid 915741:tid 915934] [client 57.141.18.114:44202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXHwABziA"]
[Mon Jul 20 06:24:59.603778 2026] [security2:error] [pid 915741:tid 915928] [client 77.110.127.138:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYLwAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.603883 2026] [security2:error] [pid 915741:tid 915928] [client 77.110.127.138:62093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYLwAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.623093 2026] [security2:error] [pid 915741:tid 915955] [client 14.225.17.146:64536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Tm6-615n1P-attmzYCQAAAeM"]
[Mon Jul 20 06:24:59.692462 2026] [security2:error] [pid 915741:tid 915954] [client 34.74.185.202:56372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYNQAAAeI"]
[Mon Jul 20 06:24:59.851319 2026] [security2:error] [pid 915741:tid 915957] [client 77.110.127.138:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYOwAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.851443 2026] [security2:error] [pid 915741:tid 915957] [client 77.110.127.138:62094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYOwAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.863525 2026] [security2:error] [pid 915741:tid 915958] [client 57.141.18.85:29274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXPgAB5ic"]
[Mon Jul 20 06:24:59.934402 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tm6-615n1P-attmzYPQAAAZ4"]
[Mon Jul 20 06:24:59.934509 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:62155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tm6-615n1P-attmzYPQAAAZ4"]
[Mon Jul 20 06:24:59.950892 2026] [security2:error] [pid 915741:tid 915805] [remote 72.252.198.245:55576] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4Tm6-615n1P-attmzYPgABnD8"]
[Mon Jul 20 06:24:59.968020 2026] [security2:error] [pid 915741:tid 915941] [client 35.233.110.193:55598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYPwAAAdU"]
[Mon Jul 20 06:25:00.053780 2026] [security2:error] [pid 915741:tid 915877] [client 14.225.17.146:56343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzXwwAAAZU"], referer: http://margaretspeckogawa.com/WP
[Mon Jul 20 06:25:00.081468 2026] [security2:error] [pid 915741:tid 915998] [client 34.74.185.202:58748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYRwAAAg4"]
[Mon Jul 20 06:25:00.165267 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.72:37176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXVQAB5B4"]
[Mon Jul 20 06:25:00.283507 2026] [security2:error] [pid 915741:tid 915984] [client 45.116.69.230:62388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TnK-615n1P-attmzYWwAAAgA"]
[Mon Jul 20 06:25:00.283642 2026] [security2:error] [pid 915741:tid 915984] [client 45.116.69.230:62388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TnK-615n1P-attmzYWwAAAgA"]
[Mon Jul 20 06:25:00.407551 2026] [security2:error] [pid 915741:tid 915906] [client 34.74.185.202:54462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYZAAAAbI"]
[Mon Jul 20 06:25:00.408112 2026] [security2:error] [pid 915741:tid 915930] [client 14.225.17.146:56367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4TnK-615n1P-attmzYTQAAAco"], referer: http://maxenengineering.com/WP
[Mon Jul 20 06:25:00.545885 2026] [security2:error] [pid 915741:tid 915931] [client 74.208.214.194:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TnK-615n1P-attmzYawAAAcs"]
[Mon Jul 20 06:25:00.642138 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.56:33008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXawAB7Xc"]
[Mon Jul 20 06:25:00.813381 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:52516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYgQAAAbc"]
[Mon Jul 20 06:25:00.823951 2026] [security2:error] [pid 915741:tid 915973] [client 35.233.110.193:52543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYhQAAAfU"]
[Mon Jul 20 06:25:00.905434 2026] [security2:error] [pid 915741:tid 915984] [client 216.73.216.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYgAAAAgA"], referer: https://www.effingweirdmuseums.com/sitemap.xml
[Mon Jul 20 06:25:01.072974 2026] [security2:error] [pid 915741:tid 915818] [remote 176.56.118.182:33576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tna-615n1P-attmzYnQABqUw"]
[Mon Jul 20 06:25:01.140182 2026] [security2:error] [pid 915741:tid 915920] [client 34.74.185.202:49938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tna-615n1P-attmzYogAAAcA"]
[Mon Jul 20 06:25:01.214402 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.126:63606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzXpAABlkk"]
[Mon Jul 20 06:25:01.237280 2026] [security2:error] [pid 915741:tid 915895] [client 14.225.17.146:62009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Tna-615n1P-attmzYoQAAAac"]
[Mon Jul 20 06:25:01.309673 2026] [security2:error] [pid 915741:tid 915864] [remote 176.56.118.182:33576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tna-615n1P-attmzYsAABono"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:01.349005 2026] [security2:error] [pid 915741:tid 915951] [client 14.225.17.146:56249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Tna-615n1P-attmzYrgAAAd8"], referer: https://maxenengineering.com/WP
[Mon Jul 20 06:25:01.445427 2026] [security2:error] [pid 915741:tid 915956] [client 35.233.110.193:61567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tna-615n1P-attmzYtgAAAeQ"]
[Mon Jul 20 06:25:01.560174 2026] [security2:error] [pid 915741:tid 915893] [client 34.73.38.214:50021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tna-615n1P-attmzYvAAAAaU"]
[Mon Jul 20 06:25:01.807016 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tna-615n1P-attmzY1AAAAaA"]
[Mon Jul 20 06:25:01.807131 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tna-615n1P-attmzY1AAAAaA"]
[Mon Jul 20 06:25:02.053716 2026] [security2:error] [pid 915741:tid 915887] [client 57.141.18.22:38612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzX5gABnxA"]
[Mon Jul 20 06:25:02.301907 2026] [security2:error] [pid 915741:tid 915939] [client 41.173.37.102:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tnq-615n1P-attmzZBgAAAdM"]
[Mon Jul 20 06:25:02.301994 2026] [security2:error] [pid 915741:tid 915939] [client 41.173.37.102:3193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tnq-615n1P-attmzZBgAAAdM"]
[Mon Jul 20 06:25:02.385110 2026] [security2:error] [pid 915741:tid 915872] [client 35.233.110.193:55877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tnq-615n1P-attmzZDwAAAZA"]
[Mon Jul 20 06:25:02.454261 2026] [security2:error] [pid 915741:tid 915956] [client 34.73.38.214:57221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tnq-615n1P-attmzZFgAAAeQ"]
[Mon Jul 20 06:25:02.514723 2026] [security2:error] [pid 915741:tid 915927] [client 57.141.18.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZDQAAAcc"]
[Mon Jul 20 06:25:02.665008 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZIgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:02.665164 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:62100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZIgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:02.812980 2026] [security2:error] [pid 915741:tid 915886] [client 187.94.223.220:33945] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZMwAAAZ4"]
[Mon Jul 20 06:25:03.010024 2026] [security2:error] [pid 915741:tid 915876] [client 14.225.17.146:62608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZPAAAAZQ"], referer: http://headachescarpaltunnelfibromyalgia.com/WP
[Mon Jul 20 06:25:03.016518 2026] [security2:error] [pid 915741:tid 915886] [client 187.94.223.220:33945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZMwAAAZ4"]
[Mon Jul 20 06:25:03.040051 2026] [security2:error] [pid 915741:tid 915940] [client 35.233.110.193:49719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tn6-615n1P-attmzZSwAAAdQ"]
[Mon Jul 20 06:25:03.073371 2026] [security2:error] [pid 915741:tid 915950] [client 77.110.127.138:62103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZJAAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:03.148664 2026] [security2:error] [pid 915741:tid 915939] [client 116.179.32.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZQQAAAdM"]
[Mon Jul 20 06:25:03.379013 2026] [security2:error] [pid 915741:tid 915896] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.llr.lqn.mybluehost.me"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZSQAAAag"]
[Mon Jul 20 06:25:03.452306 2026] [security2:error] [pid 915741:tid 915955] [client 57.141.18.22:38652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYdwAB4xc"]
[Mon Jul 20 06:25:03.478279 2026] [security2:error] [pid 915741:tid 915872] [client 3.85.191.173:23340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.191.85.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Tn6-615n1P-attmzZaQAAAZA"]
[Mon Jul 20 06:25:03.507737 2026] [security2:error] [pid 915741:tid 915897] [client 43.135.115.233:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.115.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/mcd/mcd_quiz.php"] [unique_id "al4Tn6-615n1P-attmzZagAAAak"]
[Mon Jul 20 06:25:03.513114 2026] [security2:error] [pid 915741:tid 915982] [client 57.141.18.13:48906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYeAAB_nQ"]
[Mon Jul 20 06:25:03.650226 2026] [security2:error] [pid 915741:tid 915938] [client 57.141.18.38:54324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYigAB0lI"]
[Mon Jul 20 06:25:03.694093 2026] [security2:error] [pid 915741:tid 915873] [client 98.159.234.160:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tn6-615n1P-attmzZfQAAAZE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:03.780224 2026] [security2:error] [pid 915741:tid 915940] [client 34.73.38.214:63186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tn6-615n1P-attmzZjAAAAdQ"]
[Mon Jul 20 06:25:03.948855 2026] [security2:error] [pid 915741:tid 915965] [client 14.225.17.146:64361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4Tn6-615n1P-attmzZlAAAAe0"], referer: http://nextlvlmarketingco.com/WP
[Mon Jul 20 06:25:03.988938 2026] [security2:error] [pid 915741:tid 915913] [client 35.233.110.193:51369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tn6-615n1P-attmzZmwAAAbk"]
[Mon Jul 20 06:25:04.461199 2026] [security2:error] [pid 915741:tid 915931] [client 3.85.28.216:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ToK-615n1P-attmzZwgAAAcs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:25:04.486983 2026] [security2:error] [pid 915741:tid 915872] [client 51.68.236.91:31857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "think-islam.com"] [uri "/robots.txt"] [unique_id "al4ToK-615n1P-attmzZygAAAZA"]
[Mon Jul 20 06:25:04.487120 2026] [security2:error] [pid 915741:tid 915872] [client 51.68.236.91:31857] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "think-islam.com"] [uri "/robots.txt"] [unique_id "al4ToK-615n1P-attmzZygAAAZA"]
[Mon Jul 20 06:25:04.592812 2026] [security2:error] [pid 915741:tid 915868] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ToK-615n1P-attmzZ1AAByn4"]
[Mon Jul 20 06:25:04.593016 2026] [security2:error] [pid 915741:tid 915930] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ToK-615n1P-attmzZ1AAByn4"]
[Mon Jul 20 06:25:04.809676 2026] [security2:error] [pid 915741:tid 915920] [client 57.141.18.21:48446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzY9QABwHI"]
[Mon Jul 20 06:25:04.832544 2026] [security2:error] [pid 915741:tid 915986] [client 34.73.38.214:53443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ToK-615n1P-attmzZ5wAAAgI"]
[Mon Jul 20 06:25:04.852088 2026] [security2:error] [pid 915741:tid 915926] [client 35.233.110.193:54888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ToK-615n1P-attmzZ6gAAAcY"]
[Mon Jul 20 06:25:04.875264 2026] [security2:error] [pid 915741:tid 915901] [client 57.141.18.39:25607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZBQABrXU"]
[Mon Jul 20 06:25:05.217031 2026] [security2:error] [pid 915741:tid 915976] [client 57.141.18.74:45588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZJQAB-Eo"]
[Mon Jul 20 06:25:05.460089 2026] [security2:error] [pid 915741:tid 915933] [client 223.185.13.213:6453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Toa-615n1P-attmzaDQAAAc0"]
[Mon Jul 20 06:25:05.460239 2026] [security2:error] [pid 915741:tid 915933] [client 223.185.13.213:6453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Toa-615n1P-attmzaDQAAAc0"]
[Mon Jul 20 06:25:05.642724 2026] [security2:error] [pid 915741:tid 915939] [client 35.233.110.193:61647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Toa-615n1P-attmzaFQAAAdM"]
[Mon Jul 20 06:25:05.803220 2026] [security2:error] [pid 915741:tid 915915] [client 34.73.38.214:60651] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Toa-615n1P-attmzaIAAAAbs"]
[Mon Jul 20 06:25:05.890792 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:62799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4Toa-615n1P-attmzaKAAAAd0"]
[Mon Jul 20 06:25:05.973241 2026] [security2:error] [pid 915741:tid 915982] [client 14.225.17.146:62111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4ToK-615n1P-attmzZtQAAAf4"], referer: http://swafforddetailing.com/WP
[Mon Jul 20 06:25:06.221318 2026] [security2:error] [pid 915741:tid 915928] [client 57.141.18.92:32852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tn6-615n1P-attmzZcgAByHk"]
[Mon Jul 20 06:25:06.286394 2026] [security2:error] [pid 915741:tid 915988] [client 104.234.53.83:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Toq-615n1P-attmzaSwAAAgQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:06.431868 2026] [security2:error] [pid 915741:tid 915881] [client 35.233.110.193:53619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Toq-615n1P-attmzaWwAAAZk"]
[Mon Jul 20 06:25:06.461045 2026] [security2:error] [pid 915741:tid 915814] [remote 72.167.132.114:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Toq-615n1P-attmzaXAAB3kg"]
[Mon Jul 20 06:25:06.557600 2026] [security2:error] [pid 915741:tid 915913] [client 57.141.18.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Toq-615n1P-attmzaWQAAAbk"]
[Mon Jul 20 06:25:06.641091 2026] [security2:error] [pid 915741:tid 915750] [remote 97.74.87.194:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4Toq-615n1P-attmzaZwAB4gg"]
[Mon Jul 20 06:25:06.641236 2026] [security2:error] [pid 915741:tid 915954] [client 97.74.87.194:54208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4Toq-615n1P-attmzaZwAB4gg"]
[Mon Jul 20 06:25:06.651248 2026] [security2:error] [pid 915741:tid 915953] [client 57.141.18.44:48044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ToK-615n1P-attmzZqgAB4RY"]
[Mon Jul 20 06:25:06.676269 2026] [security2:error] [pid 915741:tid 915877] [client 57.141.18.50:47646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ToK-615n1P-attmzZsAABlVM"]
[Mon Jul 20 06:25:06.704425 2026] [security2:error] [pid 915741:tid 915874] [client 34.73.38.214:59060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Toq-615n1P-attmzaawAAAZI"]
[Mon Jul 20 06:25:06.728224 2026] [security2:error] [pid 915741:tid 915774] [remote 72.167.132.114:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Toq-615n1P-attmzabAAByCA"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:25:06.835199 2026] [security2:error] [pid 915741:tid 915755] [remote 209.42.18.223:45788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Toq-615n1P-attmzacAABpA0"]
[Mon Jul 20 06:25:07.008219 2026] [security2:error] [pid 915741:tid 915897] [client 14.225.17.146:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4Toq-615n1P-attmzaeQAAAak"], referer: http://entuvy.com/WP
[Mon Jul 20 06:25:07.023012 2026] [security2:error] [pid 915741:tid 915955] [client 35.233.110.193:64926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4To6-615n1P-attmzahQAAAeM"]
[Mon Jul 20 06:25:07.026840 2026] [security2:error] [pid 915741:tid 915810] [remote 209.42.18.223:45788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4To6-615n1P-attmzagwAB3kQ"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:25:07.160795 2026] [security2:error] [pid 915741:tid 915866] [remote 173.249.4.11:29590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4To6-615n1P-attmzakwAB1nw"]
[Mon Jul 20 06:25:07.201781 2026] [proxy:error] [pid 915741:tid 915933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:07.201856 2026] [proxy_http:error] [pid 915741:tid 915933] [client 34.73.38.214:63251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:07.202447 2026] [proxy:error] [pid 915741:tid 915933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:07.202472 2026] [proxy_http:error] [pid 915741:tid 915933] [client 34.73.38.214:63251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:07.232052 2026] [security2:error] [pid 915741:tid 915873] [client 14.225.17.146:49240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzalQAAAZE"], referer: http://collectingrealestate.com/WP
[Mon Jul 20 06:25:07.298562 2026] [security2:error] [pid 915741:tid 915932] [client 104.234.53.94:45017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4To6-615n1P-attmzamQAAAcw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:07.368076 2026] [security2:error] [pid 915741:tid 915909] [client 178.20.43.173:50512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4To6-615n1P-attmzaoAAAAbU"], referer: https://retzkolonglogistics.com/
[Mon Jul 20 06:25:07.376312 2026] [security2:error] [pid 915741:tid 915830] [remote 173.249.4.11:29590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4To6-615n1P-attmzaoQABt1g"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:25:07.717586 2026] [security2:error] [pid 915741:tid 915988] [client 35.233.110.193:51935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4To6-615n1P-attmzauQAAAgQ"]
[Mon Jul 20 06:25:07.914209 2026] [security2:error] [pid 915741:tid 915890] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzawAAAAaI"]
[Mon Jul 20 06:25:08.076971 2026] [security2:error] [pid 915741:tid 915953] [client 50.116.65.227:46164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzazAAAAeE"]
[Mon Jul 20 06:25:08.214649 2026] [security2:error] [pid 915741:tid 915933] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.makeupyourskin.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzaxQAAAc0"]
[Mon Jul 20 06:25:08.286881 2026] [security2:error] [pid 915741:tid 915957] [client 50.116.65.227:46166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TpK-615n1P-attmza4AAAAeU"]
[Mon Jul 20 06:25:08.318592 2026] [security2:error] [pid 915741:tid 915946] [client 34.73.38.214:55675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TpK-615n1P-attmza7gAAAdo"]
[Mon Jul 20 06:25:08.333178 2026] [security2:error] [pid 915741:tid 915897] [client 35.233.110.193:62828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TpK-615n1P-attmza8QAAAak"]
[Mon Jul 20 06:25:08.926811 2026] [security2:error] [pid 915741:tid 915900] [client 171.60.139.123:54330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TpK-615n1P-attmzbHQAAAaw"]
[Mon Jul 20 06:25:08.926955 2026] [security2:error] [pid 915741:tid 915900] [client 171.60.139.123:54330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TpK-615n1P-attmzbHQAAAaw"]
[Mon Jul 20 06:25:08.992719 2026] [security2:error] [pid 915741:tid 915919] [client 57.141.18.123:53054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Toq-615n1P-attmzafwABvyM"]
[Mon Jul 20 06:25:09.108899 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.61:22194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzaiwABnSc"]
[Mon Jul 20 06:25:09.195993 2026] [security2:error] [pid 915741:tid 915941] [client 34.73.38.214:65247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tpa-615n1P-attmzbMAAAAdU"]
[Mon Jul 20 06:25:09.201217 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:09.201278 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:65407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:09.201853 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:09.201880 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:65407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:09.602873 2026] [security2:error] [pid 915741:tid 915881] [client 14.225.17.146:49482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4Tpa-615n1P-attmzbQwAAAZk"], referer: http://cheesewithjam.com/WP
[Mon Jul 20 06:25:10.172790 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.52:25876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TpK-615n1P-attmza4gAB7SI"]
[Mon Jul 20 06:25:10.261568 2026] [security2:error] [pid 915741:tid 915902] [client 14.225.17.146:49247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbZwAAAa4"], referer: http://nomorewetsheets.net/WP
[Mon Jul 20 06:25:10.571802 2026] [security2:error] [pid 915741:tid 915908] [client 103.141.108.143:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbmAAAAbQ"]
[Mon Jul 20 06:25:10.572993 2026] [security2:error] [pid 915741:tid 915908] [client 103.141.108.143:62656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbmAAAAbQ"]
[Mon Jul 20 06:25:10.722291 2026] [security2:error] [pid 915741:tid 915953] [client 103.153.183.69:1196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..\\\\/..\\\\/etc/passwd"] [unique_id "al4Tpq-615n1P-attmzbnwAAAeE"], referer: https://www.reddit.com/
[Mon Jul 20 06:25:10.802836 2026] [security2:error] [pid 915741:tid 915995] [client 77.110.127.138:62126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbkwAAAgs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:10.807451 2026] [security2:error] [pid 915741:tid 915875] [client 57.141.18.4:36546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TpK-615n1P-attmzbEwABkxw"]
[Mon Jul 20 06:25:10.824655 2026] [proxy:error] [pid 915741:tid 915996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:10.824735 2026] [proxy_http:error] [pid 915741:tid 915996] [client 34.73.38.214:61540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:10.825411 2026] [proxy:error] [pid 915741:tid 915996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:10.825454 2026] [proxy_http:error] [pid 915741:tid 915996] [client 34.73.38.214:61540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:10.848088 2026] [security2:error] [pid 915741:tid 915882] [client 34.73.38.214:58304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tpq-615n1P-attmzbpgAAAZo"]
[Mon Jul 20 06:25:10.861023 2026] [security2:error] [pid 915741:tid 915893] [client 45.116.69.230:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbqAAAAaU"]
[Mon Jul 20 06:25:10.861149 2026] [security2:error] [pid 915741:tid 915893] [client 45.116.69.230:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbqAAAAaU"]
[Mon Jul 20 06:25:11.071729 2026] [security2:error] [pid 915741:tid 915989] [client 14.225.17.146:59626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbrQAAAgU"], referer: http://709fx.com/WP
[Mon Jul 20 06:25:11.232293 2026] [security2:error] [pid 915741:tid 915972] [client 57.141.18.65:61246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tpa-615n1P-attmzbOgAB9Fk"]
[Mon Jul 20 06:25:11.270200 2026] [security2:error] [pid 915741:tid 915906] [client 77.110.127.138:62134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzbtwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:11.418481 2026] [proxy:error] [pid 915741:tid 915909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:11.418535 2026] [proxy_http:error] [pid 915741:tid 915909] [client 34.73.38.214:51285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:11.419512 2026] [proxy:error] [pid 915741:tid 915909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:11.419544 2026] [proxy_http:error] [pid 915741:tid 915909] [client 34.73.38.214:51285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:11.552319 2026] [security2:error] [pid 915741:tid 915951] [client 104.234.53.92:38319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tp6-615n1P-attmzb6wAAAd8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:11.824477 2026] [security2:error] [pid 915741:tid 915961] [client 57.141.18.12:54724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tpa-615n1P-attmzbXQAB6Wc"]
[Mon Jul 20 06:25:12.253155 2026] [security2:error] [pid 915741:tid 915983] [client 34.73.38.214:65206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TqK-615n1P-attmzcLwAAAf8"]
[Mon Jul 20 06:25:12.344761 2026] [security2:error] [pid 915741:tid 915957] [client 57.141.18.34:58730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbgwAB5Vo"]
[Mon Jul 20 06:25:12.534794 2026] [security2:error] [pid 915741:tid 915841] [remote 173.212.252.15:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4TqK-615n1P-attmzcQAABk2M"]
[Mon Jul 20 06:25:12.773489 2026] [security2:error] [pid 915741:tid 915890] [client 74.208.214.194:57160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TqK-615n1P-attmzcVQAAAaI"]
[Mon Jul 20 06:25:12.782363 2026] [security2:error] [pid 915741:tid 915918] [client 62.150.67.110:62782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4TqK-615n1P-attmzcKAAAAb4"]
[Mon Jul 20 06:25:12.792991 2026] [security2:error] [pid 915741:tid 915816] [remote 173.212.252.15:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4TqK-615n1P-attmzcVwABo0o"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:25:12.827809 2026] [security2:error] [pid 915741:tid 915881] [client 114.119.130.221:38643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/robots.txt"] [unique_id "al4TqK-615n1P-attmzcWQAAAZk"], referer: http://locketsandcharms.com/robots.txt
[Mon Jul 20 06:25:12.995167 2026] [security2:error] [pid 915741:tid 915984] [client 41.173.37.102:3605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TqK-615n1P-attmzcYwAAAgA"]
[Mon Jul 20 06:25:12.995279 2026] [security2:error] [pid 915741:tid 915984] [client 41.173.37.102:3605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TqK-615n1P-attmzcYwAAAgA"]
[Mon Jul 20 06:25:13.491679 2026] [security2:error] [pid 915741:tid 915983] [client 34.73.38.214:55708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tqa-615n1P-attmzchwAAAf8"]
[Mon Jul 20 06:25:13.552401 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzckAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:13.552513 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzckAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:13.591509 2026] [security2:error] [pid 915741:tid 915944] [client 14.225.17.146:54992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzcFAAAAdg"], referer: http://idigress.group/WP
[Mon Jul 20 06:25:13.649614 2026] [security2:error] [pid 915741:tid 915989] [client 57.141.18.22:27636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzb6AACBSQ"]
[Mon Jul 20 06:25:13.689046 2026] [security2:error] [pid 915741:tid 915885] [client 14.225.17.146:51217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcjQAAAZ0"], referer: http://solkeetw.com/WP
[Mon Jul 20 06:25:13.691399 2026] [security2:error] [pid 915741:tid 915995] [client 104.234.53.50:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Tqa-615n1P-attmzclwAAAgs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:13.703351 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzcmgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:13.703452 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzcmgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:14.028204 2026] [security2:error] [pid 915741:tid 915959] [client 57.141.18.112:20106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzcEgAB5xQ"]
[Mon Jul 20 06:25:14.166774 2026] [security2:error] [pid 915741:tid 915994] [client 77.110.127.138:62144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcjAAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:14.268687 2026] [security2:error] [pid 915741:tid 915807] [remote 103.75.185.95:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tqq-615n1P-attmzcyAABpkE"]
[Mon Jul 20 06:25:14.268978 2026] [security2:error] [pid 915741:tid 915894] [client 103.75.185.95:35396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tqq-615n1P-attmzcyAABpkE"]
[Mon Jul 20 06:25:15.018371 2026] [security2:error] [pid 915741:tid 915763] [remote 103.75.185.95:41072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4Tq6-615n1P-attmzdCQABwRU"]
[Mon Jul 20 06:25:15.042743 2026] [security2:error] [pid 915741:tid 915905] [client 57.141.18.33:48956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcbQABsRo"]
[Mon Jul 20 06:25:15.143283 2026] [security2:error] [pid 915741:tid 915958] [client 57.141.18.112:20112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcewAB5mY"]
[Mon Jul 20 06:25:15.187297 2026] [security2:error] [pid 915741:tid 915892] [client 45.157.112.60:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tq6-615n1P-attmzdEQAAAaQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:15.208253 2026] [security2:error] [pid 915741:tid 915989] [client 112.208.70.94:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tq6-615n1P-attmzdEgAAAgU"]
[Mon Jul 20 06:25:15.208364 2026] [security2:error] [pid 915741:tid 915989] [client 112.208.70.94:42586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tq6-615n1P-attmzdEgAAAgU"]
[Mon Jul 20 06:25:15.391963 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:62156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdJgAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:15.392109 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:62156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdJgAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:15.424506 2026] [security2:error] [pid 915741:tid 915932] [client 14.225.17.146:59450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4Tqq-615n1P-attmzcvQAAAcw"], referer: http://backandneckpainrelieflaceychiropractor.com/WP
[Mon Jul 20 06:25:15.478562 2026] [security2:error] [pid 915741:tid 915991] [client 34.73.38.214:55590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tq6-615n1P-attmzdMwAAAgc"]
[Mon Jul 20 06:25:15.487384 2026] [cgid:error] [pid 915741:tid 915877] [client 66.132.186.171:25792] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: http://www.smtracking.genesismbs.com:80/cgi-bin
[Mon Jul 20 06:25:15.538384 2026] [security2:error] [pid 915741:tid 915760] [remote 103.75.185.95:41072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4Tq6-615n1P-attmzdNQABkhI"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 06:25:15.866396 2026] [security2:error] [pid 915741:tid 915914] [client 62.197.45.116:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.45.197.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.maxenengineering.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdSgAAAbo"], referer: https://www.maxenengineering.com/complete-construction-equipment-under-one-roof/
[Mon Jul 20 06:25:15.866501 2026] [security2:error] [pid 915741:tid 915914] [client 62.197.45.116:53333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.maxenengineering.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdSgAAAbo"], referer: https://www.maxenengineering.com/complete-construction-equipment-under-one-roof/
[Mon Jul 20 06:25:16.035336 2026] [security2:error] [pid 915741:tid 915920] [client 34.73.38.214:53220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TrK-615n1P-attmzdWAAAAcA"]
[Mon Jul 20 06:25:16.070856 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.111:24068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqq-615n1P-attmzcxAAB7VM"]
[Mon Jul 20 06:25:16.155403 2026] [security2:error] [pid 915741:tid 915998] [client 57.141.18.4:36568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqq-615n1P-attmzc0gACDi4"]
[Mon Jul 20 06:25:16.218842 2026] [security2:error] [pid 915741:tid 915921] [client 50.116.65.227:58050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TrK-615n1P-attmzdYgAAAcE"]
[Mon Jul 20 06:25:16.228282 2026] [security2:error] [pid 915741:tid 915913] [client 50.116.65.227:58058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TrK-615n1P-attmzdYwAAAbk"]
[Mon Jul 20 06:25:16.446783 2026] [security2:error] [pid 915741:tid 915932] [client 185.132.186.96:48305] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "harborhealth.us"] [uri "/wordpress/wp-admin/includes/"] [unique_id "al4TrK-615n1P-attmzdegAAAcw"]
[Mon Jul 20 06:25:16.616493 2026] [security2:error] [pid 915741:tid 915993] [client 77.110.127.138:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdjAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.616593 2026] [security2:error] [pid 915741:tid 915993] [client 77.110.127.138:62159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdjAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767841 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlwAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767843 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767944 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:62161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlwAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767944 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.920574 2026] [security2:error] [pid 915741:tid 915808] [remote 100.42.189.89:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4TrK-615n1P-attmzdpwABlEI"]
[Mon Jul 20 06:25:16.935672 2026] [security2:error] [pid 915741:tid 915758] [remote 91.142.222.105:57132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4TrK-615n1P-attmzdpQABwRA"]
[Mon Jul 20 06:25:16.982721 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TrK-615n1P-attmzdnQAAAeQ"]
[Mon Jul 20 06:25:17.001453 2026] [security2:error] [pid 915741:tid 915933] [client 34.73.38.214:56882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tra-615n1P-attmzdrAAAAc0"]
[Mon Jul 20 06:25:17.168509 2026] [security2:error] [pid 915741:tid 915809] [remote 91.142.222.105:57132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4Tra-615n1P-attmzdswACDkM"], referer: https://blaizeaccountingservices.com/wp-login.php
[Mon Jul 20 06:25:17.175413 2026] [security2:error] [pid 915741:tid 915742] [remote 100.42.189.89:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4Tra-615n1P-attmzdtAAB1wA"], referer: https://royalart-lb.com/wp-login.php
[Mon Jul 20 06:25:17.448794 2026] [security2:error] [pid 915741:tid 915901] [client 14.225.17.146:58443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzdvAAAAa0"]
[Mon Jul 20 06:25:17.655387 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:62164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzdywAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:17.986148 2026] [security2:error] [pid 915741:tid 915976] [client 187.94.223.220:34189] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tra-615n1P-attmzd7wAAAfg"]
[Mon Jul 20 06:25:18.060114 2026] [security2:error] [pid 915741:tid 915953] [client 104.234.53.71:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Trq-615n1P-attmzd9AAAAeE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:18.145740 2026] [security2:error] [pid 915741:tid 915976] [client 187.94.223.220:34189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tra-615n1P-attmzd7wAAAfg"]
[Mon Jul 20 06:25:18.428650 2026] [core:error] [pid 915741:tid 915934] [client 14.225.17.146:58432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:18.428672 2026] [core:error] [pid 915741:tid 915934] [client 14.225.17.146:58432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:18.498167 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Trq-615n1P-attmzeHgAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:18.498283 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:62165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Trq-615n1P-attmzeHgAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:18.527101 2026] [security2:error] [pid 915741:tid 915912] [client 57.141.18.22:45698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TrK-615n1P-attmzdiwABuFE"]
[Mon Jul 20 06:25:18.711401 2026] [security2:error] [pid 915741:tid 915865] [remote 154.66.198.148:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4Trq-615n1P-attmzeKQACCns"]
[Mon Jul 20 06:25:18.929449 2026] [security2:error] [pid 915741:tid 915998] [client 14.225.17.146:51092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4Trq-615n1P-attmzeNQAAAg4"], referer: http://sarahholyfield.com/WP
[Mon Jul 20 06:25:19.076237 2026] [security2:error] [pid 915741:tid 915908] [client 57.141.18.14:47066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzdtgABtBg"]
[Mon Jul 20 06:25:19.142212 2026] [security2:error] [pid 915741:tid 915974] [client 34.73.38.214:50795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tr6-615n1P-attmzeWwAAAfY"]
[Mon Jul 20 06:25:19.243193 2026] [security2:error] [pid 915741:tid 915754] [remote 154.66.198.148:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4Tr6-615n1P-attmzeZQABzgw"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:25:19.550987 2026] [security2:error] [pid 915741:tid 915857] [remote 20.89.80.94:26824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4Tr6-615n1P-attmzegAAB7nM"]
[Mon Jul 20 06:25:19.570305 2026] [security2:error] [pid 915741:tid 915899] [client 14.225.17.146:58257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4Trq-615n1P-attmzeFgAAAas"], referer: http://idigress.agency/WP
[Mon Jul 20 06:25:19.688077 2026] [security2:error] [pid 915741:tid 915990] [client 171.60.139.123:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tr6-615n1P-attmzejQAAAgY"]
[Mon Jul 20 06:25:19.688389 2026] [security2:error] [pid 915741:tid 915990] [client 171.60.139.123:54850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tr6-615n1P-attmzejQAAAgY"]
[Mon Jul 20 06:25:19.919994 2026] [security2:error] [pid 915741:tid 915777] [remote 20.89.80.94:26824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4Tr6-615n1P-attmzeoQAB9iM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:25:19.951948 2026] [security2:error] [pid 915741:tid 915971] [client 57.141.18.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Tr6-615n1P-attmzemQAAAfM"]
[Mon Jul 20 06:25:20.100328 2026] [security2:error] [pid 915741:tid 915993] [client 14.225.17.146:63740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzd8wAAAgk"], referer: http://www.justinagrayman.com/WP
[Mon Jul 20 06:25:20.259513 2026] [security2:error] [pid 915741:tid 915987] [client 34.73.38.214:53476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TsK-615n1P-attmzewQAAAgM"]
[Mon Jul 20 06:25:20.396740 2026] [security2:error] [pid 915741:tid 915894] [client 104.234.53.50:47959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TsK-615n1P-attmzezQAAAaY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:20.589551 2026] [security2:error] [pid 915741:tid 915896] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4TsK-615n1P-attmze0gAAAag"]
[Mon Jul 20 06:25:20.661622 2026] [security2:error] [pid 915741:tid 915819] [remote 81.173.115.7:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TsK-615n1P-attmze4wACCE0"]
[Mon Jul 20 06:25:21.378466 2026] [security2:error] [pid 915741:tid 915759] [remote 57.141.18.49:33050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tr6-615n1P-attmzeegABkhE"]
[Mon Jul 20 06:25:21.519581 2026] [http2:info] [pid 925208:tid 925208] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:25:21.542959 2026] [security2:error] [pid 925208:tid 925347] [client 34.73.38.214:60324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TscRX7OrFkv0FyuIMkwAAAAk"]
[Mon Jul 20 06:25:21.565850 2026] [security2:error] [pid 915741:tid 915989] [client 57.141.18.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4Trq-615n1P-attmzeMgAAAgU"]
[Mon Jul 20 06:25:21.591422 2026] [security2:error] [pid 925208:tid 925359] [client 54.244.177.189:32636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4TscRX7OrFkv0FyuIMpAAAABU"]
[Mon Jul 20 06:25:21.591423 2026] [security2:error] [pid 925208:tid 925363] [client 34.221.76.50:65156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4TscRX7OrFkv0FyuIMowAAABk"]
[Mon Jul 20 06:25:21.803506 2026] [security2:error] [pid 925208:tid 925348] [client 103.141.108.143:63120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM1gAAAAo"]
[Mon Jul 20 06:25:21.803726 2026] [security2:error] [pid 925208:tid 925348] [client 103.141.108.143:63120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM1gAAAAo"]
[Mon Jul 20 06:25:21.853299 2026] [security2:error] [pid 925208:tid 925449] [client 34.73.38.214:50574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TscRX7OrFkv0FyuIM3AAAAG8"]
[Mon Jul 20 06:25:21.862925 2026] [security2:error] [pid 925208:tid 925371] [client 45.116.69.230:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM3wAAACE"]
[Mon Jul 20 06:25:21.863084 2026] [security2:error] [pid 925208:tid 925371] [client 45.116.69.230:63506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM3wAAACE"]
[Mon Jul 20 06:25:21.867304 2026] [security2:error] [pid 925208:tid 925239] [remote 81.173.115.7:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TscRX7OrFkv0FyuIM4AAADh4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:25:21.942195 2026] [security2:error] [pid 915741:tid 915839] [remote 57.141.18.49:33054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tr6-615n1P-attmzeqQABumE"]
[Mon Jul 20 06:25:22.180115 2026] [security2:error] [pid 925208:tid 925423] [client 185.68.184.237:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.184.68.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuIM-AAAAFU"], referer: https://amberhillstyle.com/cgi-sys/suspendedpage.cgi
[Mon Jul 20 06:25:22.180143 2026] [security2:error] [pid 925208:tid 925249] [remote 38.242.157.30:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4TssRX7OrFkv0FyuIM-QAAHyg"]
[Mon Jul 20 06:25:22.201038 2026] [security2:error] [pid 925208:tid 925356] [client 187.94.223.220:34269] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TssRX7OrFkv0FyuIM-wAAABI"]
[Mon Jul 20 06:25:22.370141 2026] [security2:error] [pid 925208:tid 925356] [client 187.94.223.220:34269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TssRX7OrFkv0FyuIM-wAAABI"]
[Mon Jul 20 06:25:22.501352 2026] [security2:error] [pid 925208:tid 925262] [remote 38.242.157.30:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4TssRX7OrFkv0FyuINEgAABjU"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:25:22.759001 2026] [security2:error] [pid 925208:tid 925373] [client 34.73.38.214:61840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TssRX7OrFkv0FyuINHwAAACM"]
[Mon Jul 20 06:25:22.779679 2026] [security2:error] [pid 925208:tid 925362] [client 104.234.53.55:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TssRX7OrFkv0FyuINIAAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:23.314406 2026] [security2:error] [pid 925208:tid 925401] [client 43.135.107.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Ts8RX7OrFkv0FyuINTwAAAD8"]
[Mon Jul 20 06:25:23.573481 2026] [security2:error] [pid 925208:tid 925458] [client 41.173.37.102:3814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINaAAAAHg"]
[Mon Jul 20 06:25:23.573565 2026] [security2:error] [pid 925208:tid 925458] [client 41.173.37.102:3814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINaAAAAHg"]
[Mon Jul 20 06:25:23.726392 2026] [security2:error] [pid 925208:tid 925355] [client 57.141.18.110:51426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TscRX7OrFkv0FyuIMngAAEQU"]
[Mon Jul 20 06:25:23.770987 2026] [security2:error] [pid 925208:tid 925424] [client 34.73.38.214:53151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ts8RX7OrFkv0FyuINdQAAAFY"]
[Mon Jul 20 06:25:23.898475 2026] [security2:error] [pid 925208:tid 925306] [remote 72.167.132.114:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINeAAAUWE"]
[Mon Jul 20 06:25:23.898697 2026] [security2:error] [pid 925208:tid 925419] [client 72.167.132.114:43804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINeAAAUWE"]
[Mon Jul 20 06:25:23.973235 2026] [security2:error] [pid 925208:tid 925453] [client 57.141.18.109:31008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TscRX7OrFkv0FyuIM6AAAcyE"]
[Mon Jul 20 06:25:24.076500 2026] [security2:error] [pid 925208:tid 925361] [client 57.141.18.88:40810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TscRX7OrFkv0FyuIM8gAAFyU"]
[Mon Jul 20 06:25:24.097912 2026] [security2:error] [pid 925208:tid 925317] [remote 192.241.143.148:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TtMRX7OrFkv0FyuINkQAACGw"]
[Mon Jul 20 06:25:24.308516 2026] [security2:error] [pid 925208:tid 925324] [remote 192.241.143.148:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TtMRX7OrFkv0FyuINpgAAInM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:24.578267 2026] [security2:error] [pid 925208:tid 925331] [remote 15.206.251.117:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TtMRX7OrFkv0FyuINtwAAHHo"]
[Mon Jul 20 06:25:24.764494 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TtMRX7OrFkv0FyuINwAAALn0"], referer: http://aleishapenny.ca/WP
[Mon Jul 20 06:25:24.771155 2026] [security2:error] [pid 925208:tid 925408] [client 146.75.222.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuINKgAAAEY"]
[Mon Jul 20 06:25:24.913456 2026] [security2:error] [pid 925208:tid 925358] [client 57.141.18.91:41938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuINKQAAFEA"]
[Mon Jul 20 06:25:24.928372 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.110:51440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuINLQAATkI"]
[Mon Jul 20 06:25:25.061438 2026] [security2:error] [pid 925208:tid 925396] [client 57.141.18.50:64466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ts8RX7OrFkv0FyuINQAAAOkg"]
[Mon Jul 20 06:25:25.156805 2026] [security2:error] [pid 925208:tid 925220] [remote 15.206.251.117:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TtcRX7OrFkv0FyuIN4wAABgs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:25:25.267962 2026] [security2:error] [pid 925208:tid 925457] [client 14.225.17.146:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIN4AAAAHc"], referer: http://ncsynchro.com/WP
[Mon Jul 20 06:25:25.288125 2026] [security2:error] [pid 925208:tid 925341] [client 57.141.18.49:33062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ts8RX7OrFkv0FyuINUQAAA04"]
[Mon Jul 20 06:25:25.297820 2026] [proxy:error] [pid 925208:tid 925401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.297857 2026] [proxy_http:error] [pid 925208:tid 925401] [client 205.210.31.2:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.298275 2026] [proxy:error] [pid 925208:tid 925401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.298296 2026] [proxy_http:error] [pid 925208:tid 925401] [client 205.210.31.2:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.298987 2026] [proxy:error] [pid 925208:tid 925386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.299095 2026] [proxy_http:error] [pid 925208:tid 925386] [client 205.210.31.2:60950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.300223 2026] [proxy:error] [pid 925208:tid 925386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.300262 2026] [proxy_http:error] [pid 925208:tid 925386] [client 205.210.31.2:60950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.514553 2026] [security2:error] [pid 925208:tid 925365] [client 87.199.196.160:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.justinagrayman.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOBgAAABs"], referer: https://www.justinagrayman.com/bw-2/
[Mon Jul 20 06:25:25.514688 2026] [security2:error] [pid 925208:tid 925365] [client 87.199.196.160:52830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.justinagrayman.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOBgAAABs"], referer: https://www.justinagrayman.com/bw-2/
[Mon Jul 20 06:25:25.536039 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOCgAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.536130 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:62167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOCgAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.659835 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIODAAALhg"], referer: https://aleishapenny.ca/WP
[Mon Jul 20 06:25:25.707622 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOIwAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.707740 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOIwAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.834484 2026] [security2:error] [pid 925208:tid 925344] [client 74.7.227.179:42498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIOIQAABis"], referer: https://tejasenvironmental.com/p=894903
[Mon Jul 20 06:25:25.927985 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOMQAAAD8"]
[Mon Jul 20 06:25:25.928091 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:62201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOMQAAAD8"]
[Mon Jul 20 06:25:26.039823 2026] [security2:error] [pid 925208:tid 925263] [remote 5.161.225.162:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TtsRX7OrFkv0FyuIOOQAABzY"]
[Mon Jul 20 06:25:26.204990 2026] [security2:error] [pid 925208:tid 925465] [client 57.141.18.33:29378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtMRX7OrFkv0FyuINkwAAf20"]
[Mon Jul 20 06:25:26.312861 2026] [security2:error] [pid 925208:tid 925274] [remote 5.161.225.162:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TtsRX7OrFkv0FyuIOTAAAIkE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:26.539192 2026] [security2:error] [pid 925208:tid 925405] [client 77.110.127.138:62196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIOEwAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:26.824302 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOcwAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:26.824418 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOcwAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:26.843527 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TtsRX7OrFkv0FyuIOdgAAADg"]
[Mon Jul 20 06:25:26.843635 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:32560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TtsRX7OrFkv0FyuIOdgAAADg"]
[Mon Jul 20 06:25:26.880455 2026] [security2:error] [pid 925208:tid 925409] [client 45.217.95.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOawAAAEc"]
[Mon Jul 20 06:25:26.926826 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOfAAAACk"]
[Mon Jul 20 06:25:26.926945 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOfAAAACk"]
[Mon Jul 20 06:25:27.158068 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOegAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:27.174095 2026] [security2:error] [pid 925208:tid 925414] [client 150.109.154.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOggAATFo"], referer: https://www.aleishapenny.ca/listing/page/132?view=list&paged=1&posts_per_page=24
[Mon Jul 20 06:25:27.201229 2026] [security2:error] [pid 925208:tid 925464] [client 57.141.18.123:27104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIN5AAAfhQ"]
[Mon Jul 20 06:25:27.320615 2026] [security2:error] [pid 925208:tid 925392] [client 112.208.70.94:42989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOpwAAADY"]
[Mon Jul 20 06:25:27.320821 2026] [security2:error] [pid 925208:tid 925392] [client 112.208.70.94:42989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOpwAAADY"]
[Mon Jul 20 06:25:27.321936 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:64207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOnQAAAE0"], referer: http://maplerespiteservices.com/WP
[Mon Jul 20 06:25:27.425509 2026] [security2:error] [pid 925208:tid 925434] [client 57.141.18.42:24576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIN9AAAYBw"]
[Mon Jul 20 06:25:27.488941 2026] [security2:error] [pid 925208:tid 925301] [remote 81.173.115.7:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOtQAASlw"]
[Mon Jul 20 06:25:27.516407 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOuAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:27.516507 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOuAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:27.702900 2026] [security2:error] [pid 925208:tid 925313] [remote 81.173.115.7:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOwwAAT2g"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:25:27.760464 2026] [security2:error] [pid 925208:tid 925390] [client 14.225.17.146:64362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOPAAAADQ"], referer: http://secretkeynumerology.com/WP
[Mon Jul 20 06:25:27.761591 2026] [security2:error] [pid 925208:tid 925442] [client 13.201.64.214:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOxgAAAGg"]
[Mon Jul 20 06:25:27.761685 2026] [security2:error] [pid 925208:tid 925442] [client 13.201.64.214:56336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOxgAAAGg"]
[Mon Jul 20 06:25:27.884698 2026] [security2:error] [pid 925208:tid 925465] [client 158.173.166.181:22261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOzQAAAH8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:28.103248 2026] [security2:error] [pid 925208:tid 925333] [remote 5.161.225.162:38266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIO3wAALnw"]
[Mon Jul 20 06:25:28.268663 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIO6wAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.268800 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIO6wAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.324794 2026] [security2:error] [pid 925208:tid 925273] [remote 5.161.225.162:38266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIO9AAACkA"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:25:28.457265 2026] [security2:error] [pid 925208:tid 925227] [remote 20.153.140.50:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIPAgAAFBI"]
[Mon Jul 20 06:25:28.483764 2026] [security2:error] [pid 925208:tid 925440] [client 57.141.18.103:31888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOVQAAZkc"]
[Mon Jul 20 06:25:28.520413 2026] [security2:error] [pid 925208:tid 925395] [client 192.178.16.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4Tt8RX7OrFkv0FyuIO1wAAOXQ"], referer: https://packerjanitorial.com/checkout/order-pay/34096/
[Mon Jul 20 06:25:28.637270 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPDQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.637373 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPDQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.786738 2026] [security2:error] [pid 925208:tid 925441] [client 14.225.17.146:58599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TuMRX7OrFkv0FyuIPCAAAAGc"], referer: https://secretkeynumerology.com/WP
[Mon Jul 20 06:25:28.843786 2026] [security2:error] [pid 925208:tid 925347] [client 14.225.17.146:58665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4TuMRX7OrFkv0FyuIPGQAAAAk"]
[Mon Jul 20 06:25:28.853434 2026] [security2:error] [pid 925208:tid 925221] [remote 20.153.140.50:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIPIgAAKQw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:25:28.870694 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPJgAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.870804 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPJgAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.144313 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPPgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.144404 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPPgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.430692 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:62219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TucRX7OrFkv0FyuIPRAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.549428 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPYQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.549523 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPYQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.736788 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPdwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.736895 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPdwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.744544 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:58565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4TuMRX7OrFkv0FyuIO7AAAACM"]
[Mon Jul 20 06:25:30.121704 2026] [security2:error] [pid 925208:tid 925401] [client 34.74.185.202:50225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4TusRX7OrFkv0FyuIPlAAAAD8"]
[Mon Jul 20 06:25:30.401568 2026] [security2:error] [pid 925208:tid 925454] [client 77.110.127.138:62227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPqgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.401668 2026] [security2:error] [pid 925208:tid 925454] [client 77.110.127.138:62227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPqgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.537296 2026] [security2:error] [pid 925208:tid 925449] [client 171.60.139.123:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TusRX7OrFkv0FyuIPtQAAAG8"]
[Mon Jul 20 06:25:30.537408 2026] [security2:error] [pid 925208:tid 925449] [client 171.60.139.123:55366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TusRX7OrFkv0FyuIPtQAAAG8"]
[Mon Jul 20 06:25:30.539869 2026] [security2:error] [pid 925208:tid 925437] [client 34.74.185.202:57311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TusRX7OrFkv0FyuIPtgAAAGM"]
[Mon Jul 20 06:25:30.569872 2026] [security2:error] [pid 925208:tid 925339] [client 187.94.223.220:34390] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPuQAAAAE"]
[Mon Jul 20 06:25:30.665803 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:58591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4TusRX7OrFkv0FyuIPtwAAACM"], referer: http://effingweirdmuseums.com/WP
[Mon Jul 20 06:25:30.714682 2026] [security2:error] [pid 925208:tid 925339] [client 187.94.223.220:34390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPuQAAAAE"]
[Mon Jul 20 06:25:30.747507 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPwgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.747600 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPwgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.819635 2026] [security2:error] [pid 925208:tid 925418] [client 34.74.185.202:56629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TusRX7OrFkv0FyuIPyQAAAFA"]
[Mon Jul 20 06:25:30.832441 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPygAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.832604 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPygAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:31.151563 2026] [security2:error] [pid 925208:tid 925365] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TusRX7OrFkv0FyuIP4QAAABs"]
[Mon Jul 20 06:25:31.175809 2026] [security2:error] [pid 925208:tid 925409] [client 136.107.64.51:54419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sgmachinehouston.com"] [uri "/xmlrpc.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP6QAAAEc"]
[Mon Jul 20 06:25:31.175910 2026] [security2:error] [pid 925208:tid 925409] [client 136.107.64.51:54419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sgmachinehouston.com"] [uri "/xmlrpc.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP6QAAAEc"]
[Mon Jul 20 06:25:31.214205 2026] [security2:error] [pid 925208:tid 925430] [client 34.74.185.202:61508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tu8RX7OrFkv0FyuIP6wAAAFw"]
[Mon Jul 20 06:25:31.536617 2026] [security2:error] [pid 925208:tid 925427] [client 14.225.17.146:58514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP5QAAAFk"]
[Mon Jul 20 06:25:31.571846 2026] [security2:error] [pid 925208:tid 925399] [client 14.225.17.146:59235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Tu8RX7OrFkv0FyuIQBwAAAD0"], referer: https://effingweirdmuseums.com/WP
[Mon Jul 20 06:25:31.883976 2026] [security2:error] [pid 925208:tid 925338] [client 34.74.185.202:54101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tu8RX7OrFkv0FyuIQLAAAAAA"]
[Mon Jul 20 06:25:32.015707 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQNwAAACc"]
[Mon Jul 20 06:25:32.016781 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:63594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQNwAAACc"]
[Mon Jul 20 06:25:32.317913 2026] [security2:error] [pid 925208:tid 925358] [client 45.116.69.230:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQRQAAABQ"]
[Mon Jul 20 06:25:32.318111 2026] [security2:error] [pid 925208:tid 925358] [client 45.116.69.230:64028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQRQAAABQ"]
[Mon Jul 20 06:25:32.422180 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQSgAAAD8"]
[Mon Jul 20 06:25:32.422345 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:3988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQSgAAAD8"]
[Mon Jul 20 06:25:32.572571 2026] [security2:error] [pid 925208:tid 925465] [client 14.225.17.146:58925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP5wAAAH8"], referer: http://tntcatholic.com/WP
[Mon Jul 20 06:25:32.758292 2026] [security2:error] [pid 925208:tid 925396] [client 34.74.185.202:52886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TvMRX7OrFkv0FyuIQcAAAADo"]
[Mon Jul 20 06:25:32.847990 2026] [security2:error] [pid 925208:tid 925394] [client 14.225.17.146:57805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQaQAAADg"], referer: http://longevityperformanceclinic.com/WP
[Mon Jul 20 06:25:33.395803 2026] [security2:error] [pid 925208:tid 925341] [client 34.74.185.202:49938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TvcRX7OrFkv0FyuIQpAAAAAM"]
[Mon Jul 20 06:25:34.075872 2026] [security2:error] [pid 925208:tid 925409] [client 14.225.17.146:57250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQegAAAEc"], referer: http://christiancountytrumpet.com/WP
[Mon Jul 20 06:25:34.240967 2026] [security2:error] [pid 925208:tid 925375] [client 57.141.18.66:29270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQQgAAJX4"]
[Mon Jul 20 06:25:34.243596 2026] [security2:error] [pid 925208:tid 925347] [client 34.74.185.202:54005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TvsRX7OrFkv0FyuIQ5AAAAAk"]
[Mon Jul 20 06:25:34.296252 2026] [security2:error] [pid 925208:tid 925374] [client 104.234.53.55:25607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TvsRX7OrFkv0FyuIQ5gAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:34.309188 2026] [core:error] [pid 925208:tid 925446] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.309217 2026] [core:error] [pid 925208:tid 925446] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339692 2026] [core:error] [pid 925208:tid 925359] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339724 2026] [core:error] [pid 925208:tid 925359] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339797 2026] [core:error] [pid 925208:tid 925356] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339816 2026] [core:error] [pid 925208:tid 925356] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.341147 2026] [core:error] [pid 925208:tid 925400] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.341164 2026] [core:error] [pid 925208:tid 925400] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.354609 2026] [core:error] [pid 925208:tid 925457] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.354626 2026] [core:error] [pid 925208:tid 925457] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.549256 2026] [security2:error] [pid 925208:tid 925342] [client 57.141.18.8:29988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQTwAABEI"]
[Mon Jul 20 06:25:34.558739 2026] [security2:error] [pid 925208:tid 925285] [remote 81.173.115.7:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4TvsRX7OrFkv0FyuIRFgAAb0w"]
[Mon Jul 20 06:25:34.565838 2026] [security2:error] [pid 925208:tid 925392] [client 34.74.185.202:53998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TvsRX7OrFkv0FyuIRGgAAADY"]
[Mon Jul 20 06:25:34.793699 2026] [security2:error] [pid 925208:tid 925289] [remote 81.173.115.7:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4TvsRX7OrFkv0FyuIRJwAADlA"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:25:34.917646 2026] [security2:error] [pid 925208:tid 925463] [client 74.208.214.194:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TvsRX7OrFkv0FyuIRLgAAAH0"]
[Mon Jul 20 06:25:34.953963 2026] [security2:error] [pid 925208:tid 925406] [client 14.225.17.146:64058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4TvcRX7OrFkv0FyuIQsQAAAEQ"], referer: http://carolinapressurewashers.com/WP
[Mon Jul 20 06:25:35.017475 2026] [security2:error] [pid 925208:tid 925302] [remote 124.55.178.99:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRNwAAI10"]
[Mon Jul 20 06:25:35.113708 2026] [security2:error] [pid 925208:tid 925418] [client 34.74.185.202:54968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tv8RX7OrFkv0FyuIRSAAAAFA"]
[Mon Jul 20 06:25:35.436457 2026] [security2:error] [pid 925208:tid 925405] [client 14.225.17.146:57568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRSwAAAEM"]
[Mon Jul 20 06:25:35.461318 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRRAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.469640 2026] [security2:error] [pid 925208:tid 925316] [remote 124.55.178.99:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRYwAAKGs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:35.641917 2026] [security2:error] [pid 925208:tid 925330] [remote 87.106.67.224:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRcgAAd3k"]
[Mon Jul 20 06:25:35.734888 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRegAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.735007 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRegAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.878895 2026] [security2:error] [pid 925208:tid 925328] [remote 87.106.67.224:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRjAAAKHc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:25:35.903649 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRkwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.903746 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRkwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:36.117343 2026] [security2:error] [pid 925208:tid 925363] [client 14.225.17.146:59074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4TvsRX7OrFkv0FyuIRKgAAABk"], referer: http://oldracelimited.com/WP
[Mon Jul 20 06:25:36.496607 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:59017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIRsQAAACM"], referer: http://falconarrowshop.com/WP
[Mon Jul 20 06:25:36.542666 2026] [security2:error] [pid 925208:tid 925351] [client 34.74.185.202:53570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TwMRX7OrFkv0FyuIRzgAAAA0"]
[Mon Jul 20 06:25:36.713384 2026] [security2:error] [pid 925208:tid 925433] [client 14.224.227.113:55746] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4TwMRX7OrFkv0FyuIR3QAAAF8"]
[Mon Jul 20 06:25:37.040293 2026] [security2:error] [pid 925208:tid 925408] [client 34.74.185.202:53742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TwcRX7OrFkv0FyuIR7wAAAEY"]
[Mon Jul 20 06:25:37.089015 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62261] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4TwcRX7OrFkv0FyuIR8wAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:37.101553 2026] [security2:error] [pid 925208:tid 925435] [client 66.249.68.169:63936] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.bokkunst.com"] [uri "/robots.txt"] [unique_id "al4TwcRX7OrFkv0FyuIR9AAAAGE"]
[Mon Jul 20 06:25:37.185048 2026] [security2:error] [pid 925208:tid 925404] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TwcRX7OrFkv0FyuIR8QAAAEI"]
[Mon Jul 20 06:25:37.404038 2026] [security2:error] [pid 925208:tid 925252] [remote 57.141.18.2:23098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3480050"] [unique_id "al4TwcRX7OrFkv0FyuISAQAAYys"]
[Mon Jul 20 06:25:37.417624 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TwcRX7OrFkv0FyuISBAAAAC0"]
[Mon Jul 20 06:25:37.417726 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:26543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TwcRX7OrFkv0FyuISBAAAAC0"]
[Mon Jul 20 06:25:37.854303 2026] [security2:error] [pid 925208:tid 925395] [client 57.141.18.96:23932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRjQAAOT4"]
[Mon Jul 20 06:25:38.011520 2026] [security2:error] [pid 925208:tid 925423] [client 14.225.17.146:58920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIR3wAAAFU"], referer: http://whiteoutcb.com/WP
[Mon Jul 20 06:25:38.186395 2026] [security2:error] [pid 925208:tid 925420] [client 158.173.89.95:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TwsRX7OrFkv0FyuISSQAAAFI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:38.202715 2026] [security2:error] [pid 925208:tid 925355] [client 57.141.18.109:21088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIRsAAAEQ0"]
[Mon Jul 20 06:25:38.230622 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISTwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.230727 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISTwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.383398 2026] [security2:error] [pid 925208:tid 925381] [client 77.110.127.138:62267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISVAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.383535 2026] [security2:error] [pid 925208:tid 925381] [client 77.110.127.138:62267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISVAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.503243 2026] [security2:error] [pid 925208:tid 925441] [client 34.74.185.202:53581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TwsRX7OrFkv0FyuISXAAAAGc"]
[Mon Jul 20 06:25:38.647132 2026] [security2:error] [pid 925208:tid 925429] [client 14.225.17.146:57423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIR2AAAAFs"], referer: http://itdynamix.com/WP
[Mon Jul 20 06:25:39.457827 2026] [security2:error] [pid 925208:tid 925386] [client 91.92.41.115:50659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "darkknightsolutions.com"] [uri "/.env"] [unique_id "al4Tw8RX7OrFkv0FyuISogAAADA"]
[Mon Jul 20 06:25:39.729243 2026] [security2:error] [pid 925208:tid 925414] [client 14.225.17.146:57147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Tw8RX7OrFkv0FyuISrAAAAEw"], referer: https://itdynamix.com/WP
[Mon Jul 20 06:25:40.269917 2026] [security2:error] [pid 925208:tid 925362] [client 112.208.70.94:43398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TxMRX7OrFkv0FyuIS1AAAABg"]
[Mon Jul 20 06:25:40.270055 2026] [security2:error] [pid 925208:tid 925362] [client 112.208.70.94:43398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TxMRX7OrFkv0FyuIS1AAAABg"]
[Mon Jul 20 06:25:40.327697 2026] [security2:error] [pid 925208:tid 925375] [client 14.225.17.146:57114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4Tw8RX7OrFkv0FyuISnwAAACU"], referer: http://claysharecon.com/WP
[Mon Jul 20 06:25:40.845525 2026] [security2:error] [pid 925208:tid 925245] [remote 147.50.252.213:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxMRX7OrFkv0FyuITAgAAKyQ"]
[Mon Jul 20 06:25:41.303975 2026] [security2:error] [pid 925208:tid 925235] [remote 147.50.252.213:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxcRX7OrFkv0FyuITHwAAIho"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:41.376470 2026] [security2:error] [pid 925208:tid 925436] [client 77.110.127.138:62277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4TxcRX7OrFkv0FyuITLAAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:41.555103 2026] [security2:error] [pid 925208:tid 925408] [client 14.225.17.146:57644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4TxMRX7OrFkv0FyuIS0wAAAEY"], referer: http://elitetax-mi.com/WP
[Mon Jul 20 06:25:41.651450 2026] [security2:error] [pid 925208:tid 925385] [client 171.60.139.123:55888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TxcRX7OrFkv0FyuITQAAAAC8"]
[Mon Jul 20 06:25:41.651567 2026] [security2:error] [pid 925208:tid 925385] [client 171.60.139.123:55888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TxcRX7OrFkv0FyuITQAAAAC8"]
[Mon Jul 20 06:25:41.733285 2026] [security2:error] [pid 925208:tid 925324] [remote 81.173.115.7:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxcRX7OrFkv0FyuITRgAAaXM"]
[Mon Jul 20 06:25:41.949691 2026] [security2:error] [pid 925208:tid 925279] [remote 81.173.115.7:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxcRX7OrFkv0FyuITWQAAK0Y"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:42.165798 2026] [security2:error] [pid 925208:tid 925439] [client 14.225.17.146:57677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4TxMRX7OrFkv0FyuITBgAAAGU"], referer: http://iagdevelopments.com/WP
[Mon Jul 20 06:25:42.434664 2026] [security2:error] [pid 925208:tid 925396] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4TxsRX7OrFkv0FyuITdgAAADo"]
[Mon Jul 20 06:25:42.436424 2026] [security2:error] [pid 925208:tid 925400] [client 74.7.175.191:45488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phillipbloch.com"] [uri "/robots.txt"] [unique_id "al4TxsRX7OrFkv0FyuITcwAAPj0"]
[Mon Jul 20 06:25:42.549640 2026] [security2:error] [pid 925208:tid 925351] [client 62.150.67.110:63683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4TxcRX7OrFkv0FyuITWwAAAA0"]
[Mon Jul 20 06:25:42.637649 2026] [security2:error] [pid 925208:tid 925431] [client 57.141.18.15:20246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TxMRX7OrFkv0FyuITBAAAXSc"]
[Mon Jul 20 06:25:42.818436 2026] [security2:error] [pid 925208:tid 925401] [client 68.235.52.68:54442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmAAAAD8"]
[Mon Jul 20 06:25:42.818549 2026] [security2:error] [pid 925208:tid 925401] [client 68.235.52.68:54442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmAAAAD8"]
[Mon Jul 20 06:25:42.832718 2026] [security2:error] [pid 925208:tid 925354] [client 77.110.127.138:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TxsRX7OrFkv0FyuITmQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:42.832826 2026] [security2:error] [pid 925208:tid 925354] [client 77.110.127.138:62281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TxsRX7OrFkv0FyuITmQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:42.836715 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmwAAACc"]
[Mon Jul 20 06:25:42.837036 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:64061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmwAAACc"]
[Mon Jul 20 06:25:42.853400 2026] [security2:error] [pid 925208:tid 925302] [remote 97.74.93.24:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4TxsRX7OrFkv0FyuITnAAAM10"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:25:43.056187 2026] [security2:error] [pid 925208:tid 925361] [client 45.116.69.230:64541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuITtAAAABc"]
[Mon Jul 20 06:25:43.056283 2026] [security2:error] [pid 925208:tid 925361] [client 45.116.69.230:64541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuITtAAAABc"]
[Mon Jul 20 06:25:43.095846 2026] [security2:error] [pid 925208:tid 925460] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuITrgAAAHo"], referer: https://iagdevelopments.com/WP
[Mon Jul 20 06:25:43.473034 2026] [security2:error] [pid 925208:tid 925333] [remote 103.118.29.185:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT1QAAYXw"]
[Mon Jul 20 06:25:43.512806 2026] [security2:error] [pid 925208:tid 925434] [client 14.225.17.146:49655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT0AAAAGA"], referer: http://friendlyspreadsheet.com/WP
[Mon Jul 20 06:25:43.621197 2026] [security2:error] [pid 925208:tid 925318] [remote 97.74.93.24:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT6AAAMW0"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:25:43.628890 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT6QAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:43.628999 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT6QAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:43.887832 2026] [security2:error] [pid 925208:tid 925326] [remote 103.118.29.185:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT-AAADnU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:43.906149 2026] [security2:error] [pid 925208:tid 925360] [client 65.1.132.125:33668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT-QAAABY"]
[Mon Jul 20 06:25:43.906267 2026] [security2:error] [pid 925208:tid 925360] [client 65.1.132.125:33668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT-QAAABY"]
[Mon Jul 20 06:25:44.082329 2026] [security2:error] [pid 925208:tid 925454] [client 14.225.17.146:53486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT9wAAAHQ"], referer: http://samdothan.org/WP
[Mon Jul 20 06:25:44.451384 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TyMRX7OrFkv0FyuIUJgAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:44.451487 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TyMRX7OrFkv0FyuIUJgAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:44.456051 2026] [security2:error] [pid 925208:tid 925427] [client 14.225.17.146:58958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4TyMRX7OrFkv0FyuIUGgAAAFk"], referer: https://friendlyspreadsheet.com/WP
[Mon Jul 20 06:25:44.819558 2026] [security2:error] [pid 925208:tid 925388] [client 57.141.18.98:28488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TxsRX7OrFkv0FyuITlwAAMkQ"]
[Mon Jul 20 06:25:45.121084 2026] [security2:error] [pid 925208:tid 925246] [remote 173.212.252.15:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TycRX7OrFkv0FyuIUYgAAWCU"]
[Mon Jul 20 06:25:45.133531 2026] [security2:error] [pid 925208:tid 925380] [client 57.141.18.95:53632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuITuQAAKiY"]
[Mon Jul 20 06:25:45.233970 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TycRX7OrFkv0FyuIUZwAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:45.234097 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TycRX7OrFkv0FyuIUZwAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:45.390578 2026] [security2:error] [pid 925208:tid 925252] [remote 173.212.252.15:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TycRX7OrFkv0FyuIUcgAADCs"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:25:45.560295 2026] [security2:error] [pid 925208:tid 925349] [client 14.225.17.146:57599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4TycRX7OrFkv0FyuIUgwAAAAs"], referer: http://retzkolonglogistics.com/WP
[Mon Jul 20 06:25:46.023248 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIUowAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.023346 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIUowAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.537109 2026] [security2:error] [pid 925208:tid 925437] [client 57.141.18.19:64602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TyMRX7OrFkv0FyuIUQAAAYyQ"]
[Mon Jul 20 06:25:46.606443 2026] [security2:error] [pid 925208:tid 925359] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TysRX7OrFkv0FyuIUvgAAABU"]
[Mon Jul 20 06:25:46.737450 2026] [security2:error] [pid 925208:tid 925285] [remote 57.141.18.120:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2771386"] [unique_id "al4TysRX7OrFkv0FyuIU1gAAPUw"]
[Mon Jul 20 06:25:46.838914 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU5AAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.839001 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:62296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU5AAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.995939 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU8wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.996042 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU8wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.106772 2026] [security2:error] [pid 925208:tid 925449] [client 54.39.89.128:17422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4Ty8RX7OrFkv0FyuIU-wAAAG8"]
[Mon Jul 20 06:25:47.106889 2026] [security2:error] [pid 925208:tid 925449] [client 54.39.89.128:17422] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4Ty8RX7OrFkv0FyuIU-wAAAG8"]
[Mon Jul 20 06:25:47.155889 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIU_gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.155986 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIU_gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.308938 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVCQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.309037 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVCQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.507881 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVEQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.507992 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVEQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.660243 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVHgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.660343 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:62303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVHgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.756740 2026] [security2:error] [pid 925208:tid 925427] [client 104.234.53.73:49019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVIwAAAFk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:47.821325 2026] [security2:error] [pid 925208:tid 925436] [client 77.110.127.138:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVJwAAAGI"]
[Mon Jul 20 06:25:47.821449 2026] [security2:error] [pid 925208:tid 925436] [client 77.110.127.138:62304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVJwAAAGI"]
[Mon Jul 20 06:25:47.835372 2026] [security2:error] [pid 925208:tid 925386] [client 57.141.18.50:57398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TycRX7OrFkv0FyuIUkQAAMH4"]
[Mon Jul 20 06:25:47.973346 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVLQAAAHs"]
[Mon Jul 20 06:25:47.973447 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVLQAAAHs"]
[Mon Jul 20 06:25:48.125581 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVNQAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.125703 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVNQAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.243981 2026] [security2:error] [pid 925208:tid 925377] [client 57.141.18.24:40824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TysRX7OrFkv0FyuIUugAAJ0M"]
[Mon Jul 20 06:25:48.285169 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVQwAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.285258 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVQwAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.371917 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:55859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVPAAAAAA"], referer: http://mobilesurvsolutions.com/WP
[Mon Jul 20 06:25:48.442264 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVUAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.442364 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVUAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.601209 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVXAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.601295 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVXAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.752872 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVbQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.752982 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVbQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.916903 2026] [security2:error] [pid 925208:tid 925375] [client 77.110.127.138:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVdQAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.917015 2026] [security2:error] [pid 925208:tid 925375] [client 77.110.127.138:62312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVdQAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.034422 2026] [security2:error] [pid 925208:tid 925239] [remote 45.90.123.233:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TzcRX7OrFkv0FyuIVfQAADR4"]
[Mon Jul 20 06:25:49.072841 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVggAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.072920 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVggAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.238126 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVjgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.238271 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:62316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVjgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.246097 2026] [security2:error] [pid 925208:tid 925246] [remote 45.90.123.233:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TzcRX7OrFkv0FyuIVjwAAVCU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:49.393971 2026] [security2:error] [pid 925208:tid 925346] [client 57.141.18.72:41444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVDQAACEE"]
[Mon Jul 20 06:25:49.835706 2026] [security2:error] [pid 925208:tid 925418] [client 14.225.17.146:55440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVVQAAAFA"], referer: http://cloudspacesgroup.com/WP
[Mon Jul 20 06:25:49.837990 2026] [security2:error] [pid 925208:tid 925386] [client 14.225.17.146:55427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4TzcRX7OrFkv0FyuIVsQAAADA"], referer: http://taskidsvirginia.com/WP
[Mon Jul 20 06:25:49.921264 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVxgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.921360 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVxgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.947267 2026] [security2:error] [pid 925208:tid 925451] [client 57.141.18.115:46458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVKQAAcXU"]
[Mon Jul 20 06:25:50.353045 2026] [security2:error] [pid 925208:tid 925379] [client 57.141.18.83:55510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVRAAAKRA"]
[Mon Jul 20 06:25:50.354870 2026] [security2:error] [pid 925208:tid 925238] [remote 173.212.252.15:50306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4TzsRX7OrFkv0FyuIV7wAACh0"]
[Mon Jul 20 06:25:50.527232 2026] [security2:error] [pid 925208:tid 925372] [client 14.225.17.146:55835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4TzsRX7OrFkv0FyuIV8wAAACI"], referer: http://katsklar.com/WP
[Mon Jul 20 06:25:50.652299 2026] [security2:error] [pid 925208:tid 925302] [remote 173.212.252.15:50306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4TzsRX7OrFkv0FyuIWAgAABV0"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:25:50.693394 2026] [security2:error] [pid 925208:tid 925400] [client 57.141.18.45:32362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVZQAAPl8"]
[Mon Jul 20 06:25:50.762453 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzsRX7OrFkv0FyuIWCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:50.762554 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzsRX7OrFkv0FyuIWCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:51.035536 2026] [security2:error] [pid 925208:tid 925344] [client 104.234.53.75:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWJwAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:51.358230 2026] [security2:error] [pid 925208:tid 925261] [remote 124.55.178.99:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWQQAAJzQ"]
[Mon Jul 20 06:25:51.404333 2026] [security2:error] [pid 925208:tid 925341] [client 98.159.234.160:51207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWSgAAAAM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:51.462810 2026] [security2:error] [pid 925208:tid 925417] [client 57.141.18.46:37320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TzcRX7OrFkv0FyuIVsAAAT3Y"]
[Mon Jul 20 06:25:51.665657 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWYAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:51.665778 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWYAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:51.799143 2026] [security2:error] [pid 925208:tid 925305] [remote 124.55.178.99:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWZwAASGA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:52.309773 2026] [security2:error] [pid 925208:tid 925412] [client 171.60.139.123:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWiwAAAEo"]
[Mon Jul 20 06:25:52.309863 2026] [security2:error] [pid 925208:tid 925412] [client 171.60.139.123:56398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWiwAAAEo"]
[Mon Jul 20 06:25:52.453574 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0MRX7OrFkv0FyuIWmAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:52.453682 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0MRX7OrFkv0FyuIWmAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:52.652520 2026] [security2:error] [pid 925208:tid 925458] [client 104.234.53.87:64725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4T0MRX7OrFkv0FyuIWoQAAAHg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:52.745236 2026] [core:error] [pid 925208:tid 925386] [client 103.153.183.69:61178] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e/.env?_=to4fqwfm&v=hvu01), referer: https://www.google.com/search?q=5s7po7
[Mon Jul 20 06:25:52.752901 2026] [security2:error] [pid 925208:tid 925240] [remote 72.167.132.114:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4T0MRX7OrFkv0FyuIWqwAAAx8"]
[Mon Jul 20 06:25:52.794600 2026] [security2:error] [pid 925208:tid 925413] [client 112.208.70.94:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWtQAAAEs"]
[Mon Jul 20 06:25:52.794693 2026] [security2:error] [pid 925208:tid 925413] [client 112.208.70.94:43798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWtQAAAEs"]
[Mon Jul 20 06:25:52.990091 2026] [security2:error] [pid 925208:tid 925410] [client 103.153.183.69:19002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../var/www/html/.env"] [unique_id "al4T0MRX7OrFkv0FyuIWyAAAAEg"], referer: https://www.google.com/
[Mon Jul 20 06:25:52.991259 2026] [security2:error] [pid 925208:tid 925250] [remote 72.167.132.114:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4T0MRX7OrFkv0FyuIWxwAAWik"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:25:53.096437 2026] [security2:error] [pid 925208:tid 925347] [client 103.153.183.69:19002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../var/www/.env"] [unique_id "al4T0cRX7OrFkv0FyuIW0wAAAAk"], referer: https://t.co/wuwnc3mavz
[Mon Jul 20 06:25:53.241585 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW3wAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.241714 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW3wAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.260812 2026] [core:error] [pid 925208:tid 925374] [client 103.153.183.69:61192] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e/etc/passwd?_=z2dznur3&v=tajne), referer: https://news.ycombinator.com/
[Mon Jul 20 06:25:53.263147 2026] [security2:error] [pid 925208:tid 925458] [client 127.0.0.1:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4T0cRX7OrFkv0FyuIW4wAAAHg"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:25:53.351135 2026] [security2:error] [pid 925208:tid 925443] [client 104.234.53.87:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4T0cRX7OrFkv0FyuIW5gAAAGk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:53.379399 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW6QAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.379512 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW6QAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.446598 2026] [security2:error] [pid 925208:tid 925406] [client 103.141.108.143:64529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIW8QAAAEQ"]
[Mon Jul 20 06:25:53.446845 2026] [security2:error] [pid 925208:tid 925406] [client 103.141.108.143:64529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIW8QAAAEQ"]
[Mon Jul 20 06:25:53.593473 2026] [core:error] [pid 925208:tid 925434] [client 103.153.183.69:61204] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e/%u002e%u002e/.env?_=i3fuk6m5&v=rrb8j), referer: https://twitter.com/
[Mon Jul 20 06:25:53.638787 2026] [security2:error] [pid 925208:tid 925402] [client 57.141.18.31:21282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWdwAAQBc"]
[Mon Jul 20 06:25:53.700849 2026] [security2:error] [pid 925208:tid 925456] [client 45.116.69.230:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIXAwAAAHY"]
[Mon Jul 20 06:25:53.700938 2026] [security2:error] [pid 925208:tid 925456] [client 45.116.69.230:65060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIXAwAAAHY"]
[Mon Jul 20 06:25:53.749439 2026] [security2:error] [pid 925208:tid 925356] [client 57.141.18.46:49554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T0MRX7OrFkv0FyuIWhAAAEm4"]
[Mon Jul 20 06:25:54.328130 2026] [security2:error] [pid 925208:tid 925378] [client 50.116.65.227:27656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4T0sRX7OrFkv0FyuIXOgAAACg"]
[Mon Jul 20 06:25:54.331415 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:60563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXLwAAAE0"]
[Mon Jul 20 06:25:54.485658 2026] [security2:error] [pid 925208:tid 925462] [client 103.153.183.69:19002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//var/www/html/wp-config.php"] [unique_id "al4T0sRX7OrFkv0FyuIXQwAAAHw"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:25:54.636518 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:50303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXQQAAADE"], referer: http://mtlegnews.gov/WP
[Mon Jul 20 06:25:55.179495 2026] [security2:error] [pid 925208:tid 925406] [client 14.225.17.146:49941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXYQAAAEQ"], referer: http://webgardensbypaula.com/WP
[Mon Jul 20 06:25:55.288563 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXiQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.288670 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXiQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.509191 2026] [security2:error] [pid 925208:tid 925459] [client 57.141.18.116:45140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T0cRX7OrFkv0FyuIXBAAAeSg"]
[Mon Jul 20 06:25:55.511097 2026] [security2:error] [pid 925208:tid 925210] [remote 156.67.31.167:43500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXjgAABgE"]
[Mon Jul 20 06:25:55.511283 2026] [security2:error] [pid 925208:tid 925344] [client 156.67.31.167:43500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXjgAABgE"]
[Mon Jul 20 06:25:55.668048 2026] [security2:error] [pid 925208:tid 925266] [remote 8.217.108.67:21680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXoAAALDk"]
[Mon Jul 20 06:25:55.668390 2026] [security2:error] [pid 925208:tid 925382] [client 8.217.108.67:21680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXoAAALDk"]
[Mon Jul 20 06:25:55.755574 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4T08RX7OrFkv0FyuIXpAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.910027 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXqwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.910442 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXqwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.920191 2026] [security2:error] [pid 925208:tid 925348] [client 104.234.53.71:47309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4T08RX7OrFkv0FyuIXrwAAAAo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:55.925012 2026] [security2:error] [pid 925208:tid 925429] [client 14.225.17.146:60573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4T08RX7OrFkv0FyuIXpQAAAFs"], referer: http://ivetstrategies.com/WP
[Mon Jul 20 06:25:56.129272 2026] [security2:error] [pid 925208:tid 925436] [client 57.141.18.91:37136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXOwAAYkU"]
[Mon Jul 20 06:25:56.539177 2026] [security2:error] [pid 925208:tid 925359] [client 14.225.17.146:50414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4T08RX7OrFkv0FyuIXfgAAABU"]
[Mon Jul 20 06:25:56.549844 2026] [security2:error] [pid 925208:tid 925320] [remote 5.161.225.162:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T1MRX7OrFkv0FyuIX6AAAPm8"]
[Mon Jul 20 06:25:56.905888 2026] [security2:error] [pid 925208:tid 925415] [client 47.129.222.11:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T1MRX7OrFkv0FyuIYEQAAAE0"]
[Mon Jul 20 06:25:57.151313 2026] [security2:error] [pid 925208:tid 925240] [remote 5.161.225.162:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T1cRX7OrFkv0FyuIYOQAAaB8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:57.272880 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.27:64578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T08RX7OrFkv0FyuIXgAAAThg"]
[Mon Jul 20 06:25:57.341945 2026] [security2:error] [pid 925208:tid 925363] [client 14.225.17.146:50628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4T1MRX7OrFkv0FyuIX3AAAABk"], referer: http://nextlevelpressurewashing.com/WP
[Mon Jul 20 06:25:57.405539 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T1cRX7OrFkv0FyuIYRQAAAE0"]
[Mon Jul 20 06:25:57.645975 2026] [security2:error] [pid 925208:tid 925381] [client 34.48.79.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4T1cRX7OrFkv0FyuIYRAAAACs"]
[Mon Jul 20 06:25:57.816503 2026] [security2:error] [pid 925208:tid 925438] [client 34.48.79.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.79.48.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/xmlrpc.php"] [unique_id "al4T1cRX7OrFkv0FyuIYawAAAGQ"]
[Mon Jul 20 06:25:57.874835 2026] [security2:error] [pid 925208:tid 925412] [client 47.129.222.11:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T1cRX7OrFkv0FyuIYcgAAAEo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:25:58.057853 2026] [security2:error] [pid 925208:tid 925464] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYeQAAAH4"]
[Mon Jul 20 06:25:58.100687 2026] [security2:error] [pid 925208:tid 925411] [client 223.185.13.213:5435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T1sRX7OrFkv0FyuIYgAAAAEk"]
[Mon Jul 20 06:25:58.100827 2026] [security2:error] [pid 925208:tid 925411] [client 223.185.13.213:5435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T1sRX7OrFkv0FyuIYgAAAAEk"]
[Mon Jul 20 06:25:58.329817 2026] [security2:error] [pid 925208:tid 925342] [client 14.225.17.146:50084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4T1sRX7OrFkv0FyuIYjgAAAAQ"], referer: http://chestermonty.com/WP
[Mon Jul 20 06:25:58.338560 2026] [security2:error] [pid 925208:tid 925447] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYlwAAAG0"]
[Mon Jul 20 06:25:58.518004 2026] [security2:error] [pid 925208:tid 925464] [client 77.110.127.138:62351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T1sRX7OrFkv0FyuIYpgAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:58.518110 2026] [security2:error] [pid 925208:tid 925464] [client 77.110.127.138:62351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T1sRX7OrFkv0FyuIYpgAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:58.576713 2026] [security2:error] [pid 925208:tid 925411] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYrgAAAEk"]
[Mon Jul 20 06:25:58.884181 2026] [security2:error] [pid 925208:tid 925458] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYyQAAAHg"]
[Mon Jul 20 06:25:58.895964 2026] [security2:error] [pid 925208:tid 925401] [client 57.141.18.28:56964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1MRX7OrFkv0FyuIYBQAAP38"]
[Mon Jul 20 06:25:59.003757 2026] [security2:error] [pid 925208:tid 925248] [remote 217.61.143.92:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIYzgAAGSc"]
[Mon Jul 20 06:25:59.054196 2026] [security2:error] [pid 925208:tid 925303] [remote 124.55.178.99:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY0gAAdV4"]
[Mon Jul 20 06:25:59.146567 2026] [security2:error] [pid 925208:tid 925364] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIY5AAAABo"]
[Mon Jul 20 06:25:59.155662 2026] [security2:error] [pid 925208:tid 925298] [remote 117.0.21.154:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY4AAAGFk"]
[Mon Jul 20 06:25:59.246240 2026] [security2:error] [pid 925208:tid 925237] [remote 217.61.143.92:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY8gAAShw"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 06:25:59.318411 2026] [security2:error] [pid 925208:tid 925402] [client 14.225.17.146:54169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4T18RX7OrFkv0FyuIY7gAAAEA"], referer: https://chestermonty.com/WP
[Mon Jul 20 06:25:59.325512 2026] [security2:error] [pid 925208:tid 925370] [client 57.141.18.70:58930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1cRX7OrFkv0FyuIYOgAAIBs"]
[Mon Jul 20 06:25:59.382764 2026] [security2:error] [pid 925208:tid 925344] [client 103.153.183.69:41374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//var/www/html/config.php"] [unique_id "al4T18RX7OrFkv0FyuIY_gAAAAY"], referer: https://www.reddit.com/
[Mon Jul 20 06:25:59.392916 2026] [security2:error] [pid 925208:tid 925352] [client 65.1.132.125:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY_QAAAA4"]
[Mon Jul 20 06:25:59.424113 2026] [security2:error] [pid 925208:tid 925382] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZAAAAACw"]
[Mon Jul 20 06:25:59.458300 2026] [security2:error] [pid 925208:tid 925242] [remote 47.86.33.52:1380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIZAQAAbiE"]
[Mon Jul 20 06:25:59.555587 2026] [security2:error] [pid 925208:tid 925262] [remote 124.55.178.99:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIZCAAAGDU"], referer: https://snctaxgroup.com/wp-login.php
[Mon Jul 20 06:25:59.645071 2026] [security2:error] [pid 925208:tid 925464] [client 14.225.17.146:54201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4T18RX7OrFkv0FyuIY-gAAAH4"], referer: http://overloadcomedy.com/WP
[Mon Jul 20 06:25:59.712096 2026] [security2:error] [pid 925208:tid 925426] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZFwAAAFg"]
[Mon Jul 20 06:25:59.742682 2026] [security2:error] [pid 925208:tid 925412] [client 85.204.70.92:40462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZGAAAAEo"]
[Mon Jul 20 06:25:59.950995 2026] [security2:error] [pid 925208:tid 925402] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZKgAAAEA"]
[Mon Jul 20 06:26:00.250941 2026] [security2:error] [pid 925208:tid 925437] [client 57.141.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZMwAAAGM"]
[Mon Jul 20 06:26:00.266018 2026] [security2:error] [pid 925208:tid 925386] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZQwAAADA"]
[Mon Jul 20 06:26:00.311689 2026] [security2:error] [pid 925208:tid 925276] [remote 117.0.21.154:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T2MRX7OrFkv0FyuIZSAAAVEM"], referer: https://zlp.omk.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:00.312812 2026] [security2:error] [pid 925208:tid 925347] [client 85.204.70.92:40474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4T2MRX7OrFkv0FyuIZRAAAAAk"]
[Mon Jul 20 06:26:00.369609 2026] [security2:error] [pid 925208:tid 925389] [client 57.141.18.66:53138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1sRX7OrFkv0FyuIYkwAAMz4"]
[Mon Jul 20 06:26:00.525382 2026] [security2:error] [pid 925208:tid 925438] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZVQAAAGQ"]
[Mon Jul 20 06:26:00.544291 2026] [security2:error] [pid 925208:tid 925355] [client 13.201.64.214:20068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T2MRX7OrFkv0FyuIZVwAAABE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:26:00.834207 2026] [security2:error] [pid 925208:tid 925464] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZdQAAAH4"]
[Mon Jul 20 06:26:00.961823 2026] [security2:error] [pid 925208:tid 925459] [client 57.141.18.33:60928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1sRX7OrFkv0FyuIYwQAAeSQ"]
[Mon Jul 20 06:26:00.996262 2026] [security2:error] [pid 925208:tid 925385] [client 85.204.70.92:40486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZgwAAAC8"]
[Mon Jul 20 06:26:01.068146 2026] [security2:error] [pid 925208:tid 925430] [client 148.230.189.107:38477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZfQAAAFw"]
[Mon Jul 20 06:26:01.077877 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZiQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.077977 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZiQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.081872 2026] [proxy:error] [pid 925208:tid 925432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:01.081941 2026] [proxy_http:error] [pid 925208:tid 925432] [client 34.73.38.214:56458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:01.082413 2026] [proxy:error] [pid 925208:tid 925432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:01.082443 2026] [proxy_http:error] [pid 925208:tid 925432] [client 34.73.38.214:56458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:01.313331 2026] [security2:error] [pid 925208:tid 925441] [client 14.225.17.146:64192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4T18RX7OrFkv0FyuIZDQAAAGc"], referer: http://nwcarvingacademy.com/WP
[Mon Jul 20 06:26:01.324488 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZpwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.324614 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZpwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.539401 2026] [security2:error] [pid 925208:tid 925360] [client 85.204.70.92:40502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T2cRX7OrFkv0FyuIZsgAAABY"]
[Mon Jul 20 06:26:01.671567 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:56985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4T2cRX7OrFkv0FyuIZsAAAAC4"], referer: http://lifeisbetterlakeside.com/WP
[Mon Jul 20 06:26:01.704577 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZxAAAABw"]
[Mon Jul 20 06:26:01.704684 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZxAAAABw"]
[Mon Jul 20 06:26:01.841633 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZ0gAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.841722 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZ0gAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.895368 2026] [security2:error] [pid 925208:tid 925215] [remote 47.86.33.52:1380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T2cRX7OrFkv0FyuIZ1AAAKgY"], referer: https://zbj.ahr.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:02.067389 2026] [security2:error] [pid 925208:tid 925370] [client 85.204.70.92:40510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T2sRX7OrFkv0FyuIZ5gAAACA"]
[Mon Jul 20 06:26:02.310628 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ9wAAABE"]
[Mon Jul 20 06:26:02.310913 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ9wAAABE"]
[Mon Jul 20 06:26:02.422762 2026] [security2:error] [pid 925208:tid 925439] [client 34.74.185.202:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaAQAAAGU"]
[Mon Jul 20 06:26:02.447519 2026] [security2:error] [pid 925208:tid 925375] [client 14.225.17.146:54272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ6gAAACU"], referer: https://nwcarvingacademy.com/WP
[Mon Jul 20 06:26:02.525374 2026] [security2:error] [pid 925208:tid 925339] [client 57.141.18.79:34056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZRgAAARU"]
[Mon Jul 20 06:26:02.533633 2026] [security2:error] [pid 925208:tid 925396] [client 13.201.64.214:20082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaCgAAADo"]
[Mon Jul 20 06:26:02.533764 2026] [security2:error] [pid 925208:tid 925396] [client 13.201.64.214:20082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaCgAAADo"]
[Mon Jul 20 06:26:02.585312 2026] [security2:error] [pid 925208:tid 925429] [client 85.204.70.92:40516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4T2sRX7OrFkv0FyuIaDQAAAFs"]
[Mon Jul 20 06:26:02.862923 2026] [security2:error] [pid 925208:tid 925380] [client 171.60.139.123:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaKQAAACo"]
[Mon Jul 20 06:26:02.863026 2026] [security2:error] [pid 925208:tid 925380] [client 171.60.139.123:56908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaKQAAACo"]
[Mon Jul 20 06:26:02.907285 2026] [security2:error] [pid 925208:tid 925405] [client 34.74.185.202:59067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T2sRX7OrFkv0FyuIaKgAAAEM"]
[Mon Jul 20 06:26:03.046632 2026] [security2:error] [pid 925208:tid 925295] [remote 5.161.225.162:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4T28RX7OrFkv0FyuIaMgAAPVY"]
[Mon Jul 20 06:26:03.118117 2026] [security2:error] [pid 925208:tid 925425] [client 85.204.70.92:40520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIaRAAAAFc"]
[Mon Jul 20 06:26:03.171574 2026] [security2:error] [pid 925208:tid 925214] [remote 104.131.116.82:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T28RX7OrFkv0FyuIaSAAANQU"]
[Mon Jul 20 06:26:03.171891 2026] [security2:error] [pid 925208:tid 925391] [client 104.131.116.82:44762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T28RX7OrFkv0FyuIaSAAANQU"]
[Mon Jul 20 06:26:03.212018 2026] [security2:error] [pid 925208:tid 925412] [client 57.141.18.25:35386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZeAAASnQ"]
[Mon Jul 20 06:26:03.303285 2026] [security2:error] [pid 925208:tid 925284] [remote 5.161.225.162:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4T28RX7OrFkv0FyuIaUgAAGUs"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 06:26:03.410538 2026] [security2:error] [pid 925208:tid 925401] [client 34.74.185.202:56542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIaXgAAAD8"]
[Mon Jul 20 06:26:03.656488 2026] [security2:error] [pid 925208:tid 925422] [client 85.204.70.92:40532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIacgAAAFQ"]
[Mon Jul 20 06:26:03.757106 2026] [proxy:error] [pid 925208:tid 925417] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:03.757179 2026] [proxy_http:error] [pid 925208:tid 925417] [client 34.73.38.214:49453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:03.757834 2026] [proxy:error] [pid 925208:tid 925417] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:03.757865 2026] [proxy_http:error] [pid 925208:tid 925417] [client 34.73.38.214:49453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:03.797307 2026] [security2:error] [pid 925208:tid 925370] [client 45.157.112.60:35737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4T28RX7OrFkv0FyuIafgAAACA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:03.831405 2026] [security2:error] [pid 925208:tid 925440] [client 14.225.17.146:54294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ7AAAAGY"], referer: http://alrowad-hub.net/WP
[Mon Jul 20 06:26:03.984854 2026] [security2:error] [pid 925208:tid 925446] [client 34.74.185.202:61732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIalQAAAGw"]
[Mon Jul 20 06:26:04.079507 2026] [security2:error] [pid 925208:tid 925378] [client 103.141.108.143:65005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIamgAAACg"]
[Mon Jul 20 06:26:04.079620 2026] [security2:error] [pid 925208:tid 925378] [client 103.141.108.143:65005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIamgAAACg"]
[Mon Jul 20 06:26:04.146009 2026] [security2:error] [pid 925208:tid 925429] [client 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4T3MRX7OrFkv0FyuIaoQAAAFs"]
[Mon Jul 20 06:26:04.179376 2026] [security2:error] [pid 925208:tid 925421] [client 85.204.70.92:40540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIapgAAAFM"]
[Mon Jul 20 06:26:04.215790 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIarAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.215944 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIarAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.328778 2026] [security2:error] [pid 925208:tid 925396] [client 34.74.185.202:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIasgAAADo"]
[Mon Jul 20 06:26:04.347997 2026] [security2:error] [pid 925208:tid 925433] [client 52.109.124.141:21825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4T3MRX7OrFkv0FyuIaswAAAF8"]
[Mon Jul 20 06:26:04.361243 2026] [security2:error] [pid 925208:tid 925360] [client 45.116.69.230:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIatwAAABY"]
[Mon Jul 20 06:26:04.361357 2026] [security2:error] [pid 925208:tid 925360] [client 45.116.69.230:49178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIatwAAABY"]
[Mon Jul 20 06:26:04.366572 2026] [security2:error] [pid 925208:tid 925399] [client 77.110.127.138:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4T3MRX7OrFkv0FyuIauQAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.418320 2026] [security2:error] [pid 925208:tid 925376] [client 77.110.127.138:62363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIavwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.418425 2026] [security2:error] [pid 925208:tid 925376] [client 77.110.127.138:62363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIavwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.511849 2026] [security2:error] [pid 925208:tid 925391] [client 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4T3MRX7OrFkv0FyuIaywAAADU"], referer: https://thescarystory.com/wp-login.php
[Mon Jul 20 06:26:04.527237 2026] [security2:error] [pid 925208:tid 925434] [client 52.109.124.141:21825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4T3MRX7OrFkv0FyuIazQAAAGA"]
[Mon Jul 20 06:26:04.648512 2026] [proxy:error] [pid 925208:tid 925397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.648561 2026] [proxy_http:error] [pid 925208:tid 925397] [client 94.154.43.187:63690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:04.649568 2026] [proxy:error] [pid 925208:tid 925397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.649605 2026] [proxy_http:error] [pid 925208:tid 925397] [client 94.154.43.187:63690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:04.670290 2026] [security2:error] [pid 925208:tid 925464] [client 14.225.17.146:53978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4T28RX7OrFkv0FyuIaTgAAAH4"], referer: http://alaraycreative.com/WP
[Mon Jul 20 06:26:04.700716 2026] [security2:error] [pid 925208:tid 925354] [client 85.204.70.92:44374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIa4gAAABA"]
[Mon Jul 20 06:26:04.721137 2026] [security2:error] [pid 925208:tid 925415] [client 34.74.185.202:60181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIa5gAAAE0"]
[Mon Jul 20 06:26:04.760756 2026] [security2:error] [pid 925208:tid 925462] [client 57.141.18.22:57578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ8wAAfDw"]
[Mon Jul 20 06:26:04.763366 2026] [security2:error] [pid 925208:tid 925360] [client 50.116.65.227:52264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4T3MRX7OrFkv0FyuIa6wAAABY"]
[Mon Jul 20 06:26:04.773308 2026] [security2:error] [pid 925208:tid 925373] [client 50.116.65.227:52270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4T3MRX7OrFkv0FyuIa7AAAACM"]
[Mon Jul 20 06:26:04.901486 2026] [security2:error] [pid 925208:tid 925352] [client 52.109.44.112:9408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4T3MRX7OrFkv0FyuIa8QAAAA4"]
[Mon Jul 20 06:26:04.967419 2026] [security2:error] [pid 925208:tid 925422] [client 34.74.185.202:57394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIa-QAAAFQ"]
[Mon Jul 20 06:26:04.987330 2026] [proxy:error] [pid 925208:tid 925381] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.987400 2026] [proxy_http:error] [pid 925208:tid 925381] [client 94.154.43.178:16892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:04.988180 2026] [proxy:error] [pid 925208:tid 925381] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.988215 2026] [proxy_http:error] [pid 925208:tid 925381] [client 94.154.43.178:16892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:05.037202 2026] [security2:error] [pid 925208:tid 925355] [client 52.109.44.112:9408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4T3cRX7OrFkv0FyuIbBAAAABE"]
[Mon Jul 20 06:26:05.163074 2026] [security2:error] [pid 925208:tid 925350] [client 14.225.17.146:64035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4T3cRX7OrFkv0FyuIbAAAAAAw"], referer: http://kromosenergy.com/WP
[Mon Jul 20 06:26:05.223695 2026] [security2:error] [pid 925208:tid 925450] [client 85.204.70.92:44388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T3cRX7OrFkv0FyuIbGgAAAHA"]
[Mon Jul 20 06:26:05.263362 2026] [security2:error] [pid 925208:tid 925438] [client 112.208.70.94:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T3cRX7OrFkv0FyuIbHgAAAGQ"]
[Mon Jul 20 06:26:05.263455 2026] [security2:error] [pid 925208:tid 925438] [client 112.208.70.94:44198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T3cRX7OrFkv0FyuIbHgAAAGQ"]
[Mon Jul 20 06:26:05.491547 2026] [security2:error] [pid 925208:tid 925317] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4T3cRX7OrFkv0FyuIbLgAAemw"]
[Mon Jul 20 06:26:05.519330 2026] [security2:error] [pid 925208:tid 925409] [client 34.74.185.202:62406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T3cRX7OrFkv0FyuIbMQAAAEc"]
[Mon Jul 20 06:26:05.598589 2026] [security2:error] [pid 925208:tid 925274] [remote 124.55.178.99:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4T3cRX7OrFkv0FyuIbNwAAJkE"]
[Mon Jul 20 06:26:05.742829 2026] [security2:error] [pid 925208:tid 925379] [client 85.204.70.92:44392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T3cRX7OrFkv0FyuIbRwAAACk"]
[Mon Jul 20 06:26:05.788403 2026] [security2:error] [pid 925208:tid 925362] [client 14.225.17.146:63999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4T3MRX7OrFkv0FyuIapQAAABg"], referer: https://north-woods-engineering.com/WP
[Mon Jul 20 06:26:06.011962 2026] [security2:error] [pid 925208:tid 925287] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbYAAAIE4"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:26:06.044251 2026] [security2:error] [pid 925208:tid 925421] [client 34.74.185.202:61993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbZQAAAFM"]
[Mon Jul 20 06:26:06.047375 2026] [security2:error] [pid 925208:tid 925294] [remote 124.55.178.99:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbZgAAdlU"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:26:06.076690 2026] [security2:error] [pid 925208:tid 925373] [client 103.153.183.69:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//var/www/html/configuration.php"] [unique_id "al4T3sRX7OrFkv0FyuIbaAAAACM"], referer: https://www.reddit.com/
[Mon Jul 20 06:26:06.160029 2026] [security2:error] [pid 925208:tid 925230] [remote 162.19.86.63:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbdAAABBU"]
[Mon Jul 20 06:26:06.233325 2026] [security2:error] [pid 925208:tid 925420] [client 57.141.18.21:53424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T28RX7OrFkv0FyuIakwAAUkU"]
[Mon Jul 20 06:26:06.255492 2026] [security2:error] [pid 925208:tid 925243] [remote 162.19.86.63:39757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbfQAAHSI"]
[Mon Jul 20 06:26:06.274943 2026] [security2:error] [pid 925208:tid 925437] [client 34.74.185.202:58402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbfwAAAGM"]
[Mon Jul 20 06:26:06.285448 2026] [security2:error] [pid 925208:tid 925374] [client 85.204.70.92:44406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbgAAAACQ"]
[Mon Jul 20 06:26:06.392585 2026] [security2:error] [pid 925208:tid 925238] [remote 162.19.86.63:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbjQAAAR0"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:26:06.416013 2026] [security2:error] [pid 925208:tid 925424] [client 57.141.18.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbfgAAAFY"]
[Mon Jul 20 06:26:06.454009 2026] [security2:error] [pid 925208:tid 925388] [client 77.110.127.138:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3sRX7OrFkv0FyuIbkAAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:06.454120 2026] [security2:error] [pid 925208:tid 925388] [client 77.110.127.138:62419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3sRX7OrFkv0FyuIbkAAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:06.505286 2026] [security2:error] [pid 925208:tid 925217] [remote 162.19.86.63:39757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIblAAAKgg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:06.628505 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpdRvx2fFv'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4T3sRX7OrFkv0FyuIboAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:06.814511 2026] [security2:error] [pid 925208:tid 925376] [client 85.204.70.92:44422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbtAAAACY"]
[Mon Jul 20 06:26:06.816151 2026] [security2:error] [pid 925208:tid 925398] [client 34.74.185.202:55531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbtQAAADw"]
[Mon Jul 20 06:26:06.988153 2026] [security2:error] [pid 925208:tid 925435] [client 34.74.185.202:60959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbuwAAAGE"]
[Mon Jul 20 06:26:06.997560 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:06.997633 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:58510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:06.998226 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:06.998253 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:58510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:07.018765 2026] [security2:error] [pid 925208:tid 925444] [client 14.225.17.146:57006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbugAAAGo"], referer: http://ancestralidadytrance.space/WP
[Mon Jul 20 06:26:07.028764 2026] [security2:error] [pid 925208:tid 925393] [client 104.210.140.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mcandmac.com"] [uri "/index.php"] [unique_id "al4T28RX7OrFkv0FyuIadQAANyE"]
[Mon Jul 20 06:26:07.057866 2026] [core:error] [pid 925208:tid 925450] [client 103.153.183.69:13358] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e%u002f%u002e%u002e%u002fetc%u002fpasswd?_=14q9kmch&v=mswc6), referer: https://www.google.com/search?q=34cdsg
[Mon Jul 20 06:26:07.061614 2026] [security2:error] [pid 925208:tid 925432] [client 127.0.0.1:11640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4T38RX7OrFkv0FyuIbwQAAAF4"], referer: https://www.google.com/search?q=34cdsg
[Mon Jul 20 06:26:07.065393 2026] [security2:error] [pid 925208:tid 925350] [client 14.225.17.146:54228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4T3cRX7OrFkv0FyuIbWgAAAAw"], referer: http://mourgroup.com/WP
[Mon Jul 20 06:26:07.116667 2026] [security2:error] [pid 925208:tid 925387] [client 51.161.65.172:59016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "asliceofleadership.com"] [uri "/"] [unique_id "al4T38RX7OrFkv0FyuIbxgAAADE"]
[Mon Jul 20 06:26:07.116777 2026] [security2:error] [pid 925208:tid 925387] [client 51.161.65.172:59016] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "asliceofleadership.com"] [uri "/"] [unique_id "al4T38RX7OrFkv0FyuIbxgAAADE"]
[Mon Jul 20 06:26:07.190124 2026] [security2:error] [pid 925208:tid 925412] [client 57.141.18.78:37684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T3MRX7OrFkv0FyuIa7QAASmA"]
[Mon Jul 20 06:26:07.334780 2026] [security2:error] [pid 925208:tid 925344] [client 85.204.70.92:44430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIb2QAAAAY"]
[Mon Jul 20 06:26:07.449677 2026] [security2:error] [pid 925208:tid 925376] [client 34.74.185.202:49650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIb5gAAACY"]
[Mon Jul 20 06:26:07.566093 2026] [security2:error] [pid 925208:tid 925372] [client 34.74.185.202:56851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIb8gAAACI"]
[Mon Jul 20 06:26:07.578014 2026] [security2:error] [pid 925208:tid 925266] [remote 217.61.143.92:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIb8wAAPDk"]
[Mon Jul 20 06:26:07.671263 2026] [security2:error] [pid 925208:tid 925400] [client 14.225.17.146:54197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIb8AAAAD4"], referer: http://39ishlife.com/WP
[Mon Jul 20 06:26:07.680967 2026] [security2:error] [pid 925208:tid 925333] [remote 100.42.189.89:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIb_wAARnw"]
[Mon Jul 20 06:26:07.804950 2026] [security2:error] [pid 925208:tid 925460] [client 14.225.17.146:54003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbqAAAAHo"], referer: http://ravmike.com/WP
[Mon Jul 20 06:26:07.813470 2026] [security2:error] [pid 925208:tid 925225] [remote 217.61.143.92:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIcCwAAHBA"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:26:07.861603 2026] [security2:error] [pid 925208:tid 925383] [client 85.204.70.92:44438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIcDgAAAC0"]
[Mon Jul 20 06:26:07.928166 2026] [security2:error] [pid 925208:tid 925311] [remote 100.42.189.89:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIcDwAAGmY"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:26:08.014036 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:08.014137 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:64072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:08.015270 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:08.015322 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:64072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:08.018029 2026] [security2:error] [pid 925208:tid 925439] [client 34.74.185.202:56789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcFAAAAGU"]
[Mon Jul 20 06:26:08.306734 2026] [security2:error] [pid 925208:tid 925462] [client 34.74.185.202:57264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcNQAAAHw"]
[Mon Jul 20 06:26:08.310847 2026] [security2:error] [pid 925208:tid 925438] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcJwAAAGQ"]
[Mon Jul 20 06:26:08.362529 2026] [security2:error] [pid 925208:tid 925397] [client 14.225.17.146:56930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIb0wAAADs"], referer: http://getgarrison.com/WP
[Mon Jul 20 06:26:08.379174 2026] [security2:error] [pid 925208:tid 925449] [client 85.204.70.92:44452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcQQAAAG8"]
[Mon Jul 20 06:26:08.412375 2026] [security2:error] [pid 925208:tid 925448] [client 14.225.17.146:54105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbuAAAAG4"], referer: http://olearyplumbingllc.com/WP
[Mon Jul 20 06:26:08.436939 2026] [security2:error] [pid 925208:tid 925395] [client 34.74.185.202:60511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcRgAAADk"]
[Mon Jul 20 06:26:08.619816 2026] [security2:error] [pid 925208:tid 925402] [client 14.225.17.146:54466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcTAAAAEA"], referer: https://39ishlife.com/WP
[Mon Jul 20 06:26:08.722208 2026] [security2:error] [pid 925208:tid 925431] [client 34.74.185.202:56345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcYgAAAF0"]
[Mon Jul 20 06:26:08.758764 2026] [security2:error] [pid 925208:tid 925388] [client 14.225.17.146:54525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcXAAAADI"], referer: https://ravmike.com/WP
[Mon Jul 20 06:26:08.854900 2026] [security2:error] [pid 925208:tid 925421] [client 34.74.185.202:56999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcbwAAAFM"]
[Mon Jul 20 06:26:08.861221 2026] [security2:error] [pid 925208:tid 925418] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcXwAAAFA"]
[Mon Jul 20 06:26:08.870574 2026] [security2:error] [pid 925208:tid 925410] [client 14.225.17.146:54569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcRwAAAEg"]
[Mon Jul 20 06:26:08.911985 2026] [security2:error] [pid 925208:tid 925463] [client 85.204.70.92:44468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcdgAAAH0"]
[Mon Jul 20 06:26:08.924032 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:54540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcYQAAACM"], referer: http://narv.co/WP
[Mon Jul 20 06:26:09.099136 2026] [security2:error] [pid 925208:tid 925377] [client 34.74.185.202:63790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcewAAACc"]
[Mon Jul 20 06:26:09.143606 2026] [security2:error] [pid 925208:tid 925346] [client 223.185.13.213:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T4cRX7OrFkv0FyuIcggAAAAg"]
[Mon Jul 20 06:26:09.143702 2026] [security2:error] [pid 925208:tid 925346] [client 223.185.13.213:12083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T4cRX7OrFkv0FyuIcggAAAAg"]
[Mon Jul 20 06:26:09.331293 2026] [security2:error] [pid 925208:tid 925406] [client 34.74.185.202:51450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIclwAAAEQ"]
[Mon Jul 20 06:26:09.376247 2026] [security2:error] [pid 925208:tid 925340] [client 34.73.38.214:60458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcmQAAAAI"]
[Mon Jul 20 06:26:09.668137 2026] [security2:error] [pid 925208:tid 925373] [client 34.74.185.202:60338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcqgAAACM"]
[Mon Jul 20 06:26:09.718763 2026] [security2:error] [pid 925208:tid 925385] [client 34.74.185.202:61892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcsAAAAC8"]
[Mon Jul 20 06:26:09.904611 2026] [security2:error] [pid 925208:tid 925230] [remote 188.166.241.141:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T4cRX7OrFkv0FyuIcvQAAfRU"]
[Mon Jul 20 06:26:09.942802 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.14:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIb5QAAaHU"]
[Mon Jul 20 06:26:09.976039 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4cRX7OrFkv0FyuIcwwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:09.976169 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4cRX7OrFkv0FyuIcwwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.027312 2026] [security2:error] [pid 925208:tid 925306] [remote 124.55.178.99:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIcxgAAeGE"]
[Mon Jul 20 06:26:10.033170 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:54069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4T4cRX7OrFkv0FyuIcuQAAADE"], referer: https://narv.co/WP
[Mon Jul 20 06:26:10.134273 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIcygAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.134405 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIcygAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.227936 2026] [security2:error] [pid 925208:tid 925425] [client 14.225.17.146:54595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcZQAAAFc"], referer: http://cephasnext.com/WP
[Mon Jul 20 06:26:10.255543 2026] [security2:error] [pid 925208:tid 925410] [client 34.74.185.202:49816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIc2wAAAEg"]
[Mon Jul 20 06:26:10.285022 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc3gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.285163 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc3gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.333828 2026] [security2:error] [pid 925208:tid 925447] [client 57.141.18.3:27608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIcCQAAbWs"]
[Mon Jul 20 06:26:10.337713 2026] [security2:error] [pid 925208:tid 925217] [remote 188.166.241.141:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc4gAAWAg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:10.442300 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc6QAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.442400 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc6QAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.458646 2026] [security2:error] [pid 925208:tid 925463] [client 34.73.38.214:49296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIc7AAAAH0"]
[Mon Jul 20 06:26:10.482717 2026] [security2:error] [pid 925208:tid 925303] [remote 124.55.178.99:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc8QAAbl4"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:26:10.487559 2026] [security2:error] [pid 925208:tid 925402] [client 104.234.53.88:51995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc7QAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:10.548542 2026] [security2:error] [pid 925208:tid 925377] [client 34.74.185.202:63314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIc9wAAACc"]
[Mon Jul 20 06:26:10.607052 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc_AAAAF4"]
[Mon Jul 20 06:26:10.607245 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc_AAAAF4"]
[Mon Jul 20 06:26:10.642738 2026] [security2:error] [pid 925208:tid 925214] [remote 202.51.202.242:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc_gAAKQU"]
[Mon Jul 20 06:26:10.778522 2026] [security2:error] [pid 925208:tid 925425] [client 77.110.127.138:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdDAAAAFc"]
[Mon Jul 20 06:26:10.778613 2026] [security2:error] [pid 925208:tid 925425] [client 77.110.127.138:62439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdDAAAAFc"]
[Mon Jul 20 06:26:10.835336 2026] [security2:error] [pid 925208:tid 925433] [client 34.74.185.202:53562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIdFAAAAF8"]
[Mon Jul 20 06:26:10.896224 2026] [security2:error] [pid 925208:tid 925444] [client 57.141.18.33:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcRAAAalE"]
[Mon Jul 20 06:26:10.951458 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdHAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.951572 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdHAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:11.000119 2026] [security2:error] [pid 925208:tid 925368] [client 57.141.18.22:20600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcSAAAHkg"]
[Mon Jul 20 06:26:11.185943 2026] [security2:error] [pid 925208:tid 925401] [client 104.234.53.65:42667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4T48RX7OrFkv0FyuIdKwAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:11.620680 2026] [security2:error] [pid 925208:tid 925382] [client 14.225.17.146:50050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4T4cRX7OrFkv0FyuIcnAAAACw"], referer: http://younutrition.gr/WP
[Mon Jul 20 06:26:11.774363 2026] [security2:error] [pid 925208:tid 925422] [client 57.141.18.25:35390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4cRX7OrFkv0FyuIcjgAAVAo"]
[Mon Jul 20 06:26:11.832526 2026] [security2:error] [pid 925208:tid 925364] [client 14.225.17.146:54222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4T4sRX7OrFkv0FyuIc0wAAABo"], referer: http://superiorcopywriting.com/WP
[Mon Jul 20 06:26:12.706010 2026] [security2:error] [pid 925208:tid 925412] [client 34.73.38.214:61168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T5MRX7OrFkv0FyuIdmwAAAEo"]
[Mon Jul 20 06:26:12.897366 2026] [security2:error] [pid 925208:tid 925393] [client 57.141.18.110:24640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4sRX7OrFkv0FyuIczQAANw4"]
[Mon Jul 20 06:26:12.923627 2026] [security2:error] [pid 925208:tid 925339] [client 104.234.53.57:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4T5MRX7OrFkv0FyuIdqwAAAAE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:13.051430 2026] [security2:error] [pid 925208:tid 925344] [client 57.141.18.116:22858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4sRX7OrFkv0FyuIc3wAABlM"]
[Mon Jul 20 06:26:13.109625 2026] [security2:error] [pid 925208:tid 925403] [client 136.108.37.179:49262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ahirestaurant-co-nz.dbn.vkf.mybluehost.me"] [uri "/index.php"] [unique_id "al4T5MRX7OrFkv0FyuIdpgAAAEE"]
[Mon Jul 20 06:26:13.190719 2026] [security2:error] [pid 925208:tid 925364] [client 136.108.37.179:49262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahirestaurant-co-nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdvQAAABo"]
[Mon Jul 20 06:26:13.190878 2026] [security2:error] [pid 925208:tid 925364] [client 136.108.37.179:49262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ahirestaurant-co-nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdvQAAABo"]
[Mon Jul 20 06:26:13.330190 2026] [security2:error] [pid 925208:tid 925432] [client 171.60.139.123:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdzQAAAF4"]
[Mon Jul 20 06:26:13.330290 2026] [security2:error] [pid 925208:tid 925432] [client 171.60.139.123:57430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdzQAAAF4"]
[Mon Jul 20 06:26:13.378825 2026] [security2:error] [pid 925208:tid 925437] [client 14.225.17.146:49157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4T48RX7OrFkv0FyuIdSgAAAGM"], referer: http://fineartsfactory.net/WP
[Mon Jul 20 06:26:13.413967 2026] [security2:error] [pid 925208:tid 925299] [remote 57.141.18.41:26668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4966246"] [unique_id "al4T5cRX7OrFkv0FyuId1QAAK1o"]
[Mon Jul 20 06:26:13.681127 2026] [security2:error] [pid 925208:tid 925450] [client 50.116.65.227:54566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4T5cRX7OrFkv0FyuId5gAAAHA"]
[Mon Jul 20 06:26:13.690966 2026] [security2:error] [pid 925208:tid 925461] [client 50.116.65.227:54578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4T5cRX7OrFkv0FyuId6AAAAHs"]
[Mon Jul 20 06:26:13.851131 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5cRX7OrFkv0FyuId_AAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:13.851286 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5cRX7OrFkv0FyuId_AAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.005139 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.005262 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.006629 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDgAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.006757 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDgAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.156888 2026] [security2:error] [pid 925208:tid 925421] [client 57.141.18.88:26036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T48RX7OrFkv0FyuIdMQAAUyg"]
[Mon Jul 20 06:26:14.161573 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.161652 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.162083 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHwAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.162169 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHwAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.313938 2026] [security2:error] [pid 925208:tid 925452] [client 77.110.127.138:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeLAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.314075 2026] [security2:error] [pid 925208:tid 925452] [client 77.110.127.138:62464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeLAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.476830 2026] [security2:error] [pid 925208:tid 925411] [client 34.73.38.214:56981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T5sRX7OrFkv0FyuIeOwAAAEk"]
[Mon Jul 20 06:26:14.481132 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIePAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.481253 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIePAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.517346 2026] [security2:error] [pid 925208:tid 925360] [client 158.173.166.181:29653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4T5sRX7OrFkv0FyuIeQQAAABY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:14.575290 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:62468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeRQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.575422 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:62468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeRQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.645825 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeUAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.645949 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeUAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.697250 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeVQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.697372 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeVQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.782664 2026] [security2:error] [pid 925208:tid 925405] [client 103.141.108.143:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeWgAAAEM"]
[Mon Jul 20 06:26:14.782890 2026] [security2:error] [pid 925208:tid 925405] [client 103.141.108.143:65478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeWgAAAEM"]
[Mon Jul 20 06:26:14.876589 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpXm8zdKXe'%20OR%20314=(SELECT%20314%20FROM%20PG_SLEEP(15))--"] [unique_id "al4T5sRX7OrFkv0FyuIeXwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.923278 2026] [security2:error] [pid 925208:tid 925367] [client 45.116.69.230:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeYwAAAB0"]
[Mon Jul 20 06:26:14.923382 2026] [security2:error] [pid 925208:tid 925367] [client 45.116.69.230:49690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeYwAAAB0"]
[Mon Jul 20 06:26:15.307431 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIegwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.307548 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIegwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.335267 2026] [security2:error] [pid 925208:tid 925309] [remote 173.249.4.11:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T58RX7OrFkv0FyuIehwAAIWQ"]
[Mon Jul 20 06:26:15.397660 2026] [security2:error] [pid 925208:tid 925461] [client 34.73.38.214:50718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T58RX7OrFkv0FyuIeiQAAAHs"]
[Mon Jul 20 06:26:15.567966 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIemAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.568372 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIemAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.702313 2026] [security2:error] [pid 925208:tid 925318] [remote 173.249.4.11:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T58RX7OrFkv0FyuIepwAAGW0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:15.726711 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIeqQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.726859 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIeqQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.752895 2026] [security2:error] [pid 925208:tid 925378] [client 5.133.192.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "amorlis.com"] [uri "/index.php"] [unique_id "al4T5MRX7OrFkv0FyuIdiwAAKEc"]
[Mon Jul 20 06:26:15.915405 2026] [security2:error] [pid 925208:tid 925377] [client 14.225.17.146:49493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuId0gAAACc"], referer: http://onewingpictures.com/WP
[Mon Jul 20 06:26:15.952137 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:62486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIetQAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.952240 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:62486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIetQAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.972889 2026] [security2:error] [pid 925208:tid 925371] [client 34.73.38.214:57516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T58RX7OrFkv0FyuIetwAAACE"]
[Mon Jul 20 06:26:16.055505 2026] [security2:error] [pid 925208:tid 925449] [client 57.141.18.95:50098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5MRX7OrFkv0FyuIdngAAb1g"]
[Mon Jul 20 06:26:16.073305 2026] [security2:error] [pid 925208:tid 925346] [client 77.110.127.138:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6MRX7OrFkv0FyuIevwAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:16.073398 2026] [security2:error] [pid 925208:tid 925346] [client 77.110.127.138:62487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6MRX7OrFkv0FyuIevwAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:16.300298 2026] [security2:error] [pid 925208:tid 925342] [client 57.141.18.102:25422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuIdtAAABH0"]
[Mon Jul 20 06:26:16.350548 2026] [security2:error] [pid 925208:tid 925423] [client 104.234.53.80:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4T6MRX7OrFkv0FyuIe1AAAAFU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:16.672564 2026] [security2:error] [pid 925208:tid 925370] [client 34.73.38.214:59787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T6MRX7OrFkv0FyuIe7AAAACA"]
[Mon Jul 20 06:26:16.734105 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php32WfhYog')%20OR%20249=(SELECT%20249%20FROM%20PG_SLEEP(15))--"] [unique_id "al4T6MRX7OrFkv0FyuIe8QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:16.971874 2026] [security2:error] [pid 925208:tid 925442] [client 14.225.17.146:49801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4T58RX7OrFkv0FyuIeiAAAAGg"], referer: http://myspineworld.com/WP
[Mon Jul 20 06:26:17.040188 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.57:28574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuId5AAATgY"]
[Mon Jul 20 06:26:17.098384 2026] [security2:error] [pid 925208:tid 925405] [client 104.234.53.65:24387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4T6cRX7OrFkv0FyuIfEwAAAEM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:17.206812 2026] [security2:error] [pid 925208:tid 925355] [client 20.226.66.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pilarazuaga.com"] [uri "/.well-known/about.php"] [unique_id "al4T6cRX7OrFkv0FyuIfGwAAABE"]
[Mon Jul 20 06:26:17.206943 2026] [security2:error] [pid 925208:tid 925355] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "pilarazuaga.com"] [uri "/.well-known/about.php"] [unique_id "al4T6cRX7OrFkv0FyuIfGwAAABE"]
[Mon Jul 20 06:26:17.376379 2026] [security2:error] [pid 925208:tid 925366] [client 57.141.18.22:20608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuIeCQAAHEI"]
[Mon Jul 20 06:26:17.480275 2026] [security2:error] [pid 925208:tid 925347] [client 14.225.17.146:49789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4T58RX7OrFkv0FyuIehQAAAAk"], referer: http://latiendadejorge.com.gt/WP
[Mon Jul 20 06:26:17.621648 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfOQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:17.621773 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfOQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:17.673857 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfPgAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:17.673947 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfPgAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:18.016361 2026] [security2:error] [pid 925208:tid 925342] [client 14.225.17.146:52763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfUgAAAAQ"], referer: https://myspineworld.com/WP
[Mon Jul 20 06:26:18.248073 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpCxzyy7bY'))%20OR%20649=(SELECT%20649%20FROM%20PG_SLEEP(15))--"] [unique_id "al4T6sRX7OrFkv0FyuIfegAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:18.285358 2026] [security2:error] [pid 925208:tid 925424] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfVwAAAFY"]
[Mon Jul 20 06:26:18.293940 2026] [security2:error] [pid 925208:tid 925369] [client 70.115.45.82:35544] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/author/admin-2/"] [unique_id "al4T6cRX7OrFkv0FyuIfVQAAAB8"]
[Mon Jul 20 06:26:18.380369 2026] [security2:error] [pid 925208:tid 925464] [client 112.208.70.94:44595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T6sRX7OrFkv0FyuIfjQAAAH4"]
[Mon Jul 20 06:26:18.380485 2026] [security2:error] [pid 925208:tid 925464] [client 112.208.70.94:44595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T6sRX7OrFkv0FyuIfjQAAAH4"]
[Mon Jul 20 06:26:18.465015 2026] [security2:error] [pid 925208:tid 925357] [client 34.73.38.214:49937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T6sRX7OrFkv0FyuIfkwAAABM"]
[Mon Jul 20 06:26:19.236585 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf1wAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.236730 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf1wAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.286907 2026] [security2:error] [pid 925208:tid 925302] [remote 95.217.78.234:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T68RX7OrFkv0FyuIf2wAAG10"]
[Mon Jul 20 06:26:19.295379 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:59822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4T68RX7OrFkv0FyuIfxAAAACM"]
[Mon Jul 20 06:26:19.387265 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf6gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.387368 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf6gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.470779 2026] [security2:error] [pid 925208:tid 925421] [client 14.225.17.146:52407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4T6MRX7OrFkv0FyuIfBwAAAFM"], referer: http://gearwaterproof.com/WP
[Mon Jul 20 06:26:19.517582 2026] [security2:error] [pid 925208:tid 925308] [remote 95.217.78.234:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T68RX7OrFkv0FyuIf9QAAamM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:19.788349 2026] [security2:error] [pid 925208:tid 925375] [client 57.141.18.117:31836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6MRX7OrFkv0FyuIewQAAJUM"]
[Mon Jul 20 06:26:19.845988 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4T68RX7OrFkv0FyuIgFQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.877765 2026] [security2:error] [pid 925208:tid 925462] [client 223.185.13.213:6255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T68RX7OrFkv0FyuIgFwAAAHw"]
[Mon Jul 20 06:26:19.877933 2026] [security2:error] [pid 925208:tid 925462] [client 223.185.13.213:6255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T68RX7OrFkv0FyuIgFwAAAHw"]
[Mon Jul 20 06:26:20.142323 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7MRX7OrFkv0FyuIgQgAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.142488 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7MRX7OrFkv0FyuIgQgAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.403739 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:20.403830 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60781] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:20.404415 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:20.404441 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60781] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:20.494290 2026] [security2:error] [pid 925208:tid 925433] [client 34.73.38.214:56785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T7MRX7OrFkv0FyuIgiwAAAF8"]
[Mon Jul 20 06:26:20.562106 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4T7MRX7OrFkv0FyuIgkQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.624149 2026] [security2:error] [pid 925208:tid 925365] [client 77.110.127.138:62496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4T7MRX7OrFkv0FyuIglQAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.698738 2026] [security2:error] [pid 925208:tid 925341] [client 57.141.18.17:45912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfDQAAAxo"]
[Mon Jul 20 06:26:20.755928 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgjwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.951484 2026] [security2:error] [pid 925208:tid 925462] [client 103.153.183.69:6550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../srv/.env"] [unique_id "al4T7MRX7OrFkv0FyuIguwAAAHw"], referer: https://www.google.com/
[Mon Jul 20 06:26:20.973238 2026] [security2:error] [pid 925208:tid 925464] [client 77.110.127.138:62469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgpAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.976028 2026] [security2:error] [pid 925208:tid 925417] [client 14.225.17.146:52651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4T68RX7OrFkv0FyuIf-wAAAE8"], referer: http://massagelacey.com/WP
[Mon Jul 20 06:26:20.978266 2026] [security2:error] [pid 925208:tid 925380] [client 103.153.183.69:6550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/.env"] [unique_id "al4T7MRX7OrFkv0FyuIgwAAAACo"], referer: https://twitter.com/
[Mon Jul 20 06:26:21.128300 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIgzQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.128422 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIgzQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.178515 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIg0wAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.178621 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIg0wAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.367101 2026] [security2:error] [pid 925208:tid 925381] [client 34.73.38.214:60490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T7cRX7OrFkv0FyuIg3gAAACs"]
[Mon Jul 20 06:26:21.370678 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:21.370745 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:21.371432 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:21.371457 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:21.376407 2026] [access_compat:error] [pid 925208:tid 925269] [remote 117.156.187.59:6682] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:26:21.412669 2026] [security2:error] [pid 925208:tid 925423] [client 114.119.158.46:39553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/"] [unique_id "al4T7cRX7OrFkv0FyuIg5AAAAFU"], referer: https://codeczz.com/meh/d2aea4d0d88addb598818b9cdcd98bd08e96818aa5d7b8dd8489f209050081cfa3.html
[Mon Jul 20 06:26:21.520067 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIg1AAAAAM"]
[Mon Jul 20 06:26:21.701292 2026] [access_compat:error] [pid 925208:tid 925274] [remote 117.156.187.59:6682] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/favicon.ico, referer: https://www.new-menus.com/index.php?PHPSESSID=tqqgionc3fgvd2k0e2tbmulo85&topic=12.msg348;topicseen
[Mon Jul 20 06:26:21.805824 2026] [security2:error] [pid 925208:tid 925356] [client 57.141.18.62:21544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfVAAAEjI"]
[Mon Jul 20 06:26:21.807550 2026] [security2:error] [pid 925208:tid 925220] [remote 103.187.169.251:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T7cRX7OrFkv0FyuIhEwAAKgs"]
[Mon Jul 20 06:26:21.812491 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T7cRX7OrFkv0FyuIhFAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.835269 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:62480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIg9AAAAGk"]
[Mon Jul 20 06:26:22.199500 2026] [security2:error] [pid 925208:tid 925286] [remote 103.187.169.251:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T7sRX7OrFkv0FyuIhYAAAf00"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:22.245580 2026] [security2:error] [pid 925208:tid 925461] [client 57.141.18.118:36928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6sRX7OrFkv0FyuIfkQAAe0k"]
[Mon Jul 20 06:26:22.280526 2026] [security2:error] [pid 925208:tid 925442] [client 14.225.17.146:52697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgLQAAAGg"], referer: http://mrbambooplus.com/WP
[Mon Jul 20 06:26:22.320100 2026] [security2:error] [pid 925208:tid 925411] [client 57.141.18.96:34818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6sRX7OrFkv0FyuIflAAASUs"]
[Mon Jul 20 06:26:22.502197 2026] [security2:error] [pid 925208:tid 925400] [client 50.116.65.227:22524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIhfQAAAD4"]
[Mon Jul 20 06:26:22.713259 2026] [security2:error] [pid 925208:tid 925377] [client 50.116.65.227:22532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIhrwAAACc"]
[Mon Jul 20 06:26:22.732248 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh0QAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:22.732408 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh0QAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:22.811412 2026] [security2:error] [pid 925208:tid 925404] [client 14.225.17.146:59976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIg3QAAAEI"], referer: http://expertcultures.com/WP
[Mon Jul 20 06:26:22.837363 2026] [security2:error] [pid 925208:tid 925344] [client 34.73.38.214:52738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T7sRX7OrFkv0FyuIh3QAAAAY"]
[Mon Jul 20 06:26:22.865564 2026] [security2:error] [pid 925208:tid 925426] [client 104.234.53.90:21083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4AAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:22.870882 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:22.870938 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:64944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:22.871429 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:22.871455 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:64944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:22.886003 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4wAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:22.886113 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4wAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.008641 2026] [security2:error] [pid 925208:tid 925355] [client 57.141.18.123:53318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T68RX7OrFkv0FyuIf0QAAEUg"]
[Mon Jul 20 06:26:23.026134 2026] [ssl:error] [pid 925208:tid 925455] [client 66.132.172.178:56868] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.kromosenergy.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:26:23.171905 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIh5wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.174136 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIh8QAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.366054 2026] [security2:error] [pid 925208:tid 925342] [client 14.225.17.146:60067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4gAAAAQ"]
[Mon Jul 20 06:26:23.505217 2026] [security2:error] [pid 925208:tid 925378] [client 14.225.17.146:60182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiBgAAACg"], referer: http://thesoloceos.com/WP
[Mon Jul 20 06:26:23.665497 2026] [security2:error] [pid 925208:tid 925400] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiEgAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.740973 2026] [core:error] [pid 925208:tid 925388] [client 103.153.183.69:48128] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e./%u002e./.env?_=cz21y9yy&v=xqmcf), referer: https://www.google.com/search?q=vfdtar
[Mon Jul 20 06:26:23.780888 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62545] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T78RX7OrFkv0FyuIiOwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.859947 2026] [security2:error] [pid 925208:tid 925338] [client 104.234.53.49:25089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiRQAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:23.922300 2026] [proxy:error] [pid 925208:tid 925424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:23.922353 2026] [proxy_http:error] [pid 925208:tid 925424] [client 34.73.38.214:64321] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:23.922836 2026] [proxy:error] [pid 925208:tid 925424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:23.922863 2026] [proxy_http:error] [pid 925208:tid 925424] [client 34.73.38.214:64321] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:23.940628 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T78RX7OrFkv0FyuIiVAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.940776 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T78RX7OrFkv0FyuIiVAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.094567 2026] [security2:error] [pid 925208:tid 925288] [remote 192.241.143.148:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiaAAAA08"]
[Mon Jul 20 06:26:24.102558 2026] [security2:error] [pid 925208:tid 925212] [remote 20.153.140.50:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiZwAAFQM"]
[Mon Jul 20 06:26:24.146728 2026] [security2:error] [pid 925208:tid 925448] [client 171.60.139.123:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T8MRX7OrFkv0FyuIibQAAAG4"]
[Mon Jul 20 06:26:24.146909 2026] [security2:error] [pid 925208:tid 925448] [client 171.60.139.123:57948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T8MRX7OrFkv0FyuIibQAAAG4"]
[Mon Jul 20 06:26:24.148182 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiTAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.210409 2026] [security2:error] [pid 925208:tid 925309] [remote 152.228.213.32:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIidQAAPGQ"]
[Mon Jul 20 06:26:24.261922 2026] [security2:error] [pid 925208:tid 925460] [client 57.141.18.64:41772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgTQAAenU"]
[Mon Jul 20 06:26:24.267313 2026] [security2:error] [pid 925208:tid 925302] [remote 192.241.143.148:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiewAAQ10"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:24.374493 2026] [security2:error] [pid 925208:tid 925379] [client 114.119.128.46:45255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "keyq8.com"] [uri "/products/%D9%85%D9%81%D8%A7%D8%AA%D9%8A%D8%AD-%D8%B4%D8%A7%D8%B1%D8%A8-%D8%B4%D9%88%D8%AA%D8%B1"] [unique_id "al4T8MRX7OrFkv0FyuIihQAAACk"], referer: https://keyq8.com/products/%D9%85%D9%81%D8%A7%D8%AA%D9%8A%D8%AD-%D8%B4%D8%A7%D8%B1%D8%A8-%D8%B4%D9%88%D8%AA%D8%B1
[Mon Jul 20 06:26:24.438844 2026] [security2:error] [pid 925208:tid 925301] [remote 152.228.213.32:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiiwAAXVw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:24.497139 2026] [security2:error] [pid 925208:tid 925369] [client 14.225.17.146:53747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIifQAAAB8"], referer: https://thesoloceos.com/WP
[Mon Jul 20 06:26:24.517946 2026] [security2:error] [pid 925208:tid 925217] [remote 20.153.140.50:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIikAAAGgg"], referer: https://narv.co/wp-login.php
[Mon Jul 20 06:26:24.541209 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8MRX7OrFkv0FyuIikQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.541323 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8MRX7OrFkv0FyuIikQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.657690 2026] [security2:error] [pid 925208:tid 925388] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIijQAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.739547 2026] [security2:error] [pid 925208:tid 925410] [client 34.73.38.214:64185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T8MRX7OrFkv0FyuIiqwAAAEg"]
[Mon Jul 20 06:26:24.894804 2026] [security2:error] [pid 925208:tid 925440] [client 5.62.145.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIhEQAAAGY"]
[Mon Jul 20 06:26:25.001980 2026] [security2:error] [pid 925208:tid 925373] [client 57.141.18.49:42512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgtAAAI2U"]
[Mon Jul 20 06:26:25.140015 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIivQAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.217831 2026] [security2:error] [pid 925208:tid 925402] [client 57.141.18.11:47906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIgywAAQHY"]
[Mon Jul 20 06:26:25.220721 2026] [security2:error] [pid 925208:tid 925362] [client 14.225.17.146:60233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiMAAAABg"], referer: http://reosportsboats.com/WP
[Mon Jul 20 06:26:25.222837 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4AAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.222948 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4AAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.233928 2026] [security2:error] [pid 925208:tid 925380] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIiwwAAKhk"], referer: http://assasalnazaha.com/WP
[Mon Jul 20 06:26:25.277179 2026] [security2:error] [pid 925208:tid 925462] [client 43.205.139.3:10062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4QAAAHw"]
[Mon Jul 20 06:26:25.277278 2026] [security2:error] [pid 925208:tid 925462] [client 43.205.139.3:10062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4QAAAHw"]
[Mon Jul 20 06:26:25.287257 2026] [security2:error] [pid 925208:tid 925376] [client 104.234.53.90:35035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4T8cRX7OrFkv0FyuIi5AAAACY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:25.431476 2026] [security2:error] [pid 925208:tid 925409] [client 39.48.81.23:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi6wAAAEc"]
[Mon Jul 20 06:26:25.431651 2026] [security2:error] [pid 925208:tid 925409] [client 39.48.81.23:49432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi6wAAAEc"]
[Mon Jul 20 06:26:25.463460 2026] [security2:error] [pid 925208:tid 925395] [client 103.141.108.143:49560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi8wAAADk"]
[Mon Jul 20 06:26:25.463970 2026] [security2:error] [pid 925208:tid 925395] [client 103.141.108.143:49560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi8wAAADk"]
[Mon Jul 20 06:26:25.510882 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIi5gAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.576555 2026] [security2:error] [pid 925208:tid 925437] [client 45.116.69.230:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi-QAAAGM"]
[Mon Jul 20 06:26:25.576651 2026] [security2:error] [pid 925208:tid 925437] [client 45.116.69.230:50220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi-QAAAGM"]
[Mon Jul 20 06:26:25.598516 2026] [security2:error] [pid 925208:tid 925312] [remote 162.19.86.63:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8cRX7OrFkv0FyuIi-wAAG2c"]
[Mon Jul 20 06:26:25.714270 2026] [security2:error] [pid 925208:tid 925296] [remote 57.141.18.6:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4T8cRX7OrFkv0FyuIjBAAAMFc"]
[Mon Jul 20 06:26:25.829066 2026] [security2:error] [pid 925208:tid 925239] [remote 162.19.86.63:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8cRX7OrFkv0FyuIjDwAAXB4"], referer: https://zoa.jji.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:25.897395 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:62558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T8cRX7OrFkv0FyuIjEwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.948406 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIjGQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.948523 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIjGQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.051462 2026] [security2:error] [pid 925208:tid 925341] [client 14.225.17.146:60041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIjCwAAAAM"], referer: http://sesamegreenbeans.com/WP
[Mon Jul 20 06:26:26.065528 2026] [security2:error] [pid 925208:tid 925241] [remote 57.141.18.91:64824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4606669"] [unique_id "al4T8sRX7OrFkv0FyuIjJgAABSA"]
[Mon Jul 20 06:26:26.070171 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:53584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIioQAAAE0"], referer: http://alchemygroup.ca/WP
[Mon Jul 20 06:26:26.074020 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIjEAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.104986 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjJwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.105116 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjJwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.125804 2026] [security2:error] [pid 925208:tid 925372] [client 14.225.17.146:65175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjHgAAACI"], referer: https://reosportsboats.com/WP
[Mon Jul 20 06:26:26.141885 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIjGwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.421570 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjSwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.421670 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjSwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.565704 2026] [security2:error] [pid 925208:tid 925446] [client 34.73.38.214:52699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T8sRX7OrFkv0FyuIjUwAAAGw"]
[Mon Jul 20 06:26:26.590394 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjVQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.590517 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjVQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.603033 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjTgAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.660801 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjTwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.688350 2026] [security2:error] [pid 925208:tid 925385] [client 57.141.18.6:42920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIhrgAAL34"]
[Mon Jul 20 06:26:26.778462 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjaAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.778567 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjaAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.910318 2026] [security2:error] [pid 925208:tid 925350] [client 49.51.243.156:58036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.243.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjcgAAAAw"]
[Mon Jul 20 06:26:27.026808 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjhAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.026901 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjhAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.088327 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjjgAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.088444 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjjgAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.103016 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjcwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.139599 2026] [security2:error] [pid 925208:tid 925389] [client 14.225.17.146:52496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjegAAADM"], referer: https://sesamegreenbeans.com/WP
[Mon Jul 20 06:26:27.303021 2026] [security2:error] [pid 925208:tid 925464] [client 57.141.18.31:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIh-QAAfiY"]
[Mon Jul 20 06:26:27.372548 2026] [security2:error] [pid 925208:tid 925353] [client 74.7.227.179:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjoQAAD0s"], referer: https://tejasenvironmental.com/p=8401
[Mon Jul 20 06:26:27.384203 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjmwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.414276 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjswAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.414361 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjswAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.495437 2026] [security2:error] [pid 925208:tid 925286] [remote 173.249.4.11:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T88RX7OrFkv0FyuIjwAAAU00"]
[Mon Jul 20 06:26:27.680953 2026] [security2:error] [pid 925208:tid 925388] [client 51.15.143.46:33566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4T88RX7OrFkv0FyuIj0QAAADI"]
[Mon Jul 20 06:26:27.795470 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjxAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.833496 2026] [security2:error] [pid 925208:tid 925293] [remote 173.249.4.11:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T88RX7OrFkv0FyuIj4AAAI1Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:28.020983 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9MRX7OrFkv0FyuIj7gAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.021133 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9MRX7OrFkv0FyuIj7gAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.034821 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:10392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4T9MRX7OrFkv0FyuIj8gAAAD8"]
[Mon Jul 20 06:26:28.034928 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:10392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4T9MRX7OrFkv0FyuIj8gAAAD8"]
[Mon Jul 20 06:26:28.107623 2026] [security2:error] [pid 925208:tid 925360] [client 57.141.18.117:54338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiMwAAFic"]
[Mon Jul 20 06:26:28.214499 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIj8AAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.226963 2026] [security2:error] [pid 925208:tid 925249] [remote 124.55.178.99:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T9MRX7OrFkv0FyuIj_gAAZig"]
[Mon Jul 20 06:26:28.281259 2026] [security2:error] [pid 925208:tid 925444] [client 104.234.53.75:34781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4T9MRX7OrFkv0FyuIkCQAAAGo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:28.488262 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T9MRX7OrFkv0FyuIkGAAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.531015 2026] [security2:error] [pid 925208:tid 925465] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkDgAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.623622 2026] [security2:error] [pid 925208:tid 925349] [client 158.173.89.95:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4T9MRX7OrFkv0FyuIkIgAAAAs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:28.649711 2026] [security2:error] [pid 925208:tid 925224] [remote 124.55.178.99:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T9MRX7OrFkv0FyuIkJQAAcA8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:28.696501 2026] [security2:error] [pid 925208:tid 925419] [client 14.225.17.146:52017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjpAAAAFE"], referer: http://dadanetnet.net/WP
[Mon Jul 20 06:26:28.734864 2026] [security2:error] [pid 925208:tid 925353] [client 34.73.38.214:59909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T9MRX7OrFkv0FyuIkMQAAAA8"]
[Mon Jul 20 06:26:28.933634 2026] [security2:error] [pid 925208:tid 925455] [client 57.141.18.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkOwAAAHU"]
[Mon Jul 20 06:26:28.960093 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkMAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.264291 2026] [security2:error] [pid 925208:tid 925431] [client 77.110.127.138:62590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4T9cRX7OrFkv0FyuIkXQAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.314372 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkXgAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.314494 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkXgAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.512267 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.33:55600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIivAAAaGM"]
[Mon Jul 20 06:26:29.715495 2026] [security2:error] [pid 925208:tid 925419] [client 34.73.38.214:59675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T9cRX7OrFkv0FyuIkhgAAAFE"]
[Mon Jul 20 06:26:29.779964 2026] [security2:error] [pid 925208:tid 925354] [client 127.0.0.1:49170] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4T9cRX7OrFkv0FyuIkjQAAABA"], referer: https://www.bing.com/search?q=fjg0ph
[Mon Jul 20 06:26:29.897571 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkmAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.897673 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkmAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.925026 2026] [security2:error] [pid 925208:tid 925329] [remote 66.94.101.63:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T9cRX7OrFkv0FyuIkmgAAa3g"]
[Mon Jul 20 06:26:30.185783 2026] [security2:error] [pid 925208:tid 925388] [client 14.225.17.146:64858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkHAAAADI"], referer: http://aberballet.co.uk/WP
[Mon Jul 20 06:26:30.604818 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9sRX7OrFkv0FyuIkzgAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:30.604923 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9sRX7OrFkv0FyuIkzgAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:30.629487 2026] [security2:error] [pid 925208:tid 925442] [client 223.185.13.213:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T9sRX7OrFkv0FyuIk0AAAAGg"]
[Mon Jul 20 06:26:30.630135 2026] [security2:error] [pid 925208:tid 925442] [client 223.185.13.213:32533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T9sRX7OrFkv0FyuIk0AAAAGg"]
[Mon Jul 20 06:26:30.853532 2026] [security2:error] [pid 925208:tid 925367] [client 57.141.18.119:20626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjOgAAHUY"]
[Mon Jul 20 06:26:30.953147 2026] [security2:error] [pid 925208:tid 925344] [client 74.208.214.194:51248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4T9sRX7OrFkv0FyuIk6gAAAAY"]
[Mon Jul 20 06:26:31.036433 2026] [security2:error] [pid 925208:tid 925395] [client 50.116.65.227:13544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4T98RX7OrFkv0FyuIk7wAAADk"]
[Mon Jul 20 06:26:31.046178 2026] [security2:error] [pid 925208:tid 925415] [client 50.116.65.227:13556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4T98RX7OrFkv0FyuIk8QAAAE0"]
[Mon Jul 20 06:26:31.083124 2026] [security2:error] [pid 925208:tid 925416] [client 34.73.38.214:61794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T98RX7OrFkv0FyuIk9QAAAE4"]
[Mon Jul 20 06:26:31.092279 2026] [security2:error] [pid 925208:tid 925462] [client 14.225.17.146:64898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4T9cRX7OrFkv0FyuIkbQAAAHw"], referer: http://lelandumc.org/WP
[Mon Jul 20 06:26:31.464393 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:62597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/cowl/"] [unique_id "al4T98RX7OrFkv0FyuIlGQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:31.519307 2026] [security2:error] [pid 925208:tid 925422] [client 57.141.18.80:50326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjdAAAVDg"]
[Mon Jul 20 06:26:31.714673 2026] [security2:error] [pid 925208:tid 925357] [client 112.208.70.94:45004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T98RX7OrFkv0FyuIlLwAAABM"]
[Mon Jul 20 06:26:31.714816 2026] [security2:error] [pid 925208:tid 925357] [client 112.208.70.94:45004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T98RX7OrFkv0FyuIlLwAAABM"]
[Mon Jul 20 06:26:31.976812 2026] [security2:error] [pid 925208:tid 925248] [remote 91.142.222.105:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4T98RX7OrFkv0FyuIlPAAAJSc"]
[Mon Jul 20 06:26:32.080880 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62525] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4T-MRX7OrFkv0FyuIlSAAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.181021 2026] [security2:error] [pid 925208:tid 925240] [remote 66.94.101.63:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T-MRX7OrFkv0FyuIlTQAAah8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:32.218923 2026] [security2:error] [pid 925208:tid 925406] [client 106.219.188.178:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4T-MRX7OrFkv0FyuIlTwAAAEQ"]
[Mon Jul 20 06:26:32.219094 2026] [security2:error] [pid 925208:tid 925406] [client 106.219.188.178:10290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4T-MRX7OrFkv0FyuIlTwAAAEQ"]
[Mon Jul 20 06:26:32.232553 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlVgAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.232658 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlVgAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.305697 2026] [security2:error] [pid 925208:tid 925276] [remote 91.142.222.105:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4T-MRX7OrFkv0FyuIlYQAARkM"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 06:26:32.529375 2026] [security2:error] [pid 925208:tid 925445] [client 110.249.201.196:19750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sesamegreenbeans.com"] [uri "/robots.txt"] [unique_id "al4T-MRX7OrFkv0FyuIldAAAAGs"]
[Mon Jul 20 06:26:32.737243 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlhgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.737344 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlhgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.815239 2026] [security2:error] [pid 925208:tid 925365] [client 34.73.38.214:59194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T-MRX7OrFkv0FyuIljwAAABs"]
[Mon Jul 20 06:26:33.187067 2026] [security2:error] [pid 925208:tid 925398] [client 57.141.18.22:25006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkKAAAPCQ"]
[Mon Jul 20 06:26:33.384514 2026] [ssl:error] [pid 925208:tid 925412] [client 2.192.26.217:44302] AH02032: Hostname www.petpawo.com provided via SNI and hostname www.bbcgoodfood.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:26:33.409499 2026] [security2:error] [pid 925208:tid 925445] [client 14.225.17.146:61264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlvAAAAGs"], referer: http://processorstudio.com/WP
[Mon Jul 20 06:26:33.422435 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-cRX7OrFkv0FyuIlvwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:33.422534 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-cRX7OrFkv0FyuIlvwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:33.904738 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/cowl/"] [unique_id "al4T-cRX7OrFkv0FyuIl8QAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:34.055705 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62609] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4T-sRX7OrFkv0FyuImAwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:34.260784 2026] [security2:error] [pid 925208:tid 925418] [client 14.225.17.146:63095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4T-sRX7OrFkv0FyuImEgAAAFA"], referer: https://processorstudio.com/WP
[Mon Jul 20 06:26:34.263207 2026] [security2:error] [pid 925208:tid 925410] [client 34.73.38.214:62129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T-sRX7OrFkv0FyuImFQAAAEg"]
[Mon Jul 20 06:26:34.647866 2026] [security2:error] [pid 925208:tid 925344] [client 171.60.139.123:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T-sRX7OrFkv0FyuImMgAAAAY"]
[Mon Jul 20 06:26:34.648012 2026] [security2:error] [pid 925208:tid 925344] [client 171.60.139.123:58454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T-sRX7OrFkv0FyuImMgAAAAY"]
[Mon Jul 20 06:26:34.859180 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-sRX7OrFkv0FyuImSAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:34.859270 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-sRX7OrFkv0FyuImSAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:35.011943 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-8RX7OrFkv0FyuImUgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:35.012037 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:62614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-8RX7OrFkv0FyuImUgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:35.160033 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:52025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlpQAAAAA"], referer: http://dollpassionista.com/WP
[Mon Jul 20 06:26:35.229995 2026] [security2:error] [pid 925208:tid 925258] [remote 192.241.143.148:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T-8RX7OrFkv0FyuImbQAABjE"]
[Mon Jul 20 06:26:35.311635 2026] [security2:error] [pid 925208:tid 925348] [client 14.225.17.146:64968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImZgAAAAo"], referer: http://keywayconstructionclt.com/WP
[Mon Jul 20 06:26:35.407613 2026] [security2:error] [pid 925208:tid 925301] [remote 192.241.143.148:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T-8RX7OrFkv0FyuImeAAAQ1w"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:35.428305 2026] [security2:error] [pid 925208:tid 925363] [client 57.141.18.59:50568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T9sRX7OrFkv0FyuIk4gAAGRw"]
[Mon Jul 20 06:26:35.791066 2026] [security2:error] [pid 925208:tid 925396] [client 39.48.81.23:50059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T-8RX7OrFkv0FyuImmAAAADo"]
[Mon Jul 20 06:26:35.791263 2026] [security2:error] [pid 925208:tid 925396] [client 39.48.81.23:50059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T-8RX7OrFkv0FyuImmAAAADo"]
[Mon Jul 20 06:26:36.157910 2026] [security2:error] [pid 925208:tid 925359] [client 34.73.38.214:62133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T_MRX7OrFkv0FyuImtQAAABU"]
[Mon Jul 20 06:26:36.163803 2026] [security2:error] [pid 925208:tid 925440] [client 103.141.108.143:50049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImsgAAAGY"]
[Mon Jul 20 06:26:36.163915 2026] [security2:error] [pid 925208:tid 925440] [client 103.141.108.143:50049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImsgAAAGY"]
[Mon Jul 20 06:26:36.167407 2026] [security2:error] [pid 925208:tid 925401] [client 14.225.17.146:61676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImogAAAD8"], referer: https://dollpassionista.com/WP
[Mon Jul 20 06:26:36.190786 2026] [security2:error] [pid 925208:tid 925376] [client 14.225.17.146:63101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4T_MRX7OrFkv0FyuImrwAAACY"], referer: https://keywayconstructionclt.com/WP
[Mon Jul 20 06:26:36.362950 2026] [security2:error] [pid 925208:tid 925355] [client 45.116.69.230:50739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImyAAAABE"]
[Mon Jul 20 06:26:36.363054 2026] [security2:error] [pid 925208:tid 925355] [client 45.116.69.230:50739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImyAAAABE"]
[Mon Jul 20 06:26:36.436341 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_MRX7OrFkv0FyuImzgAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:36.436442 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_MRX7OrFkv0FyuImzgAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:36.880871 2026] [security2:error] [pid 925208:tid 925308] [remote 5.161.225.162:32774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4T_MRX7OrFkv0FyuIm5wAAU2M"]
[Mon Jul 20 06:26:36.965625 2026] [security2:error] [pid 925208:tid 925413] [client 14.225.17.146:52122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIluwAAAEs"], referer: http://areitoproducciones.com/WP
[Mon Jul 20 06:26:37.042369 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/cowl/"] [unique_id "al4T_cRX7OrFkv0FyuIm8wAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:37.101536 2026] [security2:error] [pid 925208:tid 925383] [client 57.141.18.68:36266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-MRX7OrFkv0FyuIlZwAALRY"]
[Mon Jul 20 06:26:37.307872 2026] [security2:error] [pid 925208:tid 925281] [remote 5.161.225.162:32774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4T_cRX7OrFkv0FyuInDAAATkg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:26:37.595868 2026] [security2:error] [pid 925208:tid 925362] [client 104.234.53.67:21935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4T_cRX7OrFkv0FyuInJQAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:37.805966 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.12:44282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlowAAVxg"]
[Mon Jul 20 06:26:38.186232 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:61383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T_sRX7OrFkv0FyuInVAAAAC4"], referer: http://fkconstructionfunding.com/WP
[Mon Jul 20 06:26:38.301033 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.84:53938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlzQAATTY"]
[Mon Jul 20 06:26:38.373248 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInbwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.373363 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInbwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.537283 2026] [security2:error] [pid 925208:tid 925352] [client 77.110.127.138:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInegAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.537383 2026] [security2:error] [pid 925208:tid 925352] [client 77.110.127.138:62636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInegAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.604550 2026] [security2:error] [pid 925208:tid 925304] [remote 74.235.96.117:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4T_sRX7OrFkv0FyuInewAAIV8"]
[Mon Jul 20 06:26:38.677635 2026] [security2:error] [pid 925208:tid 925356] [client 14.225.17.146:63295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4T_cRX7OrFkv0FyuInSgAAABI"], referer: http://aljosour-alarabia.com/WP
[Mon Jul 20 06:26:38.725434 2026] [security2:error] [pid 925208:tid 925423] [client 57.141.18.104:30916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIl9gAAVXs"]
[Mon Jul 20 06:26:38.765386 2026] [security2:error] [pid 925208:tid 925396] [client 153.51.237.35:1250] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4T_sRX7OrFkv0FyuInjAAAADo"]
[Mon Jul 20 06:26:38.902236 2026] [security2:error] [pid 925208:tid 925418] [client 34.73.38.214:62108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T_sRX7OrFkv0FyuInmQAAAFA"]
[Mon Jul 20 06:26:39.168132 2026] [security2:error] [pid 925208:tid 925340] [client 14.225.17.146:55197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T_8RX7OrFkv0FyuInqQAAAAI"], referer: https://fkconstructionfunding.com/WP
[Mon Jul 20 06:26:39.278450 2026] [security2:error] [pid 925208:tid 925240] [remote 74.235.96.117:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4T_8RX7OrFkv0FyuInswAAdB8"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 06:26:39.422640 2026] [security2:error] [pid 925208:tid 925361] [client 57.141.18.37:36990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-sRX7OrFkv0FyuImLQAAFx0"]
[Mon Jul 20 06:26:39.553281 2026] [security2:error] [pid 925208:tid 925311] [remote 202.51.202.242:39272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T_8RX7OrFkv0FyuInxQAAPWY"]
[Mon Jul 20 06:26:39.984901 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_8RX7OrFkv0FyuIn5QAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:39.985022 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_8RX7OrFkv0FyuIn5QAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.146980 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn8QAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.147088 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn8QAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.307005 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn_gAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.307126 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn_gAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.458163 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoDQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.458253 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoDQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.525796 2026] [security2:error] [pid 925208:tid 925338] [client 57.141.18.97:24200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImkAAAAEc"]
[Mon Jul 20 06:26:40.721679 2026] [security2:error] [pid 925208:tid 925381] [client 57.141.18.4:47902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImnQAAK2o"]
[Mon Jul 20 06:26:40.877799 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoMQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.877901 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoMQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.890474 2026] [security2:error] [pid 925208:tid 925438] [client 98.159.234.160:65337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UAMRX7OrFkv0FyuIoNQAAAGQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:41.042109 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoPgAAAAE"]
[Mon Jul 20 06:26:41.042205 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoPgAAAAE"]
[Mon Jul 20 06:26:41.201628 2026] [security2:error] [pid 925208:tid 925294] [remote 124.55.178.99:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAcRX7OrFkv0FyuIoRwAAOlU"]
[Mon Jul 20 06:26:41.202079 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoSAAAADY"]
[Mon Jul 20 06:26:41.202161 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoSAAAADY"]
[Mon Jul 20 06:26:41.363361 2026] [security2:error] [pid 925208:tid 925437] [client 50.116.65.227:27536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UAcRX7OrFkv0FyuIoVQAAAGM"]
[Mon Jul 20 06:26:41.373389 2026] [security2:error] [pid 925208:tid 925464] [client 50.116.65.227:27546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UAcRX7OrFkv0FyuIoVwAAAH4"]
[Mon Jul 20 06:26:41.410220 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:55219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4UAcRX7OrFkv0FyuIoQgAAADE"], referer: http://talknutritionwithlesley.com/WP
[Mon Jul 20 06:26:41.411642 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UAcRX7OrFkv0FyuIoRgAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:41.503744 2026] [security2:error] [pid 925208:tid 925448] [client 34.73.38.214:61121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UAcRX7OrFkv0FyuIoXQAAAG4"]
[Mon Jul 20 06:26:41.704849 2026] [security2:error] [pid 925208:tid 925268] [remote 124.55.178.99:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAcRX7OrFkv0FyuIocgAAOTs"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:26:41.717042 2026] [security2:error] [pid 925208:tid 925443] [client 223.185.13.213:6253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UAcRX7OrFkv0FyuIodAAAAGk"]
[Mon Jul 20 06:26:41.717139 2026] [security2:error] [pid 925208:tid 925443] [client 223.185.13.213:6253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UAcRX7OrFkv0FyuIodAAAAGk"]
[Mon Jul 20 06:26:41.774930 2026] [security2:error] [pid 925208:tid 925263] [remote 5.161.225.162:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UAcRX7OrFkv0FyuIoegAAFzY"]
[Mon Jul 20 06:26:41.838315 2026] [security2:error] [pid 925208:tid 925381] [client 74.208.214.194:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UAcRX7OrFkv0FyuIogAAAACs"]
[Mon Jul 20 06:26:42.017335 2026] [security2:error] [pid 925208:tid 925288] [remote 5.161.225.162:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIokAAAfE8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:42.064273 2026] [security2:error] [pid 925208:tid 925282] [remote 81.173.115.7:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIokQAAMEk"]
[Mon Jul 20 06:26:42.235407 2026] [security2:error] [pid 925208:tid 925393] [client 34.73.38.214:58072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UAsRX7OrFkv0FyuIooQAAADc"]
[Mon Jul 20 06:26:42.278262 2026] [security2:error] [pid 925208:tid 925363] [client 57.141.18.102:28548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T_cRX7OrFkv0FyuInKAAAGSU"]
[Mon Jul 20 06:26:42.281189 2026] [security2:error] [pid 925208:tid 925332] [remote 81.173.115.7:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIopgAATHs"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:26:42.462702 2026] [security2:error] [pid 925208:tid 925289] [remote 202.51.202.242:39272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIougAAAFA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:42.463842 2026] [security2:error] [pid 925208:tid 925426] [client 158.173.241.141:24495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIongAAWCI"]
[Mon Jul 20 06:26:42.600339 2026] [security2:error] [pid 925208:tid 925413] [client 106.219.188.178:27752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UAsRX7OrFkv0FyuIowAAAAEs"]
[Mon Jul 20 06:26:42.600453 2026] [security2:error] [pid 925208:tid 925413] [client 106.219.188.178:27752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UAsRX7OrFkv0FyuIowAAAAEs"]
[Mon Jul 20 06:26:42.604739 2026] [security2:error] [pid 925208:tid 925419] [client 114.119.134.231:61991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vfcthomasville.org"] [uri "/sermons/the-domino-effect-part-2-vision-and-voices-jamie-nunnally/"] [unique_id "al4UAsRX7OrFkv0FyuIowQAAAFE"], referer: https://www.vfcthomasville.org/
[Mon Jul 20 06:26:43.010263 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo4wAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.010388 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo4wAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.148411 2026] [security2:error] [pid 925208:tid 925408] [client 50.116.65.227:29658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4UA8RX7OrFkv0FyuIo7wAAAEY"]
[Mon Jul 20 06:26:43.161539 2026] [security2:error] [pid 925208:tid 925381] [client 50.116.65.227:27564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4UA8RX7OrFkv0FyuIo8QAAACk"]
[Mon Jul 20 06:26:43.199158 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo-AAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.199269 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo-AAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.304253 2026] [security2:error] [pid 925208:tid 925367] [client 14.225.17.146:55452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIovwAAAB0"], referer: http://idigress.studio/WP
[Mon Jul 20 06:26:43.618803 2026] [security2:error] [pid 925208:tid 925373] [client 57.141.18.42:59198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T_sRX7OrFkv0FyuInkwAAIxw"]
[Mon Jul 20 06:26:44.222298 2026] [security2:error] [pid 925208:tid 925349] [client 34.73.38.214:56060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UBMRX7OrFkv0FyuIpPwAAAAs"]
[Mon Jul 20 06:26:44.367932 2026] [security2:error] [pid 925208:tid 925339] [client 117.212.246.249:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.246.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpTQAAAAE"]
[Mon Jul 20 06:26:44.368079 2026] [security2:error] [pid 925208:tid 925339] [client 117.212.246.249:51782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arunavabanerjee.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpTQAAAAE"]
[Mon Jul 20 06:26:44.960388 2026] [security2:error] [pid 925208:tid 925368] [client 112.208.70.94:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpigAAAB4"]
[Mon Jul 20 06:26:44.960504 2026] [security2:error] [pid 925208:tid 925368] [client 112.208.70.94:45425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpigAAAB4"]
[Mon Jul 20 06:26:44.971009 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UBMRX7OrFkv0FyuIpgAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.175070 2026] [security2:error] [pid 925208:tid 925420] [client 171.60.139.123:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UBcRX7OrFkv0FyuIpnQAAAFI"]
[Mon Jul 20 06:26:45.175238 2026] [security2:error] [pid 925208:tid 925420] [client 171.60.139.123:58964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UBcRX7OrFkv0FyuIpnQAAAFI"]
[Mon Jul 20 06:26:45.181290 2026] [security2:error] [pid 925208:tid 925352] [client 77.110.127.138:62678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 440 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UBcRX7OrFkv0FyuIpnwAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.250524 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.85:48838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAMRX7OrFkv0FyuIn7QAAaAI"]
[Mon Jul 20 06:26:45.337041 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UBcRX7OrFkv0FyuIprAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.337153 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UBcRX7OrFkv0FyuIprAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.753564 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UBcRX7OrFkv0FyuIptwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:46.021594 2026] [security2:error] [pid 925208:tid 925321] [remote 81.173.115.7:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UBsRX7OrFkv0FyuIp6AAAEXA"]
[Mon Jul 20 06:26:46.099178 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.4:26538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAMRX7OrFkv0FyuIoOgAATS0"]
[Mon Jul 20 06:26:46.285727 2026] [security2:error] [pid 925208:tid 925295] [remote 128.1.121.56:52954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "abilityplus.org"] [uri "/"] [unique_id "al4UBsRX7OrFkv0FyuIqAwAAPFY"]
[Mon Jul 20 06:26:46.285851 2026] [security2:error] [pid 925208:tid 925261] [remote 81.173.115.7:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UBsRX7OrFkv0FyuIqBAAAEjQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:46.836637 2026] [security2:error] [pid 925208:tid 925459] [client 39.48.81.23:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLAAAAHk"]
[Mon Jul 20 06:26:46.836772 2026] [security2:error] [pid 925208:tid 925459] [client 39.48.81.23:50635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLAAAAHk"]
[Mon Jul 20 06:26:46.866489 2026] [security2:error] [pid 925208:tid 925371] [client 103.141.108.143:50521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLwAAACE"]
[Mon Jul 20 06:26:46.866625 2026] [security2:error] [pid 925208:tid 925371] [client 103.141.108.143:50521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLwAAACE"]
[Mon Jul 20 06:26:46.999692 2026] [security2:error] [pid 925208:tid 925420] [client 45.116.69.230:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqOQAAAFI"]
[Mon Jul 20 06:26:46.999852 2026] [security2:error] [pid 925208:tid 925420] [client 45.116.69.230:51256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqOQAAAFI"]
[Mon Jul 20 06:26:47.064667 2026] [security2:error] [pid 925208:tid 925215] [remote 68.178.160.25:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqQgAABQY"]
[Mon Jul 20 06:26:47.281971 2026] [security2:error] [pid 925208:tid 925241] [remote 45.90.123.233:34316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqWQAAKyA"]
[Mon Jul 20 06:26:47.457638 2026] [security2:error] [pid 925208:tid 925384] [client 57.141.18.14:52024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIonAAALmA"]
[Mon Jul 20 06:26:47.507362 2026] [security2:error] [pid 925208:tid 925312] [remote 45.90.123.233:34316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqaQAAI2c"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:26:47.568918 2026] [security2:error] [pid 925208:tid 925296] [remote 68.178.160.25:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqbAAAe1c"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:47.662274 2026] [security2:error] [pid 925208:tid 925346] [client 14.225.17.146:63949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4UBsRX7OrFkv0FyuIp8AAAAAg"], referer: http://bnb-engineering.com/WP
[Mon Jul 20 06:26:47.690630 2026] [security2:error] [pid 925208:tid 925378] [client 57.141.18.115:32152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIotQAAKGI"]
[Mon Jul 20 06:26:47.980095 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UB8RX7OrFkv0FyuIqigAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:47.980209 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UB8RX7OrFkv0FyuIqigAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.006671 2026] [security2:error] [pid 925208:tid 925375] [client 57.141.18.92:47848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIoxgAAJV0"]
[Mon Jul 20 06:26:48.137158 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqmgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.137320 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqmgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.303284 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqpwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.303395 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqpwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.514919 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqtQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.515021 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqtQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.681565 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqvwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.681673 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqvwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.709971 2026] [security2:error] [pid 925208:tid 925357] [client 66.249.72.165:44778] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "box5020.bluehost.com"] [uri "/robots.txt"] [unique_id "al4UCMRX7OrFkv0FyuIqwAAAABM"]
[Mon Jul 20 06:26:48.835310 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq0QAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.835400 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq0QAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.952809 2026] [security2:error] [pid 925208:tid 925434] [client 46.55.204.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4UBsRX7OrFkv0FyuIp8gAAAGA"]
[Mon Jul 20 06:26:48.987121 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq4gAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.987214 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq4gAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.168569 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq5gAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.168675 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq5gAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.327049 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq-gAAAEA"]
[Mon Jul 20 06:26:49.327170 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq-gAAAEA"]
[Mon Jul 20 06:26:49.464809 2026] [security2:error] [pid 925208:tid 925431] [client 57.141.18.11:53720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBMRX7OrFkv0FyuIpRwAAXUA"]
[Mon Jul 20 06:26:49.480138 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrCQAAAAw"]
[Mon Jul 20 06:26:49.480213 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrCQAAAAw"]
[Mon Jul 20 06:26:49.617827 2026] [proxy:error] [pid 925208:tid 925406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.617918 2026] [proxy_http:error] [pid 925208:tid 925406] [client 185.147.157.29:58298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.618647 2026] [proxy:error] [pid 925208:tid 925406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.618681 2026] [proxy_http:error] [pid 925208:tid 925406] [client 185.147.157.29:58298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.634881 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrEwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.635014 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrEwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.638497 2026] [proxy:error] [pid 925208:tid 925371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.638528 2026] [proxy_http:error] [pid 925208:tid 925371] [client 185.147.157.29:32720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.639000 2026] [proxy:error] [pid 925208:tid 925371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.639022 2026] [proxy_http:error] [pid 925208:tid 925371] [client 185.147.157.29:32720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.681005 2026] [security2:error] [pid 925208:tid 925272] [remote 192.241.143.148:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UCcRX7OrFkv0FyuIrHAAARj8"]
[Mon Jul 20 06:26:49.681178 2026] [security2:error] [pid 925208:tid 925408] [client 192.241.143.148:45464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UCcRX7OrFkv0FyuIrHAAARj8"]
[Mon Jul 20 06:26:49.778381 2026] [security2:error] [pid 925208:tid 925421] [client 57.141.18.25:51248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBMRX7OrFkv0FyuIpYgAAUw4"]
[Mon Jul 20 06:26:49.791876 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrKwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.792029 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrKwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.835881 2026] [proxy:error] [pid 925208:tid 925393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.835961 2026] [proxy_http:error] [pid 925208:tid 925393] [client 185.147.157.29:32730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.836444 2026] [proxy:error] [pid 925208:tid 925382] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.836543 2026] [proxy_http:error] [pid 925208:tid 925382] [client 185.147.157.29:32736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.836631 2026] [proxy:error] [pid 925208:tid 925393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.836663 2026] [proxy_http:error] [pid 925208:tid 925393] [client 185.147.157.29:32730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.837433 2026] [proxy:error] [pid 925208:tid 925382] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.837487 2026] [proxy_http:error] [pid 925208:tid 925382] [client 185.147.157.29:32736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.945419 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrNAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.945521 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrNAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.102173 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrSQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.102267 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrSQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.189151 2026] [security2:error] [pid 925208:tid 925395] [client 50.116.65.227:24650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/wp-cron.php"] [unique_id "al4UCsRX7OrFkv0FyuIrUQAAADk"]
[Mon Jul 20 06:26:50.217790 2026] [security2:error] [pid 925208:tid 925423] [client 14.225.17.146:61871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrTAAAAFU"], referer: http://grndl.com/WP
[Mon Jul 20 06:26:50.239416 2026] [security2:error] [pid 925208:tid 925359] [client 57.141.18.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrRwAAABU"]
[Mon Jul 20 06:26:50.258835 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrVgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.258952 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrVgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.292213 2026] [security2:error] [pid 925208:tid 925392] [client 14.225.17.146:50406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrPAAAADY"], referer: http://healthylifegourmet.org/WP
[Mon Jul 20 06:26:50.412002 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrYQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.412095 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrYQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.453513 2026] [security2:error] [pid 925208:tid 925386] [client 104.234.53.94:33545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UCsRX7OrFkv0FyuIrZgAAADA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:50.479558 2026] [security2:error] [pid 925208:tid 925369] [client 50.116.65.227:16692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UCsRX7OrFkv0FyuIraQAAAB8"]
[Mon Jul 20 06:26:50.490645 2026] [security2:error] [pid 925208:tid 925370] [client 50.116.65.227:16698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UCsRX7OrFkv0FyuIrbAAAACA"]
[Mon Jul 20 06:26:50.571582 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrcwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.571673 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrcwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.750138 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrgwAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.750269 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrgwAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.849263 2026] [security2:error] [pid 925208:tid 925360] [client 57.141.18.95:55830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBcRX7OrFkv0FyuIpuwAAFhs"]
[Mon Jul 20 06:26:50.908688 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrkAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.908791 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrkAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.969039 2026] [security2:error] [pid 925208:tid 925348] [client 57.141.18.113:22636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBcRX7OrFkv0FyuIpwQAAClk"]
[Mon Jul 20 06:26:51.062628 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrlwAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.062765 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrlwAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.178301 2026] [security2:error] [pid 925208:tid 925278] [remote 160.187.68.132:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIrngAAUEU"]
[Mon Jul 20 06:26:51.216073 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIroAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.216185 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIroAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.237121 2026] [security2:error] [pid 925208:tid 925308] [remote 160.187.68.132:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIroQAAG2M"]
[Mon Jul 20 06:26:51.371464 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIruQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.371542 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIruQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.526182 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrxgAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.526297 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:62706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrxgAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.580022 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrzQAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.580135 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrzQAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.651605 2026] [security2:error] [pid 925208:tid 925251] [remote 160.187.68.132:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIr1AAAQyo"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 06:26:51.736227 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr2QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.736340 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr2QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.749136 2026] [security2:error] [pid 925208:tid 925331] [remote 160.187.68.132:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIr3QAAIHo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:51.892202 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr6AAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.892289 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr6AAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.045621 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr9QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.045718 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr9QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.096864 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr_QAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.096959 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr_QAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.132590 2026] [security2:error] [pid 925208:tid 925427] [client 57.141.18.96:57648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBsRX7OrFkv0FyuIqMwAAWSQ"]
[Mon Jul 20 06:26:52.249170 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.249295 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.251372 2026] [security2:error] [pid 925208:tid 925390] [client 13.201.64.214:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBgAAADQ"]
[Mon Jul 20 06:26:52.251465 2026] [security2:error] [pid 925208:tid 925390] [client 13.201.64.214:64758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBgAAADQ"]
[Mon Jul 20 06:26:52.277370 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:19949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsCQAAAC0"]
[Mon Jul 20 06:26:52.277515 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:19949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsCQAAAC0"]
[Mon Jul 20 06:26:52.402948 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsEQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.403044 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsEQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.569475 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsHgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.569582 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsHgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.621368 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsIgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.621488 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsIgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.781763 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.781877 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:62713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.846635 2026] [security2:error] [pid 925208:tid 925388] [client 106.219.188.178:27748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKgAAADI"]
[Mon Jul 20 06:26:52.853236 2026] [security2:error] [pid 925208:tid 925388] [client 106.219.188.178:27748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKgAAADI"]
[Mon Jul 20 06:26:52.871505 2026] [security2:error] [pid 925208:tid 925391] [client 57.141.18.108:33030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UB8RX7OrFkv0FyuIqeQAANXE"]
[Mon Jul 20 06:26:52.874644 2026] [security2:error] [pid 925208:tid 925354] [client 45.157.112.60:48217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UDMRX7OrFkv0FyuIsLQAAABA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:52.934683 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsNAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.934777 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsNAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.049830 2026] [security2:error] [pid 925208:tid 925461] [client 171.61.165.146:15076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPAAAAHs"]
[Mon Jul 20 06:26:53.049947 2026] [security2:error] [pid 925208:tid 925461] [client 171.61.165.146:15076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPAAAAHs"]
[Mon Jul 20 06:26:53.093242 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.093377 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:62715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.194254 2026] [security2:error] [pid 925208:tid 925459] [client 57.141.18.50:46372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCMRX7OrFkv0FyuIqlgAAeXM"]
[Mon Jul 20 06:26:53.198779 2026] [security2:error] [pid 925208:tid 925338] [client 104.234.53.85:55153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UDcRX7OrFkv0FyuIsRAAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:53.248480 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsSgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.248596 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsSgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.405619 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsXAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.405714 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:62717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsXAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.728684 2026] [security2:error] [pid 925208:tid 925276] [remote 41.76.213.235:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.213.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UDcRX7OrFkv0FyuIsdAAAb0M"]
[Mon Jul 20 06:26:53.841809 2026] [security2:error] [pid 925208:tid 925349] [client 57.141.18.66:30034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCMRX7OrFkv0FyuIqvQAAC38"]
[Mon Jul 20 06:26:53.903551 2026] [security2:error] [pid 925208:tid 925448] [client 77.110.127.138:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsgAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.903686 2026] [security2:error] [pid 925208:tid 925448] [client 77.110.127.138:62718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsgAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.967960 2026] [security2:error] [pid 925208:tid 925429] [client 104.234.53.61:58351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UDcRX7OrFkv0FyuIsfgAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:54.056572 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsiwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.056675 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsiwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.057557 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 164 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UDsRX7OrFkv0FyuIsigAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.149433 2026] [security2:error] [pid 925208:tid 925419] [client 57.141.18.66:30036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCcRX7OrFkv0FyuIq5AAAUTM"]
[Mon Jul 20 06:26:54.228381 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsowAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.228519 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsowAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.264020 2026] [security2:error] [pid 925208:tid 925237] [remote 41.76.213.235:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.213.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UDsRX7OrFkv0FyuIsrgAAPxw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:54.381348 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsuwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.381469 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsuwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.460804 2026] [security2:error] [pid 925208:tid 925369] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UDsRX7OrFkv0FyuIsrQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.539203 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIswwAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.539305 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIswwAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.621702 2026] [security2:error] [pid 925208:tid 925465] [client 77.110.127.138:62725] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 972 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UDsRX7OrFkv0FyuIs0QAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.693127 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs1wAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.693227 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:62726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs1wAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.847456 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs7AAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.847548 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs7AAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.977497 2026] [security2:error] [pid 925208:tid 925344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UDsRX7OrFkv0FyuIs5gAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.154386 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:62729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 562 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UD8RX7OrFkv0FyuIs_QAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.160862 2026] [security2:error] [pid 925208:tid 925281] [remote 5.182.209.54:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UD8RX7OrFkv0FyuIs_AAAAUg"]
[Mon Jul 20 06:26:55.215164 2026] [security2:error] [pid 925208:tid 925455] [client 46.110.96.34:25294] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4UD8RX7OrFkv0FyuItAAAAAHU"]
[Mon Jul 20 06:26:55.216093 2026] [security2:error] [pid 925208:tid 925342] [client 46.110.96.34:22683] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4UD8RX7OrFkv0FyuItAQAAAAQ"]
[Mon Jul 20 06:26:55.300125 2026] [ssl:error] [pid 925208:tid 925406] [client 107.173.210.100:38812] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname kpb.qlr.mybluehost.me provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:26:55.317763 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UD8RX7OrFkv0FyuItDQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.318360 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UD8RX7OrFkv0FyuItDQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.337797 2026] [security2:error] [pid 925208:tid 925335] [remote 5.182.209.54:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UD8RX7OrFkv0FyuItDgAAC34"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:26:55.447196 2026] [proxy:error] [pid 925208:tid 925348] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:55.447272 2026] [proxy_http:error] [pid 925208:tid 925348] [client 34.73.38.214:63909] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:55.447865 2026] [proxy:error] [pid 925208:tid 925348] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:55.447890 2026] [proxy_http:error] [pid 925208:tid 925348] [client 34.73.38.214:63909] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:55.667905 2026] [security2:error] [pid 925208:tid 925440] [client 104.234.53.61:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UD8RX7OrFkv0FyuItKAAAAGY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:55.711412 2026] [security2:error] [pid 925208:tid 925437] [client 171.60.139.123:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UD8RX7OrFkv0FyuItLAAAAGM"]
[Mon Jul 20 06:26:55.711558 2026] [security2:error] [pid 925208:tid 925437] [client 171.60.139.123:59483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UD8RX7OrFkv0FyuItLAAAAGM"]
[Mon Jul 20 06:26:55.871716 2026] [security2:error] [pid 925208:tid 925340] [client 57.141.18.19:58644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrZQAAAis"]
[Mon Jul 20 06:26:56.177164 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItWAAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:56.177255 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItWAAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:56.350375 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItZAAAADA"]
[Mon Jul 20 06:26:56.350471 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItZAAAADA"]
[Mon Jul 20 06:26:56.481754 2026] [security2:error] [pid 925208:tid 925347] [client 104.234.53.78:53111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UEMRX7OrFkv0FyuItZgAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:56.728271 2026] [fcgid:warn] [pid 925208:tid 925401] (70014)End of file found: [client 66.132.186.171:16164] mod_fcgid: can't get data from http client
[Mon Jul 20 06:26:57.015461 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UEMRX7OrFkv0FyuItiQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.022158 2026] [proxy:error] [pid 925208:tid 925345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:57.022231 2026] [proxy_http:error] [pid 925208:tid 925345] [client 34.73.38.214:62512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:57.022920 2026] [proxy:error] [pid 925208:tid 925345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:57.022953 2026] [proxy_http:error] [pid 925208:tid 925345] [client 34.73.38.214:62512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:57.064630 2026] [security2:error] [pid 925208:tid 925408] [client 57.141.18.124:20350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UC8RX7OrFkv0FyuIrwwAARkw"]
[Mon Jul 20 06:26:57.169864 2026] [security2:error] [pid 925208:tid 925376] [client 77.110.127.138:62736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 970 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UEcRX7OrFkv0FyuItnwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.235578 2026] [security2:error] [pid 925208:tid 925433] [client 14.225.17.146:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UD8RX7OrFkv0FyuItKgAAAF8"], referer: http://nurturemarple.co.uk/WP
[Mon Jul 20 06:26:57.355463 2026] [security2:error] [pid 925208:tid 925435] [client 77.110.127.138:62737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItrgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.355546 2026] [security2:error] [pid 925208:tid 925435] [client 77.110.127.138:62737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItrgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.400466 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItsAAAABI"]
[Mon Jul 20 06:26:57.400590 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItsAAAABI"]
[Mon Jul 20 06:26:57.489171 2026] [security2:error] [pid 925208:tid 925360] [client 103.141.108.143:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItvAAAABY"]
[Mon Jul 20 06:26:57.489293 2026] [security2:error] [pid 925208:tid 925360] [client 103.141.108.143:50992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItvAAAABY"]
[Mon Jul 20 06:26:57.534076 2026] [security2:error] [pid 925208:tid 925261] [remote 57.141.18.2:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4UEcRX7OrFkv0FyuItvgAABzQ"]
[Mon Jul 20 06:26:57.567221 2026] [security2:error] [pid 925208:tid 925212] [remote 156.67.31.167:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4UEcRX7OrFkv0FyuItwAAAXAM"]
[Mon Jul 20 06:26:57.624091 2026] [security2:error] [pid 925208:tid 925438] [client 39.48.81.23:51083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwQAAAGQ"]
[Mon Jul 20 06:26:57.624227 2026] [security2:error] [pid 925208:tid 925438] [client 39.48.81.23:51083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwQAAAGQ"]
[Mon Jul 20 06:26:57.650709 2026] [security2:error] [pid 925208:tid 925344] [client 45.116.69.230:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwwAAAAY"]
[Mon Jul 20 06:26:57.650841 2026] [security2:error] [pid 925208:tid 925344] [client 45.116.69.230:51790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwwAAAAY"]
[Mon Jul 20 06:26:57.719029 2026] [security2:error] [pid 925208:tid 925452] [client 50.116.65.227:16730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UEcRX7OrFkv0FyuItrwAAAHI"]
[Mon Jul 20 06:26:57.750081 2026] [security2:error] [pid 925208:tid 925224] [remote 156.67.31.167:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4UEcRX7OrFkv0FyuIt0gAANw8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:26:57.920132 2026] [security2:error] [pid 925208:tid 925420] [client 50.116.65.227:16738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UEcRX7OrFkv0FyuItygAAAFI"]
[Mon Jul 20 06:26:58.108894 2026] [security2:error] [pid 925208:tid 925402] [client 112.208.70.94:45881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIt9wAAAEA"]
[Mon Jul 20 06:26:58.108989 2026] [security2:error] [pid 925208:tid 925402] [client 112.208.70.94:45881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIt9wAAAEA"]
[Mon Jul 20 06:26:58.202091 2026] [security2:error] [pid 925208:tid 925403] [client 14.225.17.146:51397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UEsRX7OrFkv0FyuIt8gAAAEE"], referer: https://nurturemarple.co.uk/WP
[Mon Jul 20 06:26:58.369271 2026] [proxy:error] [pid 925208:tid 925449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:58.369358 2026] [proxy_http:error] [pid 925208:tid 925449] [client 34.73.38.214:52771] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:58.369886 2026] [proxy:error] [pid 925208:tid 925449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:58.369915 2026] [proxy_http:error] [pid 925208:tid 925449] [client 34.73.38.214:52771] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:58.483710 2026] [security2:error] [pid 925208:tid 925416] [client 14.225.17.146:56595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4UEsRX7OrFkv0FyuIuBgAAAE4"], referer: http://adirondackengineering.com/WP
[Mon Jul 20 06:26:58.767387 2026] [security2:error] [pid 925208:tid 925368] [client 171.61.165.146:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIuJgAAAB4"]
[Mon Jul 20 06:26:58.767490 2026] [security2:error] [pid 925208:tid 925368] [client 171.61.165.146:29155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIuJgAAAB4"]
[Mon Jul 20 06:26:58.916593 2026] [core:error] [pid 925208:tid 925415] [client 185.247.137.219:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:26:58.916611 2026] [core:error] [pid 925208:tid 925415] [client 185.247.137.219:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:26:59.203580 2026] [security2:error] [pid 925208:tid 925424] [client 57.141.18.98:26888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UDcRX7OrFkv0FyuIsUAAAVnU"]
[Mon Jul 20 06:26:59.477766 2026] [security2:error] [pid 925208:tid 925448] [client 50.116.65.227:13982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UE8RX7OrFkv0FyuIucwAAAG4"]
[Mon Jul 20 06:26:59.485971 2026] [security2:error] [pid 925208:tid 925378] [client 50.116.65.227:13984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UE8RX7OrFkv0FyuIudgAAACg"]
[Mon Jul 20 06:26:59.662306 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIucgAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:59.895022 2026] [security2:error] [pid 925208:tid 925230] [remote 117.0.21.154:40244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIuigAAPxU"]
[Mon Jul 20 06:26:59.895234 2026] [security2:error] [pid 925208:tid 925401] [client 117.0.21.154:40244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIuigAAPxU"]
[Mon Jul 20 06:26:59.918410 2026] [security2:error] [pid 925208:tid 925460] [client 77.110.127.138:62746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 106 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UE8RX7OrFkv0FyuIujQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:59.981178 2026] [security2:error] [pid 925208:tid 925324] [remote 8.217.108.67:2422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIukwAAcnM"]
[Mon Jul 20 06:26:59.981378 2026] [security2:error] [pid 925208:tid 925452] [client 8.217.108.67:2422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIukwAAcnM"]
[Mon Jul 20 06:26:59.985523 2026] [security2:error] [pid 925208:tid 925353] [client 43.205.139.3:30560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIulQAAAA8"]
[Mon Jul 20 06:26:59.985610 2026] [security2:error] [pid 925208:tid 925353] [client 43.205.139.3:30560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIulQAAAA8"]
[Mon Jul 20 06:27:00.117541 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:62747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIungAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.117886 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:62747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIungAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.231353 2026] [security2:error] [pid 925208:tid 925432] [client 14.225.17.146:50777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UFMRX7OrFkv0FyuIumAAAAF4"], referer: http://mezzacraft.com/WP
[Mon Jul 20 06:27:00.295393 2026] [security2:error] [pid 925208:tid 925464] [client 57.141.18.6:56662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UDsRX7OrFkv0FyuIsxwAAfgo"]
[Mon Jul 20 06:27:00.303873 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIurgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.303999 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIurgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.457632 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIuuAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.457722 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIuuAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.548980 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:00.549033 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:59292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:00.549895 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:00.549930 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:59292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:00.632882 2026] [security2:error] [pid 925208:tid 925435] [client 14.225.17.146:64537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIuYQAAAGE"], referer: http://betterbonddogtraining.com/WP
[Mon Jul 20 06:27:00.893265 2026] [security2:error] [pid 925208:tid 925424] [client 50.116.65.227:13996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4UFMRX7OrFkv0FyuIu7gAAAFY"]
[Mon Jul 20 06:27:00.896861 2026] [security2:error] [pid 925208:tid 925352] [client 14.225.17.146:51238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIuZQAAAA4"], referer: http://recruitinginsight.us/WP
[Mon Jul 20 06:27:01.114927 2026] [security2:error] [pid 925208:tid 925370] [client 52.183.195.200:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4UFcRX7OrFkv0FyuIu_wAAACA"]
[Mon Jul 20 06:27:01.143286 2026] [security2:error] [pid 925208:tid 925376] [client 52.183.195.200:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4UFcRX7OrFkv0FyuIvAwAAACY"]
[Mon Jul 20 06:27:01.179639 2026] [security2:error] [pid 925208:tid 925394] [client 57.141.18.54:39846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UD8RX7OrFkv0FyuItGAAAOFU"]
[Mon Jul 20 06:27:01.222017 2026] [security2:error] [pid 925208:tid 925450] [client 52.183.195.200:26120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4UFcRX7OrFkv0FyuIvBwAAAHA"]
[Mon Jul 20 06:27:01.251906 2026] [security2:error] [pid 925208:tid 925413] [client 52.183.195.200:26120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4UFcRX7OrFkv0FyuIvCAAAAEs"]
[Mon Jul 20 06:27:01.267249 2026] [security2:error] [pid 925208:tid 925264] [remote 20.173.88.122:42650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UFcRX7OrFkv0FyuIvCQAATjc"]
[Mon Jul 20 06:27:01.521215 2026] [security2:error] [pid 925208:tid 925425] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UFcRX7OrFkv0FyuIvEQAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:01.731100 2026] [security2:error] [pid 925208:tid 925231] [remote 20.173.88.122:42650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UFcRX7OrFkv0FyuIvMgAAXxY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:27:01.778232 2026] [security2:error] [pid 925208:tid 925403] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metodoshanti.com"] [uri "/.well-known/about.php"] [unique_id "al4UFcRX7OrFkv0FyuIvNwAAAEE"]
[Mon Jul 20 06:27:01.778329 2026] [security2:error] [pid 925208:tid 925403] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "metodoshanti.com"] [uri "/.well-known/about.php"] [unique_id "al4UFcRX7OrFkv0FyuIvNwAAAEE"]
[Mon Jul 20 06:27:01.962239 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.1:61984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEMRX7OrFkv0FyuItaAAAaA0"]
[Mon Jul 20 06:27:01.993353 2026] [security2:error] [pid 925208:tid 925384] [client 34.73.38.214:61637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UFcRX7OrFkv0FyuIvTwAAAC4"]
[Mon Jul 20 06:27:02.102271 2026] [security2:error] [pid 925208:tid 925445] [client 158.173.166.181:61375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UFsRX7OrFkv0FyuIvVwAAAGs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:02.324140 2026] [security2:error] [pid 925208:tid 925364] [client 57.141.18.42:40466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEMRX7OrFkv0FyuItkAAAGj4"]
[Mon Jul 20 06:27:02.835684 2026] [security2:error] [pid 925208:tid 925284] [remote 57.141.18.32:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4636225"] [unique_id "al4UFsRX7OrFkv0FyuIvkAAABks"]
[Mon Jul 20 06:27:02.906247 2026] [security2:error] [pid 925208:tid 925339] [client 57.141.18.5:65376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEcRX7OrFkv0FyuItzgAAATI"]
[Mon Jul 20 06:27:02.949640 2026] [security2:error] [pid 925208:tid 925439] [client 34.73.38.214:54162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UFsRX7OrFkv0FyuIvpQAAAGU"]
[Mon Jul 20 06:27:03.111220 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIvtQAAAB8"]
[Mon Jul 20 06:27:03.111347 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:15402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIvtQAAAB8"]
[Mon Jul 20 06:27:03.420800 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UF8RX7OrFkv0FyuIvtgAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:03.590901 2026] [security2:error] [pid 925208:tid 925402] [client 57.141.18.82:62116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEsRX7OrFkv0FyuIuGQAAQCc"]
[Mon Jul 20 06:27:03.786685 2026] [security2:error] [pid 925208:tid 925366] [client 106.219.188.178:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIv4AAAABw"]
[Mon Jul 20 06:27:03.786820 2026] [security2:error] [pid 925208:tid 925366] [client 106.219.188.178:47744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIv4AAAABw"]
[Mon Jul 20 06:27:03.991395 2026] [security2:error] [pid 925208:tid 925385] [client 14.225.17.146:56305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4UFsRX7OrFkv0FyuIvjQAAAC8"], referer: http://momheadquarters.com/WP
[Mon Jul 20 06:27:04.080075 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:page_id"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UGMRX7OrFkv0FyuIv_AAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.196900 2026] [security2:error] [pid 925208:tid 925345] [client 104.234.53.74:57203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UGMRX7OrFkv0FyuIwCAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:04.233242 2026] [security2:error] [pid 925208:tid 925379] [client 34.73.38.214:61402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UGMRX7OrFkv0FyuIwCwAAACk"]
[Mon Jul 20 06:27:04.238248 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwDAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.238383 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwDAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.394982 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwFQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.395091 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwFQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.549996 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwKQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.550107 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwKQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.560098 2026] [security2:error] [pid 925208:tid 925373] [client 57.141.18.11:55212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIueQAAI2w"]
[Mon Jul 20 06:27:04.596864 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGMRX7OrFkv0FyuIwFgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.753239 2026] [security2:error] [pid 925208:tid 925298] [remote 124.55.178.99:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UGMRX7OrFkv0FyuIwPQAABlk"]
[Mon Jul 20 06:27:04.875617 2026] [security2:error] [pid 925208:tid 925343] [client 57.141.18.77:56346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIuhQAABRE"]
[Mon Jul 20 06:27:04.916481 2026] [security2:error] [pid 925208:tid 925391] [client 14.225.17.146:56121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4UF8RX7OrFkv0FyuIvwgAAADU"], referer: http://ironcitywellness.com/WP
[Mon Jul 20 06:27:04.986827 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwTAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.986936 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwTAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.201306 2026] [security2:error] [pid 925208:tid 925244] [remote 124.55.178.99:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UGcRX7OrFkv0FyuIwZAAAdyM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:27:05.254707 2026] [security2:error] [pid 925208:tid 925445] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwUQAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.560307 2026] [security2:error] [pid 925208:tid 925446] [client 178.128.183.250:54020] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.processorstudio.com"] [uri "/"] [unique_id "al4UGcRX7OrFkv0FyuIwfwAAAGw"]
[Mon Jul 20 06:27:05.686288 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwdgAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.699513 2026] [security2:error] [pid 925208:tid 925364] [client 18.184.179.151:19182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UGcRX7OrFkv0FyuIwiwAAABo"]
[Mon Jul 20 06:27:05.728679 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwkgAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.728800 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwkgAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.860181 2026] [security2:error] [pid 925208:tid 925249] [remote 185.115.217.185:56092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UGcRX7OrFkv0FyuIwmwAAdSg"]
[Mon Jul 20 06:27:05.860484 2026] [security2:error] [pid 925208:tid 925455] [client 185.115.217.185:56092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UGcRX7OrFkv0FyuIwmwAAdSg"]
[Mon Jul 20 06:27:05.906862 2026] [core:error] [pid 925208:tid 925411] [client 103.153.183.69:51164] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%%32e%%32e/.env?_=9we78yum&v=g056v), referer: https://www.facebook.com/
[Mon Jul 20 06:27:05.961913 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwpAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.962008 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwpAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.053800 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwngAAABY"]
[Mon Jul 20 06:27:06.206174 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwuQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.206286 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwuQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.321151 2026] [security2:error] [pid 925208:tid 925452] [client 14.225.17.146:61922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4UGMRX7OrFkv0FyuIwMgAAAHI"], referer: http://tacticaltreeoperations.com/WP
[Mon Jul 20 06:27:06.381010 2026] [security2:error] [pid 925208:tid 925338] [client 198.98.54.225:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.54.98.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4UGsRX7OrFkv0FyuIwyAAAAAA"]
[Mon Jul 20 06:27:06.396152 2026] [security2:error] [pid 925208:tid 925376] [client 3.75.183.99:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UGsRX7OrFkv0FyuIwyQAAACY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:27:06.425087 2026] [security2:error] [pid 925208:tid 925408] [client 34.73.38.214:50234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UGsRX7OrFkv0FyuIwzAAAAEY"]
[Mon Jul 20 06:27:06.431161 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIwvQAAAHk"]
[Mon Jul 20 06:27:06.434255 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwzgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.434334 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwzgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.447919 2026] [security2:error] [pid 925208:tid 925434] [client 114.119.130.136:37233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.qualitycoatingsinspection.com"] [uri "/contact"] [unique_id "al4UGsRX7OrFkv0FyuIw0gAAAGA"], referer: https://www.qualitycoatingsinspection.com/about
[Mon Jul 20 06:27:06.485820 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:62759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw1gAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.485970 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:62759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw1gAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.526924 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIwxgAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.606990 2026] [security2:error] [pid 925208:tid 925364] [client 171.60.139.123:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UGsRX7OrFkv0FyuIw5AAAABo"]
[Mon Jul 20 06:27:06.607166 2026] [security2:error] [pid 925208:tid 925364] [client 171.60.139.123:60004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UGsRX7OrFkv0FyuIw5AAAABo"]
[Mon Jul 20 06:27:06.715303 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.7:35420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UFcRX7OrFkv0FyuIvMAAATWI"]
[Mon Jul 20 06:27:06.755401 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:page_id"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UGsRX7OrFkv0FyuIw7QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.943395 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw_QAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.943540 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw_QAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:07.063403 2026] [security2:error] [pid 925208:tid 925405] [client 104.234.53.72:60583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UG8RX7OrFkv0FyuIxBwAAAEM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:07.103326 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UG8RX7OrFkv0FyuIxDwAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:07.103418 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UG8RX7OrFkv0FyuIxDwAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:07.139649 2026] [security2:error] [pid 925208:tid 925340] [client 14.225.17.146:62094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIw0QAAAAI"]
[Mon Jul 20 06:27:07.209499 2026] [security2:error] [pid 925208:tid 925370] [client 57.141.18.117:56870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UFsRX7OrFkv0FyuIvWgAAIEc"]
[Mon Jul 20 06:27:07.249022 2026] [security2:error] [pid 925208:tid 925392] [client 14.225.17.146:62597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwZQAAADY"], referer: http://savilerowtravel.com/WP
[Mon Jul 20 06:27:07.572451 2026] [security2:error] [pid 925208:tid 925403] [client 66.249.73.130:63481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIw9wAAAEE"]
[Mon Jul 20 06:27:07.738369 2026] [security2:error] [pid 925208:tid 925376] [client 34.73.38.214:63378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UG8RX7OrFkv0FyuIxVwAAACY"]
[Mon Jul 20 06:27:07.974578 2026] [proxy:error] [pid 925208:tid 925430] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:07.974659 2026] [proxy_http:error] [pid 925208:tid 925430] [client 185.247.137.187:46959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:07.975347 2026] [proxy:error] [pid 925208:tid 925430] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:07.975377 2026] [proxy_http:error] [pid 925208:tid 925430] [client 185.247.137.187:46959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:08.089034 2026] [security2:error] [pid 925208:tid 925212] [remote 57.141.18.79:31858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4UHMRX7OrFkv0FyuIxegAAIAM"]
[Mon Jul 20 06:27:08.140696 2026] [security2:error] [pid 925208:tid 925338] [client 103.141.108.143:51458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxfgAAAAA"]
[Mon Jul 20 06:27:08.140858 2026] [security2:error] [pid 925208:tid 925338] [client 103.141.108.143:51458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxfgAAAAA"]
[Mon Jul 20 06:27:08.172898 2026] [security2:error] [pid 925208:tid 925381] [client 57.141.18.10:36128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UF8RX7OrFkv0FyuIvvQAAK1g"]
[Mon Jul 20 06:27:08.287197 2026] [security2:error] [pid 925208:tid 925375] [client 14.225.17.146:56124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4UHMRX7OrFkv0FyuIxewAAACU"], referer: https://savilerowtravel.com/WP
[Mon Jul 20 06:27:08.352627 2026] [security2:error] [pid 925208:tid 925343] [client 45.116.69.230:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxjAAAAAU"]
[Mon Jul 20 06:27:08.352727 2026] [security2:error] [pid 925208:tid 925343] [client 45.116.69.230:52296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxjAAAAAU"]
[Mon Jul 20 06:27:08.413710 2026] [security2:error] [pid 925208:tid 925421] [client 14.225.17.146:62924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4UG8RX7OrFkv0FyuIxaQAAAFM"], referer: http://uritems.net/WP
[Mon Jul 20 06:27:08.575137 2026] [security2:error] [pid 925208:tid 925370] [client 50.116.65.227:14066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UHMRX7OrFkv0FyuIxpAAAACA"]
[Mon Jul 20 06:27:08.588026 2026] [security2:error] [pid 925208:tid 925369] [client 50.116.65.227:14072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UHMRX7OrFkv0FyuIxqAAAAB8"]
[Mon Jul 20 06:27:08.943804 2026] [security2:error] [pid 925208:tid 925403] [client 77.110.127.138:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHMRX7OrFkv0FyuIxwQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:08.943914 2026] [security2:error] [pid 925208:tid 925403] [client 77.110.127.138:62814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHMRX7OrFkv0FyuIxwQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.003733 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:62944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4UG8RX7OrFkv0FyuIxMgAAAE0"], referer: http://vinovinhowine.com/WP
[Mon Jul 20 06:27:09.004429 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIxyAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.004535 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIxyAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.061135 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIx0AAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.061286 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIx0AAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.169777 2026] [security2:error] [pid 925208:tid 925341] [client 34.73.38.214:58656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UHcRX7OrFkv0FyuIx1wAAAAM"]
[Mon Jul 20 06:27:09.335808 2026] [security2:error] [pid 925208:tid 925413] [client 77.110.127.138:62822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UHcRX7OrFkv0FyuIx5wAAAEs"]
[Mon Jul 20 06:27:09.360980 2026] [security2:error] [pid 925208:tid 925250] [remote 217.61.143.92:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4UHcRX7OrFkv0FyuIx7AAAbSk"]
[Mon Jul 20 06:27:09.414175 2026] [security2:error] [pid 925208:tid 925461] [client 57.141.18.113:52504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGMRX7OrFkv0FyuIwNgAAe0E"]
[Mon Jul 20 06:27:09.604484 2026] [security2:error] [pid 925208:tid 925267] [remote 217.61.143.92:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4UHcRX7OrFkv0FyuIyBgAABDo"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:27:09.695033 2026] [security2:error] [pid 925208:tid 925378] [client 171.61.165.146:10965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UHcRX7OrFkv0FyuIyEQAAACg"]
[Mon Jul 20 06:27:09.695142 2026] [security2:error] [pid 925208:tid 925378] [client 171.61.165.146:10965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UHcRX7OrFkv0FyuIyEQAAACg"]
[Mon Jul 20 06:27:09.718866 2026] [security2:error] [pid 925208:tid 925385] [client 104.234.53.79:42937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIyBQAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:09.739927 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:62681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIx3AAAADE"], referer: http://waterproofgoods.com/WP
[Mon Jul 20 06:27:09.900279 2026] [security2:error] [pid 925208:tid 925246] [remote 57.141.18.91:34172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2766231"] [unique_id "al4UHcRX7OrFkv0FyuIyJAAAEyU"]
[Mon Jul 20 06:27:10.161437 2026] [security2:error] [pid 925208:tid 925407] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIyKgAAAEU"]
[Mon Jul 20 06:27:10.261583 2026] [security2:error] [pid 925208:tid 925395] [client 57.141.18.17:23980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwbAAAOTU"]
[Mon Jul 20 06:27:10.393162 2026] [security2:error] [pid 925208:tid 925383] [client 57.141.18.105:61942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwggAALV8"]
[Mon Jul 20 06:27:10.521884 2026] [security2:error] [pid 925208:tid 925367] [client 34.73.38.214:49984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UHsRX7OrFkv0FyuIyWAAAAB0"]
[Mon Jul 20 06:27:10.595849 2026] [security2:error] [pid 925208:tid 925347] [client 104.234.53.79:42937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UHsRX7OrFkv0FyuIyXwAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:10.655884 2026] [security2:error] [pid 925208:tid 925361] [client 14.225.17.146:62771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyNQAAABc"], referer: http://laceycaraccident.com/WP
[Mon Jul 20 06:27:10.756092 2026] [security2:error] [pid 925208:tid 925345] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyUAAAAAc"]
[Mon Jul 20 06:27:10.927980 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIyeQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:10.928086 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIyeQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:10.979520 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIygAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:10.979682 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIygAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.052652 2026] [core:error] [pid 925208:tid 925462] [client 14.225.17.146:62209] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WP
[Mon Jul 20 06:27:11.052981 2026] [core:error] [pid 925208:tid 925462] [client 14.225.17.146:62209] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WP
[Mon Jul 20 06:27:11.061486 2026] [security2:error] [pid 925208:tid 925339] [client 57.141.18.11:55228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIwwAAAAXA"]
[Mon Jul 20 06:27:11.134603 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UH8RX7OrFkv0FyuIylQAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.134704 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:62854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UH8RX7OrFkv0FyuIylQAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.193232 2026] [security2:error] [pid 925208:tid 925368] [client 172.104.20.239:61434] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UH8RX7OrFkv0FyuIylgAAAB4"]
[Mon Jul 20 06:27:11.322456 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyiwAAABY"]
[Mon Jul 20 06:27:11.464527 2026] [security2:error] [pid 925208:tid 925425] [client 34.73.38.214:49629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UH8RX7OrFkv0FyuIysAAAAFc"]
[Mon Jul 20 06:27:11.507104 2026] [security2:error] [pid 925208:tid 925457] [client 112.208.70.94:42303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UH8RX7OrFkv0FyuIyuAAAAHc"]
[Mon Jul 20 06:27:11.507228 2026] [security2:error] [pid 925208:tid 925457] [client 112.208.70.94:42303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UH8RX7OrFkv0FyuIyuAAAAHc"]
[Mon Jul 20 06:27:11.693170 2026] [security2:error] [pid 925208:tid 925451] [client 104.234.53.93:46125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UH8RX7OrFkv0FyuIy0QAAAHE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:11.710169 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyqAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.885117 2026] [security2:error] [pid 925208:tid 925409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyzgAAAEc"]
[Mon Jul 20 06:27:12.300960 2026] [security2:error] [pid 925208:tid 925366] [client 57.141.18.104:55836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UG8RX7OrFkv0FyuIxUAAAHG8"]
[Mon Jul 20 06:27:12.434156 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIy_AAAAF4"]
[Mon Jul 20 06:27:12.535704 2026] [security2:error] [pid 925208:tid 925353] [client 54.169.146.187:15714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UIMRX7OrFkv0FyuIzFAAAAA8"]
[Mon Jul 20 06:27:12.535883 2026] [security2:error] [pid 925208:tid 925353] [client 54.169.146.187:15714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UIMRX7OrFkv0FyuIzFAAAAA8"]
[Mon Jul 20 06:27:12.627168 2026] [security2:error] [pid 925208:tid 925354] [client 34.73.38.214:53999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UIMRX7OrFkv0FyuIzGAAAABA"]
[Mon Jul 20 06:27:12.977679 2026] [security2:error] [pid 925208:tid 925409] [client 14.225.17.146:49423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzGQAAAEc"], referer: http://mcg.homes/WP
[Mon Jul 20 06:27:13.268105 2026] [security2:error] [pid 925208:tid 925398] [client 14.225.17.146:63000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIywgAAADw"], referer: http://grecruit.online/WP
[Mon Jul 20 06:27:13.288082 2026] [security2:error] [pid 925208:tid 925346] [client 104.210.140.142:5062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyegAACGY"]
[Mon Jul 20 06:27:13.323719 2026] [security2:error] [pid 925208:tid 925414] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzPAAAAEw"]
[Mon Jul 20 06:27:13.375341 2026] [security2:error] [pid 925208:tid 925396] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzMAAAADo"]
[Mon Jul 20 06:27:13.605619 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzagAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.605761 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzagAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.665233 2026] [security2:error] [pid 925208:tid 925426] [client 104.210.140.142:5062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzVwAAWGE"]
[Mon Jul 20 06:27:13.732142 2026] [security2:error] [pid 925208:tid 925445] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzXgAAAGs"]
[Mon Jul 20 06:27:13.758585 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzeQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.758689 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzeQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.819367 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzfwAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.819540 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzfwAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:14.026810 2026] [security2:error] [pid 925208:tid 925419] [client 57.141.18.14:53216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIx3QAAUSw"]
[Mon Jul 20 06:27:14.027297 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzfQAAABk"]
[Mon Jul 20 06:27:14.032253 2026] [security2:error] [pid 925208:tid 925440] [client 106.219.188.178:10272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzngAAAGY"]
[Mon Jul 20 06:27:14.034417 2026] [security2:error] [pid 925208:tid 925440] [client 106.219.188.178:10272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzngAAAGY"]
[Mon Jul 20 06:27:14.077284 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzhQAAABo"]
[Mon Jul 20 06:27:14.159633 2026] [security2:error] [pid 925208:tid 925457] [client 104.234.53.86:27447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UIsRX7OrFkv0FyuIzqwAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:14.211278 2026] [core:error] [pid 925208:tid 925342] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:14.211299 2026] [core:error] [pid 925208:tid 925342] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:14.225357 2026] [security2:error] [pid 925208:tid 925435] [client 223.185.13.213:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzsAAAAGE"]
[Mon Jul 20 06:27:14.225527 2026] [security2:error] [pid 925208:tid 925435] [client 223.185.13.213:9615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzsAAAAGE"]
[Mon Jul 20 06:27:14.317819 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIzoQAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:14.428206 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIzrwAAAFw"]
[Mon Jul 20 06:27:14.543709 2026] [security2:error] [pid 925208:tid 925411] [client 57.141.18.81:60712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIyGQAASRU"]
[Mon Jul 20 06:27:14.549971 2026] [security2:error] [pid 925208:tid 925422] [client 14.225.17.146:62151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzSwAAAFQ"], referer: http://mazzucelli.com/WP
[Mon Jul 20 06:27:14.558687 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIztwAAADU"]
[Mon Jul 20 06:27:14.615705 2026] [security2:error] [pid 925208:tid 925369] [client 14.225.17.146:62091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzSQAAAB8"], referer: http://ghivs.com/WP
[Mon Jul 20 06:27:14.643221 2026] [http2:info] [pid 929851:tid 929851] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:27:14.811081 2026] [security2:error] [pid 929851:tid 929990] [client 34.73.38.214:53813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UImV3ou772CelrLhpIQAAAIo"]
[Mon Jul 20 06:27:14.884553 2026] [security2:error] [pid 925208:tid 925381] [client 57.141.18.42:22896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyQgAAK1Q"]
[Mon Jul 20 06:27:14.965588 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIz3gAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:14.991549 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIz5wAAAGo"]
[Mon Jul 20 06:27:15.023013 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UImV3ou772CelrLhpHwAAAIc"]
[Mon Jul 20 06:27:15.325193 2026] [security2:error] [pid 929851:tid 930018] [client 172.104.20.239:9894] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UI2V3ou772CelrLhpMQAAAKY"]
[Mon Jul 20 06:27:15.399050 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0HwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:15.427398 2026] [security2:error] [pid 925208:tid 925438] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0IAAAAGQ"]
[Mon Jul 20 06:27:15.462046 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0IQAAAFM"]
[Mon Jul 20 06:27:15.823968 2026] [security2:error] [pid 925208:tid 925392] [client 104.234.53.55:34425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UI8RX7OrFkv0FyuI0VwAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:15.945833 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpPQAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:15.981692 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpQAAAAL4"]
[Mon Jul 20 06:27:16.014911 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpRgAAAMY"]
[Mon Jul 20 06:27:16.117170 2026] [security2:error] [pid 925208:tid 925357] [client 57.141.18.77:45270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyzAAAEwk"]
[Mon Jul 20 06:27:16.129063 2026] [security2:error] [pid 929851:tid 930073] [client 34.73.38.214:50426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UJGV3ou772CelrLhpUgAAAN0"]
[Mon Jul 20 06:27:16.244531 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJGV3ou772CelrLhpWQAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.244661 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:62933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJGV3ou772CelrLhpWQAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.296916 2026] [security2:error] [pid 925208:tid 925438] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJMRX7OrFkv0FyuI0bQAAAGQ"]
[Mon Jul 20 06:27:16.329300 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0gwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.329426 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0gwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.489803 2026] [security2:error] [pid 925208:tid 925383] [client 57.141.18.105:61508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIy9QAALRI"]
[Mon Jul 20 06:27:16.490821 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0lAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.490905 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0lAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.537445 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJGV3ou772CelrLhpXAAAAOs"]
[Mon Jul 20 06:27:16.623770 2026] [security2:error] [pid 929851:tid 930095] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJGV3ou772CelrLhpXgAAAPM"]
[Mon Jul 20 06:27:16.790074 2026] [security2:error] [pid 929851:tid 930112] [client 34.74.185.202:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UJGV3ou772CelrLhpbQAAAQQ"]
[Mon Jul 20 06:27:16.840626 2026] [security2:error] [pid 925208:tid 925464] [client 39.48.81.23:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UJMRX7OrFkv0FyuI0qgAAAH4"]
[Mon Jul 20 06:27:16.840767 2026] [security2:error] [pid 925208:tid 925464] [client 39.48.81.23:51533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UJMRX7OrFkv0FyuI0qgAAAH4"]
[Mon Jul 20 06:27:16.864561 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJGV3ou772CelrLhpZAAAAIg"]
[Mon Jul 20 06:27:16.921325 2026] [security2:error] [pid 925208:tid 925406] [client 14.225.17.146:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0PAAAAEQ"], referer: http://bbwipartnerconference.com/WP
[Mon Jul 20 06:27:17.032775 2026] [security2:error] [pid 925208:tid 925342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJMRX7OrFkv0FyuI0pwAAAAQ"]
[Mon Jul 20 06:27:17.062787 2026] [security2:error] [pid 925208:tid 925386] [client 57.141.18.23:46164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzGgAAMA0"]
[Mon Jul 20 06:27:17.181388 2026] [security2:error] [pid 925208:tid 925343] [client 34.74.185.202:54597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UJcRX7OrFkv0FyuI0vQAAAAU"]
[Mon Jul 20 06:27:17.337186 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJWV3ou772CelrLhpeQAAALY"]
[Mon Jul 20 06:27:17.357662 2026] [security2:error] [pid 925208:tid 925376] [client 14.225.17.146:59663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI0wAAAACY"], referer: http://omrobuildingcenter.com/WP
[Mon Jul 20 06:27:17.362934 2026] [security2:error] [pid 925208:tid 925438] [client 171.60.139.123:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UJcRX7OrFkv0FyuI0zQAAAGQ"]
[Mon Jul 20 06:27:17.363049 2026] [security2:error] [pid 925208:tid 925438] [client 171.60.139.123:60527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UJcRX7OrFkv0FyuI0zQAAAGQ"]
[Mon Jul 20 06:27:17.459914 2026] [security2:error] [pid 929851:tid 930046] [client 14.225.17.146:59790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpTAAAAMI"], referer: http://thechancersband.com/WP
[Mon Jul 20 06:27:17.537987 2026] [security2:error] [pid 925208:tid 925409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI0wQAAAEc"]
[Mon Jul 20 06:27:17.560146 2026] [security2:error] [pid 929851:tid 930019] [client 34.73.38.214:52574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UJWV3ou772CelrLhphQAAAKc"]
[Mon Jul 20 06:27:17.707310 2026] [security2:error] [pid 925208:tid 925397] [client 74.208.214.194:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UJcRX7OrFkv0FyuI04QAAADs"]
[Mon Jul 20 06:27:17.921131 2026] [security2:error] [pid 929851:tid 930083] [client 34.74.185.202:58509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UJWV3ou772CelrLhplwAAAOc"]
[Mon Jul 20 06:27:18.068669 2026] [security2:error] [pid 929851:tid 929987] [client 50.116.65.227:59866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UJmV3ou772CelrLhpnwAAAIc"]
[Mon Jul 20 06:27:18.079438 2026] [security2:error] [pid 929851:tid 930005] [client 50.116.65.227:59870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UJmV3ou772CelrLhpoQAAAJk"]
[Mon Jul 20 06:27:18.111831 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI06wAAABk"]
[Mon Jul 20 06:27:18.131636 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJsRX7OrFkv0FyuI09wAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.131722 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:62948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJsRX7OrFkv0FyuI09wAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.171315 2026] [security2:error] [pid 925208:tid 925433] [client 57.141.18.17:32314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzegAAXyY"]
[Mon Jul 20 06:27:18.307623 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhpsAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.307726 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:62951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhpsAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.321135 2026] [security2:error] [pid 929851:tid 929874] [remote 173.236.254.75:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.254.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4UJmV3ou772CelrLhpqwAAoRI"], referer: https://greenvillemovingco.com/wp-login.php
[Mon Jul 20 06:27:18.385998 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJmV3ou772CelrLhppgAAAKw"]
[Mon Jul 20 06:27:18.395007 2026] [security2:error] [pid 925208:tid 925334] [remote 217.61.143.92:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1CgAAI30"]
[Mon Jul 20 06:27:18.395154 2026] [security2:error] [pid 925208:tid 925373] [client 217.61.143.92:54336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1CgAAI30"]
[Mon Jul 20 06:27:18.416082 2026] [security2:error] [pid 925208:tid 925357] [client 34.74.185.202:54537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UJsRX7OrFkv0FyuI1DQAAABM"]
[Mon Jul 20 06:27:18.418496 2026] [security2:error] [pid 925208:tid 925408] [client 57.141.18.89:41540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzlQAARnM"]
[Mon Jul 20 06:27:18.511846 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhptgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.511963 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:62957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhptgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.542032 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJmV3ou772CelrLhptAAAAL4"]
[Mon Jul 20 06:27:18.728694 2026] [security2:error] [pid 929851:tid 929878] [remote 173.212.252.15:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4UJmV3ou772CelrLhpvwAA_hY"]
[Mon Jul 20 06:27:18.744404 2026] [security2:error] [pid 929851:tid 929879] [remote 173.236.254.75:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.254.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4UJmV3ou772CelrLhpwQAAyRc"], referer: https://greenvillemovingco.com/wp-login.php
[Mon Jul 20 06:27:18.760400 2026] [security2:error] [pid 925208:tid 925390] [client 57.141.18.62:37544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIzuQAANC0"]
[Mon Jul 20 06:27:18.829066 2026] [security2:error] [pid 925208:tid 925312] [remote 15.206.251.117:39084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UJsRX7OrFkv0FyuI1KQAAZWc"]
[Mon Jul 20 06:27:18.833408 2026] [security2:error] [pid 925208:tid 925443] [client 103.141.108.143:51935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1KwAAAGk"]
[Mon Jul 20 06:27:18.833493 2026] [security2:error] [pid 925208:tid 925443] [client 103.141.108.143:51935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1KwAAAGk"]
[Mon Jul 20 06:27:18.844847 2026] [security2:error] [pid 929851:tid 929996] [client 106.212.14.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4UJmV3ou772CelrLhpwgAAAJA"]
[Mon Jul 20 06:27:18.863986 2026] [security2:error] [pid 929851:tid 930088] [client 34.74.185.202:62748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UJmV3ou772CelrLhpxQAAAOw"]
[Mon Jul 20 06:27:18.882459 2026] [security2:error] [pid 929851:tid 930096] [client 113.160.97.242:50257] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4UJmV3ou772CelrLhpxwAAAPQ"]
[Mon Jul 20 06:27:18.942249 2026] [security2:error] [pid 925208:tid 925456] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1HgAAAHY"]
[Mon Jul 20 06:27:18.999742 2026] [security2:error] [pid 925208:tid 925463] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flowmeterfactory.com"] [uri "/.well-known/about.php"] [unique_id "al4UJsRX7OrFkv0FyuI1MQAAAH0"]
[Mon Jul 20 06:27:18.999865 2026] [security2:error] [pid 925208:tid 925463] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "flowmeterfactory.com"] [uri "/.well-known/about.php"] [unique_id "al4UJsRX7OrFkv0FyuI1MQAAAH0"]
[Mon Jul 20 06:27:19.016224 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1JgAAADw"]
[Mon Jul 20 06:27:19.049175 2026] [security2:error] [pid 925208:tid 925371] [client 57.141.18.61:48522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIz4QAAIRM"]
[Mon Jul 20 06:27:19.099494 2026] [security2:error] [pid 925208:tid 925407] [client 45.116.69.230:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1OQAAAEU"]
[Mon Jul 20 06:27:19.099611 2026] [security2:error] [pid 925208:tid 925407] [client 45.116.69.230:52808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1OQAAAEU"]
[Mon Jul 20 06:27:19.194600 2026] [security2:error] [pid 929851:tid 930108] [client 34.74.185.202:65329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UJ2V3ou772CelrLhp1gAAAQA"]
[Mon Jul 20 06:27:19.224685 2026] [security2:error] [pid 929851:tid 929881] [remote 173.212.252.15:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4UJ2V3ou772CelrLhp2AAAjRk"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:27:19.240444 2026] [security2:error] [pid 925208:tid 925309] [remote 15.206.251.117:39084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1RwAAaGQ"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:27:19.252591 2026] [security2:error] [pid 925208:tid 925457] [client 104.234.53.63:50955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1SAAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:19.272369 2026] [security2:error] [pid 925208:tid 925423] [client 14.225.17.146:59595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI02QAAAFU"], referer: http://bigwormfishing.com/WP
[Mon Jul 20 06:27:19.332229 2026] [security2:error] [pid 929851:tid 930005] [client 172.104.20.239:9898] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UJ2V3ou772CelrLhp3wAAAJk"]
[Mon Jul 20 06:27:19.389012 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhpzwAAAPg"]
[Mon Jul 20 06:27:19.398482 2026] [security2:error] [pid 925208:tid 925414] [client 14.225.17.146:63761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1DwAAAEw"], referer: http://partnerselectricalllc.com/WP
[Mon Jul 20 06:27:19.452429 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhp2QAAALs"]
[Mon Jul 20 06:27:19.534388 2026] [security2:error] [pid 929851:tid 930023] [client 158.173.89.95:48881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UJ2V3ou772CelrLhp5AAAAKs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:19.762287 2026] [security2:error] [pid 925208:tid 925398] [client 106.212.14.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1ZQAAADw"]
[Mon Jul 20 06:27:19.816610 2026] [security2:error] [pid 929851:tid 930028] [client 34.74.185.202:54064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UJ2V3ou772CelrLhp8AAAALA"]
[Mon Jul 20 06:27:19.987004 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhp5wAAAKw"]
[Mon Jul 20 06:27:20.043717 2026] [security2:error] [pid 925208:tid 925389] [client 57.141.18.43:33402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0QwAAMxc"]
[Mon Jul 20 06:27:20.154942 2026] [security2:error] [pid 929851:tid 930027] [client 34.74.185.202:50525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UKGV3ou772CelrLhp_wAAAK8"]
[Mon Jul 20 06:27:20.167356 2026] [security2:error] [pid 929851:tid 930105] [client 103.153.183.69:20128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../root/.bash_history"] [unique_id "al4UKGV3ou772CelrLhqAAAAAP0"], referer: https://duckduckgo.com/?q=k8rw9
[Mon Jul 20 06:27:20.192718 2026] [security2:error] [pid 925208:tid 925325] [remote 130.185.118.215:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thestudioatfruitland.com"] [uri "/wp-login.php"] [unique_id "al4UKMRX7OrFkv0FyuI1fwAAJXQ"]
[Mon Jul 20 06:27:20.255438 2026] [security2:error] [pid 929851:tid 930048] [client 57.141.18.0:64496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpRQAAxAE"]
[Mon Jul 20 06:27:20.256968 2026] [security2:error] [pid 929851:tid 930019] [client 14.225.17.146:51061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhp_QAAAKc"], referer: https://bigwormfishing.com/WP
[Mon Jul 20 06:27:20.373960 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:51146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqAgAAAO4"], referer: http://koaconsultants.com/WP
[Mon Jul 20 06:27:20.377620 2026] [security2:error] [pid 925208:tid 925242] [remote 130.185.118.215:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thestudioatfruitland.com"] [uri "/wp-login.php"] [unique_id "al4UKMRX7OrFkv0FyuI1iAAANCE"], referer: https://thestudioatfruitland.com/wp-login.php
[Mon Jul 20 06:27:20.509223 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqDQAAAQI"]
[Mon Jul 20 06:27:20.618478 2026] [security2:error] [pid 925208:tid 925368] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "querenciapartners.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1IAAAAB4"]
[Mon Jul 20 06:27:20.648324 2026] [security2:error] [pid 929851:tid 930101] [client 77.110.127.138:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqGQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.648468 2026] [security2:error] [pid 929851:tid 930101] [client 77.110.127.138:62943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqGQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.689983 2026] [security2:error] [pid 929851:tid 930074] [client 171.61.165.146:3569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UKGV3ou772CelrLhqHwAAAN4"]
[Mon Jul 20 06:27:20.691062 2026] [security2:error] [pid 929851:tid 930074] [client 171.61.165.146:3569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UKGV3ou772CelrLhqHwAAAN4"]
[Mon Jul 20 06:27:20.800835 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/charity/feed/0kuu8amwj3su.php"] [unique_id "al4UKGV3ou772CelrLhqJwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.838533 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKMRX7OrFkv0FyuI1rAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.838690 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKMRX7OrFkv0FyuI1rAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.849210 2026] [security2:error] [pid 925208:tid 925461] [client 34.74.185.202:51368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UKMRX7OrFkv0FyuI1rgAAAHs"]
[Mon Jul 20 06:27:20.930010 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:62947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqHAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.961951 2026] [core:error] [pid 929851:tid 930091] [client 185.247.137.75:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:20.961981 2026] [core:error] [pid 929851:tid 930091] [client 185.247.137.75:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:20.990423 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqOAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.990590 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqOAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.130217 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqJgAAALo"]
[Mon Jul 20 06:27:21.142644 2026] [security2:error] [pid 925208:tid 925435] [client 57.141.18.113:63436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJMRX7OrFkv0FyuI0ogAAYSQ"]
[Mon Jul 20 06:27:21.178988 2026] [security2:error] [pid 925208:tid 925407] [client 39.48.81.23:51994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UKcRX7OrFkv0FyuI1xQAAAEU"]
[Mon Jul 20 06:27:21.179145 2026] [security2:error] [pid 925208:tid 925407] [client 39.48.81.23:51994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UKcRX7OrFkv0FyuI1xQAAAEU"]
[Mon Jul 20 06:27:21.208287 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqKgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.233022 2026] [security2:error] [pid 929851:tid 930079] [client 104.234.53.88:34171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UKWV3ou772CelrLhqPgAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:21.277134 2026] [security2:error] [pid 929851:tid 930084] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqLwAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.525187 2026] [security2:error] [pid 929851:tid 930001] [client 34.74.185.202:61691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UKWV3ou772CelrLhqVQAAAJU"]
[Mon Jul 20 06:27:21.542645 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/cowl/feed/14dsr01kc27o.php"] [unique_id "al4UKcRX7OrFkv0FyuI14QAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.592320 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI10AAAAGY"]
[Mon Jul 20 06:27:21.642676 2026] [security2:error] [pid 925208:tid 925410] [client 14.225.17.146:58286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI1ugAAAEg"], referer: http://bruceledewitz.com/WP
[Mon Jul 20 06:27:21.927276 2026] [security2:error] [pid 929851:tid 930021] [client 34.74.185.202:61327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UKWV3ou772CelrLhqdAAAAKk"]
[Mon Jul 20 06:27:21.988529 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.112:32012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI04wAAV2k"]
[Mon Jul 20 06:27:22.175484 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKWV3ou772CelrLhqTAAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.221069 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI11QAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.222895 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI12wAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.250023 2026] [security2:error] [pid 925208:tid 925370] [client 34.74.185.202:49658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UKsRX7OrFkv0FyuI2BgAAACA"]
[Mon Jul 20 06:27:22.329110 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:63019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/course-terms-conditions/y5ni4apxsu5b.php"] [unique_id "al4UKmV3ou772CelrLhqigAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.429131 2026] [security2:error] [pid 925208:tid 925341] [client 57.141.18.53:50738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI0-AAAA3k"]
[Mon Jul 20 06:27:22.715557 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKsRX7OrFkv0FyuI2AAAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.848975 2026] [security2:error] [pid 925208:tid 925333] [remote 47.86.33.52:3808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UKsRX7OrFkv0FyuI2IQAAYHw"]
[Mon Jul 20 06:27:22.888348 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKmV3ou772CelrLhqpwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.888455 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:62929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKmV3ou772CelrLhqpwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.958000 2026] [security2:error] [pid 925208:tid 925347] [client 104.234.53.78:44891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UKsRX7OrFkv0FyuI2KQAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:23.020763 2026] [security2:error] [pid 929851:tid 930006] [client 34.74.185.202:54166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UK2V3ou772CelrLhqtQAAAJo"]
[Mon Jul 20 06:27:23.109225 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/501/feed/rl7wjedeqyzl.php"] [unique_id "al4UK2V3ou772CelrLhqwAAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.169143 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:62993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqhgAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.171111 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKsRX7OrFkv0FyuI2CwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.327447 2026] [security2:error] [pid 929851:tid 930025] [client 172.104.20.239:19258] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UK2V3ou772CelrLhqygAAAK0"]
[Mon Jul 20 06:27:23.327664 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhqyQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.327820 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhqyQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.372170 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqpgAAAOI"], referer: https://mezzacraft.com/about-mezzacraft-crochet/img_4196-2/
[Mon Jul 20 06:27:23.480137 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:63013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/chart/hl4o1aaurcbs.php"] [unique_id "al4UK8RX7OrFkv0FyuI2WAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.552650 2026] [security2:error] [pid 929851:tid 930034] [client 14.225.17.146:54890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhq1AAAALY"], referer: http://hammadownenterprises.com/WP
[Mon Jul 20 06:27:23.753347 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhq7QAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.753487 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:62934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhq7QAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.814860 2026] [security2:error] [pid 929851:tid 930111] [client 14.225.17.146:58395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqqAAAAQM"], referer: http://walkingandtalking.net/WP
[Mon Jul 20 06:27:23.918355 2026] [security2:error] [pid 929851:tid 930056] [client 57.141.18.18:23928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhp8QAAzBw"]
[Mon Jul 20 06:27:23.995302 2026] [security2:error] [pid 925208:tid 925385] [client 57.141.18.34:26798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKMRX7OrFkv0FyuI1dQAAL2E"]
[Mon Jul 20 06:27:24.139327 2026] [security2:error] [pid 929851:tid 930022] [client 112.208.70.94:42717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhq_AAAAKo"]
[Mon Jul 20 06:27:24.139492 2026] [security2:error] [pid 929851:tid 930022] [client 112.208.70.94:42717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhq_AAAAKo"]
[Mon Jul 20 06:27:24.152575 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:62958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhqxAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.184047 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhqxgAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.186888 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK8RX7OrFkv0FyuI2RgAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.435490 2026] [fcgid:warn] [pid 929851:tid 929996] (70014)End of file found: [client 199.45.154.146:33176] mod_fcgid: can't get data from http client
[Mon Jul 20 06:27:24.451456 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhq2QAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.469711 2026] [security2:error] [pid 929851:tid 929931] [remote 57.141.18.92:48200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5475098"] [unique_id "al4ULGV3ou772CelrLhrEAAAv0s"]
[Mon Jul 20 06:27:24.516149 2026] [security2:error] [pid 925208:tid 925345] [client 14.225.17.146:58346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4UKsRX7OrFkv0FyuI1_gAAAAc"], referer: http://adastra.love/WP
[Mon Jul 20 06:27:24.534397 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK8RX7OrFkv0FyuI2XgAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.537304 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK8RX7OrFkv0FyuI2agAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.709614 2026] [security2:error] [pid 929851:tid 930038] [client 14.225.17.146:54902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4ULGV3ou772CelrLhrGgAAALo"], referer: https://walkingandtalking.net/WP
[Mon Jul 20 06:27:24.722599 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ULMRX7OrFkv0FyuI2kgAAADg"]
[Mon Jul 20 06:27:24.722732 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:8325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ULMRX7OrFkv0FyuI2kgAAADg"]
[Mon Jul 20 06:27:24.759801 2026] [security2:error] [pid 929851:tid 930068] [client 106.219.188.178:47757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhrHAAAANg"]
[Mon Jul 20 06:27:24.761138 2026] [security2:error] [pid 929851:tid 930068] [client 106.219.188.178:47757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhrHAAAANg"]
[Mon Jul 20 06:27:25.123416 2026] [security2:error] [pid 929851:tid 930095] [client 52.109.52.84:19149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ULWV3ou772CelrLhrJgAAAPM"]
[Mon Jul 20 06:27:25.178100 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ULMRX7OrFkv0FyuI2gQAAAGg"], referer: 1'"3000
[Mon Jul 20 06:27:25.243082 2026] [security2:error] [pid 929851:tid 929994] [client 52.109.52.84:19149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ULWV3ou772CelrLhrLAAAAI4"]
[Mon Jul 20 06:27:25.553523 2026] [security2:error] [pid 929851:tid 930053] [client 57.141.18.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ULWV3ou772CelrLhrMwAAAMk"]
[Mon Jul 20 06:27:25.708709 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:25.708766 2026] [proxy_http:error] [pid 929851:tid 930026] [client 34.73.38.214:64849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:25.709629 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:25.709658 2026] [proxy_http:error] [pid 929851:tid 930026] [client 34.73.38.214:64849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:25.718120 2026] [security2:error] [pid 929851:tid 930047] [client 57.141.18.118:21438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKWV3ou772CelrLhqRwAAwyY"]
[Mon Jul 20 06:27:25.871138 2026] [security2:error] [pid 929851:tid 930056] [client 51.143.183.75:29505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ULWV3ou772CelrLhrVAAAAMw"]
[Mon Jul 20 06:27:25.883213 2026] [security2:error] [pid 929851:tid 929942] [remote 192.241.143.148:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ULWV3ou772CelrLhrVgAAxVY"]
[Mon Jul 20 06:27:25.944850 2026] [security2:error] [pid 929851:tid 930055] [client 57.141.18.58:22026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKWV3ou772CelrLhqXgAAyyk"]
[Mon Jul 20 06:27:26.004361 2026] [security2:error] [pid 929851:tid 930045] [client 51.143.183.75:29505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ULmV3ou772CelrLhrWwAAAME"]
[Mon Jul 20 06:27:26.073623 2026] [security2:error] [pid 925208:tid 925217] [remote 57.141.18.28:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4ULsRX7OrFkv0FyuI2vgAAEQg"]
[Mon Jul 20 06:27:26.237472 2026] [security2:error] [pid 929851:tid 930100] [client 14.225.17.146:58116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrYAAAAPg"], referer: http://sarahsnyder.net/WP
[Mon Jul 20 06:27:26.249205 2026] [security2:error] [pid 929851:tid 929947] [remote 192.241.143.148:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ULmV3ou772CelrLhrawAA51s"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:27:26.577064 2026] [security2:error] [pid 925208:tid 925339] [client 14.225.17.146:51177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4ULMRX7OrFkv0FyuI2hgAAAAE"], referer: http://securingmemories.com/WP
[Mon Jul 20 06:27:26.750476 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:26.750555 2026] [proxy_http:error] [pid 929851:tid 930079] [client 34.73.38.214:53186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:26.751113 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:26.751145 2026] [proxy_http:error] [pid 929851:tid 930079] [client 34.73.38.214:53186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:26.818990 2026] [security2:error] [pid 925208:tid 925347] [client 35.90.38.209:45470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4ULsRX7OrFkv0FyuI24wAAAAk"]
[Mon Jul 20 06:27:27.038586 2026] [security2:error] [pid 929851:tid 930050] [client 57.141.18.38:60588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqlgAAxjU"]
[Mon Jul 20 06:27:27.050814 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.125:57934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqkwAAojQ"]
[Mon Jul 20 06:27:27.238085 2026] [security2:error] [pid 925208:tid 925452] [client 14.225.17.146:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4UL8RX7OrFkv0FyuI29AAAAHI"], referer: https://sarahsnyder.net/WP
[Mon Jul 20 06:27:27.255868 2026] [security2:error] [pid 929851:tid 930056] [client 98.159.234.160:48795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UL2V3ou772CelrLhriwAAAMw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:27.353977 2026] [security2:error] [pid 929851:tid 929998] [client 172.104.20.239:19272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UL2V3ou772CelrLhrjwAAAJI"]
[Mon Jul 20 06:27:27.761159 2026] [proxy:error] [pid 929851:tid 930028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:27.761238 2026] [proxy_http:error] [pid 929851:tid 930028] [client 34.73.38.214:58104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:27.761892 2026] [proxy:error] [pid 929851:tid 930028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:27.761932 2026] [proxy_http:error] [pid 929851:tid 930028] [client 34.73.38.214:58104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:27.897516 2026] [security2:error] [pid 929851:tid 930081] [client 57.141.18.48:30298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhq0AAA5T4"]
[Mon Jul 20 06:27:28.041919 2026] [security2:error] [pid 925208:tid 925374] [client 171.60.139.123:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UMMRX7OrFkv0FyuI3FQAAACQ"]
[Mon Jul 20 06:27:28.042043 2026] [security2:error] [pid 925208:tid 925374] [client 171.60.139.123:61050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UMMRX7OrFkv0FyuI3FQAAACQ"]
[Mon Jul 20 06:27:28.230557 2026] [security2:error] [pid 929851:tid 930101] [client 47.128.46.251:17586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "floorsourcestock.com"] [uri "/robots.txt"] [unique_id "al4UMGV3ou772CelrLhrqgAAAPk"]
[Mon Jul 20 06:27:28.235795 2026] [security2:error] [pid 925208:tid 925391] [client 50.116.65.227:52156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UMMRX7OrFkv0FyuI3HQAAADU"]
[Mon Jul 20 06:27:28.244924 2026] [security2:error] [pid 925208:tid 925412] [client 50.116.65.227:52164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UMMRX7OrFkv0FyuI3HgAAAEo"]
[Mon Jul 20 06:27:28.432416 2026] [security2:error] [pid 929851:tid 929963] [remote 4.205.168.44:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4UMGV3ou772CelrLhruQAAjGs"]
[Mon Jul 20 06:27:28.487084 2026] [security2:error] [pid 929851:tid 930029] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-4c7fda08.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrZAAAALE"]
[Mon Jul 20 06:27:28.611263 2026] [security2:error] [pid 929851:tid 929965] [remote 4.205.168.44:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4UMGV3ou772CelrLhrwQAA8W0"], referer: https://faadenergy.com/wp-login.php
[Mon Jul 20 06:27:28.828690 2026] [security2:error] [pid 925208:tid 925308] [remote 45.90.123.233:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UMMRX7OrFkv0FyuI3OwAAOGM"]
[Mon Jul 20 06:27:28.856578 2026] [proxy:error] [pid 925208:tid 925419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:28.856629 2026] [proxy_http:error] [pid 925208:tid 925419] [client 34.73.38.214:55420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:28.857332 2026] [proxy:error] [pid 925208:tid 925419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:28.857365 2026] [proxy_http:error] [pid 925208:tid 925419] [client 34.73.38.214:55420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:28.941954 2026] [security2:error] [pid 929851:tid 929967] [remote 91.142.222.105:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4UMGV3ou772CelrLhrzQAAyW8"]
[Mon Jul 20 06:27:28.985960 2026] [security2:error] [pid 925208:tid 925410] [client 14.225.17.146:64346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4UMMRX7OrFkv0FyuI3QAAAAEg"], referer: http://intelligentengineeringsolutions.com/WP
[Mon Jul 20 06:27:29.213031 2026] [security2:error] [pid 925208:tid 925360] [client 57.141.18.59:54630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ULMRX7OrFkv0FyuI2lQAAFhs"]
[Mon Jul 20 06:27:29.297509 2026] [security2:error] [pid 929851:tid 929973] [remote 91.142.222.105:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4UMWV3ou772CelrLhr3gAA4nU"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 06:27:29.665106 2026] [security2:error] [pid 929851:tid 930076] [client 103.141.108.143:52409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr9gAAAOA"]
[Mon Jul 20 06:27:29.665775 2026] [security2:error] [pid 929851:tid 930076] [client 103.141.108.143:52409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr9gAAAOA"]
[Mon Jul 20 06:27:29.673959 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr4gAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:29.706918 2026] [security2:error] [pid 929851:tid 930018] [client 45.116.69.230:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr-gAAAKY"]
[Mon Jul 20 06:27:29.707030 2026] [security2:error] [pid 929851:tid 930018] [client 45.116.69.230:53326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr-gAAAKY"]
[Mon Jul 20 06:27:29.707714 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr4wAAALE"], referer: 1'"3000
[Mon Jul 20 06:27:29.790969 2026] [ssl:error] [pid 929851:tid 930021] [client 98.88.137.2:48949] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname cpanel.nzj.ghe.mybluehost.me provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:27:29.812248 2026] [security2:error] [pid 929851:tid 930059] [client 14.225.17.146:50962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4UMGV3ou772CelrLhrugAAAM8"], referer: http://scott-assist.com/WP
[Mon Jul 20 06:27:29.919160 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMcRX7OrFkv0FyuI3awAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:29.919309 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:63075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMcRX7OrFkv0FyuI3awAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:29.971021 2026] [security2:error] [pid 925208:tid 925325] [remote 45.90.123.233:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UMcRX7OrFkv0FyuI3bwAAAHQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:27:29.990211 2026] [security2:error] [pid 925208:tid 925367] [client 34.73.38.214:55425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UMcRX7OrFkv0FyuI3cAAAAB0"]
[Mon Jul 20 06:27:30.102211 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3eQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.102331 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3eQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.113663 2026] [security2:error] [pid 925208:tid 925397] [client 39.48.81.23:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UMsRX7OrFkv0FyuI3fAAAADs"]
[Mon Jul 20 06:27:30.113824 2026] [security2:error] [pid 925208:tid 925397] [client 39.48.81.23:52480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UMsRX7OrFkv0FyuI3fAAAADs"]
[Mon Jul 20 06:27:30.183589 2026] [security2:error] [pid 925208:tid 925328] [remote 199.189.225.40:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UMsRX7OrFkv0FyuI3hAAAcXc"]
[Mon Jul 20 06:27:30.197536 2026] [security2:error] [pid 929851:tid 930088] [client 14.225.17.146:64490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4UMGV3ou772CelrLhrzAAAAOw"], referer: http://wathenbartlett.co.uk/WP
[Mon Jul 20 06:27:30.229828 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UMsRX7OrFkv0FyuI3cQAAAEI"], referer: 1'"3000
[Mon Jul 20 06:27:30.254014 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.254149 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.333112 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.333278 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.366885 2026] [security2:error] [pid 925208:tid 925230] [remote 199.189.225.40:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UMsRX7OrFkv0FyuI3iwAAAhU"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:27:30.477430 2026] [security2:error] [pid 929851:tid 929856] [remote 47.86.33.52:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UMmV3ou772CelrLhsDwAAhgA"]
[Mon Jul 20 06:27:30.477615 2026] [security2:error] [pid 929851:tid 929986] [client 47.86.33.52:47670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UMmV3ou772CelrLhsDwAAhgA"]
[Mon Jul 20 06:27:30.551048 2026] [security2:error] [pid 929851:tid 930006] [client 57.141.18.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UMmV3ou772CelrLhsCwAAAJo"]
[Mon Jul 20 06:27:30.598812 2026] [security2:error] [pid 929851:tid 929859] [remote 57.141.18.67:25840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2608670"] [unique_id "al4UMmV3ou772CelrLhsEgAAlwM"]
[Mon Jul 20 06:27:30.616257 2026] [security2:error] [pid 925208:tid 925245] [remote 57.141.18.79:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5107369"] [unique_id "al4UMsRX7OrFkv0FyuI3lwAANiQ"]
[Mon Jul 20 06:27:30.650169 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:63100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3mQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.650272 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:63100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3mQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.840329 2026] [security2:error] [pid 929851:tid 930079] [client 4.154.193.167:60790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4UMmV3ou772CelrLhsGQAA4wY"]
[Mon Jul 20 06:27:30.916538 2026] [security2:error] [pid 925208:tid 925459] [client 34.73.38.214:49584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UMsRX7OrFkv0FyuI3pQAAAHk"]
[Mon Jul 20 06:27:30.990957 2026] [security2:error] [pid 929851:tid 929865] [remote 20.153.140.50:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4UMmV3ou772CelrLhsIQAA1Ak"]
[Mon Jul 20 06:27:31.002593 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3qAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.002731 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:63104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3qAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.140208 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:59269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4UM8RX7OrFkv0FyuI3rAAAAAA"], referer: https://wathenbartlett.co.uk/WP
[Mon Jul 20 06:27:31.207916 2026] [security2:error] [pid 925208:tid 925398] [client 14.225.17.146:59158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4UMcRX7OrFkv0FyuI3YQAAADw"], referer: http://blaizeaccountingservices.com/WP
[Mon Jul 20 06:27:31.297485 2026] [security2:error] [pid 929851:tid 930091] [client 74.7.227.179:46460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4UM2V3ou772CelrLhsLgAA7xA"], referer: https://tejasenvironmental.com/p=1477799
[Mon Jul 20 06:27:31.297850 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsOQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.297967 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsOQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.376037 2026] [security2:error] [pid 929851:tid 930009] [client 14.225.17.146:58765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr7QAAAJ0"], referer: http://ccsdifference.com/WP
[Mon Jul 20 06:27:31.399875 2026] [security2:error] [pid 929851:tid 929878] [remote 20.153.140.50:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4UM2V3ou772CelrLhsPAAAmhY"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:27:31.502158 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UM2V3ou772CelrLhsPwAAALw"]
[Mon Jul 20 06:27:31.502885 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:1561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UM2V3ou772CelrLhsPwAAALw"]
[Mon Jul 20 06:27:31.523429 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3wQAAACg"]
[Mon Jul 20 06:27:31.523548 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3wQAAACg"]
[Mon Jul 20 06:27:31.574138 2026] [security2:error] [pid 929851:tid 930063] [client 57.141.18.43:32020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrewAA018"]
[Mon Jul 20 06:27:31.652834 2026] [security2:error] [pid 929851:tid 930004] [client 57.141.18.59:24320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrfgAAmGA"]
[Mon Jul 20 06:27:31.721101 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.721193 2026] [proxy_http:error] [pid 929851:tid 930079] [client 198.235.24.141:61808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.721879 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.721909 2026] [proxy_http:error] [pid 929851:tid 930079] [client 198.235.24.141:61808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.731904 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.731988 2026] [proxy_http:error] [pid 929851:tid 930026] [client 198.235.24.141:61816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.732687 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.732723 2026] [proxy_http:error] [pid 929851:tid 930026] [client 198.235.24.141:61816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.789695 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:63111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3yQAAAGk"]
[Mon Jul 20 06:27:31.789833 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:63111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3yQAAAGk"]
[Mon Jul 20 06:27:31.808197 2026] [security2:error] [pid 929851:tid 930023] [client 13.201.64.214:32228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UM2V3ou772CelrLhsUAAAAKs"]
[Mon Jul 20 06:27:31.999488 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsWQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.999580 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsWQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.225614 2026] [security2:error] [pid 925208:tid 925386] [client 34.73.38.214:59865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UNMRX7OrFkv0FyuI32QAAADA"]
[Mon Jul 20 06:27:32.276148 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNGV3ou772CelrLhsYAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.328611 2026] [security2:error] [pid 929851:tid 929885] [remote 38.242.157.30:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4UNGV3ou772CelrLhsbwABAx0"]
[Mon Jul 20 06:27:32.377218 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:65315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UNGV3ou772CelrLhsawAAAKQ"], referer: https://ccsdifference.com/WP
[Mon Jul 20 06:27:32.528278 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:63120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNMRX7OrFkv0FyuI35QAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.528382 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:63120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNMRX7OrFkv0FyuI35QAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.614304 2026] [security2:error] [pid 929851:tid 929888] [remote 124.55.178.99:47312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UNGV3ou772CelrLhsegAA5SA"]
[Mon Jul 20 06:27:32.614450 2026] [security2:error] [pid 929851:tid 930081] [client 124.55.178.99:47312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UNGV3ou772CelrLhsegAA5SA"]
[Mon Jul 20 06:27:32.663969 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNMRX7OrFkv0FyuI34QAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.737345 2026] [security2:error] [pid 929851:tid 929860] [remote 38.242.157.30:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4UNGV3ou772CelrLhsgQAAqgQ"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 06:27:32.887628 2026] [security2:error] [pid 925208:tid 925410] [client 65.1.132.125:12554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UNMRX7OrFkv0FyuI39wAAAEg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:27:33.043774 2026] [security2:error] [pid 929851:tid 930070] [client 34.73.38.214:64093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UNWV3ou772CelrLhslQAAANo"]
[Mon Jul 20 06:27:33.199227 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNGV3ou772CelrLhskQAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:33.440143 2026] [security2:error] [pid 929851:tid 930062] [client 46.110.96.34:65304] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4UNWV3ou772CelrLhsqgAAANI"]
[Mon Jul 20 06:27:33.440143 2026] [security2:error] [pid 925208:tid 925369] [client 46.110.96.34:46529] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4UNcRX7OrFkv0FyuI4DQAAAB8"]
[Mon Jul 20 06:27:33.756439 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNcRX7OrFkv0FyuI4EgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:33.948812 2026] [security2:error] [pid 929851:tid 930056] [client 104.234.53.51:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UNWV3ou772CelrLhs6QAAAMw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:33.964670 2026] [security2:error] [pid 929851:tid 930021] [client 91.162.53.208:65098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UNWV3ou772CelrLhs6gAAAKk"]
[Mon Jul 20 06:27:33.980275 2026] [security2:error] [pid 929851:tid 930106] [client 70.52.223.115:38260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4UNWV3ou772CelrLhs7QAAAP4"]
[Mon Jul 20 06:27:33.998195 2026] [security2:error] [pid 925208:tid 925463] [client 88.174.200.112:28238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4UNcRX7OrFkv0FyuI4JwAAAH0"]
[Mon Jul 20 06:27:34.011236 2026] [security2:error] [pid 929851:tid 930099] [client 82.66.24.165:47066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4UNmV3ou772CelrLhs8gAAAPc"]
[Mon Jul 20 06:27:34.024822 2026] [security2:error] [pid 929851:tid 930086] [client 90.248.175.80:60210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4UNmV3ou772CelrLhs-wAAAOo"]
[Mon Jul 20 06:27:34.090986 2026] [security2:error] [pid 925208:tid 925452] [client 90.113.29.14:48826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UNsRX7OrFkv0FyuI4LwAAAHI"]
[Mon Jul 20 06:27:34.104803 2026] [security2:error] [pid 929851:tid 930018] [client 99.246.181.85:51790] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4UNmV3ou772CelrLhtAgAAAKY"]
[Mon Jul 20 06:27:34.113193 2026] [security2:error] [pid 925208:tid 925274] [remote 57.141.18.61:38270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4UNsRX7OrFkv0FyuI4MAAAMUE"]
[Mon Jul 20 06:27:34.123443 2026] [security2:error] [pid 929851:tid 930109] [client 57.141.18.111:47600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr5AABAXY"]
[Mon Jul 20 06:27:34.137090 2026] [security2:error] [pid 925208:tid 925366] [client 88.98.127.76:13488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4UNsRX7OrFkv0FyuI4MwAAABw"]
[Mon Jul 20 06:27:34.153848 2026] [security2:error] [pid 929851:tid 929954] [remote 47.86.33.52:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UNmV3ou772CelrLhtBQAA72I"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:27:34.178579 2026] [security2:error] [pid 929851:tid 929993] [client 57.141.18.58:59634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr6gAAjXg"]
[Mon Jul 20 06:27:34.237228 2026] [security2:error] [pid 929851:tid 930100] [client 2.213.247.11:49898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UNmV3ou772CelrLhtBgAAAPg"]
[Mon Jul 20 06:27:34.238631 2026] [security2:error] [pid 929851:tid 930048] [client 85.145.110.236:54110] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4UNmV3ou772CelrLhtBwAAAMQ"]
[Mon Jul 20 06:27:34.260318 2026] [security2:error] [pid 929851:tid 930101] [client 38.62.90.158:36694] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4UNmV3ou772CelrLhtCAAAAPk"]
[Mon Jul 20 06:27:34.278772 2026] [security2:error] [pid 929851:tid 930024] [client 92.208.64.126:13696] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4UNmV3ou772CelrLhtCQAAAKw"]
[Mon Jul 20 06:27:34.296922 2026] [security2:error] [pid 929851:tid 929986] [client 81.105.86.231:54320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.ttf"] [unique_id "al4UNmV3ou772CelrLhtDAAAAIY"]
[Mon Jul 20 06:27:34.337171 2026] [security2:error] [pid 925208:tid 925385] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNsRX7OrFkv0FyuI4MgAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.364654 2026] [security2:error] [pid 929851:tid 930068] [client 99.233.147.186:58888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4UNmV3ou772CelrLhtFAAAANg"]
[Mon Jul 20 06:27:34.399354 2026] [security2:error] [pid 925208:tid 925462] [client 34.73.38.214:54547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UNsRX7OrFkv0FyuI4OwAAAHw"]
[Mon Jul 20 06:27:34.481229 2026] [security2:error] [pid 929851:tid 930066] [client 103.73.107.17:37346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4UNmV3ou772CelrLhtFwAAANY"]
[Mon Jul 20 06:27:34.499679 2026] [security2:error] [pid 925208:tid 925408] [client 94.73.43.173:7708] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4UNsRX7OrFkv0FyuI4PgAAAEY"]
[Mon Jul 20 06:27:34.502543 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtGQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.502642 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtGQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.657196 2026] [security2:error] [pid 929851:tid 930040] [client 90.69.100.135:47298] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4UNmV3ou772CelrLhtJAAAALw"]
[Mon Jul 20 06:27:34.664516 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtJQAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.664603 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtJQAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.710045 2026] [security2:error] [pid 929851:tid 930023] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNmV3ou772CelrLhtGgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.844738 2026] [security2:error] [pid 925208:tid 925361] [client 95.26.107.190:7931] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UNsRX7OrFkv0FyuI4UgAAABc"]
[Mon Jul 20 06:27:35.019978 2026] [security2:error] [pid 929851:tid 930075] [client 34.73.38.214:52072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UN2V3ou772CelrLhtLwAAAN8"]
[Mon Jul 20 06:27:35.074644 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNsRX7OrFkv0FyuI4UAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.289707 2026] [security2:error] [pid 929851:tid 929997] [client 106.219.188.178:16476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UN2V3ou772CelrLhtPQAAAJE"]
[Mon Jul 20 06:27:35.290153 2026] [security2:error] [pid 929851:tid 929997] [client 106.219.188.178:16476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UN2V3ou772CelrLhtPQAAAJE"]
[Mon Jul 20 06:27:35.397087 2026] [security2:error] [pid 929851:tid 930031] [client 199.45.154.146:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.45.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aula.cimahmo.pro"] [uri "/theme/image.php/boost/theme/1713903875/favicon"] [unique_id "al4UN2V3ou772CelrLhtQQAAALM"]
[Mon Jul 20 06:27:35.434300 2026] [security2:error] [pid 925208:tid 925451] [client 223.185.13.213:11435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UN8RX7OrFkv0FyuI4awAAAHE"]
[Mon Jul 20 06:27:35.434395 2026] [security2:error] [pid 925208:tid 925451] [client 223.185.13.213:11435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UN8RX7OrFkv0FyuI4awAAAHE"]
[Mon Jul 20 06:27:35.536139 2026] [security2:error] [pid 925208:tid 925434] [client 181.172.193.121:33642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UN8RX7OrFkv0FyuI4bgAAAGA"]
[Mon Jul 20 06:27:35.553687 2026] [security2:error] [pid 925208:tid 925460] [client 74.208.214.194:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UN8RX7OrFkv0FyuI4bwAAAHo"]
[Mon Jul 20 06:27:35.680421 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UN2V3ou772CelrLhtTwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.789764 2026] [security2:error] [pid 929851:tid 930081] [client 34.73.38.214:58037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UN2V3ou772CelrLhtZAAAAOU"]
[Mon Jul 20 06:27:35.811488 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:63102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UN8RX7OrFkv0FyuI4fAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.811618 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:63102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UN8RX7OrFkv0FyuI4fAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.898558 2026] [security2:error] [pid 929851:tid 930082] [client 57.141.18.85:52780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UM2V3ou772CelrLhsMwAA5hQ"]
[Mon Jul 20 06:27:35.984999 2026] [security2:error] [pid 929851:tid 929990] [client 104.234.53.49:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UN2V3ou772CelrLhtbAAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:36.014832 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.87:33726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UM2V3ou772CelrLhsNgAAwRM"]
[Mon Jul 20 06:27:36.327915 2026] [security2:error] [pid 929851:tid 930107] [client 37.120.158.248:49149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UOGV3ou772CelrLhtfwAAAP8"]
[Mon Jul 20 06:27:36.724926 2026] [security2:error] [pid 929851:tid 929872] [remote 188.166.241.141:46782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4UOGV3ou772CelrLhtlgAA7hA"]
[Mon Jul 20 06:27:36.962837 2026] [security2:error] [pid 929851:tid 930043] [client 34.73.38.214:54667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UOGV3ou772CelrLhtoAAAAL8"]
[Mon Jul 20 06:27:37.099447 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UOGV3ou772CelrLhtnQAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:37.110014 2026] [security2:error] [pid 929851:tid 929867] [remote 188.166.241.141:46782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4UOWV3ou772CelrLhtpQAA1gs"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:27:37.325445 2026] [security2:error] [pid 929851:tid 930091] [client 50.116.65.227:22912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UOWV3ou772CelrLhtsAAAAO8"]
[Mon Jul 20 06:27:37.334313 2026] [security2:error] [pid 929851:tid 930044] [client 50.116.65.227:22922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UOWV3ou772CelrLhtsgAAAMA"]
[Mon Jul 20 06:27:37.648980 2026] [security2:error] [pid 929851:tid 929885] [remote 81.173.115.7:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UOWV3ou772CelrLhtwwABAB0"]
[Mon Jul 20 06:27:37.731397 2026] [security2:error] [pid 929851:tid 930010] [client 112.208.70.94:43171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UOWV3ou772CelrLhtyAAAAJ4"]
[Mon Jul 20 06:27:37.731524 2026] [security2:error] [pid 929851:tid 930010] [client 112.208.70.94:43171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UOWV3ou772CelrLhtyAAAAJ4"]
[Mon Jul 20 06:27:37.886973 2026] [security2:error] [pid 929851:tid 929888] [remote 81.173.115.7:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UOWV3ou772CelrLhtywAAmyA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:37.909220 2026] [security2:error] [pid 929851:tid 930065] [client 50.116.65.227:22952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UOWV3ou772CelrLhtxAAAANU"]
[Mon Jul 20 06:27:38.098104 2026] [security2:error] [pid 929851:tid 930058] [client 50.116.65.227:22968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UOWV3ou772CelrLhtzgAAAM4"]
[Mon Jul 20 06:27:38.165922 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOmV3ou772CelrLht3gAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.166046 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOmV3ou772CelrLht3gAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.278011 2026] [security2:error] [pid 925208:tid 925422] [client 57.141.18.84:56580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UNcRX7OrFkv0FyuI4IgAAVGQ"]
[Mon Jul 20 06:27:38.323326 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOsRX7OrFkv0FyuI45gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.323426 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOsRX7OrFkv0FyuI45gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.760871 2026] [security2:error] [pid 929851:tid 930048] [client 34.73.38.214:61055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UOmV3ou772CelrLht7QAAAMQ"]
[Mon Jul 20 06:27:38.826042 2026] [security2:error] [pid 925208:tid 925417] [client 43.205.139.3:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UOsRX7OrFkv0FyuI4-gAAAE8"]
[Mon Jul 20 06:27:38.827702 2026] [security2:error] [pid 925208:tid 925349] [client 171.60.139.123:61572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UOsRX7OrFkv0FyuI4-wAAAAs"]
[Mon Jul 20 06:27:38.827807 2026] [security2:error] [pid 925208:tid 925349] [client 171.60.139.123:61572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UOsRX7OrFkv0FyuI4-wAAAAs"]
[Mon Jul 20 06:27:38.972615 2026] [security2:error] [pid 925208:tid 925390] [client 57.141.18.67:37768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UNsRX7OrFkv0FyuI4RQAANDI"]
[Mon Jul 20 06:27:38.976306 2026] [fcgid:warn] [pid 929851:tid 930018] (70014)End of file found: [client 66.132.172.200:40680] mod_fcgid: can't get data from http client
[Mon Jul 20 06:27:39.177600 2026] [security2:error] [pid 929851:tid 929864] [remote 57.141.18.18:43714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4UO2V3ou772CelrLht_gAAuAg"]
[Mon Jul 20 06:27:39.524288 2026] [security2:error] [pid 929851:tid 930090] [client 34.73.38.214:65045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UO2V3ou772CelrLhuFAAAAO4"]
[Mon Jul 20 06:27:39.744577 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5IQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.744690 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:63177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5IQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.841240 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO2V3ou772CelrLhuHQAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.841334 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO2V3ou772CelrLhuHQAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.851236 2026] [security2:error] [pid 925208:tid 925446] [client 43.205.139.3:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UO8RX7OrFkv0FyuI5JAAAAGw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:27:39.919024 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:63180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5JwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.919121 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:63180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5JwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:40.194563 2026] [security2:error] [pid 929851:tid 930094] [client 66.249.74.37:48860] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.ililac.com"] [uri "/robots.txt"] [unique_id "al4UPGV3ou772CelrLhuMwAAAPI"]
[Mon Jul 20 06:27:40.314612 2026] [security2:error] [pid 929851:tid 930059] [client 103.141.108.143:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuOQAAAM8"]
[Mon Jul 20 06:27:40.314825 2026] [security2:error] [pid 929851:tid 930059] [client 103.141.108.143:52888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuOQAAAM8"]
[Mon Jul 20 06:27:40.383657 2026] [security2:error] [pid 925208:tid 925273] [remote 167.233.114.32:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UPMRX7OrFkv0FyuI5NQAAGUA"]
[Mon Jul 20 06:27:40.385590 2026] [security2:error] [pid 929851:tid 930084] [client 45.116.69.230:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuQQAAAOg"]
[Mon Jul 20 06:27:40.385723 2026] [security2:error] [pid 929851:tid 930084] [client 45.116.69.230:53861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuQQAAAOg"]
[Mon Jul 20 06:27:40.424690 2026] [security2:error] [pid 929851:tid 929913] [remote 57.141.18.112:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4UPGV3ou772CelrLhuQgAA6zk"]
[Mon Jul 20 06:27:40.512452 2026] [security2:error] [pid 925208:tid 925358] [client 57.141.18.20:24660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UOMRX7OrFkv0FyuI4jwAAFDM"]
[Mon Jul 20 06:27:40.525115 2026] [security2:error] [pid 929851:tid 930105] [client 34.73.38.214:65012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UPGV3ou772CelrLhuSgAAAP0"]
[Mon Jul 20 06:27:40.597764 2026] [security2:error] [pid 925208:tid 925211] [remote 167.233.114.32:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UPMRX7OrFkv0FyuI5PQAAZgI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:27:40.726640 2026] [security2:error] [pid 929851:tid 930021] [client 39.48.81.23:52948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuVQAAAKk"]
[Mon Jul 20 06:27:40.726837 2026] [security2:error] [pid 929851:tid 930021] [client 39.48.81.23:52948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuVQAAAKk"]
[Mon Jul 20 06:27:40.805675 2026] [security2:error] [pid 925208:tid 925221] [remote 15.206.251.117:36170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UPMRX7OrFkv0FyuI5RAAAUQw"]
[Mon Jul 20 06:27:40.890788 2026] [security2:error] [pid 929851:tid 930054] [client 172.232.181.107:48584] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4UPGV3ou772CelrLhuWwAAAMo"]
[Mon Jul 20 06:27:40.912828 2026] [security2:error] [pid 929851:tid 930112] [client 57.141.18.58:45392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UOGV3ou772CelrLhtnwABBF0"]
[Mon Jul 20 06:27:40.994974 2026] [security2:error] [pid 929851:tid 929905] [remote 3.7.185.37:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UPGV3ou772CelrLhuZAAA4zE"]
[Mon Jul 20 06:27:41.065204 2026] [security2:error] [pid 929851:tid 929884] [remote 57.141.18.22:24092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4UPWV3ou772CelrLhuagAA6Bw"]
[Mon Jul 20 06:27:41.237980 2026] [security2:error] [pid 925208:tid 925310] [remote 15.206.251.117:36170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UPcRX7OrFkv0FyuI5TwAAH2U"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:27:41.270255 2026] [security2:error] [pid 929851:tid 929930] [remote 57.141.18.112:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4UPWV3ou772CelrLhucwABAko"]
[Mon Jul 20 06:27:41.272666 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhudAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.272776 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhudAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.325526 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhueAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.325631 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhueAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.379263 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4UPWV3ou772CelrLhuewAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.395609 2026] [security2:error] [pid 929851:tid 929932] [remote 3.7.185.37:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UPWV3ou772CelrLhufAAAvUw"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:27:41.434898 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhufQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.434982 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhufQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.490427 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuggAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.490551 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuggAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.529127 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuhQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.529252 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuhQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.634070 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPWV3ou772CelrLhueQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.909145 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPcRX7OrFkv0FyuI5YgAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.909274 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPcRX7OrFkv0FyuI5YgAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.128595 2026] [security2:error] [pid 925208:tid 925413] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPcRX7OrFkv0FyuI5aAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.282424 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuoQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.282518 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuoQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.345994 2026] [security2:error] [pid 925208:tid 925434] [client 171.61.165.146:29719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UPsRX7OrFkv0FyuI5eAAAAGA"]
[Mon Jul 20 06:27:42.346126 2026] [security2:error] [pid 925208:tid 925434] [client 171.61.165.146:29719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UPsRX7OrFkv0FyuI5eAAAAGA"]
[Mon Jul 20 06:27:42.362460 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhupQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.362593 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhupQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.386861 2026] [security2:error] [pid 925208:tid 925257] [remote 3.7.185.37:52606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4UPsRX7OrFkv0FyuI5egAAATA"]
[Mon Jul 20 06:27:42.519403 2026] [security2:error] [pid 929851:tid 930111] [client 57.141.18.91:27618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UOmV3ou772CelrLht5wABAx4"]
[Mon Jul 20 06:27:42.533884 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5gQAAAFU"]
[Mon Jul 20 06:27:42.533989 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5gQAAAFU"]
[Mon Jul 20 06:27:42.591218 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPmV3ou772CelrLhuqgAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.775487 2026] [security2:error] [pid 925208:tid 925344] [client 77.110.127.138:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5kwAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.775568 2026] [security2:error] [pid 925208:tid 925344] [client 77.110.127.138:63209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5kwAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.851804 2026] [security2:error] [pid 925208:tid 925318] [remote 3.7.185.37:52606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4UPsRX7OrFkv0FyuI5mgAAG20"], referer: https://allandbeckson.com/wp-login.php
[Mon Jul 20 06:27:42.966009 2026] [security2:error] [pid 929851:tid 929934] [remote 15.206.251.117:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UPmV3ou772CelrLhuwgAAoE4"]
[Mon Jul 20 06:27:42.976554 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuwwAAAP4"]
[Mon Jul 20 06:27:42.976672 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:63213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuwwAAAP4"]
[Mon Jul 20 06:27:43.188240 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPmV3ou772CelrLhuvQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:43.401340 2026] [security2:error] [pid 929851:tid 929920] [remote 15.206.251.117:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UP2V3ou772CelrLhu2gAAxEA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:43.682793 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.31:63674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UO2V3ou772CelrLhuHAAA3yo"]
[Mon Jul 20 06:27:43.738640 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4UP2V3ou772CelrLhu8AAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:43.791341 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UP2V3ou772CelrLhu8QAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:43.791444 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UP2V3ou772CelrLhu8QAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.079493 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UP2V3ou772CelrLhu9gAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.440336 2026] [security2:error] [pid 929851:tid 929921] [remote 57.141.18.80:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3079353"] [unique_id "al4UQGV3ou772CelrLhvEgAAyUE"]
[Mon Jul 20 06:27:44.582099 2026] [security2:error] [pid 925208:tid 925342] [client 114.119.136.111:38169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sesamegreenbeans.com"] [uri "/singapore-to-seoul-without-flying-21-to-30-dec-2024/"] [unique_id "al4UQMRX7OrFkv0FyuI52AAAAAQ"], referer: http://sesamegreenbeans.com/rugby-world-cup-2019-match-experiences-in-kyushu/
[Mon Jul 20 06:27:44.613249 2026] [security2:error] [pid 929851:tid 930101] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UQGV3ou772CelrLhvEwAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.715184 2026] [security2:error] [pid 929851:tid 930042] [client 45.157.112.60:34189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UQGV3ou772CelrLhvIAAAAL4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:44.831740 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQGV3ou772CelrLhvKgAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.831886 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQGV3ou772CelrLhvKgAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.897079 2026] [security2:error] [pid 929851:tid 930079] [client 172.232.181.107:39908] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4UQGV3ou772CelrLhvKwAAAOM"]
[Mon Jul 20 06:27:45.253994 2026] [security2:error] [pid 929851:tid 930093] [client 57.141.18.15:65438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPWV3ou772CelrLhuiAAA8UU"]
[Mon Jul 20 06:27:45.294200 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQWV3ou772CelrLhvOQAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:45.294313 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQWV3ou772CelrLhvOQAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:45.444509 2026] [security2:error] [pid 925208:tid 925368] [client 57.141.18.67:32054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPcRX7OrFkv0FyuI5YAAAHh8"]
[Mon Jul 20 06:27:45.455173 2026] [authz_core:error] [pid 925208:tid 925349] [client 209.85.238.228:48688] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:27:45.690183 2026] [security2:error] [pid 929851:tid 930088] [client 106.219.188.178:16474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UQWV3ou772CelrLhvSwAAAOw"]
[Mon Jul 20 06:27:45.694457 2026] [security2:error] [pid 929851:tid 930088] [client 106.219.188.178:16474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UQWV3ou772CelrLhvSwAAAOw"]
[Mon Jul 20 06:27:45.807470 2026] [security2:error] [pid 925208:tid 925463] [client 57.141.18.64:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPsRX7OrFkv0FyuI5cgAAfQc"]
[Mon Jul 20 06:27:45.809628 2026] [security2:error] [pid 929851:tid 930084] [client 14.225.17.146:53263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4UQWV3ou772CelrLhvOgAAAOg"], referer: http://gearwaterproof.com/old
[Mon Jul 20 06:27:45.967444 2026] [security2:error] [pid 925208:tid 925221] [remote 91.142.222.105:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UQcRX7OrFkv0FyuI6FQAARAw"]
[Mon Jul 20 06:27:45.970312 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UQWV3ou772CelrLhvUAAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.112140 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:63200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4UQsRX7OrFkv0FyuI6GwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.240966 2026] [security2:error] [pid 925208:tid 925217] [remote 91.142.222.105:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UQsRX7OrFkv0FyuI6HwAAZQg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:27:46.306997 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQmV3ou772CelrLhvbQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.307151 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQmV3ou772CelrLhvbQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.386030 2026] [security2:error] [pid 925208:tid 925443] [client 57.141.18.94:22336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPsRX7OrFkv0FyuI5mAAAaXw"]
[Mon Jul 20 06:27:46.390958 2026] [security2:error] [pid 929851:tid 930028] [client 14.225.17.146:57372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvZgAAALA"], referer: https://north-woods-engineering.com/old
[Mon Jul 20 06:27:46.889588 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvgQAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.066456 2026] [security2:error] [pid 925208:tid 925385] [client 77.110.127.138:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6PwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.066564 2026] [security2:error] [pid 925208:tid 925385] [client 77.110.127.138:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6PwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.420312 2026] [security2:error] [pid 929851:tid 930101] [client 68.235.52.68:34130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpAAAAPk"]
[Mon Jul 20 06:27:47.420448 2026] [security2:error] [pid 929851:tid 930101] [client 68.235.52.68:34130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpAAAAPk"]
[Mon Jul 20 06:27:47.428357 2026] [security2:error] [pid 929851:tid 930069] [client 223.185.13.213:31944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpQAAANk"]
[Mon Jul 20 06:27:47.428485 2026] [security2:error] [pid 929851:tid 930069] [client 223.185.13.213:31944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpQAAANk"]
[Mon Jul 20 06:27:47.474521 2026] [security2:error] [pid 929851:tid 929924] [remote 159.65.81.207:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4UQ2V3ou772CelrLhvpwAAskQ"]
[Mon Jul 20 06:27:47.678920 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.67:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQGV3ou772CelrLhvAQAA2yM"]
[Mon Jul 20 06:27:47.694662 2026] [security2:error] [pid 929851:tid 930080] [client 57.141.18.70:49840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQGV3ou772CelrLhvAgAA5EM"]
[Mon Jul 20 06:27:47.873812 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6fgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.873897 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:63249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6fgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.897258 2026] [security2:error] [pid 929851:tid 929928] [remote 159.65.81.207:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4UQ2V3ou772CelrLhvvgAAnEg"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:27:47.928012 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ2V3ou772CelrLhvwQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.928137 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ2V3ou772CelrLhvwQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.971945 2026] [security2:error] [pid 929851:tid 929962] [remote 147.50.252.213:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UQ2V3ou772CelrLhvwgAAxGo"]
[Mon Jul 20 06:27:48.150245 2026] [security2:error] [pid 925208:tid 925399] [client 57.141.18.65:22046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQMRX7OrFkv0FyuI5zAAAPX8"]
[Mon Jul 20 06:27:48.344659 2026] [security2:error] [pid 925208:tid 925431] [client 77.110.127.138:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URMRX7OrFkv0FyuI6lAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:48.344763 2026] [security2:error] [pid 925208:tid 925431] [client 77.110.127.138:63251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URMRX7OrFkv0FyuI6lAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:48.372623 2026] [security2:error] [pid 929851:tid 930111] [client 14.225.17.146:57729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvjAAAAQM"], referer: http://colinkeyphotography.com/old
[Mon Jul 20 06:27:48.427308 2026] [security2:error] [pid 929851:tid 929969] [remote 147.50.252.213:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4URGV3ou772CelrLhv2gAAk3E"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:48.839002 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:63253] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501*if(now()=sysdate(),sleep(15),0)/amp/"] [unique_id "al4URMRX7OrFkv0FyuI6qQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:48.895961 2026] [security2:error] [pid 929851:tid 930089] [client 172.232.181.107:39908] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4URGV3ou772CelrLhv6QAAAO0"]
[Mon Jul 20 06:27:49.164802 2026] [security2:error] [pid 929851:tid 929997] [client 158.173.166.181:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4URWV3ou772CelrLhv-wAAAJE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:49.257568 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:63226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URcRX7OrFkv0FyuI6uQAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.257665 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:63226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URcRX7OrFkv0FyuI6uQAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.279349 2026] [security2:error] [pid 929851:tid 930031] [client 14.225.17.146:57359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4URWV3ou772CelrLhv_QAAALM"], referer: http://katsklar.com/old
[Mon Jul 20 06:27:49.383703 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwCQAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.383815 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:63257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwCQAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.600774 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwFwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.600890 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwFwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.748657 2026] [security2:error] [pid 929851:tid 930042] [client 171.60.139.123:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4URWV3ou772CelrLhwHgAAAL4"]
[Mon Jul 20 06:27:49.748855 2026] [security2:error] [pid 929851:tid 930042] [client 171.60.139.123:62090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4URWV3ou772CelrLhwHgAAAL4"]
[Mon Jul 20 06:27:49.788467 2026] [security2:error] [pid 929851:tid 930109] [client 57.141.18.22:27774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQWV3ou772CelrLhvWAABAXY"]
[Mon Jul 20 06:27:50.166556 2026] [security2:error] [pid 929851:tid 930035] [client 57.141.18.99:24070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvdAAAt1c"]
[Mon Jul 20 06:27:50.504899 2026] [security2:error] [pid 925208:tid 925379] [client 57.141.18.97:21704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQsRX7OrFkv0FyuI6MAAAKUo"]
[Mon Jul 20 06:27:50.737804 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:63234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI67QAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:50.737921 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:63234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI67QAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:50.801990 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:63264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI68gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:50.802095 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:63264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI68gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.018732 2026] [security2:error] [pid 929851:tid 930073] [client 103.141.108.143:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwWQAAAN0"]
[Mon Jul 20 06:27:51.018919 2026] [security2:error] [pid 929851:tid 930073] [client 103.141.108.143:53360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwWQAAAN0"]
[Mon Jul 20 06:27:51.063799 2026] [security2:error] [pid 929851:tid 929989] [client 57.141.18.54:42594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQ2V3ou772CelrLhvnAAAiWM"]
[Mon Jul 20 06:27:51.095568 2026] [security2:error] [pid 925208:tid 925388] [client 45.116.69.230:54430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UR8RX7OrFkv0FyuI6_gAAADI"]
[Mon Jul 20 06:27:51.095669 2026] [security2:error] [pid 925208:tid 925388] [client 45.116.69.230:54430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UR8RX7OrFkv0FyuI6_gAAADI"]
[Mon Jul 20 06:27:51.145301 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.145391 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.152044 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.152119 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.172398 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwVgAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.210021 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwYgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.210128 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwYgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.407406 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwbgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.407551 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwbgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.540491 2026] [security2:error] [pid 925208:tid 925450] [client 77.110.127.138:63208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7CgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.540634 2026] [security2:error] [pid 925208:tid 925450] [client 77.110.127.138:63208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7CgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.566367 2026] [security2:error] [pid 929851:tid 930076] [client 39.48.81.23:53417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwdwAAAOA"]
[Mon Jul 20 06:27:51.566525 2026] [security2:error] [pid 929851:tid 930076] [client 39.48.81.23:53417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwdwAAAOA"]
[Mon Jul 20 06:27:51.634269 2026] [security2:error] [pid 929851:tid 930056] [client 93.152.221.118:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UR2V3ou772CelrLhweQAAAMw"], referer: https://wordpress.org/
[Mon Jul 20 06:27:51.653577 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:63273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7EAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.653669 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:63273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7EAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.707526 2026] [security2:error] [pid 929851:tid 930040] [client 14.225.17.146:55898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4UR2V3ou772CelrLhwewAAALw"], referer: http://dasmarque.com/old
[Mon Jul 20 06:27:51.795523 2026] [security2:error] [pid 925208:tid 925279] [remote 192.241.143.148:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UR8RX7OrFkv0FyuI7EwAAEUY"]
[Mon Jul 20 06:27:51.853065 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwhQAAAMg"]
[Mon Jul 20 06:27:51.853211 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwhQAAAMg"]
[Mon Jul 20 06:27:51.884859 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63275] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/5010'XOR(501*if(now()=sysdate(),sleep(15),0))XOR'Z/amp/"] [unique_id "al4UR2V3ou772CelrLhwhwAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.909049 2026] [security2:error] [pid 929851:tid 930033] [client 93.152.221.118:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UR2V3ou772CelrLhwiwAAALU"]
[Mon Jul 20 06:27:51.930145 2026] [security2:error] [pid 929851:tid 930096] [client 116.76.196.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwTQAAAPQ"]
[Mon Jul 20 06:27:51.950555 2026] [security2:error] [pid 929851:tid 930070] [client 57.141.18.81:25120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URGV3ou772CelrLhvyQAA2m4"]
[Mon Jul 20 06:27:51.985467 2026] [security2:error] [pid 925208:tid 925309] [remote 192.241.143.148:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UR8RX7OrFkv0FyuI7GAAAE2Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:27:52.002938 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7GQAAABQ"]
[Mon Jul 20 06:27:52.003059 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7GQAAABQ"]
[Mon Jul 20 06:27:52.472375 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.115:28060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URGV3ou772CelrLhv6wAAlnw"]
[Mon Jul 20 06:27:52.478740 2026] [security2:error] [pid 925208:tid 925407] [client 77.110.127.138:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7MgAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:52.478849 2026] [security2:error] [pid 925208:tid 925407] [client 77.110.127.138:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7MgAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:52.893175 2026] [security2:error] [pid 929851:tid 930111] [client 172.232.181.107:39908] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4USGV3ou772CelrLhwrgAAAQM"]
[Mon Jul 20 06:27:53.164671 2026] [security2:error] [pid 925208:tid 925369] [client 171.61.165.146:31211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7UAAAAB8"]
[Mon Jul 20 06:27:53.165724 2026] [security2:error] [pid 925208:tid 925369] [client 171.61.165.146:31211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7UAAAAB8"]
[Mon Jul 20 06:27:53.227112 2026] [security2:error] [pid 925208:tid 925457] [client 93.152.221.118:54027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UScRX7OrFkv0FyuI7UgAAAHc"]
[Mon Jul 20 06:27:53.233502 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63221] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4USWV3ou772CelrLhwxgAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.551848 2026] [security2:error] [pid 929851:tid 930059] [client 14.225.17.146:55889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwzQAAAM8"], referer: http://reosportsboats.com/old
[Mon Jul 20 06:27:53.634539 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwzgAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.773589 2026] [security2:error] [pid 925208:tid 925397] [client 112.208.70.94:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7YgAAADs"]
[Mon Jul 20 06:27:53.773703 2026] [security2:error] [pid 925208:tid 925397] [client 112.208.70.94:43569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7YgAAADs"]
[Mon Jul 20 06:27:53.794164 2026] [security2:error] [pid 929851:tid 929981] [remote 154.66.198.148:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4USWV3ou772CelrLhw6AAAxn0"]
[Mon Jul 20 06:27:53.841019 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USWV3ou772CelrLhw6wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.841146 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USWV3ou772CelrLhw6wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.934310 2026] [security2:error] [pid 929851:tid 930012] [client 57.141.18.55:47266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwPwAAoBg"]
[Mon Jul 20 06:27:53.992096 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/5010\\"XOR(501*if(now()=sysdate(),sleep(15),0))XOR\\"Z/amp/"] [unique_id "al4USWV3ou772CelrLhw9QAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:54.042663 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USmV3ou772CelrLhw-AAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:54.042790 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USmV3ou772CelrLhw-AAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:54.073539 2026] [security2:error] [pid 929851:tid 929998] [client 57.141.18.26:33408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwRgAAkgY"]
[Mon Jul 20 06:27:54.332356 2026] [security2:error] [pid 929851:tid 929903] [remote 154.66.198.148:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4USmV3ou772CelrLhxCAAA6S8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:54.430132 2026] [security2:error] [pid 929851:tid 930041] [client 57.141.18.103:42072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwWAAAvQ4"]
[Mon Jul 20 06:27:54.526393 2026] [security2:error] [pid 929851:tid 930063] [client 14.225.17.146:60743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4USmV3ou772CelrLhxDgAAANM"], referer: https://reosportsboats.com/old
[Mon Jul 20 06:27:54.622595 2026] [security2:error] [pid 929851:tid 930100] [client 57.141.18.0:55026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UR2V3ou772CelrLhwZQAA-BY"]
[Mon Jul 20 06:27:54.826858 2026] [security2:error] [pid 929851:tid 930105] [client 104.234.53.57:21505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4USmV3ou772CelrLhxIgAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:55.089499 2026] [security2:error] [pid 929851:tid 930109] [client 57.141.18.100:37108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UR2V3ou772CelrLhwfQABAQ8"]
[Mon Jul 20 06:27:55.250013 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4US8RX7OrFkv0FyuI7qAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:55.250118 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4US8RX7OrFkv0FyuI7qAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:55.275108 2026] [security2:error] [pid 929851:tid 929914] [remote 8.217.108.67:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4US2V3ou772CelrLhxLgAAjzo"]
[Mon Jul 20 06:27:55.426963 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63297] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4US2V3ou772CelrLhxOgAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:55.522845 2026] [security2:error] [pid 925208:tid 925310] [remote 100.42.189.89:48238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4US8RX7OrFkv0FyuI7tQAAfmU"]
[Mon Jul 20 06:27:55.730127 2026] [security2:error] [pid 925208:tid 925238] [remote 100.42.189.89:48238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4US8RX7OrFkv0FyuI7wQAAKh0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:55.736389 2026] [security2:error] [pid 925208:tid 925381] [client 103.153.183.69:60932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/apache2/apache2.conf"] [unique_id "al4US8RX7OrFkv0FyuI7wgAAACs"], referer: https://www.google.com/
[Mon Jul 20 06:27:55.775422 2026] [security2:error] [pid 929851:tid 930047] [client 14.225.17.146:60544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4US2V3ou772CelrLhxTgAAAMM"], referer: http://processorstudio.com/old
[Mon Jul 20 06:27:55.781739 2026] [security2:error] [pid 929851:tid 929926] [remote 8.217.108.67:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4US2V3ou772CelrLhxUgAAqUY"], referer: https://roguedragonstudio.com/wp-login.php
[Mon Jul 20 06:27:55.813820 2026] [security2:error] [pid 925208:tid 925372] [client 57.141.18.63:59106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USMRX7OrFkv0FyuI7KAAAInU"]
[Mon Jul 20 06:27:55.870033 2026] [security2:error] [pid 929851:tid 929860] [remote 154.66.198.148:24610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4US2V3ou772CelrLhxVAAAswQ"]
[Mon Jul 20 06:27:56.347371 2026] [security2:error] [pid 929851:tid 930074] [client 106.219.188.178:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UTGV3ou772CelrLhxYgAAAN4"]
[Mon Jul 20 06:27:56.347499 2026] [security2:error] [pid 929851:tid 930074] [client 106.219.188.178:51782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UTGV3ou772CelrLhxYgAAAN4"]
[Mon Jul 20 06:27:56.367772 2026] [security2:error] [pid 925208:tid 925460] [client 104.234.53.53:29097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UTMRX7OrFkv0FyuI72wAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:56.443732 2026] [security2:error] [pid 929851:tid 929940] [remote 154.66.198.148:24610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UTGV3ou772CelrLhxZQAAn1Q"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:56.528424 2026] [security2:error] [pid 929851:tid 930058] [client 57.141.18.79:36322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USGV3ou772CelrLhwtgAAzmQ"]
[Mon Jul 20 06:27:56.653770 2026] [security2:error] [pid 925208:tid 925387] [client 104.234.53.53:29097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UTMRX7OrFkv0FyuI76AAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:56.714822 2026] [security2:error] [pid 929851:tid 930089] [client 57.141.18.44:44756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwwAAA7Qg"]
[Mon Jul 20 06:27:56.808969 2026] [security2:error] [pid 929851:tid 930028] [client 14.225.17.146:53198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxeQAAALA"], referer: https://processorstudio.com/old
[Mon Jul 20 06:27:56.844361 2026] [security2:error] [pid 929851:tid 930007] [client 57.141.18.113:64624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwyAAAmys"]
[Mon Jul 20 06:27:57.091505 2026] [security2:error] [pid 929851:tid 930103] [client 50.116.65.227:18708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UTWV3ou772CelrLhxjAAAAPs"]
[Mon Jul 20 06:27:57.104086 2026] [security2:error] [pid 929851:tid 930002] [client 50.116.65.227:18710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UTWV3ou772CelrLhxjQAAAJY"]
[Mon Jul 20 06:27:57.137515 2026] [security2:error] [pid 929851:tid 930071] [client 18.192.166.72:49040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxiAAAANs"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:27:57.168219 2026] [security2:error] [pid 925208:tid 925381] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UTMRX7OrFkv0FyuI78gAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.240690 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.57:43388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhw2gAA_iw"]
[Mon Jul 20 06:27:57.263085 2026] [security2:error] [pid 929851:tid 929986] [client 223.185.13.213:25435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UTWV3ou772CelrLhxkQAAAIY"]
[Mon Jul 20 06:27:57.263221 2026] [security2:error] [pid 929851:tid 929986] [client 223.185.13.213:25435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UTWV3ou772CelrLhxkQAAAIY"]
[Mon Jul 20 06:27:57.371105 2026] [security2:error] [pid 929851:tid 930063] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxewAA01Y"], referer: http://ardhalwafaa.com/old
[Mon Jul 20 06:27:57.377540 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:63304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTcRX7OrFkv0FyuI8AAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.377621 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:63304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTcRX7OrFkv0FyuI8AAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.773967 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxowAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.774077 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxowAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.924723 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxqQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.924818 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxqQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.027342 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.103:42082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USmV3ou772CelrLhxEQAA1zM"]
[Mon Jul 20 06:27:58.050826 2026] [security2:error] [pid 925208:tid 925269] [remote 84.247.172.23:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4UTsRX7OrFkv0FyuI8FwAATDw"]
[Mon Jul 20 06:27:58.072880 2026] [cgid:error] [pid 929851:tid 930061] [client 66.132.186.196:58328] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: http://www.website-fa490990.threethirds.co:80/cgi-bin
[Mon Jul 20 06:27:58.175930 2026] [security2:error] [pid 925208:tid 925393] [client 57.141.18.22:46752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USsRX7OrFkv0FyuI7hwAANwU"]
[Mon Jul 20 06:27:58.300991 2026] [security2:error] [pid 925208:tid 925309] [remote 84.247.172.23:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4UTsRX7OrFkv0FyuI8JQAARmQ"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 06:27:58.308152 2026] [security2:error] [pid 929851:tid 930039] [client 45.3.44.200:50425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/xmlrpc.php"] [unique_id "al4UTmV3ou772CelrLhxvgAAALs"], referer: https://t.co/
[Mon Jul 20 06:27:58.625046 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTmV3ou772CelrLhxzAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.625183 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTmV3ou772CelrLhxzAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.707801 2026] [security2:error] [pid 925208:tid 925396] [client 57.141.18.56:32690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4US8RX7OrFkv0FyuI7nwAAOg0"]
[Mon Jul 20 06:27:58.762217 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UTmV3ou772CelrLhx1wAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.971393 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:60686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4UTmV3ou772CelrLhxyAAAAKQ"], referer: http://overloadcomedy.com/old
[Mon Jul 20 06:27:59.063923 2026] [security2:error] [pid 925208:tid 925359] [client 50.116.65.227:54726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/08/IMG_8766.jpeg"] [unique_id "al4UT8RX7OrFkv0FyuI8RgAAAGU"]
[Mon Jul 20 06:27:59.261787 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.91:63684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4US2V3ou772CelrLhxUQAA-kc"]
[Mon Jul 20 06:27:59.525918 2026] [security2:error] [pid 925208:tid 925274] [remote 49.12.216.176:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4UT8RX7OrFkv0FyuI8XAAAa0E"]
[Mon Jul 20 06:27:59.542084 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.4:22070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxVwAA2E8"]
[Mon Jul 20 06:27:59.609342 2026] [security2:error] [pid 929851:tid 930107] [client 14.225.17.146:63770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4UT2V3ou772CelrLhx9wAAAP8"], referer: http://taskidsvirginia.com/old
[Mon Jul 20 06:27:59.696381 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UT8RX7OrFkv0FyuI8WgAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:59.728058 2026] [security2:error] [pid 925208:tid 925306] [remote 49.12.216.176:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4UT8RX7OrFkv0FyuI8XwAAEmE"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:27:59.734202 2026] [security2:error] [pid 925208:tid 925452] [client 47.128.30.83:25910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zonemist.com"] [uri "/robots.txt"] [unique_id "al4UT8RX7OrFkv0FyuI8YAAAAHI"]
[Mon Jul 20 06:27:59.859710 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UT2V3ou772CelrLhyCAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:59.859837 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UT2V3ou772CelrLhyCAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:59.996948 2026] [security2:error] [pid 929851:tid 930060] [client 14.225.17.146:60467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4UT2V3ou772CelrLhyBwAAANA"], referer: http://cephasnext.com/old
[Mon Jul 20 06:28:00.017033 2026] [security2:error] [pid 925208:tid 925351] [client 14.225.17.146:60576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4UTsRX7OrFkv0FyuI8KQAAAA0"], referer: http://ksands.co.uk/old
[Mon Jul 20 06:28:00.055777 2026] [security2:error] [pid 929851:tid 929960] [remote 160.187.68.132:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyFAAAhWg"]
[Mon Jul 20 06:28:00.060642 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.34:42824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxbwAAuU4"]
[Mon Jul 20 06:28:00.228544 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UUGV3ou772CelrLhyEwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:00.282231 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUMRX7OrFkv0FyuI8cwAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:00.282326 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:63200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUMRX7OrFkv0FyuI8cwAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:00.293102 2026] [security2:error] [pid 929851:tid 930029] [client 14.225.17.146:60721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4UUGV3ou772CelrLhyGAAAALE"], referer: http://samdothan.org/old
[Mon Jul 20 06:28:00.437610 2026] [security2:error] [pid 925208:tid 925405] [client 171.60.139.123:62620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UUMRX7OrFkv0FyuI8eQAAAEM"]
[Mon Jul 20 06:28:00.437731 2026] [security2:error] [pid 925208:tid 925405] [client 171.60.139.123:62620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UUMRX7OrFkv0FyuI8eQAAAEM"]
[Mon Jul 20 06:28:00.573934 2026] [security2:error] [pid 929851:tid 929967] [remote 160.187.68.132:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyKQAAzm8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:00.658588 2026] [security2:error] [pid 929851:tid 929973] [remote 162.19.86.63:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyMAAApnU"]
[Mon Jul 20 06:28:00.747773 2026] [fcgid:warn] [pid 925208:tid 925378] (70014)End of file found: [client 199.45.154.146:44016] mod_fcgid: can't get data from http client
[Mon Jul 20 06:28:00.869063 2026] [security2:error] [pid 929851:tid 929963] [remote 162.19.86.63:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyOgAArWs"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:28:00.933610 2026] [security2:error] [pid 929851:tid 930024] [client 57.141.18.31:54210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTWV3ou772CelrLhxlgAArBE"]
[Mon Jul 20 06:28:00.976279 2026] [security2:error] [pid 925208:tid 925459] [client 14.225.17.146:50363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4UT8RX7OrFkv0FyuI8YQAAAHk"], referer: http://sarahholyfield.com/old
[Mon Jul 20 06:28:01.001966 2026] [security2:error] [pid 925208:tid 925357] [client 57.141.18.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UUMRX7OrFkv0FyuI8iAAAABM"]
[Mon Jul 20 06:28:01.173407 2026] [security2:error] [pid 925208:tid 925374] [client 77.110.127.138:63325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UUcRX7OrFkv0FyuI8kgAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:01.316716 2026] [security2:error] [pid 929851:tid 930083] [client 57.141.18.63:32078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTWV3ou772CelrLhxqAAA50s"]
[Mon Jul 20 06:28:01.677913 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUWV3ou772CelrLhyXQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:01.678021 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUWV3ou772CelrLhyXQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:01.699050 2026] [security2:error] [pid 925208:tid 925352] [client 103.141.108.143:53837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8qwAAAA4"]
[Mon Jul 20 06:28:01.699199 2026] [security2:error] [pid 925208:tid 925352] [client 103.141.108.143:53837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8qwAAAA4"]
[Mon Jul 20 06:28:01.699524 2026] [security2:error] [pid 929851:tid 930094] [client 50.116.65.227:42652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4UUWV3ou772CelrLhyXwAAAPI"]
[Mon Jul 20 06:28:01.711445 2026] [security2:error] [pid 929851:tid 929988] [client 50.116.65.227:54758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4UUWV3ou772CelrLhyYwAAAOE"]
[Mon Jul 20 06:28:01.789808 2026] [security2:error] [pid 929851:tid 930015] [client 181.121.225.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4UT2V3ou772CelrLhx6QAAAKM"]
[Mon Jul 20 06:28:01.828191 2026] [security2:error] [pid 925208:tid 925434] [client 45.116.69.230:54959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8swAAAGA"]
[Mon Jul 20 06:28:01.828432 2026] [security2:error] [pid 925208:tid 925434] [client 45.116.69.230:54959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8swAAAGA"]
[Mon Jul 20 06:28:02.039462 2026] [security2:error] [pid 929851:tid 930010] [client 39.48.81.23:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UUmV3ou772CelrLhycwAAAJ4"]
[Mon Jul 20 06:28:02.040283 2026] [security2:error] [pid 929851:tid 930010] [client 39.48.81.23:53889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UUmV3ou772CelrLhycwAAAJ4"]
[Mon Jul 20 06:28:02.075958 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UUcRX7OrFkv0FyuI8sQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.079797 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:63337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8vwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.079922 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:63337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8vwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.106116 2026] [security2:error] [pid 929851:tid 930035] [client 57.141.18.51:62386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTmV3ou772CelrLhxzQAAt1A"]
[Mon Jul 20 06:28:02.135173 2026] [security2:error] [pid 929851:tid 929856] [remote 109.234.164.108:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.164.234.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhydwAA0AA"]
[Mon Jul 20 06:28:02.179906 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUmV3ou772CelrLhyewAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.180018 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:63303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUmV3ou772CelrLhyewAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.228027 2026] [security2:error] [pid 925208:tid 925410] [client 57.141.18.1:45118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTsRX7OrFkv0FyuI8OgAASFM"]
[Mon Jul 20 06:28:02.296599 2026] [security2:error] [pid 929851:tid 929879] [remote 217.61.143.92:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyfwAAqRc"]
[Mon Jul 20 06:28:02.329932 2026] [security2:error] [pid 929851:tid 929982] [remote 109.234.164.108:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.164.234.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyggAA934"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 06:28:02.333963 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xAAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.334110 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:63343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xAAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.419572 2026] [security2:error] [pid 929851:tid 929866] [remote 100.42.189.89:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyhgAAoQo"]
[Mon Jul 20 06:28:02.476965 2026] [security2:error] [pid 925208:tid 925349] [client 194.187.171.135:55479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xQAACyI"]
[Mon Jul 20 06:28:02.504192 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8zAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.504324 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8zAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.622337 2026] [security2:error] [pid 929851:tid 929955] [remote 100.42.189.89:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyjAAAkWM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:28:02.658077 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI81QAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.658220 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI81QAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.660458 2026] [security2:error] [pid 929851:tid 929872] [remote 217.61.143.92:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyjgAArRA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:28:03.078170 2026] [security2:error] [pid 929851:tid 930031] [client 104.234.53.56:30625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UUmV3ou772CelrLhyngAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:03.181923 2026] [security2:error] [pid 929851:tid 929994] [client 14.225.17.146:60507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4UUmV3ou772CelrLhyhwAAAI4"], referer: http://oldracelimited.com/old
[Mon Jul 20 06:28:03.248496 2026] [security2:error] [pid 925208:tid 925212] [remote 57.141.18.65:43140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4415964"] [unique_id "al4UU8RX7OrFkv0FyuI85gAATgM"]
[Mon Jul 20 06:28:03.520562 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UU8RX7OrFkv0FyuI86wAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:03.710535 2026] [proxy:error] [pid 925208:tid 925354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:03.710604 2026] [proxy_http:error] [pid 925208:tid 925354] [client 34.73.38.214:51054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:03.711798 2026] [proxy:error] [pid 925208:tid 925354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:03.711830 2026] [proxy_http:error] [pid 925208:tid 925354] [client 34.73.38.214:51054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:03.714286 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:63354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UU8RX7OrFkv0FyuI89wAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:03.714369 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:63354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UU8RX7OrFkv0FyuI89wAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:03.837011 2026] [security2:error] [pid 929851:tid 929888] [remote 130.51.180.8:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UU2V3ou772CelrLhyyAAAhiA"]
[Mon Jul 20 06:28:03.881412 2026] [security2:error] [pid 925208:tid 925370] [client 57.141.18.89:44520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUMRX7OrFkv0FyuI8fAAAIHo"]
[Mon Jul 20 06:28:03.921982 2026] [security2:error] [pid 929851:tid 930093] [client 57.141.18.96:35472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUGV3ou772CelrLhyKAAA8Wo"]
[Mon Jul 20 06:28:03.964659 2026] [security2:error] [pid 929851:tid 930075] [client 104.234.53.56:30625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UU2V3ou772CelrLhyywAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:04.180369 2026] [security2:error] [pid 929851:tid 930052] [client 171.61.165.146:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UVGV3ou772CelrLhyzgAAAMg"]
[Mon Jul 20 06:28:04.180477 2026] [security2:error] [pid 929851:tid 930052] [client 171.61.165.146:4808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UVGV3ou772CelrLhyzgAAAMg"]
[Mon Jul 20 06:28:04.196597 2026] [security2:error] [pid 929851:tid 929857] [remote 130.51.180.8:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UVGV3ou772CelrLhy0wAA6QE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:28:04.345251 2026] [security2:error] [pid 925208:tid 925423] [client 50.116.65.227:54788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4UU8RX7OrFkv0FyuI8-AAAAFU"]
[Mon Jul 20 06:28:04.347472 2026] [security2:error] [pid 929851:tid 930067] [client 146.120.227.216:55318] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4UVGV3ou772CelrLhy2AAAANc"]
[Mon Jul 20 06:28:04.391168 2026] [security2:error] [pid 929851:tid 930050] [client 186.189.111.130:49320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4UVGV3ou772CelrLhy2wAAAMY"]
[Mon Jul 20 06:28:04.410376 2026] [security2:error] [pid 929851:tid 930081] [client 64.233.172.3:38682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UVGV3ou772CelrLhy1AAAAOU"]
[Mon Jul 20 06:28:04.539608 2026] [security2:error] [pid 929851:tid 930105] [client 57.141.18.8:23532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUWV3ou772CelrLhyQwAA_Vo"]
[Mon Jul 20 06:28:04.623858 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.62:36782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUcRX7OrFkv0FyuI8kwAAVyw"]
[Mon Jul 20 06:28:04.787547 2026] [security2:error] [pid 929851:tid 930102] [client 71.249.119.72:39914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UVGV3ou772CelrLhy7AAAAPo"]
[Mon Jul 20 06:28:04.787807 2026] [proxy:error] [pid 929851:tid 930108] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:04.787885 2026] [proxy_http:error] [pid 929851:tid 930108] [client 34.73.38.214:50777] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:04.788557 2026] [proxy:error] [pid 929851:tid 930108] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:04.788601 2026] [proxy_http:error] [pid 929851:tid 930108] [client 34.73.38.214:50777] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:04.928827 2026] [security2:error] [pid 929851:tid 929995] [client 50.116.65.227:54806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4UVGV3ou772CelrLhy2QAAAI8"]
[Mon Jul 20 06:28:05.059651 2026] [security2:error] [pid 929851:tid 929988] [client 75.158.224.112:35566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4UVWV3ou772CelrLhy9AAAAIg"]
[Mon Jul 20 06:28:05.063101 2026] [security2:error] [pid 925208:tid 925413] [client 57.141.18.71:45694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUcRX7OrFkv0FyuI8sgAASxU"]
[Mon Jul 20 06:28:05.064514 2026] [security2:error] [pid 929851:tid 930039] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UVGV3ou772CelrLhy8AAAALs"]
[Mon Jul 20 06:28:05.187810 2026] [security2:error] [pid 929851:tid 930074] [client 139.28.49.104:54664] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4UVWV3ou772CelrLhy-QAAAN4"]
[Mon Jul 20 06:28:05.212306 2026] [security2:error] [pid 929851:tid 930099] [client 41.90.172.147:9795] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UVWV3ou772CelrLhy_gAAAPc"]
[Mon Jul 20 06:28:05.492976 2026] [security2:error] [pid 925208:tid 925458] [client 78.160.164.3:33198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4UVcRX7OrFkv0FyuI9OwAAAHg"]
[Mon Jul 20 06:28:05.540541 2026] [security2:error] [pid 929851:tid 930097] [client 131.196.114.35:54798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4UVWV3ou772CelrLhzCgAAAPU"]
[Mon Jul 20 06:28:05.603946 2026] [security2:error] [pid 929851:tid 930019] [client 196.187.145.251:41505] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UVWV3ou772CelrLhzEAAAAKc"]
[Mon Jul 20 06:28:05.740170 2026] [security2:error] [pid 929851:tid 930066] [client 58.186.167.209:63691] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4UVWV3ou772CelrLhzHQAAANY"]
[Mon Jul 20 06:28:05.832043 2026] [security2:error] [pid 929851:tid 930088] [client 65.1.132.125:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UVWV3ou772CelrLhzJAAAAOw"]
[Mon Jul 20 06:28:05.836514 2026] [proxy:error] [pid 929851:tid 930093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:05.836574 2026] [proxy_http:error] [pid 929851:tid 930093] [client 34.73.38.214:58201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:05.837278 2026] [proxy:error] [pid 929851:tid 930093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:05.837306 2026] [proxy_http:error] [pid 929851:tid 930093] [client 34.73.38.214:58201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:05.850443 2026] [security2:error] [pid 929851:tid 929981] [remote 97.74.87.194:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UVWV3ou772CelrLhzJgAA230"]
[Mon Jul 20 06:28:05.867257 2026] [security2:error] [pid 925208:tid 925445] [client 57.141.18.118:61464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xgAAaz8"]
[Mon Jul 20 06:28:05.881893 2026] [security2:error] [pid 929851:tid 930040] [client 14.225.17.146:60318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzGwAAALw"], referer: http://dadanetnet.net/old
[Mon Jul 20 06:28:05.957728 2026] [security2:error] [pid 929851:tid 930036] [client 57.141.18.48:36874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUmV3ou772CelrLhyiAAAuHc"]
[Mon Jul 20 06:28:05.966001 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UVcRX7OrFkv0FyuI9SAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:06.011251 2026] [security2:error] [pid 925208:tid 925342] [client 59.103.220.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4UVcRX7OrFkv0FyuI9RQAAAAQ"]
[Mon Jul 20 06:28:06.019431 2026] [security2:error] [pid 925208:tid 925380] [client 57.141.18.65:28762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUsRX7OrFkv0FyuI80AAAKgc"]
[Mon Jul 20 06:28:06.138307 2026] [security2:error] [pid 929851:tid 930108] [client 14.225.17.146:53820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzMAAAAQA"], referer: http://ivetstrategies.com/old
[Mon Jul 20 06:28:06.246699 2026] [security2:error] [pid 929851:tid 930031] [client 14.225.17.146:53825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UVmV3ou772CelrLhzMgAAALM"], referer: http://mezzacraft.com/old
[Mon Jul 20 06:28:06.414513 2026] [security2:error] [pid 929851:tid 930064] [client 45.225.44.179:57149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UVmV3ou772CelrLhzSgAAANQ"]
[Mon Jul 20 06:28:06.497509 2026] [security2:error] [pid 925208:tid 925389] [client 213.139.53.205:52486] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4UVsRX7OrFkv0FyuI9aAAAADM"]
[Mon Jul 20 06:28:06.608725 2026] [security2:error] [pid 929851:tid 929861] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4UVmV3ou772CelrLhzUAAA4gU"]
[Mon Jul 20 06:28:06.634720 2026] [security2:error] [pid 929851:tid 930006] [client 50.116.65.227:54850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UVmV3ou772CelrLhzVQAAAJo"]
[Mon Jul 20 06:28:06.645231 2026] [security2:error] [pid 925208:tid 925417] [client 50.116.65.227:54866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UVsRX7OrFkv0FyuI9bwAAAE8"]
[Mon Jul 20 06:28:06.697670 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UVmV3ou772CelrLhzWwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:06.697772 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UVmV3ou772CelrLhzWwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:06.706389 2026] [security2:error] [pid 925208:tid 925421] [client 104.234.53.89:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UVsRX7OrFkv0FyuI9cwAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:06.710965 2026] [proxy:error] [pid 929851:tid 930087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:06.711007 2026] [proxy_http:error] [pid 929851:tid 930087] [client 34.73.38.214:57839] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:06.711694 2026] [proxy:error] [pid 929851:tid 930087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:06.711717 2026] [proxy_http:error] [pid 929851:tid 930087] [client 34.73.38.214:57839] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:06.803237 2026] [security2:error] [pid 929851:tid 930106] [client 106.219.188.178:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UVmV3ou772CelrLhzYwAAAP4"]
[Mon Jul 20 06:28:06.810869 2026] [security2:error] [pid 929851:tid 930106] [client 106.219.188.178:40974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UVmV3ou772CelrLhzYwAAAP4"]
[Mon Jul 20 06:28:06.822823 2026] [security2:error] [pid 929851:tid 930021] [client 49.147.198.12:49119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4UVmV3ou772CelrLhzZwAAAKk"]
[Mon Jul 20 06:28:06.886863 2026] [security2:error] [pid 929851:tid 929999] [client 37.114.177.7:4896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4UVmV3ou772CelrLhzbAAAAJM"]
[Mon Jul 20 06:28:06.892834 2026] [security2:error] [pid 929851:tid 930083] [client 43.205.139.3:21350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UVmV3ou772CelrLhzbQAAAOc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:28:06.908712 2026] [security2:error] [pid 929851:tid 929906] [remote 97.74.87.194:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UVmV3ou772CelrLhzbgAAvjI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:28:07.057549 2026] [security2:error] [pid 925208:tid 925464] [client 115.69.212.210:59518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UV8RX7OrFkv0FyuI9iAAAAH4"]
[Mon Jul 20 06:28:07.176782 2026] [security2:error] [pid 925208:tid 925460] [client 185.187.77.183:18818] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UV8RX7OrFkv0FyuI9jAAAAHo"]
[Mon Jul 20 06:28:07.266138 2026] [security2:error] [pid 929851:tid 930031] [client 112.208.70.94:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UV2V3ou772CelrLhzdwAAALM"]
[Mon Jul 20 06:28:07.266302 2026] [security2:error] [pid 929851:tid 930031] [client 112.208.70.94:43987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UV2V3ou772CelrLhzdwAAALM"]
[Mon Jul 20 06:28:07.273174 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UV8RX7OrFkv0FyuI9hwAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:07.290704 2026] [security2:error] [pid 929851:tid 930099] [client 152.59.19.173:47592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4UV2V3ou772CelrLhzeAAAAPc"]
[Mon Jul 20 06:28:07.431757 2026] [security2:error] [pid 929851:tid 929884] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4UV2V3ou772CelrLhzhAABAhw"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:28:07.433553 2026] [security2:error] [pid 929851:tid 930086] [client 144.48.151.179:49176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4UV2V3ou772CelrLhzhQAAAOo"]
[Mon Jul 20 06:28:07.719812 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UV8RX7OrFkv0FyuI9ogAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:07.914824 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UV8RX7OrFkv0FyuI9sAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:07.914944 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UV8RX7OrFkv0FyuI9sAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.067573 2026] [security2:error] [pid 929851:tid 930100] [client 14.225.17.146:54194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4UV2V3ou772CelrLhzigAAAPg"], referer: http://nwcarvingacademy.com/old
[Mon Jul 20 06:28:08.074585 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWGV3ou772CelrLhzpAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.074693 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWGV3ou772CelrLhzpAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.135304 2026] [security2:error] [pid 925208:tid 925340] [client 57.141.18.20:27898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVMRX7OrFkv0FyuI9HQAAAjk"]
[Mon Jul 20 06:28:08.144047 2026] [security2:error] [pid 925208:tid 925238] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "omenana.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4UWMRX7OrFkv0FyuI9vAAAOh0"]
[Mon Jul 20 06:28:08.147875 2026] [security2:error] [pid 929851:tid 930066] [client 116.204.228.180:33220] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4UWGV3ou772CelrLhzpwAAANY"]
[Mon Jul 20 06:28:08.248521 2026] [security2:error] [pid 929851:tid 930077] [client 104.234.53.91:37443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UWGV3ou772CelrLhztwAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:08.408496 2026] [security2:error] [pid 929851:tid 929997] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzqAAAAJE"]
[Mon Jul 20 06:28:08.423538 2026] [security2:error] [pid 929851:tid 929930] [remote 160.187.68.132:34022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UWGV3ou772CelrLhzwwAA50o"]
[Mon Jul 20 06:28:08.459800 2026] [security2:error] [pid 925208:tid 925384] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9yAAAAC4"]
[Mon Jul 20 06:28:08.473291 2026] [security2:error] [pid 929851:tid 930054] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzsAAAAMo"]
[Mon Jul 20 06:28:08.476006 2026] [security2:error] [pid 929851:tid 929998] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzrgAAAJI"]
[Mon Jul 20 06:28:08.480161 2026] [security2:error] [pid 929851:tid 930040] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzrQAAALw"]
[Mon Jul 20 06:28:08.487271 2026] [security2:error] [pid 929851:tid 930053] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzrwAAAMk"]
[Mon Jul 20 06:28:08.488033 2026] [security2:error] [pid 925208:tid 925385] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9yQAAAC8"]
[Mon Jul 20 06:28:08.531816 2026] [security2:error] [pid 925208:tid 925297] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "omenana.com"] [uri "/.env"] [unique_id "al4UWMRX7OrFkv0FyuI93AAAV1g"]
[Mon Jul 20 06:28:08.554695 2026] [security2:error] [pid 929851:tid 930101] [client 34.73.38.214:63240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UWGV3ou772CelrLhzyQAAAPk"]
[Mon Jul 20 06:28:08.575621 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9zwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.725362 2026] [security2:error] [pid 929851:tid 930027] [client 57.141.18.25:29206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzAwAAr3s"]
[Mon Jul 20 06:28:08.738386 2026] [security2:error] [pid 925208:tid 925323] [remote 130.51.180.8:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UWMRX7OrFkv0FyuI95gAAJnI"]
[Mon Jul 20 06:28:08.747120 2026] [security2:error] [pid 929851:tid 930004] [client 14.225.17.146:64124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhz0AAAAJg"], referer: http://nextlvlmarketingco.com/old
[Mon Jul 20 06:28:08.838420 2026] [security2:error] [pid 925208:tid 925452] [client 57.141.18.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9vwAAAHI"]
[Mon Jul 20 06:28:08.865009 2026] [security2:error] [pid 925208:tid 925281] [remote 20.173.88.122:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UWMRX7OrFkv0FyuI97AAAP0g"]
[Mon Jul 20 06:28:08.865162 2026] [security2:error] [pid 925208:tid 925401] [client 20.173.88.122:35016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UWMRX7OrFkv0FyuI97AAAP0g"]
[Mon Jul 20 06:28:08.906458 2026] [fcgid:warn] [pid 929851:tid 930007] (70014)End of file found: [client 91.230.168.151:48411] mod_fcgid: can't get data from http client
[Mon Jul 20 06:28:08.910681 2026] [security2:error] [pid 929851:tid 929940] [remote 160.187.68.132:34022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UWGV3ou772CelrLhz3QAAx1Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:08.940712 2026] [security2:error] [pid 925208:tid 925231] [remote 130.51.180.8:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UWMRX7OrFkv0FyuI98gAAShY"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:08.944024 2026] [security2:error] [pid 929851:tid 930084] [client 57.141.18.55:39694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzEwAA6Gw"]
[Mon Jul 20 06:28:09.143285 2026] [security2:error] [pid 929851:tid 930109] [client 14.225.17.146:57104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhz3wAAAQE"], referer: https://nwcarvingacademy.com/old
[Mon Jul 20 06:28:09.182733 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.33:53560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzIgAAzyc"]
[Mon Jul 20 06:28:09.207129 2026] [security2:error] [pid 929851:tid 930026] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzyAAAAK4"]
[Mon Jul 20 06:28:09.296179 2026] [security2:error] [pid 929851:tid 930038] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzywAAALo"]
[Mon Jul 20 06:28:09.303974 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:23069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UWcRX7OrFkv0FyuI-BAAAAB8"]
[Mon Jul 20 06:28:09.304088 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:23069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UWcRX7OrFkv0FyuI-BAAAAB8"]
[Mon Jul 20 06:28:09.313208 2026] [security2:error] [pid 929851:tid 929985] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzzgAAAIU"]
[Mon Jul 20 06:28:09.330208 2026] [security2:error] [pid 929851:tid 930053] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWWV3ou772CelrLhz6wAAAMk"]
[Mon Jul 20 06:28:09.345843 2026] [security2:error] [pid 925208:tid 925438] [client 34.73.38.214:62618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UWcRX7OrFkv0FyuI-CAAAAGQ"]
[Mon Jul 20 06:28:09.456019 2026] [security2:error] [pid 925208:tid 925368] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI93QAAAB4"]
[Mon Jul 20 06:28:09.508288 2026] [security2:error] [pid 925208:tid 925365] [client 158.173.89.95:54427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UWcRX7OrFkv0FyuI-EQAAABs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:09.662683 2026] [security2:error] [pid 929851:tid 929899] [remote 45.150.79.142:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UWWV3ou772CelrLh0CAAA5is"]
[Mon Jul 20 06:28:09.823302 2026] [security2:error] [pid 929851:tid 929898] [remote 45.150.79.142:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UWWV3ou772CelrLh0EgAAlCo"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:28:09.860025 2026] [security2:error] [pid 925208:tid 925417] [client 14.164.183.65:47910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4UWcRX7OrFkv0FyuI-FQAAAE8"]
[Mon Jul 20 06:28:09.950867 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWWV3ou772CelrLh0CwAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:10.007185 2026] [security2:error] [pid 925208:tid 925274] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "omenana.com"] [uri "/.env.local"] [unique_id "al4UWsRX7OrFkv0FyuI-HgAALUE"]
[Mon Jul 20 06:28:10.063288 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWmV3ou772CelrLh0GAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:10.063394 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWmV3ou772CelrLh0GAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:10.157409 2026] [security2:error] [pid 925208:tid 925432] [client 14.225.17.146:64039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI94wAAAF4"], referer: http://tntcatholic.com/old
[Mon Jul 20 06:28:10.373264 2026] [security2:error] [pid 929851:tid 930026] [client 198.13.214.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4UWmV3ou772CelrLh0GwAArlg"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91singularity-studio-escala-1-4-malenia/
[Mon Jul 20 06:28:10.520714 2026] [security2:error] [pid 929851:tid 930010] [client 51.158.58.168:57890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4UWmV3ou772CelrLh0NwAAAJ4"]
[Mon Jul 20 06:28:10.659916 2026] [security2:error] [pid 925208:tid 925461] [client 34.74.185.202:62873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UWsRX7OrFkv0FyuI-PwAAAHs"]
[Mon Jul 20 06:28:10.675663 2026] [security2:error] [pid 929851:tid 930112] [client 57.141.18.121:37380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UV2V3ou772CelrLhzdgABBA8"]
[Mon Jul 20 06:28:10.689033 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWmV3ou772CelrLh0MgAAAIY"]
[Mon Jul 20 06:28:10.698259 2026] [security2:error] [pid 925208:tid 925259] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.env.old"] [unique_id "al4UWsRX7OrFkv0FyuI-QQAAaTI"]
[Mon Jul 20 06:28:10.698265 2026] [security2:error] [pid 925208:tid 925245] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.env.backup"] [unique_id "al4UWsRX7OrFkv0FyuI-QgAAaSQ"]
[Mon Jul 20 06:28:10.698272 2026] [security2:error] [pid 925208:tid 925215] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.env.bak"] [unique_id "al4UWsRX7OrFkv0FyuI-QwAAaQY"]
[Mon Jul 20 06:28:10.700326 2026] [security2:error] [pid 925208:tid 925236] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/backend/.env"] [unique_id "al4UWsRX7OrFkv0FyuI-RQAAaRs"]
[Mon Jul 20 06:28:10.700450 2026] [security2:error] [pid 925208:tid 925270] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/api/.env"] [unique_id "al4UWsRX7OrFkv0FyuI-RgAAaT0"]
[Mon Jul 20 06:28:10.975771 2026] [security2:error] [pid 929851:tid 930078] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWmV3ou772CelrLh0PQAAAOI"]
[Mon Jul 20 06:28:11.062776 2026] [security2:error] [pid 925208:tid 925413] [client 57.141.18.109:54274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UV8RX7OrFkv0FyuI9pAAASzM"]
[Mon Jul 20 06:28:11.113183 2026] [security2:error] [pid 929851:tid 930024] [client 171.60.139.123:63148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UW2V3ou772CelrLh0SgAAAKw"]
[Mon Jul 20 06:28:11.113376 2026] [security2:error] [pid 929851:tid 930024] [client 171.60.139.123:63148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UW2V3ou772CelrLh0SgAAAKw"]
[Mon Jul 20 06:28:11.127347 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWsRX7OrFkv0FyuI-VgAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:11.276671 2026] [security2:error] [pid 929851:tid 930022] [client 34.73.38.214:62951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UW2V3ou772CelrLh0UAAAAKo"]
[Mon Jul 20 06:28:11.281999 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UW8RX7OrFkv0FyuI-YwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:11.282092 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UW8RX7OrFkv0FyuI-YwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:11.287579 2026] [security2:error] [pid 925208:tid 925251] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/config/.env"] [unique_id "al4UW8RX7OrFkv0FyuI-ZQAADio"]
[Mon Jul 20 06:28:11.547197 2026] [security2:error] [pid 925208:tid 925447] [client 34.74.185.202:60180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UW8RX7OrFkv0FyuI-cgAAAG0"]
[Mon Jul 20 06:28:11.589209 2026] [security2:error] [pid 925208:tid 925377] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UW8RX7OrFkv0FyuI-aAAAACc"]
[Mon Jul 20 06:28:12.097293 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXGV3ou772CelrLh0eAAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.097402 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXGV3ou772CelrLh0eAAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.154348 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:63375] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 218 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UXGV3ou772CelrLh0fgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.308369 2026] [security2:error] [pid 925208:tid 925419] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXMRX7OrFkv0FyuI-hAAAAFE"]
[Mon Jul 20 06:28:12.308968 2026] [security2:error] [pid 929851:tid 929973] [remote 72.167.132.114:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4UXGV3ou772CelrLh0jgAAyHU"]
[Mon Jul 20 06:28:12.329451 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:63433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXMRX7OrFkv0FyuI-kgAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.329585 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:63433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXMRX7OrFkv0FyuI-kgAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.442266 2026] [security2:error] [pid 925208:tid 925413] [client 103.141.108.143:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UXMRX7OrFkv0FyuI-mQAAAEs"]
[Mon Jul 20 06:28:12.442961 2026] [security2:error] [pid 925208:tid 925413] [client 103.141.108.143:54323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UXMRX7OrFkv0FyuI-mQAAAEs"]
[Mon Jul 20 06:28:12.466197 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:55485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UXGV3ou772CelrLh0lQAAAMU"]
[Mon Jul 20 06:28:12.466306 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:55485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UXGV3ou772CelrLh0lQAAAMU"]
[Mon Jul 20 06:28:12.514243 2026] [security2:error] [pid 929851:tid 929971] [remote 72.167.132.114:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4UXGV3ou772CelrLh0lgAA2nM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:28:12.694106 2026] [security2:error] [pid 929851:tid 930093] [client 104.234.53.73:34635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UXGV3ou772CelrLh0oAAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:13.014728 2026] [security2:error] [pid 929851:tid 930100] [client 39.48.81.23:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UXWV3ou772CelrLh0rQAAAPg"]
[Mon Jul 20 06:28:13.014891 2026] [security2:error] [pid 929851:tid 930100] [client 39.48.81.23:54374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UXWV3ou772CelrLh0rQAAAPg"]
[Mon Jul 20 06:28:13.256905 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-uQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:13.283290 2026] [security2:error] [pid 929851:tid 930089] [client 34.73.38.214:52187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UXWV3ou772CelrLh0ugAAAO0"]
[Mon Jul 20 06:28:13.308234 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXWV3ou772CelrLh0uwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:13.308340 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXWV3ou772CelrLh0uwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:13.328887 2026] [security2:error] [pid 929851:tid 930108] [client 14.225.17.146:54427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4UXWV3ou772CelrLh0tAAAAQA"], referer: http://myspineworld.com/old
[Mon Jul 20 06:28:13.348392 2026] [security2:error] [pid 929851:tid 930000] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXWV3ou772CelrLh0sgAAAJQ"]
[Mon Jul 20 06:28:13.349257 2026] [security2:error] [pid 925208:tid 925412] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-wwAAAEo"]
[Mon Jul 20 06:28:13.705529 2026] [security2:error] [pid 925208:tid 925340] [client 34.74.185.202:62176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UXcRX7OrFkv0FyuI-5gAAAAI"]
[Mon Jul 20 06:28:13.831801 2026] [security2:error] [pid 925208:tid 925358] [client 119.157.66.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4UXMRX7OrFkv0FyuI-mgAAABQ"]
[Mon Jul 20 06:28:13.843233 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:13.843270 2026] [proxy_http:error] [pid 925208:tid 925405] [client 205.210.31.23:62750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:13.843920 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:13.843950 2026] [proxy_http:error] [pid 925208:tid 925405] [client 205.210.31.23:62750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:13.910986 2026] [security2:error] [pid 925208:tid 925434] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northplating.com"] [uri "/.well-known/about.php"] [unique_id "al4UXcRX7OrFkv0FyuI-9AAAAGA"]
[Mon Jul 20 06:28:13.911071 2026] [security2:error] [pid 925208:tid 925434] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "northplating.com"] [uri "/.well-known/about.php"] [unique_id "al4UXcRX7OrFkv0FyuI-9AAAAGA"]
[Mon Jul 20 06:28:13.958429 2026] [security2:error] [pid 925208:tid 925351] [client 34.73.38.214:53385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UXcRX7OrFkv0FyuI-9gAAAA0"]
[Mon Jul 20 06:28:13.994456 2026] [security2:error] [pid 929851:tid 930061] [client 77.110.127.138:63397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 833 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UXWV3ou772CelrLh0xwAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.163224 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXmV3ou772CelrLh01AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.163311 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:63443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXmV3ou772CelrLh01AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.213381 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:63407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXsRX7OrFkv0FyuI-_AAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.213488 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:63407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXsRX7OrFkv0FyuI-_AAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.259902 2026] [security2:error] [pid 925208:tid 925252] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/.ssh/id_ed25519"] [unique_id "al4UXsRX7OrFkv0FyuI_BQAAECs"]
[Mon Jul 20 06:28:14.261455 2026] [security2:error] [pid 925208:tid 925228] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.ssh/id_rsa"] [unique_id "al4UXsRX7OrFkv0FyuI_AgAAEBM"]
[Mon Jul 20 06:28:14.285733 2026] [authz_core:error] [pid 929851:tid 929993] [client 34.24.141.69:0] AH01630: client denied by server configuration: /home1/omenanac/public_html/.htpasswd
[Mon Jul 20 06:28:14.291492 2026] [security2:error] [pid 925208:tid 925342] [client 57.141.18.5:43360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UWsRX7OrFkv0FyuI-WQAABCE"]
[Mon Jul 20 06:28:14.310528 2026] [security2:error] [pid 929851:tid 930093] [client 65.1.132.125:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UXmV3ou772CelrLh08QAAAPE"]
[Mon Jul 20 06:28:14.366310 2026] [security2:error] [pid 929851:tid 930010] [client 34.74.185.202:59857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UXmV3ou772CelrLh08wAAAJ4"]
[Mon Jul 20 06:28:14.394361 2026] [security2:error] [pid 925208:tid 925430] [client 14.225.17.146:49402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4UXsRX7OrFkv0FyuI-_QAAAFw"], referer: https://myspineworld.com/old
[Mon Jul 20 06:28:14.523487 2026] [security2:error] [pid 929851:tid 930104] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh06AAAAPw"]
[Mon Jul 20 06:28:14.523519 2026] [security2:error] [pid 929851:tid 930042] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh06QAAAL4"]
[Mon Jul 20 06:28:14.566924 2026] [security2:error] [pid 929851:tid 929985] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh06wAAAIU"]
[Mon Jul 20 06:28:14.593551 2026] [security2:error] [pid 929851:tid 930067] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh07AAAANc"]
[Mon Jul 20 06:28:14.630296 2026] [security2:error] [pid 929851:tid 930062] [client 104.234.53.81:42443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UXmV3ou772CelrLh0-AAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:14.886897 2026] [security2:error] [pid 929851:tid 930105] [client 14.225.17.146:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh03QAAAP0"]
[Mon Jul 20 06:28:15.075309 2026] [security2:error] [pid 929851:tid 930041] [client 171.61.165.146:15048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UX2V3ou772CelrLh1DgAAAL0"]
[Mon Jul 20 06:28:15.078006 2026] [security2:error] [pid 925208:tid 925336] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/id_dsa"] [unique_id "al4UX8RX7OrFkv0FyuI_LgAAH38"]
[Mon Jul 20 06:28:15.081657 2026] [security2:error] [pid 929851:tid 930041] [client 171.61.165.146:15048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UX2V3ou772CelrLh1DgAAAL0"]
[Mon Jul 20 06:28:15.171529 2026] [security2:error] [pid 929851:tid 930110] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh1CwAAAQI"]
[Mon Jul 20 06:28:15.200127 2026] [security2:error] [pid 925208:tid 925305] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/.ssh/known_hosts"] [unique_id "al4UX8RX7OrFkv0FyuI_NQAAFmA"]
[Mon Jul 20 06:28:15.201825 2026] [security2:error] [pid 925208:tid 925286] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/id_rsa"] [unique_id "al4UX8RX7OrFkv0FyuI_NwAAFk0"]
[Mon Jul 20 06:28:15.201825 2026] [security2:error] [pid 925208:tid 925260] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.ssh/id_dsa"] [unique_id "al4UX8RX7OrFkv0FyuI_NgAAFjM"]
[Mon Jul 20 06:28:15.278780 2026] [security2:error] [pid 929851:tid 930093] [client 13.201.64.214:27596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UX2V3ou772CelrLh1GwAAAPE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:28:15.439892 2026] [security2:error] [pid 929851:tid 930042] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1FgAAAL4"]
[Mon Jul 20 06:28:15.458256 2026] [security2:error] [pid 929851:tid 930104] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1FwAAAPw"]
[Mon Jul 20 06:28:15.460280 2026] [security2:error] [pid 929851:tid 930107] [client 34.73.38.214:64666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UX2V3ou772CelrLh1KwAAAP8"]
[Mon Jul 20 06:28:15.462194 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:15.462262 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:51425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:15.462706 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:15.462755 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:51425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:15.542711 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UX8RX7OrFkv0FyuI_QAAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:15.595185 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:63427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UX8RX7OrFkv0FyuI_SAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:15.595298 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:63427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UX8RX7OrFkv0FyuI_SAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:15.652250 2026] [security2:error] [pid 925208:tid 925452] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UX8RX7OrFkv0FyuI_RQAAAHI"]
[Mon Jul 20 06:28:15.671293 2026] [security2:error] [pid 929851:tid 930111] [client 34.74.185.202:60307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UX2V3ou772CelrLh1QAAAAQM"]
[Mon Jul 20 06:28:15.740672 2026] [security2:error] [pid 929851:tid 930060] [client 57.141.18.49:38542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXGV3ou772CelrLh0iwAA0G8"]
[Mon Jul 20 06:28:15.781895 2026] [security2:error] [pid 925208:tid 925351] [client 14.225.17.146:49852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4UX8RX7OrFkv0FyuI_PAAAAA0"]
[Mon Jul 20 06:28:15.865197 2026] [security2:error] [pid 929851:tid 930015] [client 14.225.17.146:65356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1RgAAAKM"], referer: http://lutheranphilosopher.com/old
[Mon Jul 20 06:28:16.022847 2026] [security2:error] [pid 925208:tid 925371] [client 57.141.18.124:39056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXMRX7OrFkv0FyuI-nAAAIXE"]
[Mon Jul 20 06:28:16.201996 2026] [security2:error] [pid 929851:tid 930104] [client 34.74.185.202:57955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UYGV3ou772CelrLh1WAAAAPw"]
[Mon Jul 20 06:28:16.220214 2026] [security2:error] [pid 925208:tid 925377] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_ZQAAACc"]
[Mon Jul 20 06:28:16.232554 2026] [security2:error] [pid 925208:tid 925415] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_ZAAAAE0"]
[Mon Jul 20 06:28:16.295285 2026] [security2:error] [pid 929851:tid 929985] [client 77.110.127.138:63375] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 511 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UYGV3ou772CelrLh1XQAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.386044 2026] [security2:error] [pid 929851:tid 930102] [client 37.140.192.175:45154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1TwAAAPo"]
[Mon Jul 20 06:28:16.647258 2026] [security2:error] [pid 929851:tid 929975] [remote 173.249.4.11:33965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4UYGV3ou772CelrLh1awAAjHc"]
[Mon Jul 20 06:28:16.696061 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYGV3ou772CelrLh1bwAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.696180 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:63455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYGV3ou772CelrLh1bwAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.740272 2026] [security2:error] [pid 925208:tid 925411] [client 57.141.18.59:45746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-zgAASTw"]
[Mon Jul 20 06:28:16.745801 2026] [security2:error] [pid 925208:tid 925363] [client 47.128.96.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_eAAAABk"]
[Mon Jul 20 06:28:16.767220 2026] [security2:error] [pid 929851:tid 930002] [client 98.159.234.160:20351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UYGV3ou772CelrLh1cAAAAJY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:16.926572 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYMRX7OrFkv0FyuI_jwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.926697 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYMRX7OrFkv0FyuI_jwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:17.055444 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.34:45874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-2gAAV0Y"]
[Mon Jul 20 06:28:17.186005 2026] [security2:error] [pid 925208:tid 925360] [client 14.225.17.146:65378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4UYcRX7OrFkv0FyuI_kgAAABY"], referer: http://ccsdifference.com/old
[Mon Jul 20 06:28:17.213136 2026] [security2:error] [pid 925208:tid 925313] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/privatekey.key"] [unique_id "al4UYcRX7OrFkv0FyuI_nwAAIWg"]
[Mon Jul 20 06:28:17.213136 2026] [security2:error] [pid 925208:tid 925307] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/key.pem"] [unique_id "al4UYcRX7OrFkv0FyuI_oAAAIWI"]
[Mon Jul 20 06:28:17.229544 2026] [security2:error] [pid 929851:tid 929862] [remote 173.249.4.11:33965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4UYWV3ou772CelrLh1hgAA5QY"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 06:28:17.341184 2026] [security2:error] [pid 929851:tid 929878] [remote 217.61.143.92:41500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1kwAA_xY"]
[Mon Jul 20 06:28:17.341339 2026] [security2:error] [pid 929851:tid 930107] [client 217.61.143.92:41500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1kwAA_xY"]
[Mon Jul 20 06:28:17.350827 2026] [security2:error] [pid 929851:tid 929989] [client 106.219.188.178:25948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1lQAAAIk"]
[Mon Jul 20 06:28:17.351002 2026] [security2:error] [pid 929851:tid 929989] [client 106.219.188.178:25948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1lQAAAIk"]
[Mon Jul 20 06:28:17.367588 2026] [security2:error] [pid 925208:tid 925422] [client 65.111.24.142:30929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UYcRX7OrFkv0FyuI_pwAAAFQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:17.448234 2026] [security2:error] [pid 925208:tid 925352] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYcRX7OrFkv0FyuI_ngAAAA4"]
[Mon Jul 20 06:28:17.462550 2026] [security2:error] [pid 929851:tid 930089] [client 34.74.185.202:57378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UYWV3ou772CelrLh1nAAAAO0"]
[Mon Jul 20 06:28:17.472308 2026] [security2:error] [pid 929851:tid 930082] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/public../.env"] [unique_id "al4UYWV3ou772CelrLh1nQAAAOY"], referer: https://duckduckgo.com/?q=05mxa
[Mon Jul 20 06:28:17.501637 2026] [security2:error] [pid 929851:tid 929997] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1igAAAJE"]
[Mon Jul 20 06:28:17.529498 2026] [security2:error] [pid 929851:tid 930105] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1iwAAAP0"]
[Mon Jul 20 06:28:17.547746 2026] [security2:error] [pid 929851:tid 930004] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1jAAAAJg"]
[Mon Jul 20 06:28:17.563019 2026] [security2:error] [pid 929851:tid 930054] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1jQAAAMo"]
[Mon Jul 20 06:28:17.653437 2026] [security2:error] [pid 929851:tid 929885] [remote 103.161.172.221:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UYWV3ou772CelrLh1oQAAsR0"]
[Mon Jul 20 06:28:17.767124 2026] [security2:error] [pid 929851:tid 930101] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/resources../.env"] [unique_id "al4UYWV3ou772CelrLh1rAAAAPk"], referer: https://www.facebook.com/
[Mon Jul 20 06:28:17.985807 2026] [security2:error] [pid 929851:tid 930090] [client 34.73.38.214:54381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UYWV3ou772CelrLh1ugAAAO4"]
[Mon Jul 20 06:28:18.021084 2026] [security2:error] [pid 929851:tid 929988] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4UYmV3ou772CelrLh1wAAAAIg"], referer: https://www.google.com/
[Mon Jul 20 06:28:18.027045 2026] [security2:error] [pid 929851:tid 930087] [client 45.3.52.99:51483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UYmV3ou772CelrLh1vQAAAOs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:18.049344 2026] [security2:error] [pid 929851:tid 929926] [remote 103.161.172.221:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UYmV3ou772CelrLh1xAAAkUY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:28:18.128276 2026] [security2:error] [pid 929851:tid 930031] [client 216.73.216.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.slutilities.com"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh1vwAAALM"], referer: http://www.slutilities.com/sitemap.xml
[Mon Jul 20 06:28:18.135953 2026] [proxy:error] [pid 929851:tid 930084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.136024 2026] [proxy_http:error] [pid 929851:tid 930084] [client 34.73.38.214:59959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:18.136595 2026] [proxy:error] [pid 929851:tid 930084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.136621 2026] [proxy_http:error] [pid 929851:tid 930084] [client 34.73.38.214:59959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:18.235699 2026] [security2:error] [pid 929851:tid 930042] [client 14.225.17.146:49266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh1wwAAAL4"], referer: https://ccsdifference.com/old
[Mon Jul 20 06:28:18.292440 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYmV3ou772CelrLh10QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:18.292553 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYmV3ou772CelrLh10QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:18.848743 2026] [security2:error] [pid 929851:tid 929996] [client 34.73.38.214:65352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UYmV3ou772CelrLh17gAAAJA"]
[Mon Jul 20 06:28:18.851298 2026] [proxy:error] [pid 929851:tid 930054] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.851381 2026] [proxy_http:error] [pid 929851:tid 930054] [client 34.73.38.214:52217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:18.852153 2026] [proxy:error] [pid 929851:tid 930054] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.852187 2026] [proxy_http:error] [pid 929851:tid 930054] [client 34.73.38.214:52217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:19.230927 2026] [security2:error] [pid 925208:tid 925272] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.openclaw/.env"] [unique_id "al4UY8RX7OrFkv0FyuI_5AAAUz8"]
[Mon Jul 20 06:28:19.432190 2026] [security2:error] [pid 925208:tid 925334] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.hermes/.env"] [unique_id "al4UY8RX7OrFkv0FyuI_7gAAUX0"]
[Mon Jul 20 06:28:19.444686 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:63478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:noamp"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UY2V3ou772CelrLh2IAAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.607338 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:63480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2JgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.607453 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:63480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2JgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.660010 2026] [security2:error] [pid 929851:tid 930068] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2EwAAANg"]
[Mon Jul 20 06:28:19.674206 2026] [security2:error] [pid 929851:tid 930076] [client 14.225.17.146:60074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2KAAAAOA"], referer: http://grndl.com/old
[Mon Jul 20 06:28:19.714451 2026] [security2:error] [pid 929851:tid 930058] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2IQAAAM4"]
[Mon Jul 20 06:28:19.714772 2026] [security2:error] [pid 929851:tid 930029] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2IgAAALE"]
[Mon Jul 20 06:28:19.735007 2026] [security2:error] [pid 929851:tid 930089] [client 50.116.65.227:44172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4UY2V3ou772CelrLh2LwAAAO0"]
[Mon Jul 20 06:28:19.738436 2026] [security2:error] [pid 929851:tid 930009] [client 14.225.17.146:50164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh11AAAAJ0"]
[Mon Jul 20 06:28:19.795032 2026] [security2:error] [pid 929851:tid 930090] [client 34.73.38.214:54940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UY2V3ou772CelrLh2MgAAAO4"]
[Mon Jul 20 06:28:19.813586 2026] [security2:error] [pid 929851:tid 929998] [client 223.185.13.213:18992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UY2V3ou772CelrLh2NAAAAJI"]
[Mon Jul 20 06:28:19.813689 2026] [security2:error] [pid 929851:tid 929998] [client 223.185.13.213:18992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UY2V3ou772CelrLh2NAAAAJI"]
[Mon Jul 20 06:28:19.820471 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2NQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.820556 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2NQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.891584 2026] [security2:error] [pid 925208:tid 925369] [client 57.141.18.8:48450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_bwAAHyc"]
[Mon Jul 20 06:28:19.930457 2026] [security2:error] [pid 925208:tid 925259] [remote 47.86.33.52:22500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4UY8RX7OrFkv0FyuI_9wAAETI"]
[Mon Jul 20 06:28:20.019417 2026] [security2:error] [pid 929851:tid 930061] [client 112.208.70.94:44366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UZGV3ou772CelrLh2RwAAANE"]
[Mon Jul 20 06:28:20.019605 2026] [security2:error] [pid 929851:tid 930061] [client 112.208.70.94:44366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UZGV3ou772CelrLh2RwAAANE"]
[Mon Jul 20 06:28:20.133764 2026] [security2:error] [pid 925208:tid 925389] [client 34.74.185.202:56801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UZMRX7OrFkv0FyuI__AAAADM"]
[Mon Jul 20 06:28:20.171783 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:20.171849 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:64254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:20.173187 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:20.173237 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:64254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:20.196733 2026] [security2:error] [pid 929851:tid 930064] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2QgAAANQ"]
[Mon Jul 20 06:28:20.198806 2026] [security2:error] [pid 929851:tid 930052] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2RQAAAMg"]
[Mon Jul 20 06:28:20.323171 2026] [security2:error] [pid 929851:tid 929948] [remote 220.181.108.178:12247] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UZGV3ou772CelrLh2WQAAjFw"]
[Mon Jul 20 06:28:20.328734 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZMRX7OrFkv0FyuJACQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:20.329030 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZMRX7OrFkv0FyuJACQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:20.454681 2026] [security2:error] [pid 929851:tid 930106] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UZGV3ou772CelrLh2UQAAAP4"]
[Mon Jul 20 06:28:20.527820 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.2:22030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYGV3ou772CelrLh1eQAAuSE"]
[Mon Jul 20 06:28:20.724793 2026] [security2:error] [pid 929851:tid 929896] [remote 78.46.157.202:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4UZGV3ou772CelrLh2dwAAnyg"]
[Mon Jul 20 06:28:20.755527 2026] [security2:error] [pid 929851:tid 930060] [client 216.73.216.123:5836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techexecutive.me"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2KQAA0A8"]
[Mon Jul 20 06:28:20.761603 2026] [security2:error] [pid 929851:tid 929983] [remote 47.86.33.52:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4UZGV3ou772CelrLh2eQAA238"]
[Mon Jul 20 06:28:20.807719 2026] [security2:error] [pid 925208:tid 925372] [client 57.141.18.26:47848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYcRX7OrFkv0FyuI_owAAImk"]
[Mon Jul 20 06:28:20.862883 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UZGV3ou772CelrLh2bgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:20.941933 2026] [security2:error] [pid 929851:tid 929945] [remote 78.46.157.202:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4UZGV3ou772CelrLh2fwAA1lk"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 06:28:21.107274 2026] [security2:error] [pid 925208:tid 925241] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omenana.com"] [uri "/graphql"] [unique_id "al4UZcRX7OrFkv0FyuJAKwAAeyA"]
[Mon Jul 20 06:28:21.159737 2026] [security2:error] [pid 925208:tid 925394] [client 34.74.185.202:56603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UZcRX7OrFkv0FyuJALgAAADg"]
[Mon Jul 20 06:28:21.160177 2026] [core:error] [pid 929851:tid 930110] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:21.160207 2026] [core:error] [pid 929851:tid 930110] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:21.265536 2026] [security2:error] [pid 929851:tid 930010] [client 34.73.38.214:57066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UZWV3ou772CelrLh2nwAAAJ4"]
[Mon Jul 20 06:28:21.388275 2026] [security2:error] [pid 929851:tid 929856] [remote 47.86.33.52:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4UZWV3ou772CelrLh2ogAAxgA"], referer: https://schuttfarms.com/wp-login.php
[Mon Jul 20 06:28:21.531170 2026] [security2:error] [pid 925208:tid 925335] [remote 81.173.115.7:43620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4UZcRX7OrFkv0FyuJAQAAARH4"]
[Mon Jul 20 06:28:21.726823 2026] [security2:error] [pid 925208:tid 925295] [remote 81.173.115.7:43620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4UZcRX7OrFkv0FyuJARAAAFVY"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:28:21.731373 2026] [security2:error] [pid 925208:tid 925381] [client 171.60.139.123:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UZcRX7OrFkv0FyuJARQAAACs"]
[Mon Jul 20 06:28:21.731489 2026] [security2:error] [pid 925208:tid 925381] [client 171.60.139.123:63660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UZcRX7OrFkv0FyuJARQAAACs"]
[Mon Jul 20 06:28:21.819274 2026] [security2:error] [pid 929851:tid 930008] [client 14.188.210.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4UZWV3ou772CelrLh2uAAAAJw"]
[Mon Jul 20 06:28:21.973782 2026] [security2:error] [pid 929851:tid 930095] [client 14.225.17.146:60084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2DwAAAPM"]
[Mon Jul 20 06:28:22.007192 2026] [security2:error] [pid 925208:tid 925422] [client 34.73.38.214:61452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UZsRX7OrFkv0FyuJASgAAAFQ"]
[Mon Jul 20 06:28:22.039939 2026] [security2:error] [pid 925208:tid 925420] [client 34.74.185.202:59056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UZsRX7OrFkv0FyuJATQAAAFI"]
[Mon Jul 20 06:28:22.241340 2026] [security2:error] [pid 925208:tid 925399] [client 77.110.127.138:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZsRX7OrFkv0FyuJAVgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:22.241474 2026] [security2:error] [pid 925208:tid 925399] [client 77.110.127.138:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZsRX7OrFkv0FyuJAVgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:22.250282 2026] [security2:error] [pid 929851:tid 930087] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env"] [unique_id "al4UZmV3ou772CelrLh20wAAAOs"], referer: https://www.facebook.com/
[Mon Jul 20 06:28:22.266240 2026] [security2:error] [pid 929851:tid 930096] [client 14.225.17.146:50164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4UZWV3ou772CelrLh2wgAAAPQ"], referer: http://www.justinagrayman.com/old
[Mon Jul 20 06:28:22.498562 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.118:33142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh18QAAlmw"]
[Mon Jul 20 06:28:22.776241 2026] [security2:error] [pid 925208:tid 925266] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omenana.com"] [uri "/api/graphql"] [unique_id "al4UZsRX7OrFkv0FyuJAZwAAbDk"]
[Mon Jul 20 06:28:22.818100 2026] [security2:error] [pid 929851:tid 929981] [remote 111.225.214.197:63434] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UZmV3ou772CelrLh29AABAH0"]
[Mon Jul 20 06:28:23.032583 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:49326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4UZmV3ou772CelrLh28wAAAO4"], referer: http://falconarrowshop.com/old
[Mon Jul 20 06:28:23.050481 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UZ2V3ou772CelrLh3BQAAAIs"]
[Mon Jul 20 06:28:23.105006 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3CwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.105128 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3CwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.137906 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:56011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3DQAAAPk"]
[Mon Jul 20 06:28:23.137988 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:56011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3DQAAAPk"]
[Mon Jul 20 06:28:23.152945 2026] [security2:error] [pid 929851:tid 930046] [client 57.141.18.8:57416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2JAAAwlg"]
[Mon Jul 20 06:28:23.167014 2026] [security2:error] [pid 929851:tid 930040] [client 103.141.108.143:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3EAAAALw"]
[Mon Jul 20 06:28:23.167643 2026] [security2:error] [pid 929851:tid 930040] [client 103.141.108.143:54806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3EAAAALw"]
[Mon Jul 20 06:28:23.267252 2026] [security2:error] [pid 929851:tid 929867] [remote 217.61.143.92:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UZ2V3ou772CelrLh3GAAA9Qs"]
[Mon Jul 20 06:28:23.411662 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3HQAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.411758 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3HQAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.512391 2026] [security2:error] [pid 929851:tid 929901] [remote 217.61.143.92:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UZ2V3ou772CelrLh3JAAAii0"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:28:23.558152 2026] [security2:error] [pid 929851:tid 929996] [client 40.77.167.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nyradigitalsolutions.com"] [uri "/index.php"] [unique_id "al4UZmV3ou772CelrLh23QAAkGo"]
[Mon Jul 20 06:28:23.572258 2026] [security2:error] [pid 925208:tid 925339] [client 103.153.183.69:59348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/ssh/sshd_config"] [unique_id "al4UZ8RX7OrFkv0FyuJAhAAAAAE"], referer: https://www.reddit.com/
[Mon Jul 20 06:28:23.573647 2026] [security2:error] [pid 925208:tid 925349] [client 34.24.141.69:39210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UZ8RX7OrFkv0FyuJAeQAAC2I"]
[Mon Jul 20 06:28:23.749507 2026] [security2:error] [pid 929851:tid 930101] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4UZ2V3ou772CelrLh3OQAAAPk"], referer: https://twitter.com/
[Mon Jul 20 06:28:23.756335 2026] [security2:error] [pid 929851:tid 930031] [client 216.73.217.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3NQAAALM"]
[Mon Jul 20 06:28:23.775015 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3LgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.775443 2026] [security2:error] [pid 929851:tid 929997] [client 14.225.17.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3NgAAAJE"], referer: http://daseighty.net/old
[Mon Jul 20 06:28:23.800471 2026] [security2:error] [pid 929851:tid 930060] [client 39.48.81.23:54852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3PQAAANA"]
[Mon Jul 20 06:28:23.800568 2026] [security2:error] [pid 929851:tid 930060] [client 39.48.81.23:54852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3PQAAANA"]
[Mon Jul 20 06:28:24.120000 2026] [security2:error] [pid 925208:tid 925407] [client 34.74.185.202:55124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UaMRX7OrFkv0FyuJAlwAAAEU"]
[Mon Jul 20 06:28:24.120148 2026] [security2:error] [pid 929851:tid 930085] [client 57.141.18.9:40202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZGV3ou772CelrLh2XgAA6U8"]
[Mon Jul 20 06:28:24.246158 2026] [security2:error] [pid 925208:tid 925294] [remote 173.249.4.11:14374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4UaMRX7OrFkv0FyuJAnAAAcVU"]
[Mon Jul 20 06:28:24.246326 2026] [security2:error] [pid 925208:tid 925451] [client 173.249.4.11:14374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4UaMRX7OrFkv0FyuJAnAAAcVU"]
[Mon Jul 20 06:28:24.255942 2026] [security2:error] [pid 929851:tid 930075] [client 34.73.38.214:49702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UaGV3ou772CelrLh3UgAAAN8"]
[Mon Jul 20 06:28:24.258294 2026] [security2:error] [pid 929851:tid 930026] [client 34.73.38.214:49775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UaGV3ou772CelrLh3VAAAAK4"]
[Mon Jul 20 06:28:24.324964 2026] [security2:error] [pid 925208:tid 925439] [client 57.141.18.52:57226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZMRX7OrFkv0FyuJAGgAAZSY"]
[Mon Jul 20 06:28:24.354756 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaGV3ou772CelrLh3WwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:24.354841 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaGV3ou772CelrLh3WwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:24.426988 2026] [security2:error] [pid 929851:tid 929937] [remote 111.225.214.164:49451] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UaGV3ou772CelrLh3YAAAsFE"]
[Mon Jul 20 06:28:24.550411 2026] [security2:error] [pid 925208:tid 925277] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omenana.com"] [uri "/v1/graphql"] [unique_id "al4UaMRX7OrFkv0FyuJApQAAVUQ"]
[Mon Jul 20 06:28:24.773076 2026] [security2:error] [pid 925208:tid 925378] [client 34.74.185.202:53630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UaMRX7OrFkv0FyuJAqAAAACg"]
[Mon Jul 20 06:28:25.036227 2026] [security2:error] [pid 929851:tid 930078] [client 34.73.38.214:50642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UaWV3ou772CelrLh3hAAAAOI"]
[Mon Jul 20 06:28:25.046517 2026] [security2:error] [pid 929851:tid 930087] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env"] [unique_id "al4UaWV3ou772CelrLh3hgAAAOs"], referer: https://duckduckgo.com/?q=12m6t
[Mon Jul 20 06:28:25.070160 2026] [security2:error] [pid 929851:tid 930048] [client 34.73.38.214:61593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UaWV3ou772CelrLh3iQAAAMQ"]
[Mon Jul 20 06:28:25.119808 2026] [security2:error] [pid 929851:tid 930010] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4UaWV3ou772CelrLh3jQAAAJ4"], referer: https://t.co/2r7sg09vqt
[Mon Jul 20 06:28:25.337848 2026] [security2:error] [pid 929851:tid 930101] [client 34.74.185.202:59055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UaWV3ou772CelrLh3lwAAAPk"]
[Mon Jul 20 06:28:25.367595 2026] [security2:error] [pid 929851:tid 929998] [client 50.116.65.227:30680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UaWV3ou772CelrLh3mwAAAJI"]
[Mon Jul 20 06:28:25.378623 2026] [security2:error] [pid 925208:tid 925342] [client 50.116.65.227:30690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UacRX7OrFkv0FyuJAuwAAAAQ"]
[Mon Jul 20 06:28:25.543975 2026] [security2:error] [pid 925208:tid 925408] [client 14.225.17.146:53705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4UacRX7OrFkv0FyuJAtgAAAEY"], referer: http://adastra.love/old
[Mon Jul 20 06:28:25.671575 2026] [security2:error] [pid 925208:tid 925324] [remote 45.90.123.233:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4UacRX7OrFkv0FyuJAvgAAMXM"]
[Mon Jul 20 06:28:25.691713 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaWV3ou772CelrLh3qAAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:25.691839 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaWV3ou772CelrLh3qAAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:26.107130 2026] [security2:error] [pid 929851:tid 930096] [client 171.61.165.146:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh3wAAAAPQ"]
[Mon Jul 20 06:28:26.107237 2026] [security2:error] [pid 929851:tid 930096] [client 171.61.165.146:26594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh3wAAAAPQ"]
[Mon Jul 20 06:28:26.306966 2026] [security2:error] [pid 929851:tid 930008] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.llr.lqn.mybluehost.me"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3vgAAAJw"]
[Mon Jul 20 06:28:26.319385 2026] [security2:error] [pid 929851:tid 930058] [client 34.73.38.214:57601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UamV3ou772CelrLh3zwAAAM4"]
[Mon Jul 20 06:28:26.343715 2026] [security2:error] [pid 929851:tid 930110] [client 57.141.18.59:62908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZmV3ou772CelrLh27gABAl8"]
[Mon Jul 20 06:28:26.368891 2026] [security2:error] [pid 929851:tid 929971] [remote 60.205.8.163:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.8.205.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh30wAA7XM"]
[Mon Jul 20 06:28:26.369146 2026] [security2:error] [pid 929851:tid 930089] [client 60.205.8.163:33486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh30wAA7XM"]
[Mon Jul 20 06:28:26.384794 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UasRX7OrFkv0FyuJAzQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:26.384909 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:63526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UasRX7OrFkv0FyuJAzQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:26.704249 2026] [security2:error] [pid 925208:tid 925252] [remote 45.90.123.233:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4UasRX7OrFkv0FyuJA1QAAOSs"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:28:26.765618 2026] [security2:error] [pid 929851:tid 929915] [remote 173.249.4.11:21034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UamV3ou772CelrLh37QAAmjs"]
[Mon Jul 20 06:28:26.785527 2026] [security2:error] [pid 929851:tid 930061] [client 34.73.38.214:62472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UamV3ou772CelrLh38QAAANE"]
[Mon Jul 20 06:28:27.207860 2026] [security2:error] [pid 929851:tid 930007] [client 14.225.17.146:53553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4UaWV3ou772CelrLh3pwAAAJs"], referer: http://careysheatingandcooling.com/old
[Mon Jul 20 06:28:27.251888 2026] [security2:error] [pid 929851:tid 929986] [client 14.225.17.146:58790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3xAAAAIY"], referer: http://ncsynchro.com/old
[Mon Jul 20 06:28:27.309610 2026] [security2:error] [pid 929851:tid 930064] [client 57.141.18.24:42580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3OAAA1Dw"]
[Mon Jul 20 06:28:27.425947 2026] [security2:error] [pid 929851:tid 929893] [remote 173.249.4.11:21034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Ua2V3ou772CelrLh4IQAA0SU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:27.683567 2026] [security2:error] [pid 929851:tid 930056] [client 34.73.38.214:59868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Ua2V3ou772CelrLh4LwAAAMw"]
[Mon Jul 20 06:28:27.746400 2026] [security2:error] [pid 929851:tid 930051] [client 65.111.23.116:33011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Ua2V3ou772CelrLh4MgAAAMc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:27.866219 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.30:30900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UaGV3ou772CelrLh3WAAAzRg"]
[Mon Jul 20 06:28:27.934642 2026] [security2:error] [pid 929851:tid 930010] [client 104.234.53.64:36565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ua2V3ou772CelrLh4PwAAAJ4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:28.046842 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.109:31254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UaGV3ou772CelrLh3YwAA2CQ"]
[Mon Jul 20 06:28:28.095782 2026] [security2:error] [pid 929851:tid 930024] [client 74.208.214.194:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UbGV3ou772CelrLh4RwAAAKw"]
[Mon Jul 20 06:28:28.190670 2026] [security2:error] [pid 929851:tid 930008] [client 14.225.17.146:60241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4QwAAAJw"], referer: http://backandneckpainrelieflaceychiropractor.com/old
[Mon Jul 20 06:28:28.198208 2026] [security2:error] [pid 929851:tid 930070] [client 57.141.18.91:54212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UaGV3ou772CelrLh3dgAA2j8"]
[Mon Jul 20 06:28:28.393273 2026] [security2:error] [pid 925208:tid 925363] [client 103.153.183.69:59348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../root/.ssh/id_rsa"] [unique_id "al4UbMRX7OrFkv0FyuJBBAAAABk"], referer: https://www.facebook.com/
[Mon Jul 20 06:28:28.501874 2026] [security2:error] [pid 929851:tid 930063] [client 34.73.38.214:59691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UbGV3ou772CelrLh4WwAAANM"]
[Mon Jul 20 06:28:28.515793 2026] [security2:error] [pid 929851:tid 930014] [client 106.219.188.178:25941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UbGV3ou772CelrLh4XQAAAKI"]
[Mon Jul 20 06:28:28.517376 2026] [security2:error] [pid 929851:tid 930014] [client 106.219.188.178:25941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UbGV3ou772CelrLh4XQAAAKI"]
[Mon Jul 20 06:28:28.518344 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4VQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:29.138781 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbWV3ou772CelrLh4egAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:29.138872 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:63551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbWV3ou772CelrLh4egAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:29.285741 2026] [security2:error] [pid 929851:tid 929994] [client 14.225.17.146:52931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4VgAAAI4"]
[Mon Jul 20 06:28:29.426538 2026] [ssl:error] [pid 925208:tid 925416] [client 104.48.69.105:37972] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:28:29.456852 2026] [security2:error] [pid 929851:tid 930013] [client 57.141.18.31:57758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3uwAAoUg"]
[Mon Jul 20 06:28:29.659293 2026] [security2:error] [pid 925208:tid 925397] [client 57.141.18.37:25902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UasRX7OrFkv0FyuJAygAAOwk"]
[Mon Jul 20 06:28:29.765060 2026] [security2:error] [pid 925208:tid 925390] [client 14.225.17.146:65120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4Ua8RX7OrFkv0FyuJA6gAAADQ"], referer: http://younutrition.gr/old
[Mon Jul 20 06:28:29.961385 2026] [proxy:error] [pid 929851:tid 930102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:29.961440 2026] [proxy_http:error] [pid 929851:tid 930102] [client 34.73.38.214:65458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:29.961994 2026] [proxy:error] [pid 929851:tid 930102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:29.962020 2026] [proxy_http:error] [pid 929851:tid 930102] [client 34.73.38.214:65458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.028652 2026] [proxy:error] [pid 925208:tid 925365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.028735 2026] [proxy_http:error] [pid 925208:tid 925365] [client 34.73.38.214:49195] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.029358 2026] [proxy:error] [pid 925208:tid 925365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.029389 2026] [proxy_http:error] [pid 925208:tid 925365] [client 34.73.38.214:49195] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.296695 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.55:32964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3-wAAzwA"]
[Mon Jul 20 06:28:30.450068 2026] [proxy:error] [pid 929851:tid 930050] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.450131 2026] [proxy_http:error] [pid 929851:tid 930050] [client 34.73.38.214:62881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.450572 2026] [proxy:error] [pid 929851:tid 930050] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.450601 2026] [proxy_http:error] [pid 929851:tid 930050] [client 34.73.38.214:62881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.551298 2026] [security2:error] [pid 929851:tid 930013] [client 50.116.65.227:37266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4UbmV3ou772CelrLh4wAAAAKE"]
[Mon Jul 20 06:28:30.556406 2026] [security2:error] [pid 929851:tid 930087] [client 223.185.13.213:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UbmV3ou772CelrLh4wQAAAOs"]
[Mon Jul 20 06:28:30.556516 2026] [security2:error] [pid 929851:tid 930087] [client 223.185.13.213:28863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UbmV3ou772CelrLh4wQAAAOs"]
[Mon Jul 20 06:28:30.566658 2026] [security2:error] [pid 929851:tid 930081] [client 50.116.65.227:19982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4UbmV3ou772CelrLh4wgAAAOU"]
[Mon Jul 20 06:28:30.795804 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbmV3ou772CelrLh4ywAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:30.795949 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:63559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbmV3ou772CelrLh4ywAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:30.958670 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:63560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UbsRX7OrFkv0FyuJBVgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.149182 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.80:28656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ua2V3ou772CelrLh4MQAAwXQ"]
[Mon Jul 20 06:28:31.210544 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:63563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh44gAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.210650 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:63563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh44gAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.406168 2026] [proxy:error] [pid 925208:tid 925411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.406229 2026] [proxy_http:error] [pid 925208:tid 925411] [client 34.73.38.214:59808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.406640 2026] [proxy:error] [pid 925208:tid 925411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.406664 2026] [proxy_http:error] [pid 925208:tid 925411] [client 34.73.38.214:59808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.484666 2026] [core:error] [pid 925208:tid 925367] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:31.484686 2026] [core:error] [pid 925208:tid 925367] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:31.485681 2026] [security2:error] [pid 925208:tid 925280] [remote 47.86.33.52:39380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBawAAOUc"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:28:31.529162 2026] [proxy:error] [pid 929851:tid 930013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.529234 2026] [proxy_http:error] [pid 929851:tid 930013] [client 34.73.38.214:63897] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.529764 2026] [proxy:error] [pid 929851:tid 930013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.529789 2026] [proxy_http:error] [pid 929851:tid 930013] [client 34.73.38.214:63897] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.603048 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBdAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.603164 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBdAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.618701 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh48gAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.618819 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh48gAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.850087 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh5AgAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.850236 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh5AgAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.917840 2026] [security2:error] [pid 929851:tid 930084] [client 57.141.18.18:34242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4YAAA6C8"]
[Mon Jul 20 06:28:31.987341 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ub2V3ou772CelrLh4_AAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:32.007639 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5CgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:32.007735 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5CgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:32.012660 2026] [security2:error] [pid 929851:tid 930063] [client 104.234.53.68:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UcGV3ou772CelrLh5CQAAANM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:32.082935 2026] [security2:error] [pid 929851:tid 930067] [client 116.179.33.206:63990] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UcGV3ou772CelrLh5DwAAANc"]
[Mon Jul 20 06:28:32.122709 2026] [security2:error] [pid 925208:tid 925392] [client 57.141.18.124:47200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbMRX7OrFkv0FyuJBEQAANkM"]
[Mon Jul 20 06:28:32.175958 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5GQAAAOM"]
[Mon Jul 20 06:28:32.176100 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5GQAAAOM"]
[Mon Jul 20 06:28:32.291692 2026] [security2:error] [pid 929851:tid 930071] [client 34.73.38.214:51691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UcGV3ou772CelrLh5IwAAANs"]
[Mon Jul 20 06:28:32.294559 2026] [security2:error] [pid 925208:tid 925359] [client 171.60.139.123:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UcMRX7OrFkv0FyuJBjgAAABU"]
[Mon Jul 20 06:28:32.294646 2026] [security2:error] [pid 925208:tid 925359] [client 171.60.139.123:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UcMRX7OrFkv0FyuJBjgAAABU"]
[Mon Jul 20 06:28:32.299995 2026] [proxy:error] [pid 929851:tid 930037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:32.300070 2026] [proxy_http:error] [pid 929851:tid 930037] [client 34.73.38.214:53121] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:32.300704 2026] [proxy:error] [pid 929851:tid 930037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:32.300739 2026] [proxy_http:error] [pid 929851:tid 930037] [client 34.73.38.214:53121] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:32.358888 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5KwAAAMs"]
[Mon Jul 20 06:28:32.359007 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5KwAAAMs"]
[Mon Jul 20 06:28:32.396948 2026] [security2:error] [pid 925208:tid 925346] [client 57.141.18.120:35180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbcRX7OrFkv0FyuJBGgAACB4"]
[Mon Jul 20 06:28:32.664207 2026] [security2:error] [pid 929851:tid 930104] [client 57.141.18.72:22122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbWV3ou772CelrLh4iwAA_Eo"]
[Mon Jul 20 06:28:32.815966 2026] [security2:error] [pid 925208:tid 925432] [client 57.141.18.114:33346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbcRX7OrFkv0FyuJBMQAAXjM"]
[Mon Jul 20 06:28:33.119667 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:44752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5XgAAAM8"]
[Mon Jul 20 06:28:33.119780 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:44752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5XgAAAM8"]
[Mon Jul 20 06:28:33.177869 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UccRX7OrFkv0FyuJBqQAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.177960 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UccRX7OrFkv0FyuJBqQAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.271110 2026] [proxy:error] [pid 925208:tid 925438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.271151 2026] [security2:error] [pid 929851:tid 930078] [client 34.73.38.214:63092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UcWV3ou772CelrLh5ZgAAAOI"]
[Mon Jul 20 06:28:33.271185 2026] [proxy_http:error] [pid 925208:tid 925438] [client 34.73.38.214:62941] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.271724 2026] [proxy:error] [pid 925208:tid 925438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.271768 2026] [proxy_http:error] [pid 925208:tid 925438] [client 34.73.38.214:62941] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.274614 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.274664 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:63191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.275094 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.275119 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:63191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.334578 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5bgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.334660 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:63588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5bgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.484597 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5gAAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.484694 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5gAAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.542077 2026] [proxy:error] [pid 925208:tid 925422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.542139 2026] [proxy_http:error] [pid 925208:tid 925422] [client 34.73.38.214:61182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.542779 2026] [proxy:error] [pid 925208:tid 925422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.542822 2026] [proxy_http:error] [pid 925208:tid 925422] [client 34.73.38.214:61182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.672704 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5kAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.672813 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5kAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.819713 2026] [security2:error] [pid 929851:tid 930108] [client 45.116.69.230:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5nAAAAQA"]
[Mon Jul 20 06:28:33.819846 2026] [security2:error] [pid 929851:tid 930108] [client 45.116.69.230:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5nAAAAQA"]
[Mon Jul 20 06:28:33.871298 2026] [security2:error] [pid 929851:tid 930020] [client 14.225.17.146:65126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5kQAAAKg"], referer: http://nurturemarple.co.uk/old
[Mon Jul 20 06:28:33.874027 2026] [security2:error] [pid 929851:tid 930007] [client 34.73.38.214:63337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UcWV3ou772CelrLh5owAAAJs"]
[Mon Jul 20 06:28:33.884635 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5pQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.884729 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5pQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.896627 2026] [security2:error] [pid 929851:tid 930022] [client 103.141.108.143:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5pwAAAKo"]
[Mon Jul 20 06:28:33.896726 2026] [security2:error] [pid 929851:tid 930022] [client 103.141.108.143:55279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5pwAAAKo"]
[Mon Jul 20 06:28:34.035513 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5sQAAAOo"]
[Mon Jul 20 06:28:34.035608 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:63594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5sQAAAOo"]
[Mon Jul 20 06:28:34.065841 2026] [security2:error] [pid 929851:tid 930052] [client 114.119.135.251:24313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aosta.nz"] [uri "/quality_auto/36a582_27c4844a2e464a7daa0e8da9b2905fa1~mv2.png"] [unique_id "al4UcmV3ou772CelrLh5tAAAAMg"], referer: https://www.aosta.nz/quality_auto/36a582_27c4844a2e464a7daa0e8da9b2905fa1~mv2.png
[Mon Jul 20 06:28:34.149853 2026] [security2:error] [pid 925208:tid 925355] [client 75.155.66.71:41056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UccRX7OrFkv0FyuJBxwAAABE"]
[Mon Jul 20 06:28:34.194116 2026] [security2:error] [pid 929851:tid 930015] [client 114.119.152.108:58353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/layering-lockets-with-the-chain-extender/locketsandcharms.origamiowl.com"] [unique_id "al4UcmV3ou772CelrLh5vAAAAKM"], referer: https://locketsandcharms.com/layering-lockets-with-the-chain-extender/
[Mon Jul 20 06:28:34.214396 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5vwAAAL8"]
[Mon Jul 20 06:28:34.214522 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5vwAAAL8"]
[Mon Jul 20 06:28:34.220970 2026] [security2:error] [pid 929851:tid 930065] [client 50.116.65.227:20004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5rAAAANU"]
[Mon Jul 20 06:28:34.257888 2026] [security2:error] [pid 929851:tid 929999] [client 14.225.17.146:61106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4UcmV3ou772CelrLh5uAAAAJM"], referer: http://collectingrealestate.com/old
[Mon Jul 20 06:28:34.294530 2026] [security2:error] [pid 925208:tid 925423] [client 57.141.18.104:24414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBYQAAVXc"]
[Mon Jul 20 06:28:34.308816 2026] [proxy:error] [pid 925208:tid 925372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.308900 2026] [proxy_http:error] [pid 925208:tid 925372] [client 34.73.38.214:61320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.309735 2026] [proxy:error] [pid 925208:tid 925372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.309787 2026] [proxy_http:error] [pid 925208:tid 925372] [client 34.73.38.214:61320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.315677 2026] [proxy:error] [pid 929851:tid 930010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.315771 2026] [proxy_http:error] [pid 929851:tid 930010] [client 34.73.38.214:61407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.316652 2026] [proxy:error] [pid 929851:tid 930010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.316703 2026] [proxy_http:error] [pid 929851:tid 930010] [client 34.73.38.214:61407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.461972 2026] [security2:error] [pid 929851:tid 930096] [client 50.116.65.227:20024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UcmV3ou772CelrLh5wAAAAPQ"]
[Mon Jul 20 06:28:34.633282 2026] [security2:error] [pid 929851:tid 929986] [client 14.224.227.113:58457] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4UcmV3ou772CelrLh52QAAAIY"]
[Mon Jul 20 06:28:34.679862 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:63603] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UcmV3ou772CelrLh53gAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:34.699963 2026] [security2:error] [pid 925208:tid 925388] [client 114.119.133.245:34899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asliceofleadership.com"] [uri "/upsurgecommunications/"] [unique_id "al4UcsRX7OrFkv0FyuJB4QAAADI"], referer: https://asliceofleadership.com/
[Mon Jul 20 06:28:34.731432 2026] [proxy:error] [pid 929851:tid 930041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.731506 2026] [proxy_http:error] [pid 929851:tid 930041] [client 34.73.38.214:53582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.732318 2026] [proxy:error] [pid 929851:tid 930041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.732351 2026] [proxy_http:error] [pid 929851:tid 930041] [client 34.73.38.214:53582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.833227 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:63604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh55AAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:34.833338 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:63604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh55AAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:34.837181 2026] [security2:error] [pid 929851:tid 930074] [client 57.141.18.102:25792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ub2V3ou772CelrLh5BgAA3kc"]
[Mon Jul 20 06:28:34.905117 2026] [security2:error] [pid 929851:tid 930089] [client 39.48.81.23:55357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UcmV3ou772CelrLh56wAAAO0"]
[Mon Jul 20 06:28:34.905225 2026] [security2:error] [pid 929851:tid 930089] [client 39.48.81.23:55357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UcmV3ou772CelrLh56wAAAO0"]
[Mon Jul 20 06:28:35.097956 2026] [core:error] [pid 925208:tid 925434] [client 198.235.24.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:35.097994 2026] [core:error] [pid 925208:tid 925434] [client 198.235.24.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:35.241926 2026] [security2:error] [pid 929851:tid 930070] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh58gAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.262376 2026] [security2:error] [pid 929851:tid 930025] [client 34.73.38.214:54872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6BQAAAK0"]
[Mon Jul 20 06:28:35.263194 2026] [security2:error] [pid 925208:tid 925441] [client 34.73.38.214:61560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc8RX7OrFkv0FyuJB8QAAAGc"]
[Mon Jul 20 06:28:35.271630 2026] [security2:error] [pid 929851:tid 930018] [client 34.73.38.214:55026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6BgAAAKY"]
[Mon Jul 20 06:28:35.346468 2026] [security2:error] [pid 929851:tid 930046] [client 74.7.227.179:59682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6AAAAwh4"], referer: https://tejasenvironmental.com/p=3228
[Mon Jul 20 06:28:35.370115 2026] [security2:error] [pid 925208:tid 925415] [client 45.157.112.60:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Uc8RX7OrFkv0FyuJB9AAAAE0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:35.395142 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uc2V3ou772CelrLh6DgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.395238 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uc2V3ou772CelrLh6DgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.599327 2026] [security2:error] [pid 929851:tid 930001] [client 14.225.17.146:61234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6FwAAAJU"], referer: https://nurturemarple.co.uk/old
[Mon Jul 20 06:28:35.700264 2026] [security2:error] [pid 925208:tid 925435] [client 104.234.53.48:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Uc8RX7OrFkv0FyuJCAgAAAGE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:35.701477 2026] [security2:error] [pid 929851:tid 930097] [client 57.141.18.32:23210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcGV3ou772CelrLh5UAAA9Ts"]
[Mon Jul 20 06:28:35.716591 2026] [security2:error] [pid 925208:tid 925221] [remote 47.86.33.52:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4Uc8RX7OrFkv0FyuJCAwAAFgw"]
[Mon Jul 20 06:28:35.807091 2026] [security2:error] [pid 925208:tid 925347] [client 34.73.38.214:56739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc8RX7OrFkv0FyuJCCAAAAAk"]
[Mon Jul 20 06:28:35.808099 2026] [security2:error] [pid 929851:tid 930034] [client 34.73.38.214:65184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6NQAAALY"]
[Mon Jul 20 06:28:35.815290 2026] [security2:error] [pid 929851:tid 930096] [client 34.73.38.214:59759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6NgAAAPQ"]
[Mon Jul 20 06:28:35.852274 2026] [security2:error] [pid 929851:tid 930092] [client 8.215.94.139:49519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6OAAAAPA"]
[Mon Jul 20 06:28:35.907607 2026] [security2:error] [pid 925208:tid 925400] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uc8RX7OrFkv0FyuJCAQAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.969492 2026] [security2:error] [pid 929851:tid 930050] [client 57.141.18.119:49480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5XAAAxnA"]
[Mon Jul 20 06:28:36.258000 2026] [security2:error] [pid 929851:tid 930097] [client 34.73.38.214:60074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6VwAAAPU"]
[Mon Jul 20 06:28:36.280013 2026] [security2:error] [pid 929851:tid 930087] [client 8.215.94.139:49527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6WAAAAOs"]
[Mon Jul 20 06:28:36.304027 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6TQAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.480310 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdGV3ou772CelrLh6YgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.480403 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdGV3ou772CelrLh6YgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.519873 2026] [security2:error] [pid 929851:tid 929868] [remote 192.241.143.148:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UdGV3ou772CelrLh6aAAAzgw"]
[Mon Jul 20 06:28:36.567740 2026] [security2:error] [pid 929851:tid 930112] [client 14.225.17.146:64948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6YAAAAQQ"], referer: http://detroitcsc.com/old
[Mon Jul 20 06:28:36.574827 2026] [security2:error] [pid 929851:tid 930025] [client 34.73.38.214:59730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6bAAAAK0"]
[Mon Jul 20 06:28:36.574880 2026] [security2:error] [pid 929851:tid 930069] [client 34.73.38.214:63183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6bQAAANk"]
[Mon Jul 20 06:28:36.629508 2026] [security2:error] [pid 929851:tid 930072] [client 57.141.18.124:47242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5jAAA3CQ"]
[Mon Jul 20 06:28:36.683076 2026] [security2:error] [pid 925208:tid 925344] [client 8.215.94.139:49537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdMRX7OrFkv0FyuJCIwAAAAY"]
[Mon Jul 20 06:28:36.689133 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6ZgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.703423 2026] [security2:error] [pid 929851:tid 929953] [remote 192.241.143.148:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UdGV3ou772CelrLh6dAAA-GE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:36.741743 2026] [security2:error] [pid 929851:tid 930057] [client 34.73.38.214:64406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6dgAAAM0"]
[Mon Jul 20 06:28:36.990807 2026] [ssl:error] [pid 925208:tid 925370] [client 104.48.69.105:37974] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:28:37.014909 2026] [security2:error] [pid 925208:tid 925422] [client 34.73.38.214:59667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UdcRX7OrFkv0FyuJCLgAAAFQ"]
[Mon Jul 20 06:28:37.031728 2026] [security2:error] [pid 929851:tid 930102] [client 34.73.38.214:59389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UdWV3ou772CelrLh6kgAAAPo"]
[Mon Jul 20 06:28:37.046906 2026] [security2:error] [pid 925208:tid 925357] [client 171.61.165.146:18663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UdcRX7OrFkv0FyuJCLwAAABM"]
[Mon Jul 20 06:28:37.047034 2026] [security2:error] [pid 925208:tid 925357] [client 171.61.165.146:18663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UdcRX7OrFkv0FyuJCLwAAABM"]
[Mon Jul 20 06:28:37.050968 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6hgAAAI8"]
[Mon Jul 20 06:28:37.100040 2026] [security2:error] [pid 925208:tid 925448] [client 8.215.94.139:49546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdcRX7OrFkv0FyuJCMwAAAG4"]
[Mon Jul 20 06:28:37.154581 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:63624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UdWV3ou772CelrLh6nAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.253983 2026] [security2:error] [pid 929851:tid 929986] [client 14.225.17.146:52494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6WQAAAIY"], referer: http://retzkolonglogistics.com/old
[Mon Jul 20 06:28:37.323992 2026] [security2:error] [pid 929851:tid 930016] [client 77.110.127.138:63627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UdWV3ou772CelrLh6rQAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.343143 2026] [security2:error] [pid 925208:tid 925242] [remote 47.86.33.52:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4UdcRX7OrFkv0FyuJCOQAATSE"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:28:37.346764 2026] [security2:error] [pid 925208:tid 925429] [client 158.173.166.181:25489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UdcRX7OrFkv0FyuJCOgAAAFs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:37.351566 2026] [security2:error] [pid 929851:tid 930054] [client 57.141.18.122:29144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcmV3ou772CelrLh5xwAAyg4"]
[Mon Jul 20 06:28:37.474909 2026] [security2:error] [pid 929851:tid 930006] [client 14.225.17.146:51868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh6qgAAAJo"], referer: http://koaconsultants.com/old
[Mon Jul 20 06:28:37.480729 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6uQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.480883 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6uQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.485288 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh6pwAAAKA"]
[Mon Jul 20 06:28:37.515315 2026] [security2:error] [pid 929851:tid 930065] [client 8.215.94.139:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh6uwAAANU"]
[Mon Jul 20 06:28:37.601627 2026] [security2:error] [pid 929851:tid 930110] [client 34.73.38.214:50274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UdWV3ou772CelrLh6wAAAAQI"]
[Mon Jul 20 06:28:37.630534 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xAAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.630626 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xAAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.634189 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.634289 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.685019 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6ywAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.685164 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6ywAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.757666 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60AAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.757776 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:63606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60AAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.789984 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60gAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.790097 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60gAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.894403 2026] [security2:error] [pid 925208:tid 925355] [client 34.73.38.214:64512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UdcRX7OrFkv0FyuJCRgAAABE"]
[Mon Jul 20 06:28:37.896304 2026] [security2:error] [pid 925208:tid 925457] [client 34.73.38.214:52034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UdcRX7OrFkv0FyuJCRwAAAHc"]
[Mon Jul 20 06:28:37.908871 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh63QAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.908966 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh63QAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.922450 2026] [security2:error] [pid 929851:tid 930005] [client 8.215.94.139:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh63wAAAJk"]
[Mon Jul 20 06:28:37.941286 2026] [security2:error] [pid 925208:tid 925419] [client 77.110.127.138:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdcRX7OrFkv0FyuJCSQAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.941364 2026] [security2:error] [pid 925208:tid 925419] [client 77.110.127.138:63636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdcRX7OrFkv0FyuJCSQAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.946105 2026] [security2:error] [pid 925208:tid 925446] [client 34.74.185.202:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UdcRX7OrFkv0FyuJCSgAAAGw"]
[Mon Jul 20 06:28:37.994420 2026] [security2:error] [pid 929851:tid 930062] [client 77.110.127.138:63609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh64QAAANI"]
[Mon Jul 20 06:28:37.994542 2026] [security2:error] [pid 929851:tid 930062] [client 77.110.127.138:63609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh64QAAANI"]
[Mon Jul 20 06:28:38.027948 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh65AAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.028096 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh65AAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.046527 2026] [ssl:error] [pid 929851:tid 930016] [client 104.48.69.105:54886] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:28:38.047892 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66AAAAKA"]
[Mon Jul 20 06:28:38.048007 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66AAAAKA"]
[Mon Jul 20 06:28:38.112407 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66wAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.112515 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66wAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.134574 2026] [security2:error] [pid 929851:tid 930010] [client 57.141.18.22:40374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh59QAAnk0"]
[Mon Jul 20 06:28:38.187696 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:63640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCTgAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.187801 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:63640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCTgAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.198156 2026] [security2:error] [pid 929851:tid 930095] [client 34.74.185.202:58908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh69AAAAPM"]
[Mon Jul 20 06:28:38.228430 2026] [security2:error] [pid 925208:tid 925408] [client 57.141.18.95:29684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uc8RX7OrFkv0FyuJB7gAARmY"]
[Mon Jul 20 06:28:38.366962 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6-wAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.367096 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6-wAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.426833 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCXQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.427006 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:63586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCXQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.447565 2026] [security2:error] [pid 929851:tid 930097] [client 34.73.38.214:51242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh6_gAAAPU"]
[Mon Jul 20 06:28:38.482819 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6_wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.482942 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6_wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.533173 2026] [security2:error] [pid 929851:tid 930031] [client 57.141.18.42:39154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6GQAAsyM"]
[Mon Jul 20 06:28:38.620814 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7BgAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.620920 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:63642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7BgAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.640187 2026] [security2:error] [pid 929851:tid 930075] [client 62.164.177.222:35778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4UdmV3ou772CelrLh7BwAAAN8"]
[Mon Jul 20 06:28:38.640291 2026] [security2:error] [pid 929851:tid 930075] [client 62.164.177.222:35778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4UdmV3ou772CelrLh7BwAAAN8"]
[Mon Jul 20 06:28:38.678118 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7CwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.678212 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:63643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7CwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.737931 2026] [security2:error] [pid 925208:tid 925459] [client 34.73.38.214:52227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UdsRX7OrFkv0FyuJCYQAAAHk"]
[Mon Jul 20 06:28:38.770234 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:63591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7EwAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.770335 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:63591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7EwAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.903056 2026] [security2:error] [pid 929851:tid 930068] [client 34.74.185.202:52096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh7HgAAANg"]
[Mon Jul 20 06:28:38.941266 2026] [security2:error] [pid 929851:tid 930089] [client 34.73.38.214:58299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh7JgAAAO0"]
[Mon Jul 20 06:28:38.941283 2026] [security2:error] [pid 929851:tid 930063] [client 34.73.38.214:56172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh7JQAAANM"]
[Mon Jul 20 06:28:39.101788 2026] [security2:error] [pid 925208:tid 925438] [client 62.164.177.222:38982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCaAAAAGQ"]
[Mon Jul 20 06:28:39.101863 2026] [security2:error] [pid 925208:tid 925438] [client 62.164.177.222:38982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCaAAAAGQ"]
[Mon Jul 20 06:28:39.142724 2026] [security2:error] [pid 929851:tid 930059] [client 106.219.188.178:47757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ud2V3ou772CelrLh7MgAAAM8"]
[Mon Jul 20 06:28:39.151279 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCbQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.151385 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCbQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.151717 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63647] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ud2V3ou772CelrLh7MwAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.165918 2026] [security2:error] [pid 929851:tid 930059] [client 106.219.188.178:47757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ud2V3ou772CelrLh7MgAAAM8"]
[Mon Jul 20 06:28:39.183576 2026] [security2:error] [pid 929851:tid 930013] [client 66.249.73.172:60287] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "jmq.beb.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4Ud2V3ou772CelrLh7NgAAAKE"]
[Mon Jul 20 06:28:39.227480 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:63625] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ud2V3ou772CelrLh7OwAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.256708 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud2V3ou772CelrLh7PAAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.256927 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud2V3ou772CelrLh7PAAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.273044 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:61717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCaQAAAAA"], referer: http://secretkeynumerology.com/old
[Mon Jul 20 06:28:39.345138 2026] [security2:error] [pid 929851:tid 930091] [client 34.73.38.214:54028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7QAAAAO8"]
[Mon Jul 20 06:28:39.421234 2026] [security2:error] [pid 929851:tid 930024] [client 34.73.38.214:50506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7RwAAAKw"]
[Mon Jul 20 06:28:39.487401 2026] [security2:error] [pid 929851:tid 930008] [client 34.73.38.214:61479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7TwAAAJw"]
[Mon Jul 20 06:28:39.531688 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.52:47972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6XgAA11o"]
[Mon Jul 20 06:28:39.762533 2026] [security2:error] [pid 925208:tid 925420] [client 34.74.185.202:54026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud8RX7OrFkv0FyuJCfQAAAFI"]
[Mon Jul 20 06:28:39.814004 2026] [security2:error] [pid 929851:tid 929993] [client 54.244.177.189:54446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ud2V3ou772CelrLh7aAAAAI0"], referer: https://curlsnpearlsss.com/wp-cron.php?doing_wp_cron=1784550519.5384230613708496093750
[Mon Jul 20 06:28:39.862296 2026] [security2:error] [pid 929851:tid 930041] [client 14.225.17.146:61729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4UdmV3ou772CelrLh7FgAAAL0"], referer: http://adultdaycarereno.com/old
[Mon Jul 20 06:28:39.862611 2026] [security2:error] [pid 929851:tid 930109] [client 34.73.38.214:65525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7bAAAAQE"]
[Mon Jul 20 06:28:40.044635 2026] [security2:error] [pid 925208:tid 925395] [client 104.234.53.65:46883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UeMRX7OrFkv0FyuJCjAAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:40.047068 2026] [security2:error] [pid 925208:tid 925437] [client 57.141.18.100:22538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdMRX7OrFkv0FyuJCKAAAYwM"]
[Mon Jul 20 06:28:40.064672 2026] [security2:error] [pid 929851:tid 930101] [client 34.73.38.214:64771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UeGV3ou772CelrLh7eAAAAPk"]
[Mon Jul 20 06:28:40.187780 2026] [security2:error] [pid 929851:tid 930085] [client 57.141.18.55:45270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6kAAA6Sg"]
[Mon Jul 20 06:28:40.403498 2026] [security2:error] [pid 929851:tid 930086] [client 34.73.38.214:56426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UeGV3ou772CelrLh7kAAAAOo"]
[Mon Jul 20 06:28:40.413157 2026] [security2:error] [pid 925208:tid 925397] [client 14.225.17.146:61435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4UeMRX7OrFkv0FyuJCkAAAADs"], referer: https://secretkeynumerology.com/old
[Mon Jul 20 06:28:40.911181 2026] [security2:error] [pid 929851:tid 930109] [client 14.225.17.146:60942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4UeGV3ou772CelrLh7qAAAAQE"], referer: https://adultdaycarereno.com/old
[Mon Jul 20 06:28:40.936936 2026] [security2:error] [pid 929851:tid 930103] [client 176.9.19.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4UeGV3ou772CelrLh7oQAAAPs"]
[Mon Jul 20 06:28:41.011108 2026] [security2:error] [pid 929851:tid 929883] [remote 147.50.252.213:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7tQAAiBs"]
[Mon Jul 20 06:28:41.044105 2026] [security2:error] [pid 925208:tid 925462] [client 14.225.17.146:61121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4UeMRX7OrFkv0FyuJClwAAAHw"], referer: http://waterproofgoods.com/old
[Mon Jul 20 06:28:41.049368 2026] [security2:error] [pid 929851:tid 930069] [client 14.225.17.146:55177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4Ud2V3ou772CelrLh7RQAAANk"], referer: http://maplerespiteservices.com/old
[Mon Jul 20 06:28:41.145475 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UeWV3ou772CelrLh7vAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:41.145593 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UeWV3ou772CelrLh7vAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:41.184344 2026] [security2:error] [pid 929851:tid 930033] [client 34.74.185.202:61978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UeWV3ou772CelrLh7vgAAALU"]
[Mon Jul 20 06:28:41.188132 2026] [security2:error] [pid 929851:tid 930026] [client 223.185.13.213:17107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UeWV3ou772CelrLh7vwAAAK4"]
[Mon Jul 20 06:28:41.188223 2026] [security2:error] [pid 929851:tid 930026] [client 223.185.13.213:17107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UeWV3ou772CelrLh7vwAAAK4"]
[Mon Jul 20 06:28:41.193814 2026] [security2:error] [pid 929851:tid 930098] [client 34.73.38.214:65055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UeWV3ou772CelrLh7wQAAAPY"]
[Mon Jul 20 06:28:41.238202 2026] [security2:error] [pid 929851:tid 929935] [remote 159.65.81.207:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7wwAA908"]
[Mon Jul 20 06:28:41.303784 2026] [security2:error] [pid 925208:tid 925246] [remote 20.153.140.50:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UecRX7OrFkv0FyuJCqQAABiU"]
[Mon Jul 20 06:28:41.327380 2026] [security2:error] [pid 929851:tid 929886] [remote 160.187.68.132:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7yQAAwh4"]
[Mon Jul 20 06:28:41.404229 2026] [security2:error] [pid 929851:tid 929974] [remote 159.65.81.207:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7zwAAx3Y"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:28:41.409505 2026] [security2:error] [pid 925208:tid 925366] [client 57.141.18.13:53032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdsRX7OrFkv0FyuJCUwAAHGc"]
[Mon Jul 20 06:28:41.478491 2026] [security2:error] [pid 929851:tid 929856] [remote 147.50.252.213:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh70gAAjgA"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:28:41.481732 2026] [security2:error] [pid 929851:tid 930095] [client 104.234.53.64:62339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UeWV3ou772CelrLh70wAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:41.602040 2026] [security2:error] [pid 929851:tid 930036] [client 144.76.19.72:39816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4UeWV3ou772CelrLh70QAAALg"]
[Mon Jul 20 06:28:41.694563 2026] [security2:error] [pid 925208:tid 925332] [remote 103.191.209.69:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.209.191.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCsAAAXns"]
[Mon Jul 20 06:28:41.694725 2026] [security2:error] [pid 925208:tid 925432] [client 103.191.209.69:38980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCsAAAXns"]
[Mon Jul 20 06:28:41.716046 2026] [security2:error] [pid 925208:tid 925232] [remote 20.153.140.50:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UecRX7OrFkv0FyuJCswAAAhc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:41.716997 2026] [security2:error] [pid 929851:tid 929860] [remote 152.228.213.32:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh74AAA8QQ"]
[Mon Jul 20 06:28:41.786975 2026] [security2:error] [pid 925208:tid 925359] [client 34.73.38.214:61463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UecRX7OrFkv0FyuJCtQAAABU"]
[Mon Jul 20 06:28:41.809287 2026] [security2:error] [pid 929851:tid 929937] [remote 160.187.68.132:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh75gAA2FE"], referer: https://fbvrealtors.com/wp-login.php
[Mon Jul 20 06:28:41.886741 2026] [security2:error] [pid 925208:tid 925410] [client 34.73.38.214:56087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UecRX7OrFkv0FyuJCvwAAAEg"]
[Mon Jul 20 06:28:41.923315 2026] [security2:error] [pid 929851:tid 929980] [remote 152.228.213.32:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh78AAA9nw"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:28:41.934209 2026] [security2:error] [pid 925208:tid 925455] [client 62.164.177.222:57746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/ar/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCwQAAAHU"]
[Mon Jul 20 06:28:41.934289 2026] [security2:error] [pid 925208:tid 925455] [client 62.164.177.222:57746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/ar/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCwQAAAHU"]
[Mon Jul 20 06:28:42.020658 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UemV3ou772CelrLh79QAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.020771 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:63663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UemV3ou772CelrLh79QAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.069485 2026] [security2:error] [pid 929851:tid 929987] [client 34.74.185.202:58566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UemV3ou772CelrLh7-QAAAIc"]
[Mon Jul 20 06:28:42.082073 2026] [security2:error] [pid 929851:tid 929990] [client 45.61.188.240:60337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.aandarealtygroup.com"] [uri "/"] [unique_id "al4UemV3ou772CelrLh7-gAAAIo"]
[Mon Jul 20 06:28:42.242264 2026] [security2:error] [pid 925208:tid 925408] [client 34.73.38.214:62606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UesRX7OrFkv0FyuJCxQAAAEY"]
[Mon Jul 20 06:28:42.348279 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.110:30538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ud2V3ou772CelrLh7UwAAohg"]
[Mon Jul 20 06:28:42.358494 2026] [security2:error] [pid 925208:tid 925403] [client 45.61.188.240:60392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.aandarealtygroup.com"] [uri "/"] [unique_id "al4UesRX7OrFkv0FyuJCygAAAEE"]
[Mon Jul 20 06:28:42.420125 2026] [security2:error] [pid 929851:tid 930066] [client 62.164.177.222:32820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp/xmlrpc.php"] [unique_id "al4UemV3ou772CelrLh8EAAAANY"]
[Mon Jul 20 06:28:42.420233 2026] [security2:error] [pid 929851:tid 930066] [client 62.164.177.222:32820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/wp/xmlrpc.php"] [unique_id "al4UemV3ou772CelrLh8EAAAANY"]
[Mon Jul 20 06:28:42.449115 2026] [security2:error] [pid 929851:tid 930061] [client 170.23.24.119:8508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4UemV3ou772CelrLh8CAAA0Uk"]
[Mon Jul 20 06:28:42.481808 2026] [security2:error] [pid 929851:tid 930095] [client 14.225.17.146:63165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4UemV3ou772CelrLh8DgAAAPM"], referer: http://intelligentengineeringsolutions.com/old
[Mon Jul 20 06:28:42.549515 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:63667] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UesRX7OrFkv0FyuJC0AAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.595130 2026] [security2:error] [pid 929851:tid 930015] [client 57.141.18.69:64400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ud2V3ou772CelrLh7awAAoyo"]
[Mon Jul 20 06:28:42.663612 2026] [core:error] [pid 925208:tid 925349] [client 159.89.133.65:50020] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Mon Jul 20 06:28:42.714611 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:63670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UesRX7OrFkv0FyuJC2wAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.714723 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:63670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UesRX7OrFkv0FyuJC2wAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.913843 2026] [security2:error] [pid 925208:tid 925373] [client 62.164.177.222:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/site/xmlrpc.php"] [unique_id "al4UesRX7OrFkv0FyuJC4AAAACM"]
[Mon Jul 20 06:28:42.913968 2026] [security2:error] [pid 925208:tid 925373] [client 62.164.177.222:36354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/site/xmlrpc.php"] [unique_id "al4UesRX7OrFkv0FyuJC4AAAACM"]
[Mon Jul 20 06:28:42.927081 2026] [security2:error] [pid 929851:tid 930110] [client 34.74.185.202:52539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UemV3ou772CelrLh8LgAAAQI"]
[Mon Jul 20 06:28:42.933391 2026] [security2:error] [pid 929851:tid 930024] [client 57.141.18.96:45748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UeGV3ou772CelrLh7fQAArBY"]
[Mon Jul 20 06:28:42.941783 2026] [security2:error] [pid 929851:tid 930020] [client 45.61.188.240:60509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.civitansuncitiesaz.org"] [uri "/"] [unique_id "al4UemV3ou772CelrLh8LwAAAKg"]
[Mon Jul 20 06:28:43.056294 2026] [security2:error] [pid 929851:tid 930101] [client 34.73.38.214:56159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8MQAAAPk"]
[Mon Jul 20 06:28:43.169089 2026] [security2:error] [pid 929851:tid 930078] [client 171.60.139.123:64724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8PAAAAOI"]
[Mon Jul 20 06:28:43.169204 2026] [security2:error] [pid 929851:tid 930078] [client 171.60.139.123:64724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8PAAAAOI"]
[Mon Jul 20 06:28:43.198930 2026] [security2:error] [pid 925208:tid 925430] [client 50.116.65.227:10876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Ue8RX7OrFkv0FyuJC6QAAAFw"]
[Mon Jul 20 06:28:43.215568 2026] [security2:error] [pid 929851:tid 930056] [client 50.116.65.227:52596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Ue2V3ou772CelrLh8RAAAAPw"]
[Mon Jul 20 06:28:43.215617 2026] [security2:error] [pid 929851:tid 930054] [client 45.61.188.240:60557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.civitansuncitiesaz.org"] [uri "/"] [unique_id "al4Ue2V3ou772CelrLh8RQAAAMo"]
[Mon Jul 20 06:28:43.259163 2026] [security2:error] [pid 929851:tid 929998] [client 34.73.38.214:60896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8RwAAAJI"]
[Mon Jul 20 06:28:43.378993 2026] [security2:error] [pid 929851:tid 930095] [client 62.164.177.222:39420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/news/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8TgAAAPM"]
[Mon Jul 20 06:28:43.379081 2026] [security2:error] [pid 929851:tid 930095] [client 62.164.177.222:39420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/news/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8TgAAAPM"]
[Mon Jul 20 06:28:43.533695 2026] [security2:error] [pid 925208:tid 925348] [client 34.74.185.202:61817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue8RX7OrFkv0FyuJC8gAAAAo"]
[Mon Jul 20 06:28:43.750861 2026] [security2:error] [pid 929851:tid 930036] [client 34.73.38.214:55976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8ZgAAALg"]
[Mon Jul 20 06:28:43.788071 2026] [security2:error] [pid 929851:tid 930027] [client 57.141.18.22:40092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UeWV3ou772CelrLh7wAAArxw"]
[Mon Jul 20 06:28:43.834371 2026] [security2:error] [pid 929851:tid 930077] [client 57.141.18.72:62600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UeWV3ou772CelrLh7vQAA4Vc"]
[Mon Jul 20 06:28:43.868106 2026] [security2:error] [pid 929851:tid 930078] [client 34.73.38.214:63668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8cgAAAOI"]
[Mon Jul 20 06:28:43.870089 2026] [security2:error] [pid 929851:tid 929994] [client 62.164.177.222:42606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/web/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8cwAAAI4"]
[Mon Jul 20 06:28:43.870211 2026] [security2:error] [pid 929851:tid 929994] [client 62.164.177.222:42606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/web/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8cwAAAI4"]
[Mon Jul 20 06:28:43.934547 2026] [security2:error] [pid 929851:tid 929933] [remote 57.141.18.87:26290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5138828"] [unique_id "al4Ue2V3ou772CelrLh8fQAA_E0"]
[Mon Jul 20 06:28:44.116120 2026] [security2:error] [pid 925208:tid 925361] [client 34.73.38.214:57288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UfMRX7OrFkv0FyuJC_wAAABc"]
[Mon Jul 20 06:28:44.119247 2026] [security2:error] [pid 925208:tid 925437] [client 50.116.65.227:52600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UfMRX7OrFkv0FyuJDAAAAAGM"]
[Mon Jul 20 06:28:44.133014 2026] [security2:error] [pid 925208:tid 925440] [client 50.116.65.227:52604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UfMRX7OrFkv0FyuJDAwAAAGY"]
[Mon Jul 20 06:28:44.304155 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8jAAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.304264 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8jAAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.320937 2026] [security2:error] [pid 925208:tid 925464] [client 62.164.177.222:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/main/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDCwAAAH4"]
[Mon Jul 20 06:28:44.321047 2026] [security2:error] [pid 925208:tid 925464] [client 62.164.177.222:45598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/main/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDCwAAAH4"]
[Mon Jul 20 06:28:44.439614 2026] [security2:error] [pid 925208:tid 925391] [client 57.141.18.104:45940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UecRX7OrFkv0FyuJCtwAANSo"]
[Mon Jul 20 06:28:44.546622 2026] [security2:error] [pid 925208:tid 925439] [client 45.116.69.230:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDFAAAAGU"]
[Mon Jul 20 06:28:44.546757 2026] [security2:error] [pid 925208:tid 925439] [client 45.116.69.230:57085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDFAAAAGU"]
[Mon Jul 20 06:28:44.606833 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8nAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.606940 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8nAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.649784 2026] [security2:error] [pid 929851:tid 930027] [client 34.74.185.202:64184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UfGV3ou772CelrLh8ngAAAK8"]
[Mon Jul 20 06:28:44.678796 2026] [security2:error] [pid 925208:tid 925426] [client 103.141.108.143:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGAAAAFg"]
[Mon Jul 20 06:28:44.678913 2026] [security2:error] [pid 925208:tid 925426] [client 103.141.108.143:55766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGAAAAFg"]
[Mon Jul 20 06:28:44.766083 2026] [security2:error] [pid 929851:tid 930001] [client 77.110.127.138:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8ogAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.766428 2026] [security2:error] [pid 929851:tid 930001] [client 77.110.127.138:63683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8ogAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.796644 2026] [security2:error] [pid 925208:tid 925378] [client 62.164.177.222:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/cms/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGQAAACg"]
[Mon Jul 20 06:28:44.796762 2026] [security2:error] [pid 925208:tid 925378] [client 62.164.177.222:49088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/cms/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGQAAACg"]
[Mon Jul 20 06:28:44.880488 2026] [security2:error] [pid 929851:tid 930011] [client 74.208.214.194:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UfGV3ou772CelrLh8qgAAAJ8"]
[Mon Jul 20 06:28:44.912780 2026] [security2:error] [pid 929851:tid 929991] [client 14.225.17.146:54790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4UfGV3ou772CelrLh8mwAAAIs"], referer: http://transparentservices.online/old
[Mon Jul 20 06:28:45.043352 2026] [security2:error] [pid 925208:tid 925448] [client 34.74.185.202:52402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UfcRX7OrFkv0FyuJDIQAAAG4"]
[Mon Jul 20 06:28:45.065866 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.82:59124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UemV3ou772CelrLh8EwAA-jA"]
[Mon Jul 20 06:28:45.066464 2026] [security2:error] [pid 929851:tid 930079] [client 34.73.38.214:63722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UfWV3ou772CelrLh8tAAAAOM"]
[Mon Jul 20 06:28:45.075019 2026] [security2:error] [pid 925208:tid 925316] [remote 154.61.75.100:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UfcRX7OrFkv0FyuJDIwAATms"]
[Mon Jul 20 06:28:45.078689 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8tgAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.078792 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8tgAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.123517 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8uAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.123610 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:63685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8uAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.272081 2026] [security2:error] [pid 929851:tid 930085] [client 62.164.177.222:52428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh8wgAAAOk"]
[Mon Jul 20 06:28:45.272169 2026] [security2:error] [pid 929851:tid 930085] [client 62.164.177.222:52428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh8wgAAAOk"]
[Mon Jul 20 06:28:45.302299 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8xQAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.302419 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8xQAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.457202 2026] [security2:error] [pid 929851:tid 930057] [client 77.110.127.138:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh81AAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.457283 2026] [security2:error] [pid 929851:tid 930057] [client 77.110.127.138:63690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh81AAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.509545 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfcRX7OrFkv0FyuJDLwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.509645 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:63660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfcRX7OrFkv0FyuJDLwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.551204 2026] [security2:error] [pid 925208:tid 925287] [remote 154.61.75.100:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UfcRX7OrFkv0FyuJDMwAAEU4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:45.567484 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:63692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UfcRX7OrFkv0FyuJDOAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.616957 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh85QAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.617089 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh85QAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.637403 2026] [security2:error] [pid 925208:tid 925389] [client 39.48.81.23:55872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UfcRX7OrFkv0FyuJDPAAAADM"]
[Mon Jul 20 06:28:45.637512 2026] [security2:error] [pid 925208:tid 925389] [client 39.48.81.23:55872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UfcRX7OrFkv0FyuJDPAAAADM"]
[Mon Jul 20 06:28:45.757547 2026] [security2:error] [pid 929851:tid 930102] [client 62.164.177.222:55652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/old/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh86AAAAPo"]
[Mon Jul 20 06:28:45.757644 2026] [security2:error] [pid 929851:tid 930102] [client 62.164.177.222:55652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/old/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh86AAAAPo"]
[Mon Jul 20 06:28:45.814463 2026] [security2:error] [pid 925208:tid 925414] [client 13.215.47.127:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UfcRX7OrFkv0FyuJDQQAAAEw"]
[Mon Jul 20 06:28:45.995474 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh87AAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:46.039547 2026] [security2:error] [pid 925208:tid 925437] [client 112.208.70.94:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UfsRX7OrFkv0FyuJDUQAAAGM"]
[Mon Jul 20 06:28:46.039664 2026] [security2:error] [pid 925208:tid 925437] [client 112.208.70.94:45183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UfsRX7OrFkv0FyuJDUQAAAGM"]
[Mon Jul 20 06:28:46.091705 2026] [security2:error] [pid 929851:tid 930085] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh89wAAAOk"]
[Mon Jul 20 06:28:46.181178 2026] [security2:error] [pid 925208:tid 925456] [client 34.74.185.202:53027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UfsRX7OrFkv0FyuJDXAAAAHY"]
[Mon Jul 20 06:28:46.182636 2026] [security2:error] [pid 929851:tid 930107] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh89gAAAP8"]
[Mon Jul 20 06:28:46.202072 2026] [security2:error] [pid 929851:tid 929990] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh89AAAAIo"]
[Mon Jul 20 06:28:46.287164 2026] [security2:error] [pid 929851:tid 930068] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9AwAAANg"]
[Mon Jul 20 06:28:46.330672 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.117:37492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ue2V3ou772CelrLh8awAAoiY"]
[Mon Jul 20 06:28:46.550796 2026] [security2:error] [pid 925208:tid 925450] [client 57.141.18.47:58302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfMRX7OrFkv0FyuJDBQAAcB0"]
[Mon Jul 20 06:28:46.661420 2026] [security2:error] [pid 929851:tid 930079] [client 65.111.23.40:30443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UfmV3ou772CelrLh9HwAAAOM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:46.695861 2026] [security2:error] [pid 929851:tid 930006] [client 54.169.146.187:20556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UfmV3ou772CelrLh9IgAAAJo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:28:46.942719 2026] [security2:error] [pid 925208:tid 925396] [client 57.141.18.71:48830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfMRX7OrFkv0FyuJDEwAAOnU"]
[Mon Jul 20 06:28:46.998891 2026] [security2:error] [pid 925208:tid 925353] [client 14.225.17.146:52112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4UfcRX7OrFkv0FyuJDKwAAAA8"], referer: http://superiorcopywriting.com/old
[Mon Jul 20 06:28:47.408003 2026] [security2:error] [pid 929851:tid 930092] [client 62.164.177.222:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Uf2V3ou772CelrLh9QAAAAPA"], referer: https://youpositive.co/wp-admin/
[Mon Jul 20 06:28:47.415046 2026] [security2:error] [pid 929851:tid 930018] [client 14.225.17.146:63929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9EAAAAKY"], referer: http://travelbyfire.com/old
[Mon Jul 20 06:28:47.588907 2026] [security2:error] [pid 925208:tid 925440] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Uf8RX7OrFkv0FyuJDfwAAAGY"]
[Mon Jul 20 06:28:47.769408 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uf2V3ou772CelrLh9UgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:47.769537 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uf2V3ou772CelrLh9UgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:47.782823 2026] [security2:error] [pid 925208:tid 925385] [client 57.141.18.49:34100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfcRX7OrFkv0FyuJDLgAAL08"]
[Mon Jul 20 06:28:47.856270 2026] [security2:error] [pid 929851:tid 930079] [client 62.164.177.222:41484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Uf2V3ou772CelrLh9WgAAAOM"]
[Mon Jul 20 06:28:47.866162 2026] [security2:error] [pid 929851:tid 930066] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Uf2V3ou772CelrLh9UwAAANY"]
[Mon Jul 20 06:28:47.877289 2026] [security2:error] [pid 929851:tid 930074] [client 104.234.53.75:25741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Uf2V3ou772CelrLh9WAAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:48.023650 2026] [security2:error] [pid 929851:tid 930033] [client 34.74.185.202:61536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UgGV3ou772CelrLh9ZgAAALU"]
[Mon Jul 20 06:28:48.099509 2026] [security2:error] [pid 929851:tid 930095] [client 43.205.139.3:46220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UgGV3ou772CelrLh9aQAAAPM"]
[Mon Jul 20 06:28:48.099593 2026] [security2:error] [pid 929851:tid 930095] [client 43.205.139.3:46220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UgGV3ou772CelrLh9aQAAAPM"]
[Mon Jul 20 06:28:48.359360 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:63206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9eAAAANU"], referer: https://travelbyfire.com/old
[Mon Jul 20 06:28:48.391004 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:63701] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 921 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UgGV3ou772CelrLh9fAAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.441985 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgMRX7OrFkv0FyuJDowAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.442100 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgMRX7OrFkv0FyuJDowAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.521292 2026] [security2:error] [pid 929851:tid 930048] [client 57.141.18.67:59678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9FAAAxGo"]
[Mon Jul 20 06:28:48.847065 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:63674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgGV3ou772CelrLh9nAAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.847196 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:63674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgGV3ou772CelrLh9nAAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.911993 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.82:29156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9MgAA_hs"]
[Mon Jul 20 06:28:49.232619 2026] [security2:error] [pid 925208:tid 925400] [client 57.141.18.75:33850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uf8RX7OrFkv0FyuJDdgAAPis"]
[Mon Jul 20 06:28:49.313807 2026] [security2:error] [pid 929851:tid 930112] [client 51.222.31.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Uf2V3ou772CelrLh9RwAAAQQ"]
[Mon Jul 20 06:28:49.417436 2026] [security2:error] [pid 929851:tid 930014] [client 171.61.165.146:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh9wAAAAKI"]
[Mon Jul 20 06:28:49.418427 2026] [security2:error] [pid 929851:tid 930014] [client 171.61.165.146:9186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh9wAAAAKI"]
[Mon Jul 20 06:28:49.634804 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgWV3ou772CelrLh9vgAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:49.732547 2026] [security2:error] [pid 925208:tid 925419] [client 34.74.185.202:54807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UgcRX7OrFkv0FyuJD0AAAAFE"]
[Mon Jul 20 06:28:49.858988 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh93AAAAOY"]
[Mon Jul 20 06:28:49.859271 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:10290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh93AAAAOY"]
[Mon Jul 20 06:28:50.114691 2026] [security2:error] [pid 925208:tid 925413] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgcRX7OrFkv0FyuJD1AAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.339492 2026] [security2:error] [pid 925208:tid 925244] [remote 100.42.189.89:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD4AAAMCM"]
[Mon Jul 20 06:28:50.353210 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.124:21608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9ewAAliw"]
[Mon Jul 20 06:28:50.532230 2026] [security2:error] [pid 925208:tid 925262] [remote 100.42.189.89:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD6QAAOjU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:50.591778 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:63711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgsRX7OrFkv0FyuJD7QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.591876 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:63711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgsRX7OrFkv0FyuJD7QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.604867 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgmV3ou772CelrLh9-wAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.714490 2026] [security2:error] [pid 929851:tid 930104] [client 57.141.18.34:31718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9ngAA_Aw"]
[Mon Jul 20 06:28:50.715508 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.112:61122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9nQAAzxg"]
[Mon Jul 20 06:28:50.745302 2026] [security2:error] [pid 929851:tid 929992] [client 77.110.127.138:63712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 253 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UgmV3ou772CelrLh-EQAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.951260 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgmV3ou772CelrLh-HgAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.951351 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgmV3ou772CelrLh-HgAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.985660 2026] [security2:error] [pid 925208:tid 925417] [client 14.225.17.146:51836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4UgsRX7OrFkv0FyuJD9wAAAE8"], referer: http://claysharecon.com/old
[Mon Jul 20 06:28:51.000698 2026] [security2:error] [pid 925208:tid 925235] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.141.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omenana.com"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD-wAAbRo"], referer: https://omenana.com/login
[Mon Jul 20 06:28:51.030454 2026] [security2:error] [pid 925208:tid 925280] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.141.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omenana.com"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD-gAAbUc"], referer: https://omenana.com/wp-admin/
[Mon Jul 20 06:28:51.035631 2026] [security2:error] [pid 925208:tid 925304] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.141.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omenana.com"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD-QAAbV8"], referer: https://omenana.com/wp-admin/
[Mon Jul 20 06:28:51.133916 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ug2V3ou772CelrLh-JwAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.134098 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ug2V3ou772CelrLh-JwAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.143691 2026] [security2:error] [pid 929851:tid 930065] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgmV3ou772CelrLh-GwAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.274833 2026] [security2:error] [pid 925208:tid 925400] [client 34.31.203.120:13568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEAAAAPhk"]
[Mon Jul 20 06:28:51.311259 2026] [security2:error] [pid 925208:tid 925349] [client 54.196.52.99:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4UgsRX7OrFkv0FyuJD6gAAAAs"]
[Mon Jul 20 06:28:51.382724 2026] [security2:error] [pid 929851:tid 930039] [client 54.196.52.99:59470] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4UgmV3ou772CelrLh-AwAAALs"]
[Mon Jul 20 06:28:51.405641 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:51714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4UgWV3ou772CelrLh9zAAAAO4"], referer: http://windowtx.com/old
[Mon Jul 20 06:28:51.585975 2026] [security2:error] [pid 925208:tid 925350] [client 34.31.203.120:13568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEGQAADDg"]
[Mon Jul 20 06:28:51.615856 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEFwAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.803366 2026] [security2:error] [pid 929851:tid 930006] [client 57.141.18.21:23736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgmV3ou772CelrLh98AAAmnk"]
[Mon Jul 20 06:28:52.078405 2026] [security2:error] [pid 925208:tid 925338] [client 223.185.13.213:24486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UhMRX7OrFkv0FyuJEOQAAAAA"]
[Mon Jul 20 06:28:52.078570 2026] [security2:error] [pid 925208:tid 925338] [client 223.185.13.213:24486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UhMRX7OrFkv0FyuJEOQAAAAA"]
[Mon Jul 20 06:28:52.179604 2026] [security2:error] [pid 929851:tid 930098] [client 14.225.17.146:63704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-UAAAAPY"], referer: http://thefriendlyspreadsheet.com/old
[Mon Jul 20 06:28:52.200156 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ug2V3ou772CelrLh-RAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:52.207794 2026] [security2:error] [pid 925208:tid 925446] [client 34.31.203.120:13568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UhMRX7OrFkv0FyuJENQAAbGM"]
[Mon Jul 20 06:28:52.271170 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.43:26686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgsRX7OrFkv0FyuJD6wAATiA"]
[Mon Jul 20 06:28:52.497951 2026] [security2:error] [pid 925208:tid 925231] [remote 81.173.115.7:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UhMRX7OrFkv0FyuJETAAAUhY"]
[Mon Jul 20 06:28:52.535780 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-WwAAAME"]
[Mon Jul 20 06:28:52.663299 2026] [security2:error] [pid 925208:tid 925367] [client 57.141.18.114:47062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJD_gAAHX4"]
[Mon Jul 20 06:28:52.713708 2026] [security2:error] [pid 925208:tid 925282] [remote 81.173.115.7:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UhMRX7OrFkv0FyuJEUQAAfEk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:52.913338 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UhMRX7OrFkv0FyuJETgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:52.945538 2026] [security2:error] [pid 925208:tid 925380] [client 57.141.18.60:20454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJECgAAKkM"]
[Mon Jul 20 06:28:53.031100 2026] [security2:error] [pid 925208:tid 925343] [client 57.141.18.69:59892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEEgAABXA"]
[Mon Jul 20 06:28:53.042515 2026] [security2:error] [pid 925208:tid 925392] [client 50.116.65.227:25350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UhcRX7OrFkv0FyuJEXgAAADY"]
[Mon Jul 20 06:28:53.053936 2026] [security2:error] [pid 925208:tid 925368] [client 50.116.65.227:25366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UhcRX7OrFkv0FyuJEXwAAAB4"]
[Mon Jul 20 06:28:53.112468 2026] [security2:error] [pid 929851:tid 930095] [client 14.225.17.146:61266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-egAAAPM"], referer: http://scott-assist.com/old
[Mon Jul 20 06:28:53.205534 2026] [security2:error] [pid 929851:tid 929934] [remote 173.212.252.15:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UhWV3ou772CelrLh-iAAA0U4"]
[Mon Jul 20 06:28:53.414370 2026] [security2:error] [pid 925208:tid 925353] [client 57.141.18.46:60184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEKQAADzM"]
[Mon Jul 20 06:28:53.472487 2026] [security2:error] [pid 929851:tid 930001] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UhWV3ou772CelrLh-iQAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.546435 2026] [security2:error] [pid 929851:tid 929862] [remote 173.212.252.15:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UhWV3ou772CelrLh-lwAAnAY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:28:53.569780 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-mAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.569893 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-mAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.754226 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 906 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UhWV3ou772CelrLh-qAAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.808014 2026] [proxy:error] [pid 925208:tid 925379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:53.808108 2026] [proxy_http:error] [pid 925208:tid 925379] [client 34.73.38.214:50648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:53.808714 2026] [proxy:error] [pid 925208:tid 925379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:53.808742 2026] [proxy_http:error] [pid 925208:tid 925379] [client 34.73.38.214:50648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:53.874564 2026] [security2:error] [pid 929851:tid 930111] [client 171.60.139.123:65269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UhWV3ou772CelrLh-swAAAQM"]
[Mon Jul 20 06:28:53.874676 2026] [security2:error] [pid 929851:tid 930111] [client 171.60.139.123:65269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UhWV3ou772CelrLh-swAAAQM"]
[Mon Jul 20 06:28:53.916587 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:63741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-uAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.916696 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:63741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-uAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.967708 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-vQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.967813 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-vQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:54.360414 2026] [security2:error] [pid 925208:tid 925426] [client 121.229.156.62:46596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2010-commission/"] [unique_id "al4UhsRX7OrFkv0FyuJEiAAAAFg"]
[Mon Jul 20 06:28:54.360536 2026] [security2:error] [pid 925208:tid 925426] [client 121.229.156.62:46596] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2010-commission/"] [unique_id "al4UhsRX7OrFkv0FyuJEiAAAAFg"]
[Mon Jul 20 06:28:54.530807 2026] [security2:error] [pid 929851:tid 930090] [client 146.75.222.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-aAAAAO4"]
[Mon Jul 20 06:28:54.748307 2026] [security2:error] [pid 925208:tid 925404] [client 104.234.53.53:32153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UhsRX7OrFkv0FyuJEkwAAAEI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:54.935387 2026] [security2:error] [pid 925208:tid 925450] [client 14.225.17.146:50961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4UhsRX7OrFkv0FyuJEkAAAAHA"], referer: http://healthylifegourmet.org/old
[Mon Jul 20 06:28:55.012168 2026] [security2:error] [pid 925208:tid 925455] [client 104.234.53.53:32153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEnAAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:55.279631 2026] [security2:error] [pid 925208:tid 925442] [client 45.116.69.230:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEqQAAAGg"]
[Mon Jul 20 06:28:55.280380 2026] [security2:error] [pid 925208:tid 925442] [client 45.116.69.230:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEqQAAAGg"]
[Mon Jul 20 06:28:55.300336 2026] [security2:error] [pid 929851:tid 930095] [client 103.141.108.143:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh2V3ou772CelrLh-_gAAAPM"]
[Mon Jul 20 06:28:55.301399 2026] [security2:error] [pid 929851:tid 930095] [client 103.141.108.143:56243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh2V3ou772CelrLh-_gAAAPM"]
[Mon Jul 20 06:28:55.363084 2026] [security2:error] [pid 925208:tid 925441] [client 14.225.17.146:63629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEqwAAAGc"], referer: http://friendlyspreadsheet.com/old
[Mon Jul 20 06:28:55.411469 2026] [security2:error] [pid 925208:tid 925388] [client 57.141.18.107:60046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhcRX7OrFkv0FyuJEdgAAMhQ"]
[Mon Jul 20 06:28:55.440375 2026] [security2:error] [pid 925208:tid 925446] [client 57.141.18.121:29686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhcRX7OrFkv0FyuJEdAAAbAw"]
[Mon Jul 20 06:28:55.446226 2026] [proxy:error] [pid 929851:tid 930025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.446312 2026] [proxy_http:error] [pid 929851:tid 930025] [client 34.73.38.214:57499] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:55.447017 2026] [proxy:error] [pid 929851:tid 930025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.447047 2026] [proxy_http:error] [pid 929851:tid 930025] [client 34.73.38.214:57499] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:55.486121 2026] [security2:error] [pid 925208:tid 925329] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env"] [unique_id "al4Uh8RX7OrFkv0FyuJErQAAEHg"]
[Mon Jul 20 06:28:55.507001 2026] [security2:error] [pid 925208:tid 925289] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/rclone.conf"] [unique_id "al4Uh8RX7OrFkv0FyuJEsAAAZVA"]
[Mon Jul 20 06:28:55.507908 2026] [security2:error] [pid 925208:tid 925297] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.git/HEAD"] [unique_id "al4Uh8RX7OrFkv0FyuJEsgAAZVg"]
[Mon Jul 20 06:28:55.507908 2026] [security2:error] [pid 925208:tid 925272] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.git/config"] [unique_id "al4Uh8RX7OrFkv0FyuJEtAAAZT8"]
[Mon Jul 20 06:28:55.508104 2026] [security2:error] [pid 925208:tid 925288] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-json"] [unique_id "al4Uh8RX7OrFkv0FyuJEswAAZU8"]
[Mon Jul 20 06:28:55.508143 2026] [security2:error] [pid 925208:tid 925439] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.git/config"] [unique_id "al4Uh8RX7OrFkv0FyuJEtAAAZT8"]
[Mon Jul 20 06:28:55.508158 2026] [security2:error] [pid 925208:tid 925216] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.aws/credentials"] [unique_id "al4Uh8RX7OrFkv0FyuJEuQAAZQc"]
[Mon Jul 20 06:28:55.508277 2026] [security2:error] [pid 925208:tid 925439] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-json"] [unique_id "al4Uh8RX7OrFkv0FyuJEswAAZU8"]
[Mon Jul 20 06:28:55.719189 2026] [security2:error] [pid 929851:tid 930061] [client 14.225.17.146:51024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh_EAAAANE"], referer: http://bigwormfishing.com/old
[Mon Jul 20 06:28:55.814667 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.76:49238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhmV3ou772CelrLh-0gAAuR4"]
[Mon Jul 20 06:28:55.835241 2026] [security2:error] [pid 925208:tid 925434] [client 104.234.53.80:32141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEwwAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:55.887134 2026] [security2:error] [pid 925208:tid 925245] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4Uh8RX7OrFkv0FyuJExgAAZSQ"]
[Mon Jul 20 06:28:55.887280 2026] [security2:error] [pid 925208:tid 925439] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4Uh8RX7OrFkv0FyuJExgAAZSQ"]
[Mon Jul 20 06:28:55.923925 2026] [security2:error] [pid 925208:tid 925302] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.old"] [unique_id "al4Uh8RX7OrFkv0FyuJEywAAZV0"]
[Mon Jul 20 06:28:55.924678 2026] [security2:error] [pid 925208:tid 925275] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.backup"] [unique_id "al4Uh8RX7OrFkv0FyuJEzQAAZUI"]
[Mon Jul 20 06:28:55.949721 2026] [security2:error] [pid 929851:tid 929994] [client 50.116.65.227:44506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4Uh2V3ou772CelrLh_IwAAAI4"]
[Mon Jul 20 06:28:55.963570 2026] [security2:error] [pid 929851:tid 930054] [client 50.116.65.227:25404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4Uh2V3ou772CelrLh_JQAAAIg"]
[Mon Jul 20 06:28:55.969165 2026] [proxy:error] [pid 929851:tid 930082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.969248 2026] [proxy_http:error] [pid 929851:tid 930082] [client 34.73.38.214:56028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:55.970088 2026] [proxy:error] [pid 929851:tid 930082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.970134 2026] [proxy_http:error] [pid 929851:tid 930082] [client 34.73.38.214:56028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:56.009260 2026] [security2:error] [pid 929851:tid 930105] [client 14.225.17.146:50637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh_GgAAAP0"], referer: http://savilerowtravel.com/old
[Mon Jul 20 06:28:56.044969 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:63752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4UiGV3ou772CelrLh_LAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.151631 2026] [security2:error] [pid 925208:tid 925285] [remote 72.167.132.114:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UiMRX7OrFkv0FyuJE1gAAJUw"]
[Mon Jul 20 06:28:56.195965 2026] [security2:error] [pid 929851:tid 930015] [client 57.141.18.33:33462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhmV3ou772CelrLh-5wAAozs"]
[Mon Jul 20 06:28:56.209037 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_NQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.209162 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_NQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.298304 2026] [security2:error] [pid 925208:tid 925218] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.jeffjaeger.com"] [uri "/graphql"] [unique_id "al4UiMRX7OrFkv0FyuJE3AAAZQk"]
[Mon Jul 20 06:28:56.367408 2026] [security2:error] [pid 929851:tid 929931] [remote 57.141.18.5:32648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5956503"] [unique_id "al4UiGV3ou772CelrLh_PQAA0Es"]
[Mon Jul 20 06:28:56.368300 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:63762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_PgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.368420 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:63762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_PgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.384930 2026] [security2:error] [pid 925208:tid 925246] [remote 72.167.132.114:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UiMRX7OrFkv0FyuJE4QAAWSU"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:28:56.398988 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:51594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_OgAAANU"], referer: https://friendlyspreadsheet.com/old
[Mon Jul 20 06:28:56.410352 2026] [security2:error] [pid 925208:tid 925227] [remote 216.73.216.55:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4UiMRX7OrFkv0FyuJE4wAAbhI"]
[Mon Jul 20 06:28:56.419460 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiMRX7OrFkv0FyuJE5AAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.419591 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiMRX7OrFkv0FyuJE5AAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.445810 2026] [security2:error] [pid 925208:tid 925303] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/api/.env"] [unique_id "al4UiMRX7OrFkv0FyuJE5wAAZV4"]
[Mon Jul 20 06:28:56.472008 2026] [security2:error] [pid 929851:tid 930077] [client 77.110.127.138:63720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UiGV3ou772CelrLh_RQAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.476738 2026] [security2:error] [pid 929851:tid 930018] [client 57.141.18.23:43138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh-9gAApmo"]
[Mon Jul 20 06:28:56.491702 2026] [security2:error] [pid 925208:tid 925334] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.jeffjaeger.com"] [uri "/api/graphql"] [unique_id "al4UiMRX7OrFkv0FyuJE6QAAZX0"]
[Mon Jul 20 06:28:56.504035 2026] [security2:error] [pid 929851:tid 930090] [client 39.48.81.23:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UiGV3ou772CelrLh_SAAAAO4"]
[Mon Jul 20 06:28:56.504166 2026] [security2:error] [pid 929851:tid 930090] [client 39.48.81.23:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UiGV3ou772CelrLh_SAAAAO4"]
[Mon Jul 20 06:28:56.510536 2026] [security2:error] [pid 929851:tid 930026] [client 57.141.18.116:45412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh-9QAArkM"]
[Mon Jul 20 06:28:56.631612 2026] [security2:error] [pid 925208:tid 925300] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/backend/.env"] [unique_id "al4UiMRX7OrFkv0FyuJE9QAAd1s"]
[Mon Jul 20 06:28:56.631737 2026] [security2:error] [pid 925208:tid 925325] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/config/.env"] [unique_id "al4UiMRX7OrFkv0FyuJE9gAAd3Q"]
[Mon Jul 20 06:28:56.778628 2026] [security2:error] [pid 929851:tid 930011] [client 14.225.17.146:50646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_UgAAAJ8"], referer: https://bigwormfishing.com/old
[Mon Jul 20 06:28:56.841226 2026] [security2:error] [pid 925208:tid 925291] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.jeffjaeger.com"] [uri "/v1/graphql"] [unique_id "al4UiMRX7OrFkv0FyuJE_QAAVVI"]
[Mon Jul 20 06:28:57.098223 2026] [security2:error] [pid 929851:tid 930091] [client 14.225.17.146:51114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_XgAAAO8"], referer: https://savilerowtravel.com/old
[Mon Jul 20 06:28:57.162250 2026] [security2:error] [pid 925208:tid 925251] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.docker/config.json"] [unique_id "al4UicRX7OrFkv0FyuJFEAAAZyo"]
[Mon Jul 20 06:28:57.162518 2026] [security2:error] [pid 925208:tid 925441] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.docker/config.json"] [unique_id "al4UicRX7OrFkv0FyuJFEAAAZyo"]
[Mon Jul 20 06:28:57.184854 2026] [security2:error] [pid 929851:tid 930066] [client 157.52.92.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UhWV3ou772CelrLh-rwAAANY"]
[Mon Jul 20 06:28:57.184857 2026] [security2:error] [pid 929851:tid 930036] [client 157.52.92.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UhWV3ou772CelrLh-rgAAALg"]
[Mon Jul 20 06:28:57.295342 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:57.295387 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:58713] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:57.295810 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:57.295832 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:58713] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:57.504328 2026] [security2:error] [pid 925208:tid 925258] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.npmrc"] [unique_id "al4UicRX7OrFkv0FyuJFIQAAcTE"]
[Mon Jul 20 06:28:57.506572 2026] [security2:error] [pid 925208:tid 925313] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/.vscode/launch.json"] [unique_id "al4UicRX7OrFkv0FyuJFIgAAcWg"]
[Mon Jul 20 06:28:57.608817 2026] [security2:error] [pid 925208:tid 925253] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.s3cfg"] [unique_id "al4UicRX7OrFkv0FyuJFLAAAdCw"]
[Mon Jul 20 06:28:57.609008 2026] [security2:error] [pid 925208:tid 925454] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.s3cfg"] [unique_id "al4UicRX7OrFkv0FyuJFLAAAdCw"]
[Mon Jul 20 06:28:57.609325 2026] [authz_core:error] [pid 925208:tid 925276] [remote 34.66.252.77:54426] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 06:28:57.609703 2026] [security2:error] [pid 925208:tid 925335] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.ssh/id_rsa"] [unique_id "al4UicRX7OrFkv0FyuJFJwAAdH4"]
[Mon Jul 20 06:28:57.796790 2026] [security2:error] [pid 925208:tid 925247] [remote 103.75.185.95:47570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UicRX7OrFkv0FyuJFNwAAMyY"]
[Mon Jul 20 06:28:57.796996 2026] [security2:error] [pid 925208:tid 925389] [client 103.75.185.95:47570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UicRX7OrFkv0FyuJFNwAAMyY"]
[Mon Jul 20 06:28:57.864843 2026] [security2:error] [pid 925208:tid 925323] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.ssh/id_dsa"] [unique_id "al4UicRX7OrFkv0FyuJFRAAAWnI"]
[Mon Jul 20 06:28:57.868862 2026] [security2:error] [pid 925208:tid 925237] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/id_rsa"] [unique_id "al4UicRX7OrFkv0FyuJFRgAAIxw"]
[Mon Jul 20 06:28:57.877027 2026] [security2:error] [pid 925208:tid 925316] [remote 176.56.118.182:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UicRX7OrFkv0FyuJFRQAASms"]
[Mon Jul 20 06:28:57.972236 2026] [security2:error] [pid 925208:tid 925257] [remote 95.217.78.234:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UicRX7OrFkv0FyuJFSQAAVDA"]
[Mon Jul 20 06:28:57.994019 2026] [security2:error] [pid 925208:tid 925330] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.ssh/known_hosts"] [unique_id "al4UicRX7OrFkv0FyuJFTAAAAHk"]
[Mon Jul 20 06:28:57.995480 2026] [security2:error] [pid 925208:tid 925333] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4UicRX7OrFkv0FyuJFTwAAAHw"]
[Mon Jul 20 06:28:57.995568 2026] [security2:error] [pid 925208:tid 925338] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4UicRX7OrFkv0FyuJFTwAAAHw"]
[Mon Jul 20 06:28:58.074003 2026] [security2:error] [pid 929851:tid 929865] [remote 167.233.114.32:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UimV3ou772CelrLh_kgAAwwk"]
[Mon Jul 20 06:28:58.074256 2026] [security2:error] [pid 925208:tid 925418] [client 158.173.89.95:32855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UisRX7OrFkv0FyuJFUAAAAFA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:58.169567 2026] [security2:error] [pid 925208:tid 925240] [remote 176.56.118.182:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UisRX7OrFkv0FyuJFUgAARh8"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 06:28:58.206794 2026] [security2:error] [pid 929851:tid 930089] [client 57.141.18.115:30070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UiWV3ou772CelrLh_aAAA7XI"]
[Mon Jul 20 06:28:58.215951 2026] [security2:error] [pid 925208:tid 925222] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/privatekey.key"] [unique_id "al4UisRX7OrFkv0FyuJFVwAAGQ0"]
[Mon Jul 20 06:28:58.216247 2026] [security2:error] [pid 925208:tid 925320] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/key.pem"] [unique_id "al4UisRX7OrFkv0FyuJFVgAAGW8"]
[Mon Jul 20 06:28:58.257787 2026] [security2:error] [pid 925208:tid 925242] [remote 95.217.78.234:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UisRX7OrFkv0FyuJFWQAAayE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:58.344684 2026] [security2:error] [pid 925208:tid 925216] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/localhost.key"] [unique_id "al4UisRX7OrFkv0FyuJFZwAAaAc"]
[Mon Jul 20 06:28:58.344878 2026] [security2:error] [pid 925208:tid 925442] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/localhost.key"] [unique_id "al4UisRX7OrFkv0FyuJFZwAAaAc"]
[Mon Jul 20 06:28:58.389191 2026] [security2:error] [pid 929851:tid 929966] [remote 167.233.114.32:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UimV3ou772CelrLh_qgAA024"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:28:58.546973 2026] [security2:error] [pid 925208:tid 925259] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.aider.conf.yml"] [unique_id "al4UisRX7OrFkv0FyuJFdAAADjI"]
[Mon Jul 20 06:28:58.609371 2026] [security2:error] [pid 925208:tid 925267] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.hermes/.env"] [unique_id "al4UisRX7OrFkv0FyuJFdwAAPjo"]
[Mon Jul 20 06:28:58.609459 2026] [security2:error] [pid 925208:tid 925302] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.openclaw/.env"] [unique_id "al4UisRX7OrFkv0FyuJFeAAAPl0"]
[Mon Jul 20 06:28:58.622209 2026] [security2:error] [pid 929851:tid 930041] [client 119.8.170.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_XQAAvVk"], referer: https://www.aleishapenny.ca/listing/page/1140?paged=1140&view=list
[Mon Jul 20 06:28:58.758013 2026] [security2:error] [pid 925208:tid 925393] [client 77.110.127.138:63784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UisRX7OrFkv0FyuJFggAAADc"]
[Mon Jul 20 06:28:58.864385 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:63710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/amp0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4UisRX7OrFkv0FyuJFhgAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.012695 2026] [security2:error] [pid 929851:tid 930056] [client 171.61.165.146:13954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ui2V3ou772CelrLh_0gAAAMw"]
[Mon Jul 20 06:28:59.020894 2026] [security2:error] [pid 929851:tid 930056] [client 171.61.165.146:13954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ui2V3ou772CelrLh_0gAAAMw"]
[Mon Jul 20 06:28:59.026586 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_0wAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.026701 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_0wAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.060850 2026] [security2:error] [pid 925208:tid 925332] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.bashrc"] [unique_id "al4Ui8RX7OrFkv0FyuJFkgAAdns"]
[Mon Jul 20 06:28:59.109758 2026] [security2:error] [pid 925208:tid 925262] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-config.php.old"] [unique_id "al4Ui8RX7OrFkv0FyuJFkwAAdjU"]
[Mon Jul 20 06:28:59.109868 2026] [security2:error] [pid 925208:tid 925236] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-config.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFlAAAdhs"]
[Mon Jul 20 06:28:59.110023 2026] [security2:error] [pid 925208:tid 925278] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.profile"] [unique_id "al4Ui8RX7OrFkv0FyuJFlQAAdkU"]
[Mon Jul 20 06:28:59.188825 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:63788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui8RX7OrFkv0FyuJFmgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.188938 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:63788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui8RX7OrFkv0FyuJFmgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.340719 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:63789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_6QAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.340834 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:63789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_6QAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.382440 2026] [security2:error] [pid 925208:tid 925235] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/laravel/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFpQAAdho"]
[Mon Jul 20 06:28:59.382463 2026] [security2:error] [pid 925208:tid 925280] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFpgAAdkc"]
[Mon Jul 20 06:28:59.393809 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:63750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1 OR 468. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 468 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ui2V3ou772CelrLh_7wAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.422074 2026] [security2:error] [pid 925208:tid 925318] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/config/.env.php"] [unique_id "al4Ui8RX7OrFkv0FyuJFpwAAdm0"]
[Mon Jul 20 06:28:59.547745 2026] [security2:error] [pid 925208:tid 925239] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/configuration.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFrQAAdh4"]
[Mon Jul 20 06:28:59.561491 2026] [security2:error] [pid 925208:tid 925270] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.swp"] [unique_id "al4Ui8RX7OrFkv0FyuJFrgAAdj0"]
[Mon Jul 20 06:28:59.563164 2026] [security2:error] [pid 925208:tid 925234] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/core/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFrwAAdhk"]
[Mon Jul 20 06:28:59.566552 2026] [security2:error] [pid 925208:tid 925265] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/config.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFsQAAdjg"]
[Mon Jul 20 06:28:59.566898 2026] [security2:error] [pid 925208:tid 925292] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/web/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFsAAAdlM"]
[Mon Jul 20 06:28:59.589257 2026] [security2:error] [pid 925208:tid 925243] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/public/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFtAAAdiI"]
[Mon Jul 20 06:28:59.847659 2026] [security2:error] [pid 929851:tid 930074] [client 57.141.18.125:55326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UimV3ou772CelrLh_rwAA3iU"]
[Mon Jul 20 06:28:59.906162 2026] [security2:error] [pid 925208:tid 925279] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/bootstrap.properties"] [unique_id "al4Ui8RX7OrFkv0FyuJFwgAAdkY"]
[Mon Jul 20 06:28:59.906333 2026] [security2:error] [pid 925208:tid 925456] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/bootstrap.properties"] [unique_id "al4Ui8RX7OrFkv0FyuJFwgAAdkY"]
[Mon Jul 20 06:28:59.915783 2026] [security2:error] [pid 929851:tid 930080] [client 34.73.38.214:55021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Ui2V3ou772CelrLiADQAAAOQ"]
[Mon Jul 20 06:29:00.005439 2026] [security2:error] [pid 929851:tid 930045] [client 14.225.17.146:62448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLiADAAAAME"], referer: http://39ishlife.com/old
[Mon Jul 20 06:29:00.010616 2026] [security2:error] [pid 929851:tid 930044] [client 14.225.17.146:64753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4UimV3ou772CelrLh_wwAAAMA"], referer: http://northbrookcpa.ca/old
[Mon Jul 20 06:29:00.063187 2026] [security2:error] [pid 929851:tid 929905] [remote 195.26.244.42:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UjGV3ou772CelrLiAFgAA_zE"]
[Mon Jul 20 06:29:00.222815 2026] [security2:error] [pid 929851:tid 929891] [remote 57.141.18.3:20614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4UjGV3ou772CelrLiAHwABASM"]
[Mon Jul 20 06:29:00.274539 2026] [security2:error] [pid 929851:tid 930089] [client 112.208.70.94:45668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiAIQAAAO0"]
[Mon Jul 20 06:29:00.274692 2026] [security2:error] [pid 929851:tid 930089] [client 112.208.70.94:45668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiAIQAAAO0"]
[Mon Jul 20 06:29:00.319479 2026] [security2:error] [pid 929851:tid 929926] [remote 195.26.244.42:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UjGV3ou772CelrLiAJAAAhkY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:00.410088 2026] [security2:error] [pid 925208:tid 925323] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/web.config"] [unique_id "al4UjMRX7OrFkv0FyuJF4AAAdnI"]
[Mon Jul 20 06:29:00.480644 2026] [security2:error] [pid 925208:tid 925315] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/appsettings.Production.json"] [unique_id "al4UjMRX7OrFkv0FyuJF4gAAdmo"]
[Mon Jul 20 06:29:00.481713 2026] [security2:error] [pid 929851:tid 930060] [client 57.141.18.23:43140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLh_4AAA0Ac"]
[Mon Jul 20 06:29:00.616257 2026] [security2:error] [pid 929851:tid 930021] [client 106.219.188.178:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiANgAAAKk"]
[Mon Jul 20 06:29:00.618984 2026] [security2:error] [pid 929851:tid 930021] [client 106.219.188.178:20187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiANgAAAKk"]
[Mon Jul 20 06:29:00.647526 2026] [security2:error] [pid 925208:tid 925240] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/local.settings.json"] [unique_id "al4UjMRX7OrFkv0FyuJF7QAAdh8"]
[Mon Jul 20 06:29:00.684884 2026] [security2:error] [pid 929851:tid 930015] [client 34.73.38.214:50869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UjGV3ou772CelrLiAOwAAAKM"]
[Mon Jul 20 06:29:00.746982 2026] [security2:error] [pid 929851:tid 929990] [client 57.141.18.73:27772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLh_9gAAimw"]
[Mon Jul 20 06:29:00.777845 2026] [security2:error] [pid 929851:tid 930017] [client 77.110.127.138:63798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/amp0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4UjGV3ou772CelrLiAQQAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.869613 2026] [security2:error] [pid 929851:tid 929997] [client 57.141.18.43:21516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLh_-AAAkTM"]
[Mon Jul 20 06:29:00.891617 2026] [security2:error] [pid 929851:tid 930086] [client 104.234.53.52:36377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UjGV3ou772CelrLiARAAAAOo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:00.934061 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjMRX7OrFkv0FyuJF-AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.934175 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:63799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjMRX7OrFkv0FyuJF-AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.984499 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjGV3ou772CelrLiASwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.984620 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjGV3ou772CelrLiASwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:01.006461 2026] [security2:error] [pid 929851:tid 930010] [client 14.225.17.146:56612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4UjGV3ou772CelrLiARgAAAJ4"], referer: https://39ishlife.com/old
[Mon Jul 20 06:29:01.007864 2026] [fcgid:warn] [pid 925208:tid 925459] (70014)End of file found: [client 66.132.195.53:60508] mod_fcgid: can't get data from http client
[Mon Jul 20 06:29:01.276136 2026] [security2:error] [pid 925208:tid 925331] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/server/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGDQAAdno"]
[Mon Jul 20 06:29:01.276172 2026] [security2:error] [pid 925208:tid 925248] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/app/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGDAAAdic"]
[Mon Jul 20 06:29:01.276235 2026] [security2:error] [pid 925208:tid 925310] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/dev/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGCgAAdmU"]
[Mon Jul 20 06:29:01.276337 2026] [security2:error] [pid 925208:tid 925268] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/frontend/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGCwAAdjs"]
[Mon Jul 20 06:29:01.294299 2026] [security2:error] [pid 925208:tid 925261] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/src/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGEQAAdjQ"]
[Mon Jul 20 06:29:01.439868 2026] [security2:error] [pid 925208:tid 925296] [remote 216.73.216.55:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4UjcRX7OrFkv0FyuJGHgAAOFc"]
[Mon Jul 20 06:29:01.449884 2026] [security2:error] [pid 925208:tid 925252] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/production/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGIgAAdis"]
[Mon Jul 20 06:29:01.450132 2026] [security2:error] [pid 925208:tid 925309] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/staging/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGIwAAdmQ"]
[Mon Jul 20 06:29:01.450154 2026] [security2:error] [pid 925208:tid 925336] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.production.bak"] [unique_id "al4UjcRX7OrFkv0FyuJGHwAAdn8"]
[Mon Jul 20 06:29:01.450283 2026] [security2:error] [pid 925208:tid 925319] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/docker/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGIAAAdm4"]
[Mon Jul 20 06:29:01.450804 2026] [security2:error] [pid 925208:tid 925285] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.prod.bak"] [unique_id "al4UjcRX7OrFkv0FyuJGIQAAdkw"]
[Mon Jul 20 06:29:01.569012 2026] [security2:error] [pid 925208:tid 925401] [client 14.225.17.146:62469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4UjMRX7OrFkv0FyuJF2QAAAD8"]
[Mon Jul 20 06:29:01.585961 2026] [security2:error] [pid 925208:tid 925306] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/@fs/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGKAAAdmE"]
[Mon Jul 20 06:29:01.598938 2026] [security2:error] [pid 929851:tid 929988] [client 104.210.140.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cathybuffini.com"] [uri "/index.php"] [unique_id "al4UjGV3ou772CelrLiAMgAAAIg"]
[Mon Jul 20 06:29:01.642436 2026] [security2:error] [pid 925208:tid 925332] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/keys/service-account.json"] [unique_id "al4UjcRX7OrFkv0FyuJGKwAAdns"]
[Mon Jul 20 06:29:01.642491 2026] [security2:error] [pid 925208:tid 925305] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/sa.json"] [unique_id "al4UjcRX7OrFkv0FyuJGLQAAdmA"]
[Mon Jul 20 06:29:01.642738 2026] [security2:error] [pid 925208:tid 925456] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/sa.json"] [unique_id "al4UjcRX7OrFkv0FyuJGLQAAdmA"]
[Mon Jul 20 06:29:01.644020 2026] [security2:error] [pid 925208:tid 925227] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/@fs/root/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGLgAAdhI"]
[Mon Jul 20 06:29:01.644180 2026] [security2:error] [pid 925208:tid 925246] [remote 34.66.252.77:54426] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "dashboard.jeffjaeger.com"] [uri "/@fs/proc/self/environ"] [unique_id "al4UjcRX7OrFkv0FyuJGMAAAdiU"]
[Mon Jul 20 06:29:01.824785 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjWV3ou772CelrLiAdgAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:01.824869 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjWV3ou772CelrLiAdgAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:01.882248 2026] [security2:error] [pid 929851:tid 929999] [client 77.110.127.138:63764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1) OR 454. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 454 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UjWV3ou772CelrLiAeQAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:02.235436 2026] [security2:error] [pid 925208:tid 925352] [client 57.141.18.117:50494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjMRX7OrFkv0FyuJF9gAADlk"]
[Mon Jul 20 06:29:02.388401 2026] [security2:error] [pid 929851:tid 930020] [client 50.116.65.227:50064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UjmV3ou772CelrLiAoAAAAKg"]
[Mon Jul 20 06:29:02.399194 2026] [security2:error] [pid 929851:tid 930059] [client 50.116.65.227:50066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UjmV3ou772CelrLiAoQAAAM8"]
[Mon Jul 20 06:29:02.432999 2026] [security2:error] [pid 925208:tid 925347] [client 34.73.38.214:62388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UjsRX7OrFkv0FyuJGQgAAAAk"]
[Mon Jul 20 06:29:02.556853 2026] [security2:error] [pid 929851:tid 929864] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/config.json"] [unique_id "al4UjmV3ou772CelrLiAswAAwQg"]
[Mon Jul 20 06:29:02.807380 2026] [security2:error] [pid 929851:tid 929963] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/env.json"] [unique_id "al4UjmV3ou772CelrLiAzAAAwWs"]
[Mon Jul 20 06:29:02.886952 2026] [security2:error] [pid 929851:tid 930021] [client 223.109.252.223:54666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2014/02/mezza41-300x300.jpg"] [unique_id "al4UjmV3ou772CelrLiA1AAAAKk"]
[Mon Jul 20 06:29:02.887094 2026] [security2:error] [pid 929851:tid 930021] [client 223.109.252.223:54666] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2014/02/mezza41-300x300.jpg"] [unique_id "al4UjmV3ou772CelrLiA1AAAAKk"]
[Mon Jul 20 06:29:02.941404 2026] [security2:error] [pid 929851:tid 930079] [client 50.116.65.227:50090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiAxwAAAOM"]
[Mon Jul 20 06:29:03.122983 2026] [security2:error] [pid 929851:tid 930033] [client 50.116.65.227:50094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiA2QAAALU"]
[Mon Jul 20 06:29:03.128833 2026] [security2:error] [pid 929851:tid 930056] [client 104.248.167.239:43176] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phillipbloch.com"] [uri "/"] [unique_id "al4Uj2V3ou772CelrLiA4QAAAMw"]
[Mon Jul 20 06:29:03.247276 2026] [security2:error] [pid 929851:tid 930095] [client 57.141.18.10:26480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjWV3ou772CelrLiAewAA8yQ"]
[Mon Jul 20 06:29:03.382714 2026] [security2:error] [pid 929851:tid 929940] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/openapi.json"] [unique_id "al4Uj2V3ou772CelrLiA-QAAwVQ"]
[Mon Jul 20 06:29:03.382926 2026] [security2:error] [pid 929851:tid 930045] [client 34.66.252.77:54436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/openapi.json"] [unique_id "al4Uj2V3ou772CelrLiA-QAAwVQ"]
[Mon Jul 20 06:29:03.560991 2026] [security2:error] [pid 929851:tid 930055] [client 57.141.18.21:31996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiAjgAAyzs"]
[Mon Jul 20 06:29:03.753893 2026] [security2:error] [pid 929851:tid 929896] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/app-config.json"] [unique_id "al4Uj2V3ou772CelrLiBGQAApCg"]
[Mon Jul 20 06:29:03.791876 2026] [security2:error] [pid 929851:tid 930087] [client 106.8.138.135:50369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiA3wAAAOs"], referer: http://bandsir.com/
[Mon Jul 20 06:29:03.841580 2026] [security2:error] [pid 929851:tid 929993] [client 114.119.137.237:36211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4Uj2V3ou772CelrLiBIgAAAI0"], referer: https://newstral.com/en/article/en/953742537/gonzales-middle-teacher-receives-ascension-fund-grant
[Mon Jul 20 06:29:03.870162 2026] [security2:error] [pid 929851:tid 929861] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/api/v1/env"] [unique_id "al4Uj2V3ou772CelrLiBJAAA4gU"]
[Mon Jul 20 06:29:03.921456 2026] [security2:error] [pid 925208:tid 925343] [client 34.73.38.214:61772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Uj8RX7OrFkv0FyuJGXgAAAAU"]
[Mon Jul 20 06:29:03.928702 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.107:38730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiAxQAA20E"]
[Mon Jul 20 06:29:04.028421 2026] [security2:error] [pid 929851:tid 929885] [remote 209.121.27.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiBGwAA_R0"]
[Mon Jul 20 06:29:04.086742 2026] [security2:error] [pid 925208:tid 925386] [client 57.141.18.121:29576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjsRX7OrFkv0FyuJGSgAAMBo"]
[Mon Jul 20 06:29:04.213966 2026] [security2:error] [pid 929851:tid 929907] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/ngsw.json"] [unique_id "al4UkGV3ou772CelrLiBRAAAkzM"]
[Mon Jul 20 06:29:04.214110 2026] [security2:error] [pid 929851:tid 929999] [client 34.66.252.77:54436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/ngsw.json"] [unique_id "al4UkGV3ou772CelrLiBRAAAkzM"]
[Mon Jul 20 06:29:04.215013 2026] [security2:error] [pid 929851:tid 929964] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/service-worker.js"] [unique_id "al4UkGV3ou772CelrLiBQQAAk2w"]
[Mon Jul 20 06:29:04.357361 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBUAAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.357504 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBUAAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.405233 2026] [security2:error] [pid 929851:tid 930000] [client 57.141.18.8:26030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiA8gAAlHk"]
[Mon Jul 20 06:29:04.514132 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBXgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.514237 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBXgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.572597 2026] [security2:error] [pid 929851:tid 929938] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/test.php"] [unique_id "al4UkGV3ou772CelrLiBZgAAklI"]
[Mon Jul 20 06:29:04.575252 2026] [security2:error] [pid 925208:tid 925458] [client 57.141.18.64:40058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uj8RX7OrFkv0FyuJGXAAAeD0"]
[Mon Jul 20 06:29:04.579310 2026] [security2:error] [pid 929851:tid 929920] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/phpinfo.php"] [unique_id "al4UkGV3ou772CelrLiBaAAAq0A"]
[Mon Jul 20 06:29:04.592971 2026] [security2:error] [pid 929851:tid 929912] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/pi.php"] [unique_id "al4UkGV3ou772CelrLiBaQAAjDg"]
[Mon Jul 20 06:29:04.603322 2026] [security2:error] [pid 929851:tid 929870] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/info.php"] [unique_id "al4UkGV3ou772CelrLiBdAAApg4"]
[Mon Jul 20 06:29:04.603527 2026] [security2:error] [pid 929851:tid 929953] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/i.php"] [unique_id "al4UkGV3ou772CelrLiBdwAApmE"]
[Mon Jul 20 06:29:04.676946 2026] [security2:error] [pid 925208:tid 925362] [client 171.60.139.123:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UkMRX7OrFkv0FyuJGegAAABg"]
[Mon Jul 20 06:29:04.677124 2026] [security2:error] [pid 925208:tid 925362] [client 171.60.139.123:49424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UkMRX7OrFkv0FyuJGegAAABg"]
[Mon Jul 20 06:29:04.682137 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:63824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBlgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.682225 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:63824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBlgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.727635 2026] [security2:error] [pid 929851:tid 930001] [client 57.141.18.91:32220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiBEAAAlVA"]
[Mon Jul 20 06:29:04.832003 2026] [security2:error] [pid 929851:tid 930054] [client 77.110.127.138:63825] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1)) OR 372. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 372 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UkGV3ou772CelrLiBrAAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.850496 2026] [security2:error] [pid 929851:tid 929915] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/app_dev.php/_profiler"] [unique_id "al4UkGV3ou772CelrLiBrwAAkzs"]
[Mon Jul 20 06:29:04.851224 2026] [security2:error] [pid 929851:tid 929958] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/app_dev.php"] [unique_id "al4UkGV3ou772CelrLiBtQAAk2Y"]
[Mon Jul 20 06:29:04.852430 2026] [security2:error] [pid 929851:tid 929906] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/trace.axd"] [unique_id "al4UkGV3ou772CelrLiBsgAAkzI"]
[Mon Jul 20 06:29:04.904643 2026] [access_compat:error] [pid 929851:tid 929857] [remote 34.66.252.77:54436] AH01797: client denied by server configuration: /var/www/html/server-status
[Mon Jul 20 06:29:04.979071 2026] [security2:error] [pid 929851:tid 929896] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/server-info"] [unique_id "al4UkGV3ou772CelrLiBxgAA8ig"]
[Mon Jul 20 06:29:04.999035 2026] [security2:error] [pid 929851:tid 929894] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/nginx_status"] [unique_id "al4UkGV3ou772CelrLiByQAAlCY"]
[Mon Jul 20 06:29:04.999300 2026] [security2:error] [pid 929851:tid 930000] [client 34.66.252.77:54436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/nginx_status"] [unique_id "al4UkGV3ou772CelrLiByQAAlCY"]
[Mon Jul 20 06:29:05.059086 2026] [security2:error] [pid 929851:tid 930026] [client 98.159.234.160:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UkWV3ou772CelrLiBzQAAAK4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:05.157081 2026] [security2:error] [pid 929851:tid 929987] [client 223.185.13.213:31164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UkWV3ou772CelrLiB0AAAAIc"]
[Mon Jul 20 06:29:05.157181 2026] [security2:error] [pid 929851:tid 929987] [client 223.185.13.213:31164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UkWV3ou772CelrLiB0AAAAIc"]
[Mon Jul 20 06:29:05.288178 2026] [security2:error] [pid 925208:tid 925213] [remote 97.74.93.24:52980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UkcRX7OrFkv0FyuJGiQAAOQQ"]
[Mon Jul 20 06:29:05.412018 2026] [security2:error] [pid 925208:tid 925211] [remote 152.228.213.32:46332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UkcRX7OrFkv0FyuJGjwAALgI"]
[Mon Jul 20 06:29:05.566145 2026] [security2:error] [pid 929851:tid 930097] [client 104.207.61.204:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UkWV3ou772CelrLiB5QAAAPU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:05.598992 2026] [security2:error] [pid 925208:tid 925313] [remote 152.228.213.32:46332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UkcRX7OrFkv0FyuJGmgAAA2g"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:29:05.703186 2026] [security2:error] [pid 929851:tid 930028] [client 57.141.18.71:33906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UkGV3ou772CelrLiBigAAsFU"]
[Mon Jul 20 06:29:05.752381 2026] [security2:error] [pid 929851:tid 929974] [remote 167.233.114.32:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UkWV3ou772CelrLiB_AAA-nY"]
[Mon Jul 20 06:29:05.930184 2026] [security2:error] [pid 929851:tid 930072] [client 14.225.17.146:56470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiB_gAAANw"], referer: http://ghivs.com/old
[Mon Jul 20 06:29:05.960643 2026] [security2:error] [pid 929851:tid 929979] [remote 167.233.114.32:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UkWV3ou772CelrLiCBwAA5Xs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:06.038337 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCEAAAAQQ"]
[Mon Jul 20 06:29:06.038469 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:56725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCEAAAAQQ"]
[Mon Jul 20 06:29:06.038744 2026] [security2:error] [pid 925208:tid 925294] [remote 97.74.93.24:52980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UksRX7OrFkv0FyuJGqQAAS1U"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:29:06.059793 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCFAAAAPk"]
[Mon Jul 20 06:29:06.059937 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:58414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCFAAAAPk"]
[Mon Jul 20 06:29:06.164212 2026] [security2:error] [pid 929851:tid 930083] [client 45.3.45.220:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UkmV3ou772CelrLiCGAAAAOc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:06.309070 2026] [security2:error] [pid 925208:tid 925382] [client 14.225.17.146:51422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4UksRX7OrFkv0FyuJGrwAAACw"], referer: http://whiteoutcb.com/old
[Mon Jul 20 06:29:06.465528 2026] [security2:error] [pid 925208:tid 925462] [client 34.73.38.214:58583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UksRX7OrFkv0FyuJGtAAAAHw"]
[Mon Jul 20 06:29:06.578341 2026] [security2:error] [pid 929851:tid 930058] [client 74.7.230.44:55552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4UkmV3ou772CelrLiCLAAAzgQ"]
[Mon Jul 20 06:29:06.650811 2026] [security2:error] [pid 929851:tid 930036] [client 57.141.18.116:59598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiB3wAAuEc"]
[Mon Jul 20 06:29:06.656932 2026] [security2:error] [pid 929851:tid 929897] [remote 102.134.101.35:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UkmV3ou772CelrLiCMgAAqyk"]
[Mon Jul 20 06:29:07.094773 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UkmV3ou772CelrLiCNgAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.142907 2026] [security2:error] [pid 929851:tid 929929] [remote 102.134.101.35:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Uk2V3ou772CelrLiCTgAAmUk"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:29:07.224558 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.224674 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.282125 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.282259 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.334665 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCWQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.334818 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCWQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.386967 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:63814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1G0cZ0do9' OR 47. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 47 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Uk2V3ou772CelrLiCXAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.423814 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCYgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.423947 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCYgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.459677 2026] [security2:error] [pid 929851:tid 930089] [client 213.152.162.79:35872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Uk2V3ou772CelrLiCZQAAAO0"]
[Mon Jul 20 06:29:07.459780 2026] [security2:error] [pid 929851:tid 930089] [client 213.152.162.79:35872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Uk2V3ou772CelrLiCZQAAAO0"]
[Mon Jul 20 06:29:07.502299 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCawAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.502430 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCawAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.585733 2026] [security2:error] [pid 929851:tid 930029] [client 45.3.55.217:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Uk2V3ou772CelrLiCbgAAALE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:07.626842 2026] [security2:error] [pid 929851:tid 930075] [client 14.225.17.146:51406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiCAwAAAN8"], referer: http://according2plant.com/old
[Mon Jul 20 06:29:07.654310 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:63854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG2QAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.654465 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:63854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG2QAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.672907 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:63855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCeAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.673011 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:63855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCeAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.760078 2026] [security2:error] [pid 925208:tid 925320] [remote 74.235.96.117:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG2gAAQW8"]
[Mon Jul 20 06:29:07.771425 2026] [security2:error] [pid 929851:tid 930079] [client 104.234.53.65:58319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Uk2V3ou772CelrLiCfgAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:07.783527 2026] [security2:error] [pid 929851:tid 930047] [client 14.225.17.146:56621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiB9wAAAMM"], referer: http://mollycahill.com/old
[Mon Jul 20 06:29:07.821467 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCgAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.821583 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCgAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.852452 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiChAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.852614 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiChAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.939596 2026] [security2:error] [pid 925208:tid 925242] [remote 74.235.96.117:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG3gAAGyE"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:29:07.968520 2026] [security2:error] [pid 925208:tid 925427] [client 57.141.18.100:31576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UksRX7OrFkv0FyuJGuAAAWUQ"]
[Mon Jul 20 06:29:07.981390 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCjQAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.981525 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCjQAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.992731 2026] [core:error] [pid 929851:tid 929995] [client 103.153.183.69:41802] AH10244: invalid URI path (/%2e%2e/.env?_=3r1d02sa&v=21mjx), referer: https://twitter.com/
[Mon Jul 20 06:29:08.034504 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:63860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiClAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:08.034593 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:63860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiClAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:08.111635 2026] [security2:error] [pid 929851:tid 929971] [remote 160.187.68.132:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UlGV3ou772CelrLiCmAAA9HM"]
[Mon Jul 20 06:29:08.124492 2026] [security2:error] [pid 929851:tid 930073] [client 14.225.17.146:62388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4UkmV3ou772CelrLiCJgAAAN0"], referer: http://swafforddetailing.com/old
[Mon Jul 20 06:29:08.220949 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCrAAAAPE"]
[Mon Jul 20 06:29:08.221046 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCrAAAAPE"]
[Mon Jul 20 06:29:08.339037 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCswAAAIc"]
[Mon Jul 20 06:29:08.339150 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCswAAAIc"]
[Mon Jul 20 06:29:08.373667 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCtgAAAOc"]
[Mon Jul 20 06:29:08.373796 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCtgAAAOc"]
[Mon Jul 20 06:29:08.430801 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlMRX7OrFkv0FyuJG6QAAAFU"]
[Mon Jul 20 06:29:08.430947 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlMRX7OrFkv0FyuJG6QAAAFU"]
[Mon Jul 20 06:29:08.613804 2026] [security2:error] [pid 929851:tid 930048] [client 39.48.81.23:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UlGV3ou772CelrLiCwgAAAMQ"]
[Mon Jul 20 06:29:08.613923 2026] [security2:error] [pid 929851:tid 930048] [client 39.48.81.23:56848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UlGV3ou772CelrLiCwgAAAMQ"]
[Mon Jul 20 06:29:08.619511 2026] [security2:error] [pid 929851:tid 929866] [remote 160.187.68.132:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UlGV3ou772CelrLiCwQAAqAo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:29:08.780712 2026] [security2:error] [pid 925208:tid 925358] [client 34.73.38.214:55326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UlMRX7OrFkv0FyuJG9QAAABQ"]
[Mon Jul 20 06:29:08.873491 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:62285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4Uk2V3ou772CelrLiCcAAAANU"], referer: http://elitetax-mi.com/old
[Mon Jul 20 06:29:09.094497 2026] [security2:error] [pid 925208:tid 925418] [client 14.225.17.146:56324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4UlMRX7OrFkv0FyuJG-wAAAFA"]
[Mon Jul 20 06:29:09.205810 2026] [security2:error] [pid 925208:tid 925354] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UlMRX7OrFkv0FyuJHBAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:09.494056 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlWV3ou772CelrLiC6QAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:09.494194 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlWV3ou772CelrLiC6QAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:09.703388 2026] [security2:error] [pid 929851:tid 930012] [client 57.141.18.59:62880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlGV3ou772CelrLiCrgAAoDo"]
[Mon Jul 20 06:29:09.775299 2026] [security2:error] [pid 929851:tid 930042] [client 57.141.18.16:60922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlGV3ou772CelrLiCtQAAvg8"]
[Mon Jul 20 06:29:09.834461 2026] [security2:error] [pid 925208:tid 925331] [remote 186.10.194.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4UlcRX7OrFkv0FyuJHFwAAMHo"], referer: https://tiokubito.cl/page/3/?s=%2B18&post_type=product
[Mon Jul 20 06:29:10.029607 2026] [security2:error] [pid 925208:tid 925421] [client 171.61.165.146:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UlsRX7OrFkv0FyuJHIwAAAFM"]
[Mon Jul 20 06:29:10.029703 2026] [security2:error] [pid 925208:tid 925421] [client 171.61.165.146:10185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UlsRX7OrFkv0FyuJHIwAAAFM"]
[Mon Jul 20 06:29:10.099000 2026] [security2:error] [pid 929851:tid 929899] [remote 130.185.118.215:44160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UlmV3ou772CelrLiDDgAA3Ss"]
[Mon Jul 20 06:29:10.297482 2026] [security2:error] [pid 929851:tid 929943] [remote 130.185.118.215:44160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UlmV3ou772CelrLiDJAAA71c"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:29:10.630674 2026] [security2:error] [pid 929851:tid 930070] [client 77.110.127.138:63883] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1JOB0LpeT') OR 771. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 771 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UlmV3ou772CelrLiDRAAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.062578 2026] [security2:error] [pid 929851:tid 930056] [client 34.73.38.214:64960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ul2V3ou772CelrLiDcgAAAMw"]
[Mon Jul 20 06:29:11.158628 2026] [security2:error] [pid 929851:tid 930090] [client 57.141.18.80:33016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlWV3ou772CelrLiC9wAA7lk"]
[Mon Jul 20 06:29:11.291274 2026] [security2:error] [pid 929851:tid 930096] [client 106.219.188.178:27751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ul2V3ou772CelrLiDgQAAAPQ"]
[Mon Jul 20 06:29:11.291386 2026] [security2:error] [pid 929851:tid 930096] [client 106.219.188.178:27751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ul2V3ou772CelrLiDgQAAAPQ"]
[Mon Jul 20 06:29:11.366137 2026] [security2:error] [pid 929851:tid 930060] [client 103.153.183.69:33744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4Ul2V3ou772CelrLiDjAAAANA"], referer: https://duckduckgo.com/?q=5q9yk
[Mon Jul 20 06:29:11.459977 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDkgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.460135 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDkgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.472589 2026] [security2:error] [pid 929851:tid 930086] [client 74.208.214.194:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Ul2V3ou772CelrLiDlQAAAOo"]
[Mon Jul 20 06:29:11.612758 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDngAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.612849 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDngAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.675471 2026] [security2:error] [pid 929851:tid 930010] [client 57.141.18.30:65110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlmV3ou772CelrLiDKwAAniY"]
[Mon Jul 20 06:29:12.108005 2026] [security2:error] [pid 929851:tid 929959] [remote 95.217.78.234:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UmGV3ou772CelrLiDxAAA8Gc"]
[Mon Jul 20 06:29:12.385151 2026] [security2:error] [pid 929851:tid 929886] [remote 95.217.78.234:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UmGV3ou772CelrLiD4gABAB4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:29:12.425626 2026] [security2:error] [pid 929851:tid 929987] [client 34.73.38.214:64125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UmGV3ou772CelrLiD6AAAAIc"]
[Mon Jul 20 06:29:12.452818 2026] [security2:error] [pid 929851:tid 930028] [client 47.128.37.62:56884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dollpassionista.com"] [uri "/robots.txt"] [unique_id "al4UmGV3ou772CelrLiD7wAAALA"]
[Mon Jul 20 06:29:12.741015 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiD9wAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:12.856166 2026] [security2:error] [pid 929851:tid 929889] [remote 91.142.222.105:48226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4UmGV3ou772CelrLiECgAAwCE"]
[Mon Jul 20 06:29:12.864543 2026] [security2:error] [pid 929851:tid 930006] [client 112.208.70.94:42090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UmGV3ou772CelrLiEDwAAAJo"]
[Mon Jul 20 06:29:12.864739 2026] [security2:error] [pid 929851:tid 930006] [client 112.208.70.94:42090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UmGV3ou772CelrLiEDwAAAJo"]
[Mon Jul 20 06:29:12.998160 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UmGV3ou772CelrLiEGwAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:12.998279 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UmGV3ou772CelrLiEGwAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:13.130523 2026] [security2:error] [pid 929851:tid 929970] [remote 91.142.222.105:48226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4UmWV3ou772CelrLiEIwABA3I"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:29:13.271546 2026] [security2:error] [pid 929851:tid 930005] [client 223.185.13.213:2277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiEMAAAAJk"]
[Mon Jul 20 06:29:13.271680 2026] [security2:error] [pid 929851:tid 930005] [client 223.185.13.213:2277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiEMAAAAJk"]
[Mon Jul 20 06:29:13.280816 2026] [security2:error] [pid 929851:tid 930109] [client 14.225.17.146:64970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Ul2V3ou772CelrLiDowAAAQE"], referer: http://headachescarpaltunnelfibromyalgia.com/old
[Mon Jul 20 06:29:13.310213 2026] [security2:error] [pid 929851:tid 930009] [client 50.116.65.227:11176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UmWV3ou772CelrLiEMQAAAJ0"]
[Mon Jul 20 06:29:13.321707 2026] [security2:error] [pid 929851:tid 930071] [client 50.116.65.227:11180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UmWV3ou772CelrLiEMwAAANs"]
[Mon Jul 20 06:29:13.338413 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.43:40600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiD3gAAwUs"]
[Mon Jul 20 06:29:13.389743 2026] [security2:error] [pid 929851:tid 930043] [client 165.165.114.112:6090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiDvwAAAL8"]
[Mon Jul 20 06:29:13.469562 2026] [security2:error] [pid 929851:tid 929940] [remote 91.142.222.105:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UmWV3ou772CelrLiESAAAhVQ"]
[Mon Jul 20 06:29:13.540061 2026] [security2:error] [pid 929851:tid 930104] [client 65.1.132.125:41130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiESwAAAPw"]
[Mon Jul 20 06:29:13.540165 2026] [security2:error] [pid 929851:tid 930104] [client 65.1.132.125:41130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiESwAAAPw"]
[Mon Jul 20 06:29:13.738259 2026] [security2:error] [pid 929851:tid 929925] [remote 91.142.222.105:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UmWV3ou772CelrLiEXAAA6UU"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:29:13.945270 2026] [security2:error] [pid 929851:tid 930005] [client 216.73.217.138:59290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4UmWV3ou772CelrLiEXgAAmV4"]
[Mon Jul 20 06:29:13.952111 2026] [security2:error] [pid 929851:tid 930112] [client 34.73.38.214:53478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UmWV3ou772CelrLiEaQAAAQQ"]
[Mon Jul 20 06:29:13.975152 2026] [security2:error] [pid 929851:tid 930076] [client 103.153.183.69:33744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4UmWV3ou772CelrLiEawAAAOA"], referer: https://twitter.com/
[Mon Jul 20 06:29:13.994215 2026] [security2:error] [pid 929851:tid 930006] [client 14.225.17.146:62781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4UmWV3ou772CelrLiEYQAAAJo"]
[Mon Jul 20 06:29:14.144867 2026] [security2:error] [pid 929851:tid 930055] [client 14.225.17.146:62255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEbQAAAMs"], referer: http://christiancountytrumpet.com/old
[Mon Jul 20 06:29:14.152122 2026] [security2:error] [pid 929851:tid 930025] [client 57.141.18.98:34694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiEFwAArRI"]
[Mon Jul 20 06:29:14.366165 2026] [security2:error] [pid 929851:tid 930059] [client 104.234.53.70:28603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UmmV3ou772CelrLiEgQAAAM8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:14.573288 2026] [security2:error] [pid 929851:tid 930024] [client 14.225.17.146:63176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEeQAAAKw"], referer: http://massagelacey.com/old
[Mon Jul 20 06:29:14.696709 2026] [security2:error] [pid 929851:tid 929985] [client 103.153.183.69:33744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4UmmV3ou772CelrLiEpgAAAIU"], referer: https://www.reddit.com/
[Mon Jul 20 06:29:14.865801 2026] [security2:error] [pid 929851:tid 930100] [client 213.152.162.79:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UmmV3ou772CelrLiEtQAAAPg"]
[Mon Jul 20 06:29:14.865960 2026] [security2:error] [pid 929851:tid 930100] [client 213.152.162.79:49352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UmmV3ou772CelrLiEtQAAAPg"]
[Mon Jul 20 06:29:15.000042 2026] [security2:error] [pid 929851:tid 929992] [client 104.234.53.80:22573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UmmV3ou772CelrLiEwgAAAIw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:15.225828 2026] [security2:error] [pid 929851:tid 930054] [client 57.141.18.65:59224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEbwAAyhg"]
[Mon Jul 20 06:29:15.247473 2026] [security2:error] [pid 929851:tid 930046] [client 34.73.38.214:52023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Um2V3ou772CelrLiE3wAAAMI"]
[Mon Jul 20 06:29:15.368127 2026] [security2:error] [pid 929851:tid 930019] [client 171.60.139.123:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Um2V3ou772CelrLiE4gAAAKc"]
[Mon Jul 20 06:29:15.368309 2026] [security2:error] [pid 929851:tid 930019] [client 171.60.139.123:49958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Um2V3ou772CelrLiE4gAAAKc"]
[Mon Jul 20 06:29:15.541172 2026] [security2:error] [pid 929851:tid 930008] [client 57.141.18.22:56068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEfAAAnAE"]
[Mon Jul 20 06:29:15.558496 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:63909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1bRTmkNaz')) OR 565. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 565 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Um2V3ou772CelrLiE7wAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:15.578927 2026] [security2:error] [pid 929851:tid 930106] [client 34.73.38.214:58539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Um2V3ou772CelrLiE8wAAAP4"]
[Mon Jul 20 06:29:15.987843 2026] [security2:error] [pid 929851:tid 929985] [client 57.141.18.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Um2V3ou772CelrLiFBAAAAIU"]
[Mon Jul 20 06:29:16.138807 2026] [security2:error] [pid 929851:tid 930070] [client 104.234.53.75:21059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UnGV3ou772CelrLiFHwAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:16.375642 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFLAAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.375765 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:63920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFLAAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.540238 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.540365 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.568175 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.568311 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.576944 2026] [security2:error] [pid 929851:tid 930105] [client 57.141.18.57:42034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Um2V3ou772CelrLiE4QAA_XQ"]
[Mon Jul 20 06:29:16.656477 2026] [security2:error] [pid 929851:tid 930018] [client 103.141.108.143:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFPQAAAKY"]
[Mon Jul 20 06:29:16.656796 2026] [security2:error] [pid 929851:tid 930018] [client 103.141.108.143:57207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFPQAAAKY"]
[Mon Jul 20 06:29:16.710409 2026] [security2:error] [pid 929851:tid 930042] [client 14.225.17.146:62900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4Um2V3ou772CelrLiE2QAAAL4"], referer: http://709fx.com/old
[Mon Jul 20 06:29:16.764925 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:58971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFTgAAAMU"]
[Mon Jul 20 06:29:16.765085 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:58971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFTgAAAMU"]
[Mon Jul 20 06:29:16.874978 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFVAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.875076 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFVAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.149244 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFbAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.149344 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFbAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.188489 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFcgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.188602 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:63927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFcgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.245096 2026] [security2:error] [pid 929851:tid 930027] [client 34.73.38.214:65267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UnWV3ou772CelrLiFdQAAAK8"]
[Mon Jul 20 06:29:17.312296 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFdwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.312395 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFdwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.342629 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFfgAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.342727 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFfgAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.428602 2026] [security2:error] [pid 929851:tid 929917] [remote 38.242.157.30:44868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4UnWV3ou772CelrLiFigAAtD0"]
[Mon Jul 20 06:29:17.487820 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFjwAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.487908 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFjwAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.687220 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:57327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UnWV3ou772CelrLiFngAAAI8"]
[Mon Jul 20 06:29:17.687472 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:57327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UnWV3ou772CelrLiFngAAAI8"]
[Mon Jul 20 06:29:17.696975 2026] [security2:error] [pid 929851:tid 929922] [remote 38.242.157.30:44868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4UnWV3ou772CelrLiFnwAAqEI"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:29:17.775913 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UnWV3ou772CelrLiFlwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.879986 2026] [security2:error] [pid 929851:tid 930011] [client 14.225.17.146:62992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4UnGV3ou772CelrLiFTQAAAJ8"], referer: http://mourgroup.com/old
[Mon Jul 20 06:29:17.987788 2026] [security2:error] [pid 929851:tid 930063] [client 57.141.18.57:42038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UnGV3ou772CelrLiFTAAA03U"]
[Mon Jul 20 06:29:18.037072 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiFuAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.037159 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:63935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiFuAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.142900 2026] [security2:error] [pid 929851:tid 929967] [remote 130.185.118.215:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4UnmV3ou772CelrLiFwgAAlm8"]
[Mon Jul 20 06:29:18.384113 2026] [security2:error] [pid 929851:tid 929934] [remote 130.185.118.215:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4UnmV3ou772CelrLiF2QAArE4"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 06:29:18.497238 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF5QAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.497390 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF5QAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.771678 2026] [security2:error] [pid 929851:tid 930018] [client 14.225.17.146:59757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4UnmV3ou772CelrLiF5gAAAKY"], referer: http://securingmemories.com/old
[Mon Jul 20 06:29:18.892374 2026] [security2:error] [pid 929851:tid 930078] [client 14.225.17.146:63777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4UnmV3ou772CelrLiF1AAAAOI"], referer: http://laceycaraccident.com/old
[Mon Jul 20 06:29:18.915647 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF-wAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.915761 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF-wAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.069025 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGBwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.069176 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGBwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.088247 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.49:25480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UnWV3ou772CelrLiFpQAAzXE"]
[Mon Jul 20 06:29:19.271127 2026] [security2:error] [pid 929851:tid 930111] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4Un2V3ou772CelrLiGBAABAwA"], referer: http://assasalnazaha.com/old
[Mon Jul 20 06:29:19.405821 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGJgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.406028 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGJgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.883851 2026] [security2:error] [pid 929851:tid 929938] [remote 57.141.18.72:65362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3142824"] [unique_id "al4Un2V3ou772CelrLiGTgAAtVI"]
[Mon Jul 20 06:29:20.199473 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGcwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.199563 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGcwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.313142 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:62751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGZQAAAO4"]
[Mon Jul 20 06:29:20.635153 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.14:26664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Un2V3ou772CelrLiGMwAA2As"]
[Mon Jul 20 06:29:20.805491 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGngAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.805589 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGngAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.991996 2026] [security2:error] [pid 929851:tid 930106] [client 171.61.165.146:21667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UoGV3ou772CelrLiGpgAAAP4"]
[Mon Jul 20 06:29:20.992159 2026] [security2:error] [pid 929851:tid 930106] [client 171.61.165.146:21667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UoGV3ou772CelrLiGpgAAAP4"]
[Mon Jul 20 06:29:21.472563 2026] [security2:error] [pid 929851:tid 929922] [remote 162.19.86.63:39700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiGxwAAwUI"]
[Mon Jul 20 06:29:21.472744 2026] [security2:error] [pid 929851:tid 930045] [client 162.19.86.63:39700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiGxwAAwUI"]
[Mon Jul 20 06:29:21.591279 2026] [security2:error] [pid 929851:tid 929997] [client 14.225.17.146:59595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGXwAAAJE"], referer: http://idigress.group/old
[Mon Jul 20 06:29:21.759437 2026] [security2:error] [pid 929851:tid 929991] [client 57.141.18.65:56424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGiAAAi1A"]
[Mon Jul 20 06:29:21.804445 2026] [security2:error] [pid 929851:tid 930094] [client 106.219.188.178:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiG7QAAAPI"]
[Mon Jul 20 06:29:21.804615 2026] [security2:error] [pid 929851:tid 930094] [client 106.219.188.178:27768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiG7QAAAPI"]
[Mon Jul 20 06:29:22.033624 2026] [security2:error] [pid 929851:tid 930035] [client 14.225.17.146:59811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGcgAAALc"], referer: http://longevityperformanceclinic.com/old
[Mon Jul 20 06:29:22.284929 2026] [security2:error] [pid 929851:tid 929913] [remote 103.187.169.251:39072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UomV3ou772CelrLiHFwAA9Tk"]
[Mon Jul 20 06:29:22.357188 2026] [security2:error] [pid 929851:tid 930072] [client 14.225.17.146:59888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGoQAAANw"], referer: http://solkeetw.com/old
[Mon Jul 20 06:29:22.358097 2026] [proxy:error] [pid 929851:tid 929996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.358170 2026] [proxy_http:error] [pid 929851:tid 929996] [client 34.73.38.214:58039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:22.358881 2026] [proxy:error] [pid 929851:tid 929996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.358932 2026] [proxy_http:error] [pid 929851:tid 929996] [client 34.73.38.214:58039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:22.417522 2026] [security2:error] [pid 929851:tid 930086] [client 14.225.17.146:59927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGpAAAAOo"], referer: http://guidehunting.com/old
[Mon Jul 20 06:29:22.703770 2026] [security2:error] [pid 929851:tid 929969] [remote 103.187.169.251:39072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UomV3ou772CelrLiHRQAAnXE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:29:22.840642 2026] [security2:error] [pid 929851:tid 929998] [client 57.141.18.56:62556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UoWV3ou772CelrLiG8gAAkk0"]
[Mon Jul 20 06:29:22.988092 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.988181 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:53790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:22.989484 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.989520 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:53790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.104906 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.104960 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:62460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.105404 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.105426 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:62460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.345928 2026] [security2:error] [pid 929851:tid 930046] [client 57.141.18.107:57950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UomV3ou772CelrLiHKQAAwhM"]
[Mon Jul 20 06:29:23.417036 2026] [security2:error] [pid 929851:tid 929986] [client 158.173.166.181:51815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Uo2V3ou772CelrLiHdgAAAIY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:23.495253 2026] [proxy:error] [pid 929851:tid 930031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.495337 2026] [proxy_http:error] [pid 929851:tid 930031] [client 34.73.38.214:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.496104 2026] [proxy:error] [pid 929851:tid 930031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.496139 2026] [proxy_http:error] [pid 929851:tid 930031] [client 34.73.38.214:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.581949 2026] [security2:error] [pid 929851:tid 930107] [client 14.225.17.146:59816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHbQAAAP8"], referer: https://guidehunting.com/old
[Mon Jul 20 06:29:23.816265 2026] [proxy:error] [pid 929851:tid 930023] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.816342 2026] [proxy_http:error] [pid 929851:tid 930023] [client 34.73.38.214:58785] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.816959 2026] [proxy:error] [pid 929851:tid 930023] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.816987 2026] [proxy_http:error] [pid 929851:tid 930023] [client 34.73.38.214:58785] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.895818 2026] [security2:error] [pid 929851:tid 930014] [client 45.157.112.60:41973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Uo2V3ou772CelrLiHpgAAAKI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:23.936198 2026] [security2:error] [pid 929851:tid 929999] [client 223.185.13.213:9012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uo2V3ou772CelrLiHqAAAAJM"]
[Mon Jul 20 06:29:23.936295 2026] [security2:error] [pid 929851:tid 929999] [client 223.185.13.213:9012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uo2V3ou772CelrLiHqAAAAJM"]
[Mon Jul 20 06:29:23.969897 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHkQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.103273 2026] [security2:error] [pid 929851:tid 930091] [client 50.116.65.227:58644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UpGV3ou772CelrLiHsQAAAO8"]
[Mon Jul 20 06:29:24.113492 2026] [security2:error] [pid 929851:tid 929987] [client 50.116.65.227:58654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UpGV3ou772CelrLiHtAAAAIc"]
[Mon Jul 20 06:29:24.152151 2026] [proxy:error] [pid 929851:tid 930020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.152229 2026] [proxy_http:error] [pid 929851:tid 930020] [client 34.73.38.214:59636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.152671 2026] [proxy:error] [pid 929851:tid 930020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.152698 2026] [proxy_http:error] [pid 929851:tid 930020] [client 34.73.38.214:59636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.274420 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpGV3ou772CelrLiHywAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.274542 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpGV3ou772CelrLiHywAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.427152 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:63992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UpGV3ou772CelrLiH1QAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.506543 2026] [proxy:error] [pid 929851:tid 930091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.506597 2026] [proxy_http:error] [pid 929851:tid 930091] [client 34.73.38.214:58423] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.507191 2026] [proxy:error] [pid 929851:tid 930091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.507216 2026] [proxy_http:error] [pid 929851:tid 930091] [client 34.73.38.214:58423] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.675906 2026] [security2:error] [pid 929851:tid 930062] [client 57.141.18.37:47320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHbAAA0iY"]
[Mon Jul 20 06:29:24.952175 2026] [security2:error] [pid 929851:tid 929993] [client 57.141.18.0:23972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHfgAAjXo"]
[Mon Jul 20 06:29:25.031489 2026] [security2:error] [pid 929851:tid 930091] [client 34.73.38.214:61432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIEgAAAO8"]
[Mon Jul 20 06:29:25.110421 2026] [proxy:error] [pid 929851:tid 930056] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:25.110484 2026] [proxy_http:error] [pid 929851:tid 930056] [client 34.73.38.214:57923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:25.111309 2026] [proxy:error] [pid 929851:tid 930056] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:25.111338 2026] [proxy_http:error] [pid 929851:tid 930056] [client 34.73.38.214:57923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:25.214601 2026] [security2:error] [pid 929851:tid 930009] [client 14.225.17.146:51255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIDwAAAJ0"], referer: http://narv.co/old
[Mon Jul 20 06:29:25.257924 2026] [security2:error] [pid 929851:tid 930024] [client 213.152.162.79:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIJQAAAKw"]
[Mon Jul 20 06:29:25.258020 2026] [security2:error] [pid 929851:tid 930024] [client 213.152.162.79:48982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIJQAAAKw"]
[Mon Jul 20 06:29:25.277878 2026] [security2:error] [pid 929851:tid 929903] [remote 45.90.123.233:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UpWV3ou772CelrLiIKAAA7i8"]
[Mon Jul 20 06:29:25.291513 2026] [security2:error] [pid 929851:tid 930083] [client 57.141.18.64:55230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHqQAA5x4"]
[Mon Jul 20 06:29:25.298358 2026] [security2:error] [pid 929851:tid 930047] [client 34.73.38.214:54648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiILAAAAMM"]
[Mon Jul 20 06:29:25.341371 2026] [security2:error] [pid 929851:tid 930045] [client 14.225.17.146:58633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHpwAAAME"], referer: http://balticsteelmgmt.com/old
[Mon Jul 20 06:29:25.405666 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.10:58248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UpGV3ou772CelrLiHtwAAtSw"]
[Mon Jul 20 06:29:25.421996 2026] [security2:error] [pid 929851:tid 930012] [client 34.73.38.214:61947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIPQAAAKA"]
[Mon Jul 20 06:29:25.476857 2026] [security2:error] [pid 929851:tid 929921] [remote 45.90.123.233:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UpWV3ou772CelrLiIRAABAkE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:29:25.783630 2026] [security2:error] [pid 929851:tid 930014] [client 34.73.38.214:64881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIWAAAAKI"]
[Mon Jul 20 06:29:25.895245 2026] [security2:error] [pid 929851:tid 930064] [client 112.208.70.94:42621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIZAAAANQ"]
[Mon Jul 20 06:29:25.895349 2026] [security2:error] [pid 929851:tid 930064] [client 112.208.70.94:42621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIZAAAANQ"]
[Mon Jul 20 06:29:25.938930 2026] [security2:error] [pid 929851:tid 930082] [client 34.73.38.214:51340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIagAAAOY"]
[Mon Jul 20 06:29:26.084124 2026] [security2:error] [pid 929851:tid 930098] [client 171.60.139.123:50483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIcwAAAPY"]
[Mon Jul 20 06:29:26.084258 2026] [security2:error] [pid 929851:tid 930098] [client 171.60.139.123:50483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIcwAAAPY"]
[Mon Jul 20 06:29:26.241309 2026] [security2:error] [pid 929851:tid 930028] [client 50.116.65.227:58694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4UpmV3ou772CelrLiIfwAAALA"]
[Mon Jul 20 06:29:26.245509 2026] [security2:error] [pid 929851:tid 930043] [client 14.225.17.146:58194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIbQAAAL8"], referer: http://recruitinginsight.us/old
[Mon Jul 20 06:29:26.278037 2026] [security2:error] [pid 929851:tid 930004] [client 14.225.17.146:58574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4UpmV3ou772CelrLiIcgAAAJg"], referer: https://narv.co/old
[Mon Jul 20 06:29:26.303713 2026] [security2:error] [pid 929851:tid 930018] [client 104.207.59.142:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UpmV3ou772CelrLiIggAAAKY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:26.400822 2026] [security2:error] [pid 929851:tid 930021] [client 57.141.18.121:61216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIEwAAqUU"]
[Mon Jul 20 06:29:26.401170 2026] [security2:error] [pid 929851:tid 929880] [remote 78.46.157.202:44882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIiwAAvBg"]
[Mon Jul 20 06:29:26.401299 2026] [security2:error] [pid 929851:tid 930040] [client 78.46.157.202:44882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIiwAAvBg"]
[Mon Jul 20 06:29:26.420409 2026] [security2:error] [pid 929851:tid 930009] [client 34.74.185.202:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIjgAAAJ0"]
[Mon Jul 20 06:29:26.439058 2026] [security2:error] [pid 929851:tid 930087] [client 34.73.38.214:60547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UpmV3ou772CelrLiIkwAAAOs"]
[Mon Jul 20 06:29:26.466241 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpmV3ou772CelrLiIlgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:26.466357 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpmV3ou772CelrLiIlgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:26.481929 2026] [security2:error] [pid 929851:tid 930105] [client 34.73.38.214:63118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UpmV3ou772CelrLiImQAAAP0"]
[Mon Jul 20 06:29:26.681629 2026] [security2:error] [pid 929851:tid 930046] [client 14.225.17.146:58157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4UpGV3ou772CelrLiH7AAAAMI"], referer: http://dollpassionista.com/old
[Mon Jul 20 06:29:26.683371 2026] [security2:error] [pid 929851:tid 930091] [client 212.47.78.27:43756] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4UpmV3ou772CelrLiIqQAAAO8"]
[Mon Jul 20 06:29:27.030450 2026] [security2:error] [pid 929851:tid 930096] [client 14.225.17.146:59658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4UpmV3ou772CelrLiIvQAAAPQ"], referer: http://hammadownenterprises.com/old
[Mon Jul 20 06:29:27.156675 2026] [security2:error] [pid 929851:tid 929991] [client 57.141.18.1:25928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIXgAAizk"]
[Mon Jul 20 06:29:27.158338 2026] [security2:error] [pid 929851:tid 930039] [client 212.47.78.27:43762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4Up2V3ou772CelrLiI0gAAALs"]
[Mon Jul 20 06:29:27.199603 2026] [security2:error] [pid 929851:tid 930074] [client 103.141.108.143:57686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiI1gAAAN4"]
[Mon Jul 20 06:29:27.199772 2026] [security2:error] [pid 929851:tid 930074] [client 103.141.108.143:57686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiI1gAAAN4"]
[Mon Jul 20 06:29:27.239034 2026] [security2:error] [pid 929851:tid 930028] [client 14.225.17.146:54918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4UpmV3ou772CelrLiIvgAAALA"], referer: http://mcg.homes/old
[Mon Jul 20 06:29:27.301693 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiI4gAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.301787 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:64007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiI4gAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.316417 2026] [security2:error] [pid 929851:tid 930088] [client 14.225.17.146:58563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4UpGV3ou772CelrLiIAgAAAOw"], referer: http://drewsasburyparkbeachhouse.com/old
[Mon Jul 20 06:29:27.560299 2026] [security2:error] [pid 929851:tid 930001] [client 45.116.69.230:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJAwAAAJU"]
[Mon Jul 20 06:29:27.560454 2026] [security2:error] [pid 929851:tid 930001] [client 45.116.69.230:59509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJAwAAAJU"]
[Mon Jul 20 06:29:27.582982 2026] [security2:error] [pid 929851:tid 930008] [client 34.74.185.202:49633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Up2V3ou772CelrLiJBQAAAJw"]
[Mon Jul 20 06:29:27.615669 2026] [security2:error] [pid 929851:tid 929987] [client 212.47.78.27:58424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4Up2V3ou772CelrLiJBgAAAIc"]
[Mon Jul 20 06:29:27.709151 2026] [security2:error] [pid 929851:tid 930079] [client 34.73.38.214:51289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Up2V3ou772CelrLiJDQAAAOM"]
[Mon Jul 20 06:29:27.720693 2026] [security2:error] [pid 929851:tid 929948] [remote 97.74.87.194:39652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJCwAAq1w"]
[Mon Jul 20 06:29:27.720911 2026] [security2:error] [pid 929851:tid 930023] [client 97.74.87.194:39652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJCwAAq1w"]
[Mon Jul 20 06:29:27.721130 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiI-wAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.765970 2026] [security2:error] [pid 929851:tid 930080] [client 14.225.17.146:64561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiJBAAAAOQ"], referer: https://dollpassionista.com/old
[Mon Jul 20 06:29:27.914982 2026] [security2:error] [pid 929851:tid 930039] [client 34.73.38.214:59754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Up2V3ou772CelrLiJJgAAALs"]
[Mon Jul 20 06:29:27.929020 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiJKwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.929142 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:64011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiJKwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:28.044396 2026] [security2:error] [pid 929851:tid 930010] [client 104.234.53.90:23239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UqGV3ou772CelrLiJOAAAAJ4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:28.081447 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:64014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UqGV3ou772CelrLiJOwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:28.175270 2026] [security2:error] [pid 929851:tid 929916] [remote 66.94.101.63:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UqGV3ou772CelrLiJQAAA2Tw"]
[Mon Jul 20 06:29:28.326883 2026] [security2:error] [pid 929851:tid 930006] [client 57.141.18.18:23666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiIzAAAmgY"]
[Mon Jul 20 06:29:28.341715 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.7:45532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiIywAAoik"]
[Mon Jul 20 06:29:28.484835 2026] [security2:error] [pid 929851:tid 930104] [client 39.48.81.23:57802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UqGV3ou772CelrLiJWQAAAPw"]
[Mon Jul 20 06:29:28.484999 2026] [security2:error] [pid 929851:tid 930104] [client 39.48.81.23:57802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UqGV3ou772CelrLiJWQAAAPw"]
[Mon Jul 20 06:29:28.627349 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJSwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:28.804425 2026] [security2:error] [pid 929851:tid 930029] [client 34.74.185.202:53176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UqGV3ou772CelrLiJjwAAALE"]
[Mon Jul 20 06:29:28.918942 2026] [security2:error] [pid 929851:tid 930044] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "poopatrol608.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHkgAAwFI"]
[Mon Jul 20 06:29:29.085732 2026] [security2:error] [pid 929851:tid 930077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJoAAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.206822 2026] [security2:error] [pid 929851:tid 930045] [client 34.73.38.214:52528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UqWV3ou772CelrLiJywAAAME"]
[Mon Jul 20 06:29:29.444472 2026] [security2:error] [pid 929851:tid 930048] [client 34.73.38.214:52711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UqWV3ou772CelrLiJ2QAAAMQ"]
[Mon Jul 20 06:29:29.746499 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.73:21514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJXQAAlno"]
[Mon Jul 20 06:29:29.810014 2026] [security2:error] [pid 929851:tid 930041] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqWV3ou772CelrLiJ8AAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.954060 2026] [security2:error] [pid 929851:tid 930058] [client 77.110.127.138:64036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqWV3ou772CelrLiKBAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.954155 2026] [security2:error] [pid 929851:tid 930058] [client 77.110.127.138:64036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqWV3ou772CelrLiKBAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.990154 2026] [security2:error] [pid 929851:tid 930111] [client 34.73.38.214:63714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UqWV3ou772CelrLiKCQAAAQM"]
[Mon Jul 20 06:29:30.069070 2026] [security2:error] [pid 929851:tid 929902] [remote 115.79.143.180:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UqmV3ou772CelrLiKEwAAqS4"]
[Mon Jul 20 06:29:30.094830 2026] [security2:error] [pid 929851:tid 930055] [client 34.74.185.202:54401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UqmV3ou772CelrLiKGgAAAMs"]
[Mon Jul 20 06:29:30.110352 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.86:40880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJkgAA21c"]
[Mon Jul 20 06:29:30.305700 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqmV3ou772CelrLiKFwAAAMI"]
[Mon Jul 20 06:29:30.485304 2026] [security2:error] [pid 929851:tid 929976] [remote 115.79.143.180:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UqmV3ou772CelrLiKOQAA63g"], referer: https://vyx.sbv.mybluehost.me/wp-login.php
[Mon Jul 20 06:29:30.591094 2026] [security2:error] [pid 929851:tid 930034] [client 34.73.38.214:65306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UqmV3ou772CelrLiKRQAAALY"]
[Mon Jul 20 06:29:30.738913 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKWAAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.739045 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKWAAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.739577 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqmV3ou772CelrLiKQAAAAKc"]
[Mon Jul 20 06:29:30.789370 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKXQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.789488 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKXQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.802362 2026] [security2:error] [pid 929851:tid 930070] [client 34.73.38.214:65019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UqmV3ou772CelrLiKXgAAANo"]
[Mon Jul 20 06:29:30.974086 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:64050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UqmV3ou772CelrLiKawAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:31.024194 2026] [security2:error] [pid 929851:tid 930108] [client 34.73.38.214:60627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Uq2V3ou772CelrLiKbwAAAQA"]
[Mon Jul 20 06:29:31.131887 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.53:63836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UqWV3ou772CelrLiKAQAA-nQ"]
[Mon Jul 20 06:29:31.317223 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uq2V3ou772CelrLiKggAAAIs"], referer: 1'"3000
[Mon Jul 20 06:29:31.624936 2026] [security2:error] [pid 929851:tid 930031] [client 34.73.38.214:57304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Uq2V3ou772CelrLiKsAAAALM"]
[Mon Jul 20 06:29:31.734873 2026] [security2:error] [pid 929851:tid 930071] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uq2V3ou772CelrLiKqQAAANs"], referer: 1'"3000
[Mon Jul 20 06:29:31.885412 2026] [security2:error] [pid 929851:tid 929924] [remote 8.217.108.67:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Uq2V3ou772CelrLiKwQAAtUQ"]
[Mon Jul 20 06:29:31.918282 2026] [security2:error] [pid 929851:tid 930042] [client 171.61.165.146:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Uq2V3ou772CelrLiKxAAAAL4"]
[Mon Jul 20 06:29:31.918388 2026] [security2:error] [pid 929851:tid 930042] [client 171.61.165.146:9731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Uq2V3ou772CelrLiKxAAAAL4"]
[Mon Jul 20 06:29:31.993410 2026] [security2:error] [pid 929851:tid 930002] [client 34.74.185.202:64311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Uq2V3ou772CelrLiKyQAAAJY"]
[Mon Jul 20 06:29:32.108598 2026] [security2:error] [pid 929851:tid 930039] [client 34.73.38.214:55141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UrGV3ou772CelrLiKywAAALs"]
[Mon Jul 20 06:29:32.474585 2026] [security2:error] [pid 929851:tid 930081] [client 104.234.53.63:27693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UrGV3ou772CelrLiK6AAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:32.498407 2026] [security2:error] [pid 929851:tid 929899] [remote 66.94.101.63:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UrGV3ou772CelrLiK7QAAqys"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:32.561476 2026] [security2:error] [pid 929851:tid 930086] [client 106.219.188.178:20183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiK7wAAAOo"]
[Mon Jul 20 06:29:32.562066 2026] [security2:error] [pid 929851:tid 930086] [client 106.219.188.178:20183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiK7wAAAOo"]
[Mon Jul 20 06:29:32.619321 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UrGV3ou772CelrLiK5gAAAKc"], referer: 1'"3000
[Mon Jul 20 06:29:32.751945 2026] [security2:error] [pid 929851:tid 930082] [client 74.7.230.36:56440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bokkunst.com"] [uri "/robots.txt"] [unique_id "al4UrGV3ou772CelrLiLCgAAAOY"]
[Mon Jul 20 06:29:32.905689 2026] [security2:error] [pid 929851:tid 930026] [client 197.186.66.42:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiLFgAAAK4"]
[Mon Jul 20 06:29:32.905945 2026] [security2:error] [pid 929851:tid 930026] [client 197.186.66.42:52142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiLFgAAAK4"]
[Mon Jul 20 06:29:33.019611 2026] [security2:error] [pid 929851:tid 930074] [client 34.74.185.202:62807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLHAAAAN4"]
[Mon Jul 20 06:29:33.153873 2026] [security2:error] [pid 929851:tid 929927] [remote 188.40.28.4:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLJwAAsUc"]
[Mon Jul 20 06:29:33.189294 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLLgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.189408 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLLgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.202644 2026] [security2:error] [pid 929851:tid 930097] [client 34.73.38.214:65083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLLwAAAPU"]
[Mon Jul 20 06:29:33.240997 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLNQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.241125 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:64030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLNQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.263070 2026] [security2:error] [pid 929851:tid 930039] [client 34.73.38.214:58818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLPAAAALs"]
[Mon Jul 20 06:29:33.353677 2026] [security2:error] [pid 929851:tid 929920] [remote 188.40.28.4:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLQwAApEA"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 06:29:33.416687 2026] [security2:error] [pid 929851:tid 930026] [client 50.116.65.227:39880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UrWV3ou772CelrLiLSQAAAK4"]
[Mon Jul 20 06:29:33.427012 2026] [security2:error] [pid 929851:tid 930065] [client 50.116.65.227:39882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UrWV3ou772CelrLiLTAAAANU"]
[Mon Jul 20 06:29:33.447012 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLUAAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.447114 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:64066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLUAAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.537649 2026] [security2:error] [pid 929851:tid 930112] [client 57.141.18.37:42948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uq2V3ou772CelrLiKuQABBAU"]
[Mon Jul 20 06:29:33.592594 2026] [security2:error] [pid 929851:tid 929929] [remote 194.164.192.228:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLWAAAwEk"]
[Mon Jul 20 06:29:33.604577 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64067] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UrWV3ou772CelrLiLWwAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.774599 2026] [security2:error] [pid 929851:tid 929948] [remote 194.164.192.228:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLbQAA_1w"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:29:33.881266 2026] [security2:error] [pid 929851:tid 930032] [client 34.74.185.202:53013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLeAAAALQ"]
[Mon Jul 20 06:29:33.988247 2026] [security2:error] [pid 929851:tid 930108] [client 14.225.17.146:64456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLcgAAAQA"], referer: http://lifeisbetterlakeside.com/old
[Mon Jul 20 06:29:34.115326 2026] [security2:error] [pid 929851:tid 929923] [remote 103.187.169.251:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UrmV3ou772CelrLiLhQAA80M"]
[Mon Jul 20 06:29:34.122811 2026] [security2:error] [pid 929851:tid 929995] [client 34.74.185.202:64218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UrmV3ou772CelrLiLhgAAAI8"]
[Mon Jul 20 06:29:34.531604 2026] [security2:error] [pid 929851:tid 929972] [remote 103.187.169.251:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UrmV3ou772CelrLiLpwAA3nQ"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:29:34.917300 2026] [security2:error] [pid 929851:tid 930051] [client 57.141.18.65:59176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLHgAAxzY"]
[Mon Jul 20 06:29:34.944094 2026] [security2:error] [pid 929851:tid 930085] [client 34.73.38.214:54326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UrmV3ou772CelrLiLyQAAAOk"]
[Mon Jul 20 06:29:35.000162 2026] [security2:error] [pid 929851:tid 930039] [client 34.74.185.202:64013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UrmV3ou772CelrLiL1AAAALs"]
[Mon Jul 20 06:29:35.183996 2026] [security2:error] [pid 929851:tid 930058] [client 223.185.13.213:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Ur2V3ou772CelrLiL3gAAAM4"]
[Mon Jul 20 06:29:35.184131 2026] [security2:error] [pid 929851:tid 930058] [client 223.185.13.213:9394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Ur2V3ou772CelrLiL3gAAAM4"]
[Mon Jul 20 06:29:35.196118 2026] [ssl:error] [pid 929851:tid 929987] [client 66.132.172.139:2760] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.bridgeamazon.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:29:35.270366 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.22:31034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLMAAA_no"]
[Mon Jul 20 06:29:35.394582 2026] [security2:error] [pid 929851:tid 930033] [client 74.208.214.194:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Ur2V3ou772CelrLiL9QAAALU"]
[Mon Jul 20 06:29:35.415843 2026] [security2:error] [pid 929851:tid 930080] [client 57.141.18.81:60590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLRQAA5Dg"]
[Mon Jul 20 06:29:35.417563 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL9wAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.417646 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:64078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL9wAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.462443 2026] [security2:error] [pid 929851:tid 930057] [client 34.74.185.202:60427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiL_AAAAM0"]
[Mon Jul 20 06:29:35.468159 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL_QAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.468268 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL_QAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.741307 2026] [security2:error] [pid 929851:tid 929987] [client 34.74.185.202:57674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiMFQAAAIc"]
[Mon Jul 20 06:29:35.762414 2026] [security2:error] [pid 929851:tid 929935] [remote 47.86.33.52:6442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Ur2V3ou772CelrLiMFgAA408"]
[Mon Jul 20 06:29:35.794412 2026] [security2:error] [pid 929851:tid 930024] [client 34.73.38.214:58376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiMGwAAAKw"]
[Mon Jul 20 06:29:35.876242 2026] [security2:error] [pid 929851:tid 929918] [remote 173.212.252.15:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Ur2V3ou772CelrLiMIwAAjT4"]
[Mon Jul 20 06:29:35.975265 2026] [security2:error] [pid 929851:tid 930026] [client 34.74.185.202:52965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiMKAAAAK4"]
[Mon Jul 20 06:29:36.086008 2026] [security2:error] [pid 929851:tid 929937] [remote 173.212.252.15:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMMQAA1lE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:29:36.121571 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMPgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.121675 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:64086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMPgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.178572 2026] [security2:error] [pid 929851:tid 930055] [client 65.111.27.42:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMQAAAAMs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:36.305017 2026] [security2:error] [pid 929851:tid 930000] [client 104.234.53.74:26423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UsGV3ou772CelrLiMUQAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:36.376149 2026] [security2:error] [pid 929851:tid 929883] [remote 47.86.33.52:6442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMVgAA5Bs"], referer: https://nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:29:36.399373 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMRwAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.624742 2026] [security2:error] [pid 929851:tid 930107] [client 14.225.17.146:57686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiL7AAAAP8"]
[Mon Jul 20 06:29:36.764033 2026] [security2:error] [pid 929851:tid 929994] [client 57.141.18.59:43966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrmV3ou772CelrLiLqgAAjiQ"]
[Mon Jul 20 06:29:36.765875 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMbQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.765971 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMbQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.808425 2026] [security2:error] [pid 929851:tid 930109] [client 171.60.139.123:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UsGV3ou772CelrLiMdAAAAQE"]
[Mon Jul 20 06:29:36.808525 2026] [security2:error] [pid 929851:tid 930109] [client 171.60.139.123:51136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UsGV3ou772CelrLiMdAAAAQE"]
[Mon Jul 20 06:29:36.856805 2026] [security2:error] [pid 929851:tid 929889] [remote 8.217.108.67:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMfAAAoSE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:29:37.090094 2026] [security2:error] [pid 929851:tid 930049] [client 14.225.17.146:51311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMMAAAAMU"], referer: http://ancestralidadytrance.space/old
[Mon Jul 20 06:29:37.097094 2026] [security2:error] [pid 929851:tid 929868] [remote 57.141.18.63:54646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3396212"] [unique_id "al4UsWV3ou772CelrLiMlQAA7ww"]
[Mon Jul 20 06:29:37.134110 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMlwAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.134214 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMlwAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.178717 2026] [security2:error] [pid 929851:tid 929990] [client 104.234.53.57:41321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UsWV3ou772CelrLiMmgAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:37.430351 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMuwAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.430469 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMuwAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.581418 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMygAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.581534 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMygAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.715543 2026] [security2:error] [pid 929851:tid 930017] [client 157.52.92.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiMwgAAAKU"]
[Mon Jul 20 06:29:37.728327 2026] [security2:error] [pid 929851:tid 930095] [client 157.52.92.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiMwQAAAPM"]
[Mon Jul 20 06:29:37.730843 2026] [security2:error] [pid 929851:tid 929993] [client 14.225.17.146:64697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMZgAAAI0"], referer: http://ravmike.com/old
[Mon Jul 20 06:29:38.026843 2026] [security2:error] [pid 929851:tid 929986] [client 103.141.108.143:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM6wAAAIY"]
[Mon Jul 20 06:29:38.027513 2026] [security2:error] [pid 929851:tid 929986] [client 103.141.108.143:58296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM6wAAAIY"]
[Mon Jul 20 06:29:38.029504 2026] [security2:error] [pid 929851:tid 930044] [client 57.141.18.107:29848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiMDgAAwHs"]
[Mon Jul 20 06:29:38.191031 2026] [security2:error] [pid 929851:tid 930083] [client 45.116.69.230:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM9AAAAOc"]
[Mon Jul 20 06:29:38.191125 2026] [security2:error] [pid 929851:tid 930083] [client 45.116.69.230:60035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM9AAAAOc"]
[Mon Jul 20 06:29:38.273837 2026] [security2:error] [pid 929851:tid 930086] [client 104.234.53.74:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UsmV3ou772CelrLiM-wAAAOo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:38.276462 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.23:52560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiMJAAAtQE"]
[Mon Jul 20 06:29:38.339068 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNAQAAANw"]
[Mon Jul 20 06:29:38.339168 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNAQAAANw"]
[Mon Jul 20 06:29:38.354076 2026] [security2:error] [pid 929851:tid 929919] [remote 188.166.241.141:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UsmV3ou772CelrLiNAgAAwj8"]
[Mon Jul 20 06:29:38.407254 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.111:30394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiMKQAAuS0"]
[Mon Jul 20 06:29:38.487425 2026] [security2:error] [pid 929851:tid 930080] [client 47.128.20.144:41738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elespecialista.mx"] [uri "/robots.txt"] [unique_id "al4UsmV3ou772CelrLiNEQAAAOQ"]
[Mon Jul 20 06:29:38.687892 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNGwAAAI4"]
[Mon Jul 20 06:29:38.688068 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNGwAAAI4"]
[Mon Jul 20 06:29:38.695196 2026] [security2:error] [pid 929851:tid 929893] [remote 93.152.221.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiNFgAA8CU"]
[Mon Jul 20 06:29:38.727907 2026] [security2:error] [pid 929851:tid 929931] [remote 188.166.241.141:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UsmV3ou772CelrLiNHgAAp0s"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:38.818226 2026] [security2:error] [pid 929851:tid 930012] [client 112.208.70.94:43129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiNKwAAAKA"]
[Mon Jul 20 06:29:38.818361 2026] [security2:error] [pid 929851:tid 930012] [client 112.208.70.94:43129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiNKwAAAKA"]
[Mon Jul 20 06:29:38.858442 2026] [security2:error] [pid 929851:tid 930023] [client 14.225.17.146:58285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiNJQAAAKs"], referer: https://ravmike.com/old
[Mon Jul 20 06:29:38.859666 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNLgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:38.859826 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNLgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.036094 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Us2V3ou772CelrLiNPAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.036227 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Us2V3ou772CelrLiNPAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.254297 2026] [security2:error] [pid 929851:tid 930010] [client 57.141.18.12:54416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMfQAAnig"]
[Mon Jul 20 06:29:39.337545 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:58291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Us2V3ou772CelrLiNZwAAAI8"]
[Mon Jul 20 06:29:39.337702 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:58291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Us2V3ou772CelrLiNZwAAAI8"]
[Mon Jul 20 06:29:39.411564 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.33:40826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMjQAAzWU"]
[Mon Jul 20 06:29:39.444914 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNRQAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.709703 2026] [security2:error] [pid 929851:tid 930086] [client 14.225.17.146:64434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNSAAAAOo"], referer: http://bruceledewitz.com/old
[Mon Jul 20 06:29:39.773345 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.18:21046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiMowAA-lg"]
[Mon Jul 20 06:29:39.847539 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNewAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.866155 2026] [security2:error] [pid 929851:tid 930014] [client 74.7.227.179:56872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNgQAAoiM"], referer: https://tejasenvironmental.com/p=919923
[Mon Jul 20 06:29:40.254763 2026] [security2:error] [pid 929851:tid 930031] [client 14.225.17.146:64663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMZAAAALM"], referer: http://areitoproducciones.com/old
[Mon Jul 20 06:29:40.428671 2026] [security2:error] [pid 929851:tid 930025] [client 77.110.127.138:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtGV3ou772CelrLiNvgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.428790 2026] [security2:error] [pid 929851:tid 930025] [client 77.110.127.138:64093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtGV3ou772CelrLiNvgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.508919 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiNtgAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.694228 2026] [security2:error] [pid 929851:tid 930046] [client 104.234.53.75:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UtGV3ou772CelrLiN1wAAAMI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:40.711924 2026] [security2:error] [pid 929851:tid 929866] [remote 93.152.221.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UtGV3ou772CelrLiN2QAArAo"]
[Mon Jul 20 06:29:40.729154 2026] [security2:error] [pid 929851:tid 930056] [client 14.225.17.146:65275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiN0QAAAMw"]
[Mon Jul 20 06:29:40.803170 2026] [security2:error] [pid 929851:tid 929999] [client 57.141.18.60:30084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiM5wAAk10"]
[Mon Jul 20 06:29:40.906412 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiN1gAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.942310 2026] [security2:error] [pid 929851:tid 930020] [client 57.141.18.22:46482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiM7gAAqD0"]
[Mon Jul 20 06:29:41.232004 2026] [security2:error] [pid 929851:tid 930054] [client 57.141.18.32:38006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiNCwAAyko"]
[Mon Jul 20 06:29:41.488282 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOAwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.535347 2026] [security2:error] [pid 929851:tid 930104] [client 14.225.17.146:64781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNjAAAAPw"], referer: http://nomorewetsheets.net/old
[Mon Jul 20 06:29:41.667492 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOJAAAAIg"], referer: 1'"3000
[Mon Jul 20 06:29:41.700758 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOQQAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.700898 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOQQAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.775451 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOLgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.852453 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOTgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.852559 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOTgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.921250 2026] [security2:error] [pid 929851:tid 929969] [remote 91.142.222.105:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UtWV3ou772CelrLiOUwAAvHE"]
[Mon Jul 20 06:29:42.010456 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:64133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 190 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UtmV3ou772CelrLiOWwAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.049059 2026] [security2:error] [pid 929851:tid 929988] [client 103.153.183.69:39066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f../etc/passwd"] [unique_id "al4UtmV3ou772CelrLiOYwAAAIg"], referer: https://www.bing.com/search?q=i8cziq
[Mon Jul 20 06:29:42.066130 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOIgAAANg"]
[Mon Jul 20 06:29:42.069985 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.50:23494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiNOQAA1yw"]
[Mon Jul 20 06:29:42.162480 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UtmV3ou772CelrLiOcwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.171363 2026] [security2:error] [pid 929851:tid 929896] [remote 91.142.222.105:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOdAAArSg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:42.214544 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOWAAAAN4"], referer: 1'"3000
[Mon Jul 20 06:29:42.216525 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOWgAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.311882 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOhQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.312025 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOhQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.454727 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOigAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.454847 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOigAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.504159 2026] [security2:error] [pid 929851:tid 930076] [client 82.102.18.116:56258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4UtmV3ou772CelrLiOkAAAAOA"]
[Mon Jul 20 06:29:42.513652 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOkwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.513737 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOkwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.536429 2026] [security2:error] [pid 929851:tid 929940] [remote 162.19.86.63:46132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOlgAAilQ"]
[Mon Jul 20 06:29:42.565711 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOlwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.565835 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOlwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.609349 2026] [security2:error] [pid 929851:tid 930009] [client 197.186.66.42:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOmwAAAJ0"]
[Mon Jul 20 06:29:42.609462 2026] [security2:error] [pid 929851:tid 930009] [client 197.186.66.42:52645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOmwAAAJ0"]
[Mon Jul 20 06:29:42.715936 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOowAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.716028 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:64139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOowAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.768921 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOrgAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.769057 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:64115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOrgAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.772300 2026] [security2:error] [pid 929851:tid 929944] [remote 162.19.86.63:46132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOsAAAlFg"], referer: https://lutheranphilosopher.com/wp-login.php
[Mon Jul 20 06:29:42.803595 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:24953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOtAAAALw"]
[Mon Jul 20 06:29:42.803793 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:24953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOtAAAALw"]
[Mon Jul 20 06:29:42.817565 2026] [security2:error] [pid 929851:tid 930007] [client 50.116.65.227:35036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UtmV3ou772CelrLiOtgAAAJs"]
[Mon Jul 20 06:29:42.827655 2026] [security2:error] [pid 929851:tid 930033] [client 50.116.65.227:35052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UtmV3ou772CelrLiOuQAAALU"]
[Mon Jul 20 06:29:42.830822 2026] [security2:error] [pid 929851:tid 929950] [remote 217.61.143.92:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOuAABA14"]
[Mon Jul 20 06:29:42.857856 2026] [security2:error] [pid 929851:tid 930080] [client 82.102.18.116:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sergnotes.com"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOuwAAAOQ"]
[Mon Jul 20 06:29:42.866822 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.82:44182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNiwAAzVY"]
[Mon Jul 20 06:29:42.939780 2026] [security2:error] [pid 929851:tid 930018] [client 43.205.139.3:24144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOyAAAAKY"]
[Mon Jul 20 06:29:42.946323 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:64141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOygAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.946417 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:64141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOygAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.986656 2026] [security2:error] [pid 929851:tid 930097] [client 104.234.53.66:52429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOzwAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:43.053720 2026] [security2:error] [pid 929851:tid 929895] [remote 217.61.143.92:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Ut2V3ou772CelrLiO3QAA_yc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:29:43.082935 2026] [security2:error] [pid 929851:tid 930054] [client 66.249.79.131:55949] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "greenport-us.us"] [uri "/robots.txt"] [unique_id "al4Ut2V3ou772CelrLiO5AAAAMo"]
[Mon Jul 20 06:29:43.105082 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiO6gAAAJc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:29:43.105211 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiO6gAAAJc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:29:43.124023 2026] [security2:error] [pid 929851:tid 930041] [client 57.141.18.73:31190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiNnAAAvQ0"]
[Mon Jul 20 06:29:43.185468 2026] [security2:error] [pid 929851:tid 930099] [client 82.102.18.116:56276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Ut2V3ou772CelrLiO-wAAAPc"]
[Mon Jul 20 06:29:43.263504 2026] [security2:error] [pid 929851:tid 930017] [client 77.110.127.138:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-blanket/w4ai4r3qk8nc.php"] [unique_id "al4Ut2V3ou772CelrLiPBwAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.280783 2026] [security2:error] [pid 929851:tid 930044] [client 106.219.188.178:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPCAAAAMA"]
[Mon Jul 20 06:29:43.281114 2026] [security2:error] [pid 929851:tid 930044] [client 106.219.188.178:59904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPCAAAAMA"]
[Mon Jul 20 06:29:43.388214 2026] [security2:error] [pid 929851:tid 930080] [client 65.1.132.125:27452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPFAAAAOQ"]
[Mon Jul 20 06:29:43.388312 2026] [security2:error] [pid 929851:tid 930080] [client 65.1.132.125:27452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPFAAAAOQ"]
[Mon Jul 20 06:29:43.502316 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPGAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.502415 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:64038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPGAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.503667 2026] [security2:error] [pid 929851:tid 930026] [client 82.102.18.116:56278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Ut2V3ou772CelrLiPGgAAAK4"]
[Mon Jul 20 06:29:43.590327 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:64068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPAgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.622585 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPBQAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.625699 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPEAAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.633780 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.41:39740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiNwAAAnyY"]
[Mon Jul 20 06:29:43.669219 2026] [security2:error] [pid 929851:tid 930023] [client 77.110.127.138:64148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPIgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.669309 2026] [security2:error] [pid 929851:tid 930023] [client 77.110.127.138:64148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPIgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.727244 2026] [security2:error] [pid 929851:tid 930025] [client 79.215.172.42:64039] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4Ut2V3ou772CelrLiPKQAAAK0"]
[Mon Jul 20 06:29:43.820248 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:64149] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 778 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ut2V3ou772CelrLiPPwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.826072 2026] [security2:error] [pid 929851:tid 930092] [client 99.226.215.103:36240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4Ut2V3ou772CelrLiPQgAAAPA"]
[Mon Jul 20 06:29:43.844073 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/crochet-classes-in-surrey/sykbyjo6qckn.php"] [unique_id "al4Ut2V3ou772CelrLiPRgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.848235 2026] [security2:error] [pid 929851:tid 930042] [client 82.102.18.116:35275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Ut2V3ou772CelrLiPSQAAAL4"]
[Mon Jul 20 06:29:43.996715 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:64154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ut2V3ou772CelrLiPXwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.050601 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/img_4196-2/"] [unique_id "al4UuGV3ou772CelrLiPYwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.130406 2026] [security2:error] [pid 929851:tid 930031] [client 13.201.64.214:42380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4UuGV3ou772CelrLiPZwAAALM"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:29:44.188001 2026] [security2:error] [pid 929851:tid 930095] [client 82.102.18.116:56298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4UuGV3ou772CelrLiPdAAAAPM"]
[Mon Jul 20 06:29:44.213404 2026] [security2:error] [pid 929851:tid 930012] [client 14.225.17.146:55277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4UtmV3ou772CelrLiOpwAAAKA"], referer: http://chestermonty.com/old
[Mon Jul 20 06:29:44.371020 2026] [security2:error] [pid 929851:tid 930054] [client 104.234.53.73:38265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UuGV3ou772CelrLiPgQAAAMo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:44.427499 2026] [security2:error] [pid 929851:tid 930083] [client 14.225.17.146:55327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4UtmV3ou772CelrLiOugAAAOc"], referer: http://inspirespublishing.com/old
[Mon Jul 20 06:29:44.520433 2026] [security2:error] [pid 929851:tid 929996] [client 113.163.183.66:57203] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4UuGV3ou772CelrLiPigAAAJA"]
[Mon Jul 20 06:29:44.526494 2026] [security2:error] [pid 929851:tid 930082] [client 82.102.18.116:56304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UuGV3ou772CelrLiPiwAAAOY"]
[Mon Jul 20 06:29:44.683143 2026] [security2:error] [pid 929851:tid 930055] [client 77.193.8.9:47154] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4UuGV3ou772CelrLiPmgAAAMs"]
[Mon Jul 20 06:29:44.724586 2026] [security2:error] [pid 929851:tid 930091] [client 79.117.197.205:52268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UuGV3ou772CelrLiPoAAAAO8"]
[Mon Jul 20 06:29:44.754309 2026] [security2:error] [pid 929851:tid 929992] [client 99.252.129.110:37882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4UuGV3ou772CelrLiPpgAAAIw"]
[Mon Jul 20 06:29:44.785856 2026] [security2:error] [pid 929851:tid 930003] [client 62.216.211.191:55404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UuGV3ou772CelrLiPrAAAAJc"]
[Mon Jul 20 06:29:44.791572 2026] [http2:info] [pid 935758:tid 935758] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:29:44.855870 2026] [security2:error] [pid 929851:tid 930056] [client 57.141.18.39:39921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOPAAAzFU"]
[Mon Jul 20 06:29:44.869991 2026] [security2:error] [pid 929851:tid 930019] [client 35.231.144.158:58532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.144.231.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bzm.ppv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UuGV3ou772CelrLiPtAAAAKc"]
[Mon Jul 20 06:29:44.880527 2026] [security2:error] [pid 935758:tid 935893] [client 82.102.18.116:56320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4UuLcDxY_mIul-JSGGFAAAAQ0"]
[Mon Jul 20 06:29:44.884060 2026] [security2:error] [pid 929851:tid 930054] [client 34.74.185.202:52649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UuGV3ou772CelrLiPuQAAAMo"]
[Mon Jul 20 06:29:44.942893 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPVQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.975469 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPTgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.976899 2026] [security2:error] [pid 929851:tid 930072] [client 105.103.92.88:47748] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4UuGV3ou772CelrLiPuwAAANw"]
[Mon Jul 20 06:29:44.985617 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.10:59690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOQgAAwSU"]
[Mon Jul 20 06:29:44.988297 2026] [security2:error] [pid 929851:tid 929985] [client 86.18.126.4:59556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4UuGV3ou772CelrLiPvAAAAIU"]
[Mon Jul 20 06:29:45.019034 2026] [security2:error] [pid 929851:tid 930053] [client 188.232.7.148:51870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4UuWV3ou772CelrLiPvQAAAMk"]
[Mon Jul 20 06:29:45.221907 2026] [security2:error] [pid 929851:tid 930082] [client 82.102.18.116:56330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiPxwAAAOY"]
[Mon Jul 20 06:29:45.233553 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:64153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPWQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.239262 2026] [security2:error] [pid 929851:tid 930023] [client 223.185.13.213:5781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiPygAAAKs"]
[Mon Jul 20 06:29:45.239365 2026] [security2:error] [pid 929851:tid 930023] [client 223.185.13.213:5781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiPygAAAKs"]
[Mon Jul 20 06:29:45.305872 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP0AAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.306031 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP0AAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.329928 2026] [security2:error] [pid 929851:tid 930101] [client 35.231.144.158:62566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiP1AAAAPk"]
[Mon Jul 20 06:29:45.364122 2026] [security2:error] [pid 929851:tid 930068] [client 14.225.17.146:59108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiPzwAAANg"], referer: https://chestermonty.com/old
[Mon Jul 20 06:29:45.364210 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP3AAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.364298 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP3AAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.373518 2026] [security2:error] [pid 929851:tid 929996] [client 15.237.142.234:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiP2QAAAJA"]
[Mon Jul 20 06:29:45.373633 2026] [security2:error] [pid 929851:tid 929996] [client 15.237.142.234:43668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiP2QAAAJA"]
[Mon Jul 20 06:29:45.386328 2026] [security2:error] [pid 935758:tid 935900] [client 104.234.53.86:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UubcDxY_mIul-JSGGGgAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:45.418213 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:64070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP4gAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.418534 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:64070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP4gAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.473946 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:64118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 478 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UuWV3ou772CelrLiP5QAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.550487 2026] [security2:error] [pid 935758:tid 935904] [client 34.74.185.202:55376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UubcDxY_mIul-JSGGHwAAARg"]
[Mon Jul 20 06:29:45.564293 2026] [security2:error] [pid 935758:tid 935919] [client 82.102.18.116:56342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UubcDxY_mIul-JSGGIAAAASc"]
[Mon Jul 20 06:29:45.621061 2026] [security2:error] [pid 929851:tid 930104] [client 47.203.242.42:36939] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4UuWV3ou772CelrLiP9QAAAPw"]
[Mon Jul 20 06:29:45.627716 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UubcDxY_mIul-JSGGIwAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.645628 2026] [security2:error] [pid 935758:tid 935899] [client 5.147.122.105:62028] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UubcDxY_mIul-JSGGJQAAARM"]
[Mon Jul 20 06:29:45.679077 2026] [security2:error] [pid 929851:tid 930109] [client 77.110.127.138:64053] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/img_4196-2/"] [unique_id "al4UuWV3ou772CelrLiP-QAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.693112 2026] [security2:error] [pid 935758:tid 935901] [client 88.190.117.4:27386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UubcDxY_mIul-JSGGJgAAARU"]
[Mon Jul 20 06:29:45.702981 2026] [security2:error] [pid 929851:tid 929988] [client 57.141.18.44:28216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtmV3ou772CelrLiOiAAAiCs"]
[Mon Jul 20 06:29:45.712038 2026] [security2:error] [pid 929851:tid 930013] [client 84.123.100.20:50986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UuWV3ou772CelrLiP_AAAAKE"]
[Mon Jul 20 06:29:45.725843 2026] [security2:error] [pid 935758:tid 935932] [client 77.110.127.138:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/colour-work/sohim3j6lank.php"] [unique_id "al4UubcDxY_mIul-JSGGKAAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.732385 2026] [security2:error] [pid 929851:tid 930046] [client 35.231.144.158:59791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiP_QAAAMI"]
[Mon Jul 20 06:29:45.736819 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP_wAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.736932 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP_wAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.742420 2026] [security2:error] [pid 929851:tid 930087] [client 95.146.45.203:34714] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4UuWV3ou772CelrLiQAAAAAOs"]
[Mon Jul 20 06:29:45.792390 2026] [security2:error] [pid 929851:tid 930011] [client 70.80.217.121:40034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.ttf"] [unique_id "al4UuWV3ou772CelrLiQCAAAAJ8"]
[Mon Jul 20 06:29:45.792611 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:64116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:na"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UuWV3ou772CelrLiQBwAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.801529 2026] [security2:error] [pid 929851:tid 930043] [client 92.208.178.74:52000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4UuWV3ou772CelrLiQCQAAAL8"]
[Mon Jul 20 06:29:45.892646 2026] [security2:error] [pid 929851:tid 930073] [client 77.110.127.138:64137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiP9AAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.907374 2026] [security2:error] [pid 935758:tid 935951] [client 82.102.18.116:56350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UubcDxY_mIul-JSGGMgAAAUc"]
[Mon Jul 20 06:29:45.944718 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiQEgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.944874 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:64164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiQEgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.995624 2026] [security2:error] [pid 929851:tid 930106] [client 34.74.185.202:57211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiQEwAAAP4"]
[Mon Jul 20 06:29:46.005239 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQFAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.005337 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQFAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.056623 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQGAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.056770 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQGAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.074522 2026] [security2:error] [pid 929851:tid 930017] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiQBQAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.114411 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UubcDxY_mIul-JSGGLwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.126370 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UumV3ou772CelrLiQGwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.152807 2026] [security2:error] [pid 935758:tid 935922] [client 190.158.139.57:49232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4UurcDxY_mIul-JSGGOwAAASo"]
[Mon Jul 20 06:29:46.217383 2026] [security2:error] [pid 929851:tid 930101] [client 82.102.18.116:56362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQHwAAAPk"]
[Mon Jul 20 06:29:46.226206 2026] [security2:error] [pid 935758:tid 935963] [client 35.231.144.158:64844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UurcDxY_mIul-JSGGPAAAAVM"]
[Mon Jul 20 06:29:46.299809 2026] [security2:error] [pid 929851:tid 930071] [client 34.21.41.254:52648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/xmlrpc.php"] [unique_id "al4UumV3ou772CelrLiQIgAAANs"]
[Mon Jul 20 06:29:46.299910 2026] [security2:error] [pid 929851:tid 930071] [client 34.21.41.254:52648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "studio.xp-design.co"] [uri "/xmlrpc.php"] [unique_id "al4UumV3ou772CelrLiQIgAAANs"]
[Mon Jul 20 06:29:46.341307 2026] [security2:error] [pid 935758:tid 935965] [client 34.74.185.202:51762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UurcDxY_mIul-JSGGQwAAAVU"]
[Mon Jul 20 06:29:46.515306 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.10:59700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiO-AAA30c"]
[Mon Jul 20 06:29:46.527263 2026] [security2:error] [pid 929851:tid 930016] [client 82.102.18.116:56372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQLQAAAKQ"]
[Mon Jul 20 06:29:46.545088 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64153] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/img_4196-2/"] [unique_id "al4UumV3ou772CelrLiQLgAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.548376 2026] [security2:error] [pid 929851:tid 929996] [client 35.231.144.158:51461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQLwAAAJA"]
[Mon Jul 20 06:29:46.666204 2026] [security2:error] [pid 929851:tid 930043] [client 34.74.185.202:50286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQMwAAAL8"]
[Mon Jul 20 06:29:46.816527 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UurcDxY_mIul-JSGGTQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.816632 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UurcDxY_mIul-JSGGTQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.826382 2026] [security2:error] [pid 935758:tid 936003] [client 77.110.127.138:64158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-border/68apksk051pg.php"] [unique_id "al4UurcDxY_mIul-JSGGTwAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.839309 2026] [security2:error] [pid 929851:tid 930069] [client 82.102.18.116:56384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQPAAAANk"]
[Mon Jul 20 06:29:46.879017 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQQQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.879125 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQQQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.895122 2026] [security2:error] [pid 929851:tid 930049] [client 14.225.17.146:59040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4UumV3ou772CelrLiQHgAAAMU"], referer: http://aljosour-alarabia.com/old
[Mon Jul 20 06:29:46.916535 2026] [security2:error] [pid 935758:tid 935999] [client 35.231.144.158:64867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UurcDxY_mIul-JSGGVwAAAXc"]
[Mon Jul 20 06:29:47.031281 2026] [security2:error] [pid 929851:tid 930086] [client 57.141.18.49:34494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPHQAA6iA"]
[Mon Jul 20 06:29:47.034907 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQTQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.035043 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQTQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.047263 2026] [security2:error] [pid 929851:tid 930065] [client 77.110.127.138:64080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UumV3ou772CelrLiQOgAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.081804 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UumV3ou772CelrLiQPwAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.087726 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:64162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGYAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.087887 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:64162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGYAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.181094 2026] [security2:error] [pid 935758:tid 935920] [client 82.102.18.116:56392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGZAAAASg"]
[Mon Jul 20 06:29:47.192314 2026] [security2:error] [pid 929851:tid 930009] [client 57.141.18.46:48194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPOgAAnQ4"]
[Mon Jul 20 06:29:47.211642 2026] [security2:error] [pid 935758:tid 935894] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UurcDxY_mIul-JSGGVgAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.241453 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQWwAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.241542 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQWwAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.297522 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQXAAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.297641 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQXAAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.301137 2026] [security2:error] [pid 929851:tid 930066] [client 34.74.185.202:60667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu2V3ou772CelrLiQXgAAANY"]
[Mon Jul 20 06:29:47.353686 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQYAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.353816 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQYAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.434232 2026] [security2:error] [pid 929851:tid 930052] [client 171.60.139.123:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Uu2V3ou772CelrLiQZAAAAMg"]
[Mon Jul 20 06:29:47.434347 2026] [security2:error] [pid 929851:tid 930052] [client 171.60.139.123:51774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Uu2V3ou772CelrLiQZAAAAMg"]
[Mon Jul 20 06:29:47.440538 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.440717 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.497941 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcwAAATo"]
[Mon Jul 20 06:29:47.498132 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcwAAATo"]
[Mon Jul 20 06:29:47.527418 2026] [security2:error] [pid 935758:tid 935960] [client 82.102.18.116:56394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGdAAAAVA"]
[Mon Jul 20 06:29:47.551488 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:64142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQaQAAANQ"]
[Mon Jul 20 06:29:47.551572 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:64142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQaQAAANQ"]
[Mon Jul 20 06:29:47.573064 2026] [security2:error] [pid 935758:tid 935945] [client 35.231.144.158:62702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGdwAAAUE"]
[Mon Jul 20 06:29:47.657601 2026] [security2:error] [pid 935758:tid 935972] [client 103.153.183.69:26114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../etc/passwd"] [unique_id "al4Uu7cDxY_mIul-JSGGeQAAAVw"], referer: https://twitter.com/
[Mon Jul 20 06:29:47.865971 2026] [security2:error] [pid 929851:tid 930076] [client 34.74.185.202:50209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu2V3ou772CelrLiQcgAAAOA"]
[Mon Jul 20 06:29:47.931302 2026] [security2:error] [pid 935758:tid 935971] [client 35.231.144.158:62626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGhwAAAVs"]
[Mon Jul 20 06:29:47.969585 2026] [security2:error] [pid 929851:tid 930035] [client 57.141.18.96:47212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UuGV3ou772CelrLiPjAAAt2c"]
[Mon Jul 20 06:29:48.015116 2026] [security2:error] [pid 935758:tid 935917] [client 52.22.236.30:49834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Uu7cDxY_mIul-JSGGigAAASU"], referer: https://windowtx.com
[Mon Jul 20 06:29:48.055115 2026] [security2:error] [pid 929851:tid 929990] [client 104.234.53.93:30047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UvGV3ou772CelrLiQfAAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:48.201537 2026] [security2:error] [pid 929851:tid 930097] [client 34.74.185.202:57344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UvGV3ou772CelrLiQfwAAAPU"]
[Mon Jul 20 06:29:48.379687 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGoAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.379834 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGoAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.389716 2026] [security2:error] [pid 935758:tid 935904] [client 35.231.144.158:55913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UvLcDxY_mIul-JSGGowAAARg"]
[Mon Jul 20 06:29:48.540910 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGqQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.541011 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGqQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.593834 2026] [security2:error] [pid 929851:tid 930112] [client 77.110.127.138:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvGV3ou772CelrLiQjAAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.593946 2026] [security2:error] [pid 929851:tid 930112] [client 77.110.127.138:64172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvGV3ou772CelrLiQjAAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.680120 2026] [security2:error] [pid 935758:tid 935940] [client 103.141.108.143:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGrgAAATw"]
[Mon Jul 20 06:29:48.680273 2026] [security2:error] [pid 935758:tid 935940] [client 103.141.108.143:58881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGrgAAATw"]
[Mon Jul 20 06:29:48.704866 2026] [security2:error] [pid 929851:tid 930096] [client 57.141.18.62:25576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiP0gAA9F8"]
[Mon Jul 20 06:29:48.730706 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:64137] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UvGV3ou772CelrLiQkQAAAKA"]
[Mon Jul 20 06:29:48.749867 2026] [security2:error] [pid 935758:tid 935934] [client 34.74.185.202:50047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UvLcDxY_mIul-JSGGtAAAATY"]
[Mon Jul 20 06:29:48.774488 2026] [security2:error] [pid 935758:tid 935953] [client 45.116.69.230:60571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGuQAAAUk"]
[Mon Jul 20 06:29:48.774575 2026] [security2:error] [pid 935758:tid 935953] [client 45.116.69.230:60571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGuQAAAUk"]
[Mon Jul 20 06:29:48.795250 2026] [security2:error] [pid 935758:tid 936011] [client 14.225.17.146:59276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Uu7cDxY_mIul-JSGGYgAAAYM"], referer: http://lelandumc.org/old
[Mon Jul 20 06:29:48.828992 2026] [security2:error] [pid 935758:tid 935967] [client 35.231.144.158:53654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UvLcDxY_mIul-JSGGvwAAAVc"]
[Mon Jul 20 06:29:48.933727 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UvGV3ou772CelrLiQlQAAANc"]
[Mon Jul 20 06:29:49.018074 2026] [security2:error] [pid 929851:tid 930007] [client 83.114.245.181:42788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UvWV3ou772CelrLiQpAAAAJs"]
[Mon Jul 20 06:29:49.076460 2026] [security2:error] [pid 935758:tid 935923] [client 57.141.18.45:36318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UubcDxY_mIul-JSGGJAABKwI"]
[Mon Jul 20 06:29:49.157521 2026] [security2:error] [pid 929851:tid 930106] [client 158.173.89.95:28665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UvWV3ou772CelrLiQrAAAAP4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:49.227766 2026] [security2:error] [pid 929851:tid 930065] [client 35.231.144.158:55899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UvWV3ou772CelrLiQtQAAANU"]
[Mon Jul 20 06:29:49.458022 2026] [security2:error] [pid 935758:tid 936015] [client 34.74.185.202:55924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UvbcDxY_mIul-JSGG3AAAAYc"]
[Mon Jul 20 06:29:49.459844 2026] [security2:error] [pid 935758:tid 935929] [client 47.128.122.10:46604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG1QABMRk"]
[Mon Jul 20 06:29:49.669550 2026] [core:error] [pid 929851:tid 930012] [client 14.225.17.146:58698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:29:49.669576 2026] [core:error] [pid 929851:tid 930012] [client 14.225.17.146:58698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:29:49.688946 2026] [security2:error] [pid 929851:tid 930086] [client 121.229.156.93:42212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bluedoorbar.co.nz"] [uri "/"] [unique_id "al4UvWV3ou772CelrLiQyQAAAOo"]
[Mon Jul 20 06:29:49.689044 2026] [security2:error] [pid 929851:tid 930086] [client 121.229.156.93:42212] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bluedoorbar.co.nz"] [uri "/"] [unique_id "al4UvWV3ou772CelrLiQyQAAAOo"]
[Mon Jul 20 06:29:49.719602 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvWV3ou772CelrLiQzgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:49.719719 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvWV3ou772CelrLiQzgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:49.735131 2026] [security2:error] [pid 935758:tid 935902] [client 39.48.81.23:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UvbcDxY_mIul-JSGG4AAAARY"]
[Mon Jul 20 06:29:49.735227 2026] [security2:error] [pid 935758:tid 935902] [client 39.48.81.23:58774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UvbcDxY_mIul-JSGG4AAAARY"]
[Mon Jul 20 06:29:50.043670 2026] [security2:error] [pid 929851:tid 930055] [client 14.225.17.146:59018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4UvGV3ou772CelrLiQmwAAAMs"], referer: http://getgarrison.com/old
[Mon Jul 20 06:29:50.106621 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG5QAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.189775 2026] [security2:error] [pid 929851:tid 930083] [client 34.74.185.202:60660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UvmV3ou772CelrLiQ6QAAAOc"]
[Mon Jul 20 06:29:50.284380 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:64193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiQ8AAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.284478 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:64193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiQ8AAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.620142 2026] [security2:error] [pid 929851:tid 930012] [client 34.74.185.202:52622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UvmV3ou772CelrLiRBAAAAKA"]
[Mon Jul 20 06:29:50.632373 2026] [security2:error] [pid 929851:tid 930064] [client 104.234.53.53:41421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UvmV3ou772CelrLiQ_QAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:50.678973 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG-QAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.679168 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG-QAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.730064 2026] [security2:error] [pid 935758:tid 935992] [client 77.110.127.138:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG_AAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.730179 2026] [security2:error] [pid 935758:tid 935992] [client 77.110.127.138:64179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG_AAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.782277 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 263 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UvrcDxY_mIul-JSGHAQAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.843555 2026] [security2:error] [pid 935758:tid 936014] [client 77.110.127.138:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGHAgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.843674 2026] [security2:error] [pid 935758:tid 936014] [client 77.110.127.138:64198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGHAgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.861274 2026] [security2:error] [pid 935758:tid 935950] [client 57.141.18.113:25232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcgABRgg"]
[Mon Jul 20 06:29:50.966354 2026] [security2:error] [pid 929851:tid 930071] [client 77.110.127.138:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiRDgAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.966467 2026] [security2:error] [pid 929851:tid 930071] [client 77.110.127.138:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiRDgAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.995871 2026] [security2:error] [pid 935758:tid 935967] [client 14.225.17.146:53466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4UvrcDxY_mIul-JSGG9AAAAVc"]
[Mon Jul 20 06:29:51.227317 2026] [security2:error] [pid 935758:tid 935926] [client 14.225.17.146:57586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG5AAAAS4"], referer: http://expertcultures.com/old
[Mon Jul 20 06:29:51.376331 2026] [security2:error] [pid 929851:tid 930069] [client 14.225.17.146:57254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4UvWV3ou772CelrLiQqwAAANk"], referer: http://mrbambooplus.com/old
[Mon Jul 20 06:29:51.648126 2026] [security2:error] [pid 929851:tid 930009] [client 57.141.18.113:25260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvGV3ou772CelrLiQhAAAnSo"]
[Mon Jul 20 06:29:51.653035 2026] [security2:error] [pid 929851:tid 929987] [client 50.116.65.227:19154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Uv2V3ou772CelrLiRGQAAAIc"]
[Mon Jul 20 06:29:51.784500 2026] [security2:error] [pid 929851:tid 930018] [client 14.225.17.146:53381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Uv2V3ou772CelrLiRIAAAAKY"]
[Mon Jul 20 06:29:51.903250 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv7cDxY_mIul-JSGHJQAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.903404 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv7cDxY_mIul-JSGHJQAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.955714 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRLwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.955840 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRLwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.965775 2026] [security2:error] [pid 929851:tid 930032] [client 50.116.65.227:19168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Uv2V3ou772CelrLiRJwAAALQ"]
[Mon Jul 20 06:29:51.979247 2026] [security2:error] [pid 929851:tid 929929] [remote 173.212.252.15:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Uv2V3ou772CelrLiRMAAA10k"]
[Mon Jul 20 06:29:51.981238 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:64202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRMQAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.981343 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:64202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRMQAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.007300 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRNQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.007441 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:64137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRNQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.048644 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHKQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.049156 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHKQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.088757 2026] [security2:error] [pid 929851:tid 930048] [client 112.208.70.94:43661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UwGV3ou772CelrLiROgAAAMQ"]
[Mon Jul 20 06:29:52.088869 2026] [security2:error] [pid 929851:tid 930048] [client 112.208.70.94:43661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UwGV3ou772CelrLiROgAAAMQ"]
[Mon Jul 20 06:29:52.101334 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHLAAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.101503 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHLAAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.153990 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRPwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.154130 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRPwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.156837 2026] [security2:error] [pid 935758:tid 936005] [client 50.116.65.227:19180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UwLcDxY_mIul-JSGHMQAAAX0"]
[Mon Jul 20 06:29:52.158465 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:64212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRQAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.158537 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:64212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRQAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.167543 2026] [security2:error] [pid 935758:tid 936006] [client 50.116.65.227:19182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UwLcDxY_mIul-JSGHMwAAAX4"]
[Mon Jul 20 06:29:52.205224 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRSAAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.205329 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:64169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRSAAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.225831 2026] [security2:error] [pid 929851:tid 929888] [remote 173.212.252.15:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UwGV3ou772CelrLiRSQAA-SA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:29:52.313923 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHQAAAAXo"]
[Mon Jul 20 06:29:52.314024 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHQAAAAXo"]
[Mon Jul 20 06:29:52.498354 2026] [security2:error] [pid 929851:tid 929992] [client 104.234.53.53:41421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UwGV3ou772CelrLiRUwAAAIw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:52.525684 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHRQAAAYk"]
[Mon Jul 20 06:29:52.525776 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHRQAAAYk"]
[Mon Jul 20 06:29:52.688437 2026] [security2:error] [pid 935758:tid 936010] [client 57.141.18.6:28238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG2AABghs"]
[Mon Jul 20 06:29:52.718942 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.106:34196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvWV3ou772CelrLiQugAAzRI"]
[Mon Jul 20 06:29:52.834227 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRZQAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.834426 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRZQAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.119679 2026] [security2:error] [pid 929851:tid 929956] [remote 95.217.78.234:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UwWV3ou772CelrLiRcwAAtGQ"]
[Mon Jul 20 06:29:53.176934 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHXwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.177072 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHXwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.332654 2026] [security2:error] [pid 935758:tid 936014] [client 77.110.127.138:64219] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 969 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UwbcDxY_mIul-JSGHZwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.339022 2026] [security2:error] [pid 935758:tid 935962] [client 57.141.18.105:42774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvrcDxY_mIul-JSGG6gABUiA"]
[Mon Jul 20 06:29:53.339846 2026] [security2:error] [pid 929851:tid 929902] [remote 95.217.78.234:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UwWV3ou772CelrLiRfAAApC4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:29:53.359256 2026] [security2:error] [pid 935758:tid 935940] [client 14.225.17.146:57472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4UwbcDxY_mIul-JSGHWgAAATw"], referer: http://hilltopnurseryinc.com/old
[Mon Jul 20 06:29:53.386279 2026] [security2:error] [pid 929851:tid 930105] [client 85.87.87.122:57558] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4UwWV3ou772CelrLiRgAAAAP0"]
[Mon Jul 20 06:29:53.421122 2026] [security2:error] [pid 935758:tid 935968] [client 197.186.66.42:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHcgAAAVg"]
[Mon Jul 20 06:29:53.436364 2026] [security2:error] [pid 935758:tid 935968] [client 197.186.66.42:53354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHcgAAAVg"]
[Mon Jul 20 06:29:53.466996 2026] [security2:error] [pid 929851:tid 930094] [client 100.26.198.54:32358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.198.26.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UwWV3ou772CelrLiRiAAAAPI"]
[Mon Jul 20 06:29:53.467150 2026] [security2:error] [pid 929851:tid 930094] [client 100.26.198.54:32358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UwWV3ou772CelrLiRiAAAAPI"]
[Mon Jul 20 06:29:53.494656 2026] [security2:error] [pid 929851:tid 930106] [client 98.159.234.160:56751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UwWV3ou772CelrLiRiwAAAP4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:53.525520 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwWV3ou772CelrLiRjQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.525675 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwWV3ou772CelrLiRjQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.528520 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwbcDxY_mIul-JSGHYwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.650018 2026] [security2:error] [pid 935758:tid 935935] [client 57.141.18.94:35194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvrcDxY_mIul-JSGG8AABNyE"]
[Mon Jul 20 06:29:53.714043 2026] [security2:error] [pid 935758:tid 936016] [client 77.110.127.138:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHgAAAAYg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.714177 2026] [security2:error] [pid 935758:tid 936016] [client 77.110.127.138:64222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHgAAAAYg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.867494 2026] [security2:error] [pid 935758:tid 935891] [client 171.61.165.146:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHiwAAAQs"]
[Mon Jul 20 06:29:53.868425 2026] [security2:error] [pid 935758:tid 935891] [client 171.61.165.146:14626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHiwAAAQs"]
[Mon Jul 20 06:29:53.872784 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHjAAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.872912 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHjAAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.880160 2026] [security2:error] [pid 935758:tid 935966] [client 106.219.188.178:40187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHjQAAAVY"]
[Mon Jul 20 06:29:53.887500 2026] [security2:error] [pid 935758:tid 935966] [client 106.219.188.178:40187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHjQAAAVY"]
[Mon Jul 20 06:29:54.229961 2026] [security2:error] [pid 935758:tid 935893] [client 66.249.93.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4UwLcDxY_mIul-JSGHPwAAAQ0"]
[Mon Jul 20 06:29:54.245593 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHnAAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.276334 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHoAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.664518 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHsQAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.835252 2026] [security2:error] [pid 935758:tid 935923] [client 77.110.127.138:64230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHsgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.871139 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:64244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 401 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UwmV3ou772CelrLiR1gAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.879707 2026] [security2:error] [pid 935758:tid 935928] [client 14.225.17.146:57188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4UwLcDxY_mIul-JSGHVAAAATA"], referer: http://cheesewithjam.com/old
[Mon Jul 20 06:29:55.023322 2026] [security2:error] [pid 935758:tid 935939] [client 77.110.127.138:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHygAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.023424 2026] [security2:error] [pid 935758:tid 935939] [client 77.110.127.138:64246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHygAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.178479 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR5QAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.178570 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR5QAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.328282 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHzwAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.328414 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHzwAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.373872 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:64203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiR4AAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.378413 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR9gAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.378512 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR9gAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.558262 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR_AAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.558384 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR_AAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.738632 2026] [security2:error] [pid 935758:tid 935943] [client 14.225.17.146:53252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHqAAAAT8"], referer: http://amalia-capital.com/old
[Mon Jul 20 06:29:55.770230 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSBgAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.770347 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSBgAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.798922 2026] [security2:error] [pid 935758:tid 936009] [client 82.102.27.163:60212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Uw7cDxY_mIul-JSGH2wAAAYE"]
[Mon Jul 20 06:29:55.799012 2026] [security2:error] [pid 935758:tid 936009] [client 82.102.27.163:60212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Uw7cDxY_mIul-JSGH2wAAAYE"]
[Mon Jul 20 06:29:55.874382 2026] [security2:error] [pid 929851:tid 930096] [client 223.185.13.213:27813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uw2V3ou772CelrLiSFAAAAPQ"]
[Mon Jul 20 06:29:55.874465 2026] [security2:error] [pid 929851:tid 930096] [client 223.185.13.213:27813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uw2V3ou772CelrLiSFAAAAPQ"]
[Mon Jul 20 06:29:55.966831 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSGAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.966954 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSGAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.036175 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH5wAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.036900 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH5wAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.075289 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.98:39572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UwLcDxY_mIul-JSGHVwABhTM"]
[Mon Jul 20 06:29:56.206100 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uw7cDxY_mIul-JSGH5AAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.260796 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH7AAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.260918 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH7AAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.300629 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:53401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiSBAAAAKQ"], referer: http://eframiproperties.com/old
[Mon Jul 20 06:29:56.636200 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UxGV3ou772CelrLiSKQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.839658 2026] [security2:error] [pid 929851:tid 930060] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4UxGV3ou772CelrLiSMQAA0Ek"], referer: http://aleishapenny.ca/old
[Mon Jul 20 06:29:56.904724 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UxLcDxY_mIul-JSGIFwAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.957984 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGIGQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.958120 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGIGQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.983342 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:64263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UxLcDxY_mIul-JSGIDQAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:57.181894 2026] [security2:error] [pid 929851:tid 930041] [client 14.225.17.146:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiSAwAAAL0"], referer: http://bbwipartnerconference.com/old
[Mon Jul 20 06:29:57.367712 2026] [security2:error] [pid 935758:tid 936003] [client 57.141.18.11:52866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHnwABe0w"]
[Mon Jul 20 06:29:57.677875 2026] [security2:error] [pid 929851:tid 930070] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4UxWV3ou772CelrLiSTAAA2lg"], referer: https://aleishapenny.ca/old
[Mon Jul 20 06:29:58.154994 2026] [security2:error] [pid 935758:tid 935979] [client 171.60.139.123:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UxrcDxY_mIul-JSGIUQAAAWM"]
[Mon Jul 20 06:29:58.155193 2026] [security2:error] [pid 935758:tid 935979] [client 171.60.139.123:52309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UxrcDxY_mIul-JSGIUQAAAWM"]
[Mon Jul 20 06:29:58.406175 2026] [security2:error] [pid 929851:tid 930046] [client 57.141.18.55:65282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiR4wAAwhA"]
[Mon Jul 20 06:29:58.593126 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.44:22124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiR7wAAwUE"]
[Mon Jul 20 06:29:58.609854 2026] [security2:error] [pid 935758:tid 935767] [remote 152.53.111.131:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UxrcDxY_mIul-JSGIZwABDAY"]
[Mon Jul 20 06:29:58.832281 2026] [security2:error] [pid 935758:tid 935773] [remote 152.53.111.131:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UxrcDxY_mIul-JSGIeQABCww"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:29:58.958510 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxmV3ou772CelrLiSdQAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:58.958626 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxmV3ou772CelrLiSdQAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:58.987849 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.7:62770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiSDQAA3yw"]
[Mon Jul 20 06:29:59.112287 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ux7cDxY_mIul-JSGIiAAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.112401 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ux7cDxY_mIul-JSGIiAAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.404976 2026] [security2:error] [pid 935758:tid 935978] [client 103.141.108.143:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGImwAAAWI"]
[Mon Jul 20 06:29:59.405569 2026] [security2:error] [pid 935758:tid 935978] [client 103.141.108.143:59396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGImwAAAWI"]
[Mon Jul 20 06:29:59.526679 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ux2V3ou772CelrLiSegAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.561514 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:64273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ux7cDxY_mIul-JSGIkAAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.564594 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ux2V3ou772CelrLiSgAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.694041 2026] [security2:error] [pid 935758:tid 935892] [client 45.116.69.230:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGIpwAAAQw"]
[Mon Jul 20 06:29:59.694137 2026] [security2:error] [pid 935758:tid 935892] [client 45.116.69.230:61106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGIpwAAAQw"]
[Mon Jul 20 06:29:59.766618 2026] [security2:error] [pid 929851:tid 929924] [remote 160.187.68.132:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4Ux2V3ou772CelrLiSkgAAikQ"]
[Mon Jul 20 06:30:00.117830 2026] [security2:error] [pid 935758:tid 935966] [client 57.141.18.50:27512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UxLcDxY_mIul-JSGICAABVmg"]
[Mon Jul 20 06:30:00.168593 2026] [core:error] [pid 935758:tid 935918] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:00.168622 2026] [core:error] [pid 935758:tid 935918] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:00.294534 2026] [security2:error] [pid 929851:tid 929953] [remote 160.187.68.132:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4UyGV3ou772CelrLiSpwAArWE"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:30:00.351957 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyGV3ou772CelrLiSoAAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.393204 2026] [security2:error] [pid 935758:tid 935976] [client 63.179.149.246:36006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UyLcDxY_mIul-JSGIvgAAAWA"]
[Mon Jul 20 06:30:00.416226 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGIvwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.416337 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGIvwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.428058 2026] [security2:error] [pid 935758:tid 935960] [client 39.48.81.23:59254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UyLcDxY_mIul-JSGIwAAAAVA"]
[Mon Jul 20 06:30:00.428172 2026] [security2:error] [pid 935758:tid 935960] [client 39.48.81.23:59254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UyLcDxY_mIul-JSGIwAAAAVA"]
[Mon Jul 20 06:30:00.462624 2026] [security2:error] [pid 929851:tid 930065] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyGV3ou772CelrLiSpQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.741217 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyGV3ou772CelrLiSvQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.741367 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyGV3ou772CelrLiSvQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.791284 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGI0QAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.791396 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGI0QAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.958082 2026] [security2:error] [pid 935758:tid 935944] [client 3.75.183.99:29194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UyLcDxY_mIul-JSGI2wAAAUA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:30:00.975206 2026] [security2:error] [pid 935758:tid 935961] [client 77.110.127.138:64280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGIzQAAAVE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.013059 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGIzwAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.043228 2026] [security2:error] [pid 935758:tid 935941] [client 57.141.18.6:22956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UxbcDxY_mIul-JSGILQABPXI"]
[Mon Jul 20 06:30:01.143961 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI5QAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.144108 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI5QAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.248251 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UybcDxY_mIul-JSGI4QAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.445772 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:64286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI-wAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.445877 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:64286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI-wAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.783894 2026] [security2:error] [pid 929851:tid 930035] [client 77.110.127.138:64284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyWV3ou772CelrLiS1wAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.824110 2026] [security2:error] [pid 935758:tid 936006] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UybcDxY_mIul-JSGI-QAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.825826 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UybcDxY_mIul-JSGJAAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.909787 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyWV3ou772CelrLiS7gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.909918 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyWV3ou772CelrLiS7gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.918208 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGJFwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.918383 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGJFwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:02.338489 2026] [security2:error] [pid 929851:tid 929890] [remote 50.28.1.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4UymV3ou772CelrLiTAAAAiSI"]
[Mon Jul 20 06:30:02.338709 2026] [security2:error] [pid 929851:tid 929989] [client 50.28.1.50:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4UymV3ou772CelrLiTAAAAiSI"]
[Mon Jul 20 06:30:02.580534 2026] [security2:error] [pid 935758:tid 935902] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-27c0eea6.iwv.oao.mybluehost.me"] [uri "/index.php"] [unique_id "al4UxrcDxY_mIul-JSGIcwAAARY"]
[Mon Jul 20 06:30:02.837950 2026] [security2:error] [pid 929851:tid 930072] [client 57.141.18.94:29264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UxmV3ou772CelrLiSaAAA3CE"]
[Mon Jul 20 06:30:03.959064 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uy7cDxY_mIul-JSGJYwAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.226405 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:64293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uy7cDxY_mIul-JSGJegAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.235175 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJgQAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.406994 2026] [security2:error] [pid 935758:tid 936010] [client 57.141.18.104:42536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGItgABghk"]
[Mon Jul 20 06:30:04.427571 2026] [security2:error] [pid 935758:tid 935978] [client 197.186.66.42:53822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJngAAAWI"]
[Mon Jul 20 06:30:04.427710 2026] [security2:error] [pid 935758:tid 935978] [client 197.186.66.42:53822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJngAAAWI"]
[Mon Jul 20 06:30:04.530958 2026] [security2:error] [pid 935758:tid 935986] [client 171.61.165.146:16808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJoAAAAWo"]
[Mon Jul 20 06:30:04.531107 2026] [security2:error] [pid 935758:tid 935986] [client 171.61.165.146:16808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJoAAAAWo"]
[Mon Jul 20 06:30:04.595270 2026] [security2:error] [pid 935758:tid 935835] [remote 72.167.132.114:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4UzLcDxY_mIul-JSGJpwABR0o"]
[Mon Jul 20 06:30:04.681917 2026] [security2:error] [pid 929851:tid 929991] [client 106.219.188.178:51798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UzGV3ou772CelrLiTXwAAAIs"]
[Mon Jul 20 06:30:04.682351 2026] [security2:error] [pid 929851:tid 929991] [client 106.219.188.178:51798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UzGV3ou772CelrLiTXwAAAIs"]
[Mon Jul 20 06:30:04.781649 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJrwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.781766 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJrwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.791352 2026] [security2:error] [pid 935758:tid 935905] [client 57.141.18.108:61724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGIxQABGR4"]
[Mon Jul 20 06:30:04.824499 2026] [security2:error] [pid 935758:tid 935839] [remote 72.167.132.114:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4UzLcDxY_mIul-JSGJtAABaU4"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:30:04.882549 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJtwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.882716 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJtwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.934980 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:64305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJuQAAAR0"]
[Mon Jul 20 06:30:04.935101 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:64305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJuQAAAR0"]
[Mon Jul 20 06:30:05.060442 2026] [security2:error] [pid 935758:tid 935949] [client 24.216.165.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "poopatrol608.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJuAAAAUU"], referer: https://facebook.com/
[Mon Jul 20 06:30:05.147726 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJxAAAAYI"]
[Mon Jul 20 06:30:05.147853 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJxAAAAYI"]
[Mon Jul 20 06:30:05.174011 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.32:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGI1AABYx0"]
[Mon Jul 20 06:30:05.372472 2026] [security2:error] [pid 935758:tid 935895] [client 77.110.127.138:64307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJvgAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.413949 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64311] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UzWV3ou772CelrLiTegAAAKE"]
[Mon Jul 20 06:30:05.415133 2026] [security2:error] [pid 935758:tid 936003] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJvwAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.420441 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJwgAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.480019 2026] [security2:error] [pid 935758:tid 936004] [client 14.225.17.146:60518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJhwAAAXw"], referer: http://momheadquarters.com/old
[Mon Jul 20 06:30:05.535715 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzWV3ou772CelrLiTfQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.535853 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzWV3ou772CelrLiTfQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.541077 2026] [security2:error] [pid 935758:tid 935926] [client 104.234.53.61:57857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UzbcDxY_mIul-JSGJ3gAAAS4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:05.754145 2026] [security2:error] [pid 935758:tid 935802] [remote 57.141.18.77:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4107923"] [unique_id "al4UzbcDxY_mIul-JSGJ6QABESk"]
[Mon Jul 20 06:30:05.900800 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJ6AAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.907365 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ9wAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.907474 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ9wAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.960558 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ-wAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.960657 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:64287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ-wAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:06.015202 2026] [security2:error] [pid 935758:tid 935953] [client 112.208.70.94:44131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UzrcDxY_mIul-JSGJ_gAAAUk"]
[Mon Jul 20 06:30:06.015375 2026] [security2:error] [pid 935758:tid 935953] [client 112.208.70.94:44131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UzrcDxY_mIul-JSGJ_gAAAUk"]
[Mon Jul 20 06:30:06.054679 2026] [security2:error] [pid 935758:tid 936012] [client 216.73.216.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.poopscoopmarketing.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJ9AAAAYQ"]
[Mon Jul 20 06:30:06.239706 2026] [security2:error] [pid 935758:tid 935920] [client 57.141.18.30:23182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyrcDxY_mIul-JSGJHgABKC4"]
[Mon Jul 20 06:30:06.659726 2026] [security2:error] [pid 935758:tid 935968] [client 77.110.127.138:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzrcDxY_mIul-JSGKQQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:06.659839 2026] [security2:error] [pid 935758:tid 935968] [client 77.110.127.138:64319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzrcDxY_mIul-JSGKQQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:06.670788 2026] [security2:error] [pid 935758:tid 935961] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKFwAAAVE"]
[Mon Jul 20 06:30:06.702095 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKIwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.042634 2026] [security2:error] [pid 935758:tid 935951] [client 77.110.127.138:64323] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4Uz7cDxY_mIul-JSGKYgAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.046178 2026] [security2:error] [pid 929851:tid 930040] [client 72.154.155.130:33090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.seidemannlab.site"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al4Uz2V3ou772CelrLiTtAAAALw"]
[Mon Jul 20 06:30:07.079925 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzmV3ou772CelrLiTsAAAAMQ"]
[Mon Jul 20 06:30:07.196559 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.52:33176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UymV3ou772CelrLiTFwAA2C0"]
[Mon Jul 20 06:30:07.205774 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKbwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.205875 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKbwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.256890 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKdQAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.257054 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKdQAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.289869 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uz7cDxY_mIul-JSGKYAAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.434940 2026] [core:error] [pid 929851:tid 930041] [client 14.225.17.146:64220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:07.434967 2026] [core:error] [pid 929851:tid 930041] [client 14.225.17.146:64220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:07.572126 2026] [security2:error] [pid 929851:tid 930050] [client 57.141.18.111:57470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uy2V3ou772CelrLiTNgAAxhE"]
[Mon Jul 20 06:30:07.613038 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:60317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Uz2V3ou772CelrLiTyQAAAKQ"]
[Mon Jul 20 06:30:07.626552 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiTzAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.626646 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiTzAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.679621 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKhwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.679760 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKhwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.873008 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKkQAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.873147 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKkQAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.909766 2026] [security2:error] [pid 929851:tid 930104] [client 87.199.196.160:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nurturemarple.co.uk"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiT2wAAAPw"], referer: https://www.nurturemarple.co.uk/download/pre-school-september-2023/
[Mon Jul 20 06:30:07.909875 2026] [security2:error] [pid 929851:tid 930104] [client 87.199.196.160:58065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.nurturemarple.co.uk"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiT2wAAAPw"], referer: https://www.nurturemarple.co.uk/download/pre-school-september-2023/
[Mon Jul 20 06:30:07.941055 2026] [security2:error] [pid 935758:tid 936008] [client 14.225.17.146:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKAgAAAYA"], referer: http://tacticaltreeoperations.com/old
[Mon Jul 20 06:30:08.150261 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT5QAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.150398 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:64329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT5QAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.219130 2026] [security2:error] [pid 935758:tid 935967] [client 57.141.18.61:39930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJfQABV0A"]
[Mon Jul 20 06:30:08.266442 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT6gAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.266559 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT6gAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.452769 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKuAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.452908 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKuAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.583622 2026] [security2:error] [pid 935758:tid 935897] [client 14.225.17.146:54225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4Uz7cDxY_mIul-JSGKeAAAARE"], referer: http://idigress.agency/old
[Mon Jul 20 06:30:08.645378 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKvwAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.645470 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKvwAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.746192 2026] [security2:error] [pid 935758:tid 935965] [client 114.119.153.172:31841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jndsupport.com"] [uri "/heres-whats-in-store-for-the-last-windows-moments-update/"] [unique_id "al4U0LcDxY_mIul-JSGKwgAAAVU"], referer: https://jndsupport.com/blog/
[Mon Jul 20 06:30:08.877335 2026] [security2:error] [pid 935758:tid 935946] [client 57.141.18.21:41378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJpQABQkk"]
[Mon Jul 20 06:30:08.892691 2026] [security2:error] [pid 935758:tid 935890] [client 57.141.18.25:57198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJqAABCiM"]
[Mon Jul 20 06:30:09.005597 2026] [security2:error] [pid 935758:tid 935870] [remote 152.228.213.32:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4U0LcDxY_mIul-JSGK0QABTW0"]
[Mon Jul 20 06:30:09.038546 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:64337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/cowl/feed/"] [unique_id "al4U0WV3ou772CelrLiUCQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.089054 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0bcDxY_mIul-JSGK1QAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.089240 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:64316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0bcDxY_mIul-JSGK1QAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.163790 2026] [security2:error] [pid 935758:tid 935899] [client 171.60.139.123:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U0bcDxY_mIul-JSGK1gAAARM"]
[Mon Jul 20 06:30:09.163914 2026] [security2:error] [pid 935758:tid 935899] [client 171.60.139.123:52836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U0bcDxY_mIul-JSGK1gAAARM"]
[Mon Jul 20 06:30:09.198318 2026] [security2:error] [pid 935758:tid 935772] [remote 152.228.213.32:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4U0bcDxY_mIul-JSGK2gABcQs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:30:09.201550 2026] [core:error] [pid 935758:tid 935920] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.201583 2026] [core:error] [pid 935758:tid 935920] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.253723 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4U0bcDxY_mIul-JSGK3wAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.598478 2026] [security2:error] [pid 935758:tid 935888] [remote 91.142.222.105:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4U0bcDxY_mIul-JSGK8QABDn8"]
[Mon Jul 20 06:30:09.621557 2026] [security2:error] [pid 929851:tid 930070] [client 223.185.13.213:23492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0WV3ou772CelrLiUIAAAANo"]
[Mon Jul 20 06:30:09.621692 2026] [security2:error] [pid 929851:tid 930070] [client 223.185.13.213:23492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0WV3ou772CelrLiUIAAAANo"]
[Mon Jul 20 06:30:09.656464 2026] [core:error] [pid 929851:tid 930059] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.656482 2026] [core:error] [pid 929851:tid 930072] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.656491 2026] [core:error] [pid 929851:tid 930059] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.656502 2026] [core:error] [pid 929851:tid 930072] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.750696 2026] [security2:error] [pid 935758:tid 935903] [client 57.141.18.53:41958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJ3AABF1Q"]
[Mon Jul 20 06:30:09.894520 2026] [proxy:error] [pid 935758:tid 936015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:09.894573 2026] [proxy_http:error] [pid 935758:tid 936015] [client 34.73.38.214:56403] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:09.895564 2026] [proxy:error] [pid 935758:tid 936015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:09.895625 2026] [proxy_http:error] [pid 935758:tid 936015] [client 34.73.38.214:56403] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:09.928261 2026] [security2:error] [pid 935758:tid 935783] [remote 91.142.222.105:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4U0bcDxY_mIul-JSGLAgABIhY"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:30:10.000570 2026] [security2:error] [pid 929851:tid 930012] [client 14.225.17.146:60423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4U0WV3ou772CelrLiULAAAAKA"], referer: http://thechancersband.com/old
[Mon Jul 20 06:30:10.090610 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U0mV3ou772CelrLiUNAAAAQQ"]
[Mon Jul 20 06:30:10.090740 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:59885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U0mV3ou772CelrLiUNAAAAQQ"]
[Mon Jul 20 06:30:10.224458 2026] [security2:error] [pid 935758:tid 935910] [client 14.225.17.146:64074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4U0LcDxY_mIul-JSGKtwAAAR4"], referer: http://fluidtemple.org/old
[Mon Jul 20 06:30:10.312722 2026] [security2:error] [pid 935758:tid 935981] [client 158.173.166.181:46685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U0rcDxY_mIul-JSGLGAAAAWU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:10.520476 2026] [security2:error] [pid 935758:tid 935911] [client 45.116.69.230:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLLAAAAR8"]
[Mon Jul 20 06:30:10.520645 2026] [security2:error] [pid 935758:tid 935911] [client 45.116.69.230:61651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLLAAAAR8"]
[Mon Jul 20 06:30:10.675160 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0mV3ou772CelrLiURwAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:10.675313 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0mV3ou772CelrLiURwAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:10.955954 2026] [security2:error] [pid 935758:tid 935918] [client 39.48.81.23:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLPAAAASY"]
[Mon Jul 20 06:30:10.956073 2026] [security2:error] [pid 935758:tid 935918] [client 39.48.81.23:59745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLPAAAASY"]
[Mon Jul 20 06:30:10.967196 2026] [security2:error] [pid 935758:tid 936017] [client 57.141.18.102:51810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKNQABiTQ"]
[Mon Jul 20 06:30:11.049929 2026] [security2:error] [pid 935758:tid 935936] [client 50.116.65.227:45964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U07cDxY_mIul-JSGLQwAAATg"]
[Mon Jul 20 06:30:11.062963 2026] [security2:error] [pid 935758:tid 935897] [client 50.116.65.227:45978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U07cDxY_mIul-JSGLRwAAARE"]
[Mon Jul 20 06:30:11.088915 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U0mV3ou772CelrLiUTAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.213736 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:11.213836 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57269] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:11.215168 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:11.215207 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57269] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:11.314918 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U07cDxY_mIul-JSGLVQAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.315096 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U07cDxY_mIul-JSGLVQAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.366804 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/cowl/feed/"] [unique_id "al4U07cDxY_mIul-JSGLWgAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.438854 2026] [security2:error] [pid 935758:tid 935800] [remote 192.241.143.148:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U07cDxY_mIul-JSGLXAABQCc"]
[Mon Jul 20 06:30:11.585187 2026] [security2:error] [pid 935758:tid 935990] [client 57.141.18.22:49872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uz7cDxY_mIul-JSGKcwABbmY"]
[Mon Jul 20 06:30:11.621684 2026] [security2:error] [pid 935758:tid 935809] [remote 192.241.143.148:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U07cDxY_mIul-JSGLaQABVzA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:11.862146 2026] [security2:error] [pid 929851:tid 930008] [client 57.141.18.3:41510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uz2V3ou772CelrLiTzQAAnFI"]
[Mon Jul 20 06:30:12.008547 2026] [security2:error] [pid 935758:tid 935920] [client 14.225.17.146:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLHwAAASg"], referer: http://olearyplumbingllc.com/old
[Mon Jul 20 06:30:12.055210 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1LcDxY_mIul-JSGLfwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:12.055321 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1LcDxY_mIul-JSGLfwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:12.109108 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4U1LcDxY_mIul-JSGLgwAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:12.588332 2026] [proxy:error] [pid 929851:tid 930089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:12.588419 2026] [proxy_http:error] [pid 929851:tid 930089] [client 34.73.38.214:56754] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:12.589603 2026] [proxy:error] [pid 929851:tid 930089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:12.589647 2026] [proxy_http:error] [pid 929851:tid 930089] [client 34.73.38.214:56754] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:12.590563 2026] [security2:error] [pid 935758:tid 935919] [client 14.225.17.146:54491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLPQAAASc"], referer: http://floorsourcestock.com/old
[Mon Jul 20 06:30:12.733070 2026] [security2:error] [pid 935758:tid 935957] [client 14.225.17.146:54465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLNwAAAU0"], referer: http://aandarealtygroup.com/old
[Mon Jul 20 06:30:13.334742 2026] [security2:error] [pid 929851:tid 930091] [client 34.221.76.50:29440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4U1WV3ou772CelrLiUoQAAAO8"]
[Mon Jul 20 06:30:13.812367 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.37:52096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U0WV3ou772CelrLiUHwAAn2w"]
[Mon Jul 20 06:30:14.011064 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL2AAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.011217 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL2AAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.254114 2026] [security2:error] [pid 935758:tid 935983] [client 57.141.18.33:20336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U0bcDxY_mIul-JSGLCwABZwI"]
[Mon Jul 20 06:30:14.330018 2026] [security2:error] [pid 935758:tid 935790] [remote 20.173.88.122:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U1rcDxY_mIul-JSGL6QABOB0"]
[Mon Jul 20 06:30:14.359415 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/cowl/feed/"] [unique_id "al4U1rcDxY_mIul-JSGL7AAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.510845 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1mV3ou772CelrLiUzwAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.510952 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1mV3ou772CelrLiUzwAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.541381 2026] [proxy:error] [pid 935758:tid 935922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:14.541455 2026] [proxy_http:error] [pid 935758:tid 935922] [client 34.73.38.214:60308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:14.542886 2026] [proxy:error] [pid 935758:tid 935922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:14.542928 2026] [proxy_http:error] [pid 935758:tid 935922] [client 34.73.38.214:60308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:14.555366 2026] [security2:error] [pid 935758:tid 935986] [client 65.111.25.164:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U1rcDxY_mIul-JSGL8AAAAWo"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:14.573299 2026] [security2:error] [pid 935758:tid 935894] [client 14.225.17.146:54719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4U1bcDxY_mIul-JSGLugAAAQ4"], referer: http://betterbonddogtraining.com/old
[Mon Jul 20 06:30:14.634496 2026] [security2:error] [pid 935758:tid 935947] [client 57.141.18.30:45400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLHAABQxw"]
[Mon Jul 20 06:30:14.663517 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL-QAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.663631 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL-QAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.733012 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U1rcDxY_mIul-JSGL7wAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.908286 2026] [security2:error] [pid 935758:tid 935846] [remote 20.173.88.122:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U1rcDxY_mIul-JSGMBAABDFU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:14.999276 2026] [security2:error] [pid 929851:tid 930000] [client 14.225.17.146:64161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4U1mV3ou772CelrLiU4QAAAJQ"], referer: http://omrobuildingcenter.com/old
[Mon Jul 20 06:30:15.131304 2026] [security2:error] [pid 935758:tid 935976] [client 45.157.112.60:35583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U17cDxY_mIul-JSGMDAAAAWA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:15.264572 2026] [security2:error] [pid 935758:tid 935995] [client 197.186.66.42:54295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFAAAAXM"]
[Mon Jul 20 06:30:15.265024 2026] [security2:error] [pid 935758:tid 935995] [client 197.186.66.42:54295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFAAAAXM"]
[Mon Jul 20 06:30:15.328661 2026] [security2:error] [pid 935758:tid 935939] [client 171.61.165.146:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFwAAATs"]
[Mon Jul 20 06:30:15.329641 2026] [security2:error] [pid 935758:tid 935939] [client 171.61.165.146:17532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFwAAATs"]
[Mon Jul 20 06:30:15.344345 2026] [security2:error] [pid 935758:tid 935919] [client 106.219.188.178:25950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMGQAAASc"]
[Mon Jul 20 06:30:15.344745 2026] [security2:error] [pid 935758:tid 935919] [client 106.219.188.178:25950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMGQAAASc"]
[Mon Jul 20 06:30:15.647940 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMHQAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:15.974864 2026] [security2:error] [pid 935758:tid 935957] [client 34.73.38.214:63400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4U17cDxY_mIul-JSGMNAAAAU0"]
[Mon Jul 20 06:30:16.050310 2026] [security2:error] [pid 935758:tid 935868] [remote 57.141.18.102:58620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4U2LcDxY_mIul-JSGMNgABS2s"]
[Mon Jul 20 06:30:16.117075 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.2:22532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U02V3ou772CelrLiUcAAA2wY"]
[Mon Jul 20 06:30:16.153500 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U12V3ou772CelrLiVFQAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:16.163644 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2LcDxY_mIul-JSGMOQAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:16.163792 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2LcDxY_mIul-JSGMOQAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:16.174870 2026] [security2:error] [pid 935758:tid 936015] [client 57.141.18.9:46940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U07cDxY_mIul-JSGLdQABhxE"]
[Mon Jul 20 06:30:16.220490 2026] [autoindex:error] [pid 929851:tid 930110] [client 43.130.111.40:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.varmath.com
[Mon Jul 20 06:30:16.246902 2026] [security2:error] [pid 935758:tid 936003] [client 57.141.18.125:34028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U1LcDxY_mIul-JSGLgAABeyA"]
[Mon Jul 20 06:30:16.469205 2026] [security2:error] [pid 935758:tid 935879] [remote 194.164.192.228:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4U2LcDxY_mIul-JSGMQwABI3Y"]
[Mon Jul 20 06:30:16.689438 2026] [security2:error] [pid 935758:tid 935866] [remote 194.164.192.228:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4U2LcDxY_mIul-JSGMRgABCmk"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:30:16.736953 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2GV3ou772CelrLiVNQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.031183 2026] [security2:error] [pid 935758:tid 935899] [client 57.141.18.118:55038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U1LcDxY_mIul-JSGLrAABE0Q"]
[Mon Jul 20 06:30:17.074969 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2bcDxY_mIul-JSGMYQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.075142 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2bcDxY_mIul-JSGMYQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.127055 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2WV3ou772CelrLiVTgAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.127179 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2WV3ou772CelrLiVTgAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.177822 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4U2bcDxY_mIul-JSGMZAAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.342697 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2bcDxY_mIul-JSGMYgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.447906 2026] [security2:error] [pid 929851:tid 930099] [client 13.201.64.214:46334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U2WV3ou772CelrLiVWQAAAPc"]
[Mon Jul 20 06:30:17.447981 2026] [security2:error] [pid 929851:tid 930099] [client 13.201.64.214:46334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U2WV3ou772CelrLiVWQAAAPc"]
[Mon Jul 20 06:30:17.519328 2026] [security2:error] [pid 929851:tid 930104] [client 34.73.38.214:53808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4U2WV3ou772CelrLiVXAAAAPw"]
[Mon Jul 20 06:30:17.561683 2026] [core:error] [pid 929851:tid 930072] [client 103.153.183.69:37106] AH10244: invalid URI path (/../../../../etc/passwd?_=3scrqhos&v=4hezl), referer: https://duckduckgo.com/?q=7kcgk
[Mon Jul 20 06:30:17.565056 2026] [security2:error] [pid 935758:tid 935927] [client 127.0.0.1:43090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4U2bcDxY_mIul-JSGMdQAAAS8"], referer: https://duckduckgo.com/?q=7kcgk
[Mon Jul 20 06:30:17.651650 2026] [security2:error] [pid 929851:tid 930019] [client 57.141.18.4:52670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U1WV3ou772CelrLiUpQAApy0"]
[Mon Jul 20 06:30:17.888190 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2WV3ou772CelrLiVaQAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.900720 2026] [security2:error] [pid 929851:tid 930043] [client 14.225.17.146:54041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4U2GV3ou772CelrLiVMQAAAL8"], referer: http://kromosenergy.com/old
[Mon Jul 20 06:30:17.977290 2026] [security2:error] [pid 929851:tid 930076] [client 77.110.127.138:64355] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U2WV3ou772CelrLiVfAAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.990067 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4U2GV3ou772CelrLiVLwAAANU"], referer: http://ironcitywellness.com/old
[Mon Jul 20 06:30:18.152106 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMgwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.152243 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMgwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.315194 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVhQAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.315296 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:64379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVhQAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.406863 2026] [security2:error] [pid 935758:tid 935772] [remote 124.55.178.99:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4U2rcDxY_mIul-JSGMjgABfQs"]
[Mon Jul 20 06:30:18.522490 2026] [security2:error] [pid 935758:tid 935973] [client 112.208.70.94:44563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U2rcDxY_mIul-JSGMlwAAAV0"]
[Mon Jul 20 06:30:18.522678 2026] [security2:error] [pid 935758:tid 935973] [client 112.208.70.94:44563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U2rcDxY_mIul-JSGMlwAAAV0"]
[Mon Jul 20 06:30:18.530575 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:64380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMmQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.530685 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:64380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMmQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.593972 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVlwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.594078 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:64361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVlwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.645910 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVmQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.646083 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVmQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.684673 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2mV3ou772CelrLiVgwAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.712866 2026] [security2:error] [pid 929851:tid 930009] [client 77.110.127.138:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVnQAAAJ0"]
[Mon Jul 20 06:30:18.712988 2026] [security2:error] [pid 929851:tid 930009] [client 77.110.127.138:64362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVnQAAAJ0"]
[Mon Jul 20 06:30:18.863203 2026] [security2:error] [pid 935758:tid 935974] [client 77.110.127.138:64382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMpgAAAV4"]
[Mon Jul 20 06:30:18.863287 2026] [security2:error] [pid 935758:tid 935974] [client 77.110.127.138:64382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMpgAAAV4"]
[Mon Jul 20 06:30:18.863501 2026] [security2:error] [pid 935758:tid 935858] [remote 124.55.178.99:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4U2rcDxY_mIul-JSGMpwABSWE"], referer: https://travelbyfire.com/wp-login.php
[Mon Jul 20 06:30:19.171335 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2rcDxY_mIul-JSGMtAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.218848 2026] [security2:error] [pid 935758:tid 935911] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2rcDxY_mIul-JSGMugAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.336136 2026] [security2:error] [pid 935758:tid 935952] [client 57.141.18.22:49910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMCgABSFg"]
[Mon Jul 20 06:30:19.436705 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:64386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U27cDxY_mIul-JSGMygAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.436802 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:64386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U27cDxY_mIul-JSGMygAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.487175 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U22V3ou772CelrLiVuAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.487320 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U22V3ou772CelrLiVuAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.537104 2026] [security2:error] [pid 935758:tid 935907] [client 77.110.127.138:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpHaZqWM3z'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4U27cDxY_mIul-JSGM0QAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.557436 2026] [security2:error] [pid 935758:tid 935912] [client 57.141.18.64:57930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMFgABIFo"]
[Mon Jul 20 06:30:19.681498 2026] [security2:error] [pid 929851:tid 929985] [client 34.73.38.214:53832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4U22V3ou772CelrLiVwAAAAIU"]
[Mon Jul 20 06:30:19.921217 2026] [security2:error] [pid 935758:tid 936004] [client 171.60.139.123:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U27cDxY_mIul-JSGM4QAAAXw"]
[Mon Jul 20 06:30:19.921373 2026] [security2:error] [pid 935758:tid 936004] [client 171.60.139.123:53392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U27cDxY_mIul-JSGM4QAAAXw"]
[Mon Jul 20 06:30:19.928763 2026] [security2:error] [pid 935758:tid 935926] [client 57.141.18.54:53468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMKgABLmQ"]
[Mon Jul 20 06:30:20.023521 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64371] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U3LcDxY_mIul-JSGM6gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:20.195742 2026] [security2:error] [pid 935758:tid 935900] [client 104.234.53.50:38245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U3LcDxY_mIul-JSGM8AAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:20.404739 2026] [lsapi:warn] [pid 929851:tid 930065] [client 14.225.17.146:55844] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/old
[Mon Jul 20 06:30:20.404788 2026] [lsapi:warn] [pid 929851:tid 930065] [client 14.225.17.146:55844] [host oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/old
[Mon Jul 20 06:30:20.647253 2026] [security2:error] [pid 935758:tid 935799] [remote 217.61.143.92:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4U3LcDxY_mIul-JSGNDQABZCY"]
[Mon Jul 20 06:30:20.764373 2026] [security2:error] [pid 929851:tid 930032] [client 50.116.65.227:16980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U3GV3ou772CelrLiV6AAAALQ"]
[Mon Jul 20 06:30:20.775422 2026] [security2:error] [pid 935758:tid 936004] [client 50.116.65.227:16984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U3LcDxY_mIul-JSGNEQAAAXw"]
[Mon Jul 20 06:30:20.810084 2026] [security2:error] [pid 935758:tid 935960] [client 103.141.108.143:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U3LcDxY_mIul-JSGNEgAAAVA"]
[Mon Jul 20 06:30:20.810249 2026] [security2:error] [pid 935758:tid 935960] [client 103.141.108.143:60369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U3LcDxY_mIul-JSGNEgAAAVA"]
[Mon Jul 20 06:30:20.893416 2026] [security2:error] [pid 935758:tid 935803] [remote 217.61.143.92:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4U3LcDxY_mIul-JSGNGQABNCo"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:30:20.922477 2026] [lsapi:warn] [pid 935758:tid 935976] [client 50.116.65.227:17004] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:30:20.922507 2026] [lsapi:warn] [pid 935758:tid 935976] [client 50.116.65.227:17004] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:30:20.937856 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:55844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4U22V3ou772CelrLiVyAAAANU"], referer: http://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.176043 2026] [security2:error] [pid 935758:tid 935918] [client 57.141.18.100:23950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2LcDxY_mIul-JSGMSwABJj8"]
[Mon Jul 20 06:30:21.230711 2026] [security2:error] [pid 935758:tid 935923] [client 45.116.69.230:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNIwAAASs"]
[Mon Jul 20 06:30:21.231291 2026] [security2:error] [pid 935758:tid 935923] [client 45.116.69.230:62189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNIwAAASs"]
[Mon Jul 20 06:30:21.334606 2026] [security2:error] [pid 935758:tid 935911] [client 50.116.65.227:17026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNIAAAAR8"]
[Mon Jul 20 06:30:21.346402 2026] [security2:error] [pid 935758:tid 935808] [remote 45.90.123.233:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U3bcDxY_mIul-JSGNJwABDS8"]
[Mon Jul 20 06:30:21.382029 2026] [security2:error] [pid 935758:tid 935925] [client 57.141.18.115:38992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2LcDxY_mIul-JSGMVwABLVk"]
[Mon Jul 20 06:30:21.461889 2026] [security2:error] [pid 935758:tid 935909] [client 34.90.235.227:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.uzq.jkk.mybluehost.me"] [uri "/"] [unique_id "al4U3bcDxY_mIul-JSGNMQAAAR0"]
[Mon Jul 20 06:30:21.461978 2026] [security2:error] [pid 935758:tid 935909] [client 34.90.235.227:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcalendars.uzq.jkk.mybluehost.me"] [uri "/"] [unique_id "al4U3bcDxY_mIul-JSGNMQAAAR0"]
[Mon Jul 20 06:30:21.515321 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:64399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3WV3ou772CelrLiWBgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:21.515421 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:64399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3WV3ou772CelrLiWBgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:21.525934 2026] [security2:error] [pid 935758:tid 935906] [client 50.116.65.227:17034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNKQAAARo"]
[Mon Jul 20 06:30:21.568571 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/charity/feed/"] [unique_id "al4U3bcDxY_mIul-JSGNNAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:21.632142 2026] [security2:error] [pid 935758:tid 935974] [client 74.7.175.150:46312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bokverk.com"] [uri "/robots.txt"] [unique_id "al4U3bcDxY_mIul-JSGNOQAAAV4"]
[Mon Jul 20 06:30:21.649391 2026] [security2:error] [pid 935758:tid 935776] [remote 173.249.4.11:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNOgABVQ8"]
[Mon Jul 20 06:30:21.649549 2026] [security2:error] [pid 935758:tid 935965] [client 173.249.4.11:13297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNOgABVQ8"]
[Mon Jul 20 06:30:21.773776 2026] [security2:error] [pid 935758:tid 935957] [client 57.141.18.25:34794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2bcDxY_mIul-JSGMaQABTXg"]
[Mon Jul 20 06:30:21.836034 2026] [lsapi:warn] [pid 929851:tid 930106] [client 14.225.17.146:65306] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.836057 2026] [lsapi:warn] [pid 929851:tid 930106] [client 14.225.17.146:65306] [host www.oswegooperatheater.com] Backend log: PHP Warning: Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.891042 2026] [security2:error] [pid 929851:tid 930106] [client 14.225.17.146:65306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4U3WV3ou772CelrLiWFQAAAP4"], referer: https://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.920549 2026] [security2:error] [pid 935758:tid 935814] [remote 45.90.123.233:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U3bcDxY_mIul-JSGNRAABCjU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:30:21.926983 2026] [security2:error] [pid 935758:tid 935920] [client 39.48.81.23:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNRQAAASg"]
[Mon Jul 20 06:30:21.927100 2026] [security2:error] [pid 935758:tid 935920] [client 39.48.81.23:60229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNRQAAASg"]
[Mon Jul 20 06:30:21.978976 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNPAAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.091426 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWIAAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.091547 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWIAAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.119768 2026] [security2:error] [pid 929851:tid 930070] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4U3WV3ou772CelrLiWHQAAANo"]
[Mon Jul 20 06:30:22.142917 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:64374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWJQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.143038 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:64374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWJQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.292318 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpOu5CMg3U'%20OR%20672=(SELECT%20672%20FROM%20PG_SLEEP(15))--"] [unique_id "al4U3rcDxY_mIul-JSGNTQAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.380180 2026] [security2:error] [pid 935758:tid 935940] [client 34.74.185.202:49462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4U3rcDxY_mIul-JSGNVAAAATw"]
[Mon Jul 20 06:30:22.483888 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:54036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4U3rcDxY_mIul-JSGNTwAAAWo"], referer: http://bnb-engineering.com/old
[Mon Jul 20 06:30:22.508588 2026] [security2:error] [pid 929851:tid 929988] [client 34.73.38.214:49477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4U3mV3ou772CelrLiWNQAAAIg"]
[Mon Jul 20 06:30:22.778721 2026] [security2:error] [pid 935758:tid 935794] [remote 188.166.241.141:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3rcDxY_mIul-JSGNZgABaCE"]
[Mon Jul 20 06:30:22.778867 2026] [security2:error] [pid 935758:tid 935984] [client 188.166.241.141:50002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3rcDxY_mIul-JSGNZgABaCE"]
[Mon Jul 20 06:30:22.829565 2026] [security2:error] [pid 929851:tid 929957] [remote 173.212.252.15:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4U3mV3ou772CelrLiWPAAAs2U"]
[Mon Jul 20 06:30:22.878739 2026] [security2:error] [pid 935758:tid 935951] [client 77.110.127.138:64408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U3rcDxY_mIul-JSGNagAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.960535 2026] [security2:error] [pid 935758:tid 935786] [remote 8.217.108.67:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4U3rcDxY_mIul-JSGNcgABbBk"]
[Mon Jul 20 06:30:22.963173 2026] [security2:error] [pid 935758:tid 935957] [client 34.74.185.202:56534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4U3rcDxY_mIul-JSGNcwAAAU0"]
[Mon Jul 20 06:30:23.428514 2026] [security2:error] [pid 935758:tid 936003] [client 57.141.18.81:65244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2rcDxY_mIul-JSGMrQABewk"]
[Mon Jul 20 06:30:23.535679 2026] [security2:error] [pid 929851:tid 929901] [remote 173.212.252.15:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4U32V3ou772CelrLiWVgAA7S0"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:30:23.569456 2026] [security2:error] [pid 935758:tid 935966] [client 165.22.226.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.alaraycreative.com"] [uri "/index.php"] [unique_id "al4U37cDxY_mIul-JSGNiQAAAVY"], referer: https://www.alaraycreative.com/
[Mon Jul 20 06:30:23.704856 2026] [security2:error] [pid 929851:tid 930047] [client 34.74.185.202:57097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4U32V3ou772CelrLiWWwAAAMM"]
[Mon Jul 20 06:30:24.087707 2026] [security2:error] [pid 935758:tid 935908] [client 57.141.18.87:46854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U27cDxY_mIul-JSGM0AABHFs"]
[Mon Jul 20 06:30:24.126242 2026] [security2:error] [pid 935758:tid 935763] [remote 8.217.108.67:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4U4LcDxY_mIul-JSGNowABWQI"], referer: https://gescontrols.com/wp-login.php
[Mon Jul 20 06:30:24.230930 2026] [security2:error] [pid 935758:tid 936002] [client 104.207.58.75:56823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4LcDxY_mIul-JSGNpAAAAXo"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:24.324089 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNpQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.324180 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNpQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.403741 2026] [security2:error] [pid 935758:tid 935987] [client 34.74.185.202:59350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4U4LcDxY_mIul-JSGNrAAAAWs"]
[Mon Jul 20 06:30:24.462712 2026] [security2:error] [pid 929851:tid 930029] [client 57.141.18.50:54054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U22V3ou772CelrLiVzAAAsR4"]
[Mon Jul 20 06:30:24.485259 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNswAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.485349 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNswAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.485647 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:64419] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/charity/feed/"] [unique_id "al4U4LcDxY_mIul-JSGNsgAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.691116 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNuAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.691215 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNuAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.841807 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNvQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.841944 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNvQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.867076 2026] [security2:error] [pid 935758:tid 935946] [client 65.111.28.172:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4LcDxY_mIul-JSGNvgAAAUI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:24.880479 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U4LcDxY_mIul-JSGNtgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.886800 2026] [security2:error] [pid 929851:tid 930078] [client 57.141.18.124:39936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3GV3ou772CelrLiV1gAA4m4"]
[Mon Jul 20 06:30:24.959673 2026] [security2:error] [pid 935758:tid 935910] [client 34.73.38.214:49330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4U4LcDxY_mIul-JSGNxQAAAR4"]
[Mon Jul 20 06:30:24.989464 2026] [security2:error] [pid 935758:tid 935983] [client 34.74.185.202:63777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4U4LcDxY_mIul-JSGNyQAAAWc"]
[Mon Jul 20 06:30:25.011015 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWjQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.011104 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWjQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.085795 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.085901 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.162378 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzgAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.162476 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzgAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.179442 2026] [security2:error] [pid 935758:tid 935945] [client 57.141.18.10:20698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3LcDxY_mIul-JSGNBQABQXU"]
[Mon Jul 20 06:30:25.238781 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWlQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.238889 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWlQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.297722 2026] [security2:error] [pid 935758:tid 935848] [remote 47.86.33.52:10648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4U4bcDxY_mIul-JSGN1AABUVc"]
[Mon Jul 20 06:30:25.313077 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWnQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.313198 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWnQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.391440 2026] [security2:error] [pid 935758:tid 935917] [client 77.110.127.138:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phptJc3bgt3')%20OR%20985=(SELECT%20985%20FROM%20PG_SLEEP(15))--"] [unique_id "al4U4bcDxY_mIul-JSGN2QAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.400347 2026] [security2:error] [pid 929851:tid 930055] [client 34.74.185.202:57433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4U4WV3ou772CelrLiWowAAAMs"]
[Mon Jul 20 06:30:25.410857 2026] [security2:error] [pid 935758:tid 936009] [client 50.255.62.89:41480] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4U4bcDxY_mIul-JSGN3AAAAYE"]
[Mon Jul 20 06:30:25.455891 2026] [security2:error] [pid 935758:tid 935932] [client 45.3.45.248:28713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4bcDxY_mIul-JSGN4AAAATQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:25.481798 2026] [security2:error] [pid 929851:tid 930042] [client 50.255.62.89:58734] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4U4WV3ou772CelrLiWqAAAAL4"]
[Mon Jul 20 06:30:25.716438 2026] [security2:error] [pid 935758:tid 935913] [client 14.225.17.146:52654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4U4bcDxY_mIul-JSGN4QAAASE"], referer: http://mobilesurvsolutions.com/old
[Mon Jul 20 06:30:25.946977 2026] [security2:error] [pid 929851:tid 929988] [client 34.74.185.202:52455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4U4WV3ou772CelrLiWtgAAAIg"]
[Mon Jul 20 06:30:26.017579 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:64439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U4mV3ou772CelrLiWtwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:26.069185 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWuQAAAOY"]
[Mon Jul 20 06:30:26.069341 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:47744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWuQAAAOY"]
[Mon Jul 20 06:30:26.070406 2026] [security2:error] [pid 935758:tid 935967] [client 65.111.27.144:37731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4rcDxY_mIul-JSGN9gAAAVc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:26.077761 2026] [security2:error] [pid 929851:tid 930105] [client 197.186.66.42:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWugAAAP0"]
[Mon Jul 20 06:30:26.081715 2026] [security2:error] [pid 929851:tid 930105] [client 197.186.66.42:54770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWugAAAP0"]
[Mon Jul 20 06:30:26.082666 2026] [security2:error] [pid 935758:tid 935960] [client 104.234.53.75:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4U4rcDxY_mIul-JSGN9wAAAVA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:26.267462 2026] [security2:error] [pid 935758:tid 935952] [client 57.141.18.87:46870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNJgABSCU"]
[Mon Jul 20 06:30:26.278092 2026] [security2:error] [pid 929851:tid 930095] [client 171.61.165.146:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWwgAAAPM"]
[Mon Jul 20 06:30:26.279095 2026] [security2:error] [pid 929851:tid 930095] [client 171.61.165.146:12741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWwgAAAPM"]
[Mon Jul 20 06:30:26.428911 2026] [security2:error] [pid 929851:tid 930028] [client 34.74.185.202:58010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4U4mV3ou772CelrLiWzAAAALA"]
[Mon Jul 20 06:30:26.584687 2026] [security2:error] [pid 929851:tid 930001] [client 14.225.17.146:53663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4U4WV3ou772CelrLiWtAAAAJU"], referer: http://idigress.studio/old
[Mon Jul 20 06:30:26.722354 2026] [security2:error] [pid 929851:tid 930043] [client 65.111.26.110:41987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4mV3ou772CelrLiW1gAAAL8"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:26.724109 2026] [security2:error] [pid 929851:tid 930049] [client 66.249.74.35:36803] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "certasit.com"] [uri "/robots.txt"] [unique_id "al4U4mV3ou772CelrLiW1wAAAMU"]
[Mon Jul 20 06:30:26.741357 2026] [security2:error] [pid 929851:tid 930046] [client 34.73.38.214:55531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4U4mV3ou772CelrLiW2AAAAMI"]
[Mon Jul 20 06:30:26.834231 2026] [security2:error] [pid 935758:tid 935901] [client 14.225.17.146:52634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4U4bcDxY_mIul-JSGN0wAAARU"], referer: http://vinovinhowine.com/old
[Mon Jul 20 06:30:26.869029 2026] [security2:error] [pid 935758:tid 935897] [client 34.74.185.202:63758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4U4rcDxY_mIul-JSGOFgAAARE"]
[Mon Jul 20 06:30:26.882198 2026] [security2:error] [pid 929851:tid 929996] [client 123.202.189.111:2879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "blog.danwolfe.us"] [uri "/wp-content/uploads/2015/01/xBobbyJindal-Governor-louisiana-indian-american-politician-statement-reaction-300x183.jpg.pagespeed.ic.-30w9dTMBP.jpg"] [unique_id "al4U4mV3ou772CelrLiW4QAAAJA"]
[Mon Jul 20 06:30:27.096366 2026] [security2:error] [pid 929851:tid 929935] [remote 130.185.118.215:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4U42V3ou772CelrLiW6wABAU8"]
[Mon Jul 20 06:30:27.209557 2026] [security2:error] [pid 935758:tid 935946] [client 34.74.185.202:58311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4U47cDxY_mIul-JSGOIwAAAUI"]
[Mon Jul 20 06:30:27.244116 2026] [security2:error] [pid 929851:tid 930032] [client 57.141.18.55:22936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3mV3ou772CelrLiWKgAAtC4"]
[Mon Jul 20 06:30:27.246262 2026] [security2:error] [pid 935758:tid 935949] [client 57.141.18.33:42000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3rcDxY_mIul-JSGNSQABRTY"]
[Mon Jul 20 06:30:27.272385 2026] [security2:error] [pid 935758:tid 935974] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4U47cDxY_mIul-JSGOIQAAAV4"]
[Mon Jul 20 06:30:27.283919 2026] [security2:error] [pid 929851:tid 929922] [remote 130.185.118.215:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4U42V3ou772CelrLiW8gAAqEI"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:30:27.583642 2026] [security2:error] [pid 935758:tid 935918] [client 77.110.127.138:64446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/charity/feed/"] [unique_id "al4U47cDxY_mIul-JSGOOwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:27.716322 2026] [security2:error] [pid 935758:tid 936014] [client 14.225.17.146:52598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4U47cDxY_mIul-JSGOKQAAAYY"], referer: http://nextlevelpressurewashing.com/old
[Mon Jul 20 06:30:27.821803 2026] [security2:error] [pid 935758:tid 935905] [client 34.74.185.202:52574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4U47cDxY_mIul-JSGOQQAAARk"]
[Mon Jul 20 06:30:27.851407 2026] [security2:error] [pid 935758:tid 935941] [client 57.141.18.37:46120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3rcDxY_mIul-JSGNbwABPTg"]
[Mon Jul 20 06:30:28.063569 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U42V3ou772CelrLiXCQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.187678 2026] [security2:error] [pid 935758:tid 935928] [client 104.234.53.55:22827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4U5LcDxY_mIul-JSGOTgAAATA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:28.196633 2026] [security2:error] [pid 935758:tid 935883] [remote 47.86.33.52:10648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4U5LcDxY_mIul-JSGOTQABPno"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:30:28.268112 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOUQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.268196 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOUQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.313197 2026] [security2:error] [pid 929851:tid 930096] [client 34.74.185.202:49429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4U5GV3ou772CelrLiXGgAAAPQ"]
[Mon Jul 20 06:30:28.358524 2026] [security2:error] [pid 935758:tid 935894] [client 34.73.38.214:57595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4U5LcDxY_mIul-JSGOVQAAAQ4"]
[Mon Jul 20 06:30:28.419965 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOWQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.420065 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOWQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.739374 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOYQAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.739491 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:64453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOYQAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.759877 2026] [security2:error] [pid 935758:tid 935991] [client 57.141.18.125:28578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U37cDxY_mIul-JSGNkAABbxM"]
[Mon Jul 20 06:30:28.879363 2026] [security2:error] [pid 929851:tid 930053] [client 223.185.13.213:7523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U5GV3ou772CelrLiXMgAAAMk"]
[Mon Jul 20 06:30:28.879515 2026] [security2:error] [pid 929851:tid 930053] [client 223.185.13.213:7523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U5GV3ou772CelrLiXMgAAAMk"]
[Mon Jul 20 06:30:28.970708 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phprqqCqFbD'))%20OR%20468=(SELECT%20468%20FROM%20PG_SLEEP(15))--"] [unique_id "al4U5GV3ou772CelrLiXPQAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:29.105975 2026] [security2:error] [pid 935758:tid 935957] [client 104.234.53.61:57747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4U5LcDxY_mIul-JSGOagAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:29.116065 2026] [security2:error] [pid 935758:tid 935999] [client 57.141.18.41:59248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U37cDxY_mIul-JSGNnAABd04"]
[Mon Jul 20 06:30:29.470355 2026] [security2:error] [pid 935758:tid 935936] [client 104.234.53.61:57747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U5bcDxY_mIul-JSGOfgAAATg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:29.559599 2026] [security2:error] [pid 929851:tid 930024] [client 14.225.17.146:52625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXEAAAAKw"], referer: http://eduardsales.com/old
[Mon Jul 20 06:30:29.850291 2026] [security2:error] [pid 935758:tid 935907] [client 34.73.38.214:60872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4U5bcDxY_mIul-JSGOiwAAARs"]
[Mon Jul 20 06:30:30.567692 2026] [security2:error] [pid 935758:tid 935971] [client 57.141.18.108:38268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U4bcDxY_mIul-JSGNywABWyk"]
[Mon Jul 20 06:30:30.732458 2026] [security2:error] [pid 935758:tid 935898] [client 14.225.17.146:65210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4U5rcDxY_mIul-JSGOoQAAARI"]
[Mon Jul 20 06:30:31.028414 2026] [security2:error] [pid 929851:tid 930014] [client 171.60.139.123:53991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXjQAAAKI"]
[Mon Jul 20 06:30:31.028526 2026] [security2:error] [pid 929851:tid 930014] [client 171.60.139.123:53991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXjQAAAKI"]
[Mon Jul 20 06:30:31.119032 2026] [security2:error] [pid 929851:tid 929974] [remote 81.173.115.7:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXkgAAwXY"]
[Mon Jul 20 06:30:31.205570 2026] [security2:error] [pid 929851:tid 930051] [client 14.225.17.146:52613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4U5WV3ou772CelrLiXYAAAAMc"], referer: http://cloudspacesgroup.com/old
[Mon Jul 20 06:30:31.320065 2026] [security2:error] [pid 935758:tid 935963] [client 104.234.53.50:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4U57cDxY_mIul-JSGO0AAAAVM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:31.320126 2026] [security2:error] [pid 929851:tid 929982] [remote 81.173.115.7:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXnAAAzX4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:31.356607 2026] [security2:error] [pid 929851:tid 930039] [client 50.116.65.227:30108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U52V3ou772CelrLiXnwAAALs"]
[Mon Jul 20 06:30:31.366722 2026] [security2:error] [pid 929851:tid 930007] [client 50.116.65.227:30114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U52V3ou772CelrLiXoAAAAJs"]
[Mon Jul 20 06:30:31.450067 2026] [security2:error] [pid 929851:tid 929890] [remote 72.167.132.114:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXogAAniI"]
[Mon Jul 20 06:30:31.541450 2026] [security2:error] [pid 935758:tid 935928] [client 14.225.17.146:52587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4U57cDxY_mIul-JSGOxgAAATA"], referer: http://uritems.net/old
[Mon Jul 20 06:30:31.577671 2026] [security2:error] [pid 935758:tid 935933] [client 103.141.108.143:60858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U57cDxY_mIul-JSGO3wAAATU"]
[Mon Jul 20 06:30:31.577794 2026] [security2:error] [pid 935758:tid 935933] [client 103.141.108.143:60858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U57cDxY_mIul-JSGO3wAAATU"]
[Mon Jul 20 06:30:31.670424 2026] [security2:error] [pid 929851:tid 929887] [remote 72.167.132.114:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXqgAAkx8"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:30:31.938492 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U57cDxY_mIul-JSGO4QAAAYk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:31.951448 2026] [security2:error] [pid 935758:tid 935935] [client 34.73.38.214:56745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4U57cDxY_mIul-JSGO7wAAATc"]
[Mon Jul 20 06:30:31.957282 2026] [security2:error] [pid 929851:tid 929996] [client 112.208.70.94:44961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvAAAAJA"]
[Mon Jul 20 06:30:31.957377 2026] [security2:error] [pid 929851:tid 929996] [client 112.208.70.94:44961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvAAAAJA"]
[Mon Jul 20 06:30:31.979172 2026] [security2:error] [pid 929851:tid 930085] [client 45.116.69.230:62722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvQAAAOk"]
[Mon Jul 20 06:30:31.979263 2026] [security2:error] [pid 929851:tid 930085] [client 45.116.69.230:62722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvQAAAOk"]
[Mon Jul 20 06:30:32.147032 2026] [security2:error] [pid 929851:tid 930109] [client 77.110.127.138:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXyAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.147133 2026] [security2:error] [pid 929851:tid 930109] [client 77.110.127.138:64472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXyAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.164630 2026] [security2:error] [pid 935758:tid 935989] [client 39.48.81.23:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U6LcDxY_mIul-JSGO-QAAAW0"]
[Mon Jul 20 06:30:32.164828 2026] [security2:error] [pid 935758:tid 935989] [client 39.48.81.23:60714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U6LcDxY_mIul-JSGO-QAAAW0"]
[Mon Jul 20 06:30:32.324058 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXywAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.324184 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXywAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.335120 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGO_gAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.335226 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:64473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGO_gAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.497384 2026] [security2:error] [pid 935758:tid 935993] [client 57.141.18.45:26554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U4rcDxY_mIul-JSGODwABcWU"]
[Mon Jul 20 06:30:32.497718 2026] [security2:error] [pid 935758:tid 935972] [client 77.110.127.138:64475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4U6LcDxY_mIul-JSGPCAAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.684646 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX1AAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.684743 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX1AAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.879764 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX3AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.879902 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX3AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.947601 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGPIgAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.947742 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGPIgAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.168285 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4U6bcDxY_mIul-JSGPKwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.169261 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6WV3ou772CelrLiX5AAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.169357 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6WV3ou772CelrLiX5AAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.224192 2026] [security2:error] [pid 935758:tid 935983] [client 34.73.38.214:56920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4U6bcDxY_mIul-JSGPMQAAAWc"]
[Mon Jul 20 06:30:33.442718 2026] [security2:error] [pid 935758:tid 935918] [client 77.110.127.138:64485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4U6bcDxY_mIul-JSGPQAAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.462447 2026] [security2:error] [pid 935758:tid 935960] [client 57.141.18.74:34160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U47cDxY_mIul-JSGOJwABUHA"]
[Mon Jul 20 06:30:33.487293 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPQQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.487445 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPQQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.586798 2026] [core:error] [pid 929851:tid 930011] [client 14.225.17.146:51893] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:33.586826 2026] [core:error] [pid 929851:tid 930011] [client 14.225.17.146:51893] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:33.649630 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPRgAAATo"]
[Mon Jul 20 06:30:33.649726 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPRgAAATo"]
[Mon Jul 20 06:30:33.765875 2026] [security2:error] [pid 929851:tid 929991] [client 104.234.53.61:33397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U6WV3ou772CelrLiX_wAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:33.808739 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U6bcDxY_mIul-JSGPRQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.920540 2026] [security2:error] [pid 929851:tid 930023] [client 47.128.41.206:45872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "marscafe.com"] [uri "/robots.txt"] [unique_id "al4U6WV3ou772CelrLiYBQAAAKs"]
[Mon Jul 20 06:30:33.923523 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPUwAAAWY"]
[Mon Jul 20 06:30:33.923629 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPUwAAAWY"]
[Mon Jul 20 06:30:34.248639 2026] [security2:error] [pid 929851:tid 930037] [client 14.225.17.146:52634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4U6GV3ou772CelrLiXvwAAALk"], referer: http://jvcmotorsports.com/old
[Mon Jul 20 06:30:34.312008 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:64497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U6mV3ou772CelrLiYCgAAAKo"]
[Mon Jul 20 06:30:34.347254 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.91:57932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXFwAAtSw"]
[Mon Jul 20 06:30:34.443385 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:52239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4U6LcDxY_mIul-JSGPDgAAAVY"], referer: http://fineartsfactory.net/old
[Mon Jul 20 06:30:34.542150 2026] [security2:error] [pid 929851:tid 930091] [client 57.141.18.39:54653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXIgAA7wQ"]
[Mon Jul 20 06:30:34.687236 2026] [security2:error] [pid 929851:tid 930073] [client 34.73.38.214:50685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4U6mV3ou772CelrLiYJQAAAN0"]
[Mon Jul 20 06:30:34.831091 2026] [security2:error] [pid 935758:tid 935895] [client 77.110.127.138:64499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U6rcDxY_mIul-JSGPeAAAAQ8"]
[Mon Jul 20 06:30:34.957446 2026] [security2:error] [pid 929851:tid 930000] [client 57.141.18.120:58620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXPAAAlBc"]
[Mon Jul 20 06:30:35.035374 2026] [security2:error] [pid 935758:tid 936002] [client 57.141.18.22:40346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5bcDxY_mIul-JSGObQABegA"]
[Mon Jul 20 06:30:35.309236 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U62V3ou772CelrLiYNgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:35.444841 2026] [security2:error] [pid 929851:tid 930045] [client 216.73.163.114:46873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "avatrip.co"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4U62V3ou772CelrLiYQgAAAME"]
[Mon Jul 20 06:30:35.683136 2026] [security2:error] [pid 935758:tid 935848] [remote 188.166.241.141:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4U67cDxY_mIul-JSGPngABV1c"]
[Mon Jul 20 06:30:35.751893 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U67cDxY_mIul-JSGPlgAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:35.961261 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U67cDxY_mIul-JSGPqQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:35.961352 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U67cDxY_mIul-JSGPqQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.112285 2026] [security2:error] [pid 935758:tid 935855] [remote 188.166.241.141:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4U7LcDxY_mIul-JSGPsAABXl4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:30:36.122885 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGPsQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.122978 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGPsQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.173864 2026] [security2:error] [pid 935758:tid 935968] [client 136.112.200.207:15908] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "buildwithbluestem.com"] [uri "/wp-json/batch/v1"] [unique_id "al4U7LcDxY_mIul-JSGPtQAAAVg"]
[Mon Jul 20 06:30:36.492415 2026] [security2:error] [pid 929851:tid 930058] [client 57.141.18.76:62966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5mV3ou772CelrLiXdwAAzm0"]
[Mon Jul 20 06:30:36.512554 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7LcDxY_mIul-JSGPwAAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.531105 2026] [security2:error] [pid 935758:tid 935985] [client 106.219.188.178:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGPygAAAWk"]
[Mon Jul 20 06:30:36.531244 2026] [security2:error] [pid 935758:tid 935985] [client 106.219.188.178:51785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGPygAAAWk"]
[Mon Jul 20 06:30:36.720288 2026] [security2:error] [pid 935758:tid 935943] [client 197.186.66.42:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGP0AAAAT8"]
[Mon Jul 20 06:30:36.720554 2026] [security2:error] [pid 935758:tid 935943] [client 197.186.66.42:55240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGP0AAAAT8"]
[Mon Jul 20 06:30:36.771226 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:64518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 673 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U7GV3ou772CelrLiYfgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.942192 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGP2wAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.942318 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGP2wAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:37.019676 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7LcDxY_mIul-JSGP1AAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:37.147016 2026] [security2:error] [pid 935758:tid 935976] [client 34.73.38.214:57020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4U7bcDxY_mIul-JSGP4gAAAWA"]
[Mon Jul 20 06:30:37.166359 2026] [security2:error] [pid 935758:tid 935955] [client 13.201.64.214:24694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U7bcDxY_mIul-JSGP4wAAAUs"]
[Mon Jul 20 06:30:37.166457 2026] [security2:error] [pid 935758:tid 935955] [client 13.201.64.214:24694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U7bcDxY_mIul-JSGP4wAAAUs"]
[Mon Jul 20 06:30:37.242312 2026] [security2:error] [pid 929851:tid 929959] [remote 82.223.97.42:47510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4U7WV3ou772CelrLiYjwAAx2c"]
[Mon Jul 20 06:30:37.465889 2026] [security2:error] [pid 935758:tid 935924] [client 57.141.18.30:21276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U57cDxY_mIul-JSGOxwABLGw"]
[Mon Jul 20 06:30:37.474835 2026] [security2:error] [pid 929851:tid 929929] [remote 82.223.97.42:47510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4U7WV3ou772CelrLiYnAAA70k"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:30:37.487226 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7bcDxY_mIul-JSGP6QAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:37.537952 2026] [security2:error] [pid 929851:tid 930023] [client 171.61.165.146:8165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U7WV3ou772CelrLiYoAAAAKs"]
[Mon Jul 20 06:30:37.538069 2026] [security2:error] [pid 929851:tid 930023] [client 171.61.165.146:8165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U7WV3ou772CelrLiYoAAAAKs"]
[Mon Jul 20 06:30:38.070253 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7bcDxY_mIul-JSGQDQAAAVc"]
[Mon Jul 20 06:30:38.372726 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7rcDxY_mIul-JSGQHQAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:38.372905 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7rcDxY_mIul-JSGQHQAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:38.390767 2026] [security2:error] [pid 929851:tid 929990] [client 163.172.182.64:55928] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4U7mV3ou772CelrLiYxAAAAIo"]
[Mon Jul 20 06:30:38.519565 2026] [security2:error] [pid 935758:tid 935866] [remote 182.77.62.24:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U7rcDxY_mIul-JSGQJAABL2k"]
[Mon Jul 20 06:30:38.519768 2026] [security2:error] [pid 935758:tid 935927] [client 182.77.62.24:59072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U7rcDxY_mIul-JSGQJAABL2k"]
[Mon Jul 20 06:30:38.568618 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7mV3ou772CelrLiYwwAAAMg"]
[Mon Jul 20 06:30:38.592218 2026] [security2:error] [pid 935758:tid 935983] [client 104.234.53.90:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4U7rcDxY_mIul-JSGQKQAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:38.789114 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7rcDxY_mIul-JSGQKAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:38.789698 2026] [security2:error] [pid 935758:tid 935969] [client 14.225.17.146:65186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4U7bcDxY_mIul-JSGP5QAAAVk"], referer: http://xp-design.co/old
[Mon Jul 20 06:30:39.003166 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.003254 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.053620 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPwAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.053730 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPwAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.101053 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.22:40364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U6LcDxY_mIul-JSGPFgABhRg"]
[Mon Jul 20 06:30:39.199953 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQRAAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.200054 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQRAAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.368389 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQTQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.368500 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQTQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.475897 2026] [core:error] [pid 929851:tid 930106] [client 14.225.17.146:64999] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/old
[Mon Jul 20 06:30:39.475925 2026] [core:error] [pid 929851:tid 930106] [client 14.225.17.146:64999] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/old
[Mon Jul 20 06:30:39.562886 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQUwAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.562983 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQUwAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.565844 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 534 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U77cDxY_mIul-JSGQVAAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.615351 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQVQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.615487 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQVQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.683587 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:64518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.683692 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:64518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.719542 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9gAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.719664 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9gAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.798695 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.64:32886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U6bcDxY_mIul-JSGPOwABYwQ"]
[Mon Jul 20 06:30:39.850103 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQbgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.850234 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQbgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.989903 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY_wAAAOY"]
[Mon Jul 20 06:30:39.990032 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY_wAAAOY"]
[Mon Jul 20 06:30:39.999116 2026] [security2:error] [pid 929851:tid 930098] [client 223.185.13.213:28392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U72V3ou772CelrLiZAAAAAPY"]
[Mon Jul 20 06:30:39.999215 2026] [security2:error] [pid 929851:tid 930098] [client 223.185.13.213:28392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U72V3ou772CelrLiZAAAAAPY"]
[Mon Jul 20 06:30:40.142995 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQfwAAAR4"]
[Mon Jul 20 06:30:40.143187 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQfwAAAR4"]
[Mon Jul 20 06:30:40.332999 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQiAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.333116 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQiAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.406928 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQjQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.407084 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQjQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.430706 2026] [security2:error] [pid 935758:tid 935774] [remote 20.153.140.50:35958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4U8LcDxY_mIul-JSGQkQABhQ0"]
[Mon Jul 20 06:30:40.447310 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8GV3ou772CelrLiZEQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.447444 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8GV3ou772CelrLiZEQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.665392 2026] [security2:error] [pid 935758:tid 936004] [client 158.173.89.95:22305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U8LcDxY_mIul-JSGQnQAAAXw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:40.785349 2026] [security2:error] [pid 935758:tid 935944] [client 77.110.127.138:64607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQpAAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.785460 2026] [security2:error] [pid 935758:tid 935944] [client 77.110.127.138:64607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQpAAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.808898 2026] [security2:error] [pid 935758:tid 935967] [client 74.208.214.194:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4U8LcDxY_mIul-JSGQpgAAAVc"]
[Mon Jul 20 06:30:40.832427 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.22:40378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U6mV3ou772CelrLiYHwAA3zo"]
[Mon Jul 20 06:30:40.844612 2026] [security2:error] [pid 935758:tid 935865] [remote 20.153.140.50:35958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4U8LcDxY_mIul-JSGQqAABZmg"], referer: https://samueldcohen.com/wp-login.php
[Mon Jul 20 06:30:40.968513 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQtwAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.968630 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQtwAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.014471 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuQAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.014576 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuQAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.022035 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U8LcDxY_mIul-JSGQpQAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.090733 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.090881 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.128507 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.128643 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.147467 2026] [security2:error] [pid 935758:tid 935930] [client 77.110.127.138:64588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.147610 2026] [security2:error] [pid 935758:tid 935930] [client 77.110.127.138:64588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.219919 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZLgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.220035 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZLgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.252178 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQwAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.252268 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQwAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.323413 2026] [security2:error] [pid 935758:tid 935987] [client 50.116.65.227:51414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U8bcDxY_mIul-JSGQzgAAAWs"]
[Mon Jul 20 06:30:41.334315 2026] [security2:error] [pid 935758:tid 935999] [client 50.116.65.227:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U8bcDxY_mIul-JSGQ0AAAAXc"]
[Mon Jul 20 06:30:41.336169 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQ0QAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.336269 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQ0QAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.422889 2026] [security2:error] [pid 929851:tid 930009] [client 77.110.127.138:64622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 37 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U8WV3ou772CelrLiZOgAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.443915 2026] [security2:error] [pid 935758:tid 935969] [client 74.7.227.179:36170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4U8bcDxY_mIul-JSGQxQABWSY"], referer: https://tejasenvironmental.com/p=961764
[Mon Jul 20 06:30:41.903732 2026] [security2:error] [pid 929851:tid 930104] [client 57.141.18.54:20384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U62V3ou772CelrLiYSAAA_B4"]
[Mon Jul 20 06:30:41.906030 2026] [security2:error] [pid 929851:tid 930062] [client 104.234.53.54:37061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4U8WV3ou772CelrLiZTgAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:41.978523 2026] [security2:error] [pid 935758:tid 935982] [client 171.60.139.123:54544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U8bcDxY_mIul-JSGQ8gAAAWY"]
[Mon Jul 20 06:30:41.978722 2026] [security2:error] [pid 935758:tid 935982] [client 171.60.139.123:54544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U8bcDxY_mIul-JSGQ8gAAAWY"]
[Mon Jul 20 06:30:42.031355 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.46:64790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U67cDxY_mIul-JSGPnQABiHU"]
[Mon Jul 20 06:30:42.084697 2026] [security2:error] [pid 935758:tid 935805] [remote 57.141.18.22:48342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4U8rcDxY_mIul-JSGQ9QABNSw"]
[Mon Jul 20 06:30:42.318421 2026] [security2:error] [pid 935758:tid 935997] [client 14.225.17.146:52113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4U8LcDxY_mIul-JSGQuAAAAXU"], referer: http://wathenbartlett.co.uk/old
[Mon Jul 20 06:30:42.365471 2026] [security2:error] [pid 935758:tid 935922] [client 57.141.18.65:29984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U67cDxY_mIul-JSGPqgABKjs"]
[Mon Jul 20 06:30:42.407292 2026] [security2:error] [pid 935758:tid 935881] [remote 72.167.132.114:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4U8rcDxY_mIul-JSGRDAABCng"]
[Mon Jul 20 06:30:42.518725 2026] [security2:error] [pid 929851:tid 930034] [client 103.141.108.143:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZYwAAALY"]
[Mon Jul 20 06:30:42.519049 2026] [security2:error] [pid 929851:tid 930034] [client 103.141.108.143:61344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZYwAAALY"]
[Mon Jul 20 06:30:42.623394 2026] [security2:error] [pid 935758:tid 935879] [remote 72.167.132.114:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4U8rcDxY_mIul-JSGRFwABOXY"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:30:42.852316 2026] [security2:error] [pid 935758:tid 935822] [remote 124.55.178.99:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U8rcDxY_mIul-JSGRGwABNj0"]
[Mon Jul 20 06:30:42.853501 2026] [security2:error] [pid 929851:tid 930090] [client 45.116.69.230:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZbgAAAO4"]
[Mon Jul 20 06:30:42.853669 2026] [security2:error] [pid 929851:tid 930090] [client 45.116.69.230:63342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZbgAAAO4"]
[Mon Jul 20 06:30:42.944340 2026] [security2:error] [pid 935758:tid 935945] [client 74.208.214.194:45852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4U8rcDxY_mIul-JSGRHgAAAUE"]
[Mon Jul 20 06:30:42.987691 2026] [security2:error] [pid 935758:tid 936010] [client 39.48.81.23:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U8rcDxY_mIul-JSGRIwAAAYI"]
[Mon Jul 20 06:30:42.988342 2026] [security2:error] [pid 935758:tid 936010] [client 39.48.81.23:61199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U8rcDxY_mIul-JSGRIwAAAYI"]
[Mon Jul 20 06:30:43.055172 2026] [security2:error] [pid 929851:tid 929994] [client 57.141.18.125:60372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U7GV3ou772CelrLiYgAAAjn4"]
[Mon Jul 20 06:30:43.076068 2026] [security2:error] [pid 935758:tid 936009] [client 14.225.17.146:61084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4U8rcDxY_mIul-JSGQ-wAAAYE"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/old
[Mon Jul 20 06:30:43.191383 2026] [security2:error] [pid 929851:tid 930053] [client 14.225.17.146:49756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4U82V3ou772CelrLiZfAAAAMk"], referer: https://wathenbartlett.co.uk/old
[Mon Jul 20 06:30:43.217294 2026] [security2:error] [pid 935758:tid 935894] [client 136.112.200.207:18722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "buildwithbluestem.com"] [uri "/"] [unique_id "al4U87cDxY_mIul-JSGRLgAAAQ4"]
[Mon Jul 20 06:30:43.234548 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:64633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U82V3ou772CelrLiZgQAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:43.234657 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:64633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U82V3ou772CelrLiZgQAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:43.387244 2026] [security2:error] [pid 935758:tid 935830] [remote 124.55.178.99:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U87cDxY_mIul-JSGRMgABhEU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:43.513008 2026] [security2:error] [pid 935758:tid 935993] [client 185.223.152.130:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.152.223.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sarahmusica.com"] [uri "/wp-login.php"] [unique_id "al4U87cDxY_mIul-JSGRNgAAAXE"]
[Mon Jul 20 06:30:43.555631 2026] [security2:error] [pid 935758:tid 935899] [client 124.120.192.126:57670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4U87cDxY_mIul-JSGRMwAAARM"]
[Mon Jul 20 06:30:43.760143 2026] [security2:error] [pid 929851:tid 930006] [client 14.225.17.146:60980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4U82V3ou772CelrLiZjwAAAJo"], referer: http://mtlegnews.gov/old
[Mon Jul 20 06:30:44.022467 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.39:64195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U7WV3ou772CelrLiYsgAAny4"]
[Mon Jul 20 06:30:44.378166 2026] [security2:error] [pid 935758:tid 935769] [remote 57.141.18.6:27688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3802589"] [unique_id "al4U9LcDxY_mIul-JSGRbgABIQg"]
[Mon Jul 20 06:30:44.530939 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U9LcDxY_mIul-JSGRawAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:44.743405 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9LcDxY_mIul-JSGRfwAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:44.743496 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9LcDxY_mIul-JSGRfwAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:44.897266 2026] [security2:error] [pid 935758:tid 935914] [client 14.225.17.146:61421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4U9LcDxY_mIul-JSGRiAAAASI"], referer: http://nikkidesigns.net/old
[Mon Jul 20 06:30:45.010573 2026] [security2:error] [pid 929851:tid 930062] [client 104.234.53.80:23007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4U9WV3ou772CelrLiZygAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:45.022592 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRmAAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.022715 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRmAAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.024889 2026] [security2:error] [pid 935758:tid 935951] [client 57.141.18.44:38498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U7rcDxY_mIul-JSGQNwABRz4"]
[Mon Jul 20 06:30:45.230098 2026] [security2:error] [pid 935758:tid 935961] [client 57.141.18.89:47820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U77cDxY_mIul-JSGQQAABUXc"]
[Mon Jul 20 06:30:45.285056 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRoAAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.285142 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRoAAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.437039 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:64652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U9WV3ou772CelrLiZ1AAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.610052 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRuwAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.610195 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRuwAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.630535 2026] [security2:error] [pid 929851:tid 930095] [client 45.3.44.22:17819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U9WV3ou772CelrLiZ3AAAAPM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:45.736974 2026] [security2:error] [pid 929851:tid 930083] [client 57.141.18.0:28528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U72V3ou772CelrLiY8AAA5ww"]
[Mon Jul 20 06:30:45.738051 2026] [security2:error] [pid 935758:tid 935965] [client 112.208.70.94:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U9bcDxY_mIul-JSGRxgAAAVU"]
[Mon Jul 20 06:30:45.738218 2026] [security2:error] [pid 935758:tid 935965] [client 112.208.70.94:45399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U9bcDxY_mIul-JSGRxgAAAVU"]
[Mon Jul 20 06:30:45.871029 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.17:37700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U77cDxY_mIul-JSGQXgABEko"]
[Mon Jul 20 06:30:46.046900 2026] [security2:error] [pid 935758:tid 935942] [client 14.225.17.146:60878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4U9bcDxY_mIul-JSGRlwAAAT4"], referer: http://entuvy.com/old
[Mon Jul 20 06:30:46.238905 2026] [security2:error] [pid 935758:tid 935950] [client 104.207.58.240:23715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U9rcDxY_mIul-JSGR2gAAAUY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:46.510773 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGR5wAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.510872 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGR5wAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.848873 2026] [security2:error] [pid 935758:tid 936003] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U9rcDxY_mIul-JSGR7wAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.964544 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGSAAAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.964656 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGSAAAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.056825 2026] [security2:error] [pid 935758:tid 935956] [client 77.110.127.138:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSBAAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.056960 2026] [security2:error] [pid 935758:tid 935956] [client 77.110.127.138:64665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSBAAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.126039 2026] [security2:error] [pid 929851:tid 930003] [client 106.219.188.178:20191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaEAAAAJc"]
[Mon Jul 20 06:30:47.133797 2026] [security2:error] [pid 929851:tid 930003] [client 106.219.188.178:20191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaEAAAAJc"]
[Mon Jul 20 06:30:47.211876 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:64669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSCgAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.212011 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:64669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSCgAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.285544 2026] [security2:error] [pid 935758:tid 935920] [client 13.201.64.214:56076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U97cDxY_mIul-JSGSDgAAASg"]
[Mon Jul 20 06:30:47.465190 2026] [security2:error] [pid 935758:tid 935953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSDQAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.615537 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSGwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.615644 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSGwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.633855 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSHwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.633954 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:64641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSHwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.660551 2026] [security2:error] [pid 929851:tid 930103] [client 197.186.66.42:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaIgAAAPs"]
[Mon Jul 20 06:30:47.676926 2026] [security2:error] [pid 929851:tid 930017] [client 98.159.234.160:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U92V3ou772CelrLiaJgAAAKU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:47.679734 2026] [security2:error] [pid 929851:tid 930103] [client 197.186.66.42:55718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaIgAAAPs"]
[Mon Jul 20 06:30:47.796382 2026] [security2:error] [pid 929851:tid 930061] [client 57.141.18.20:49042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8WV3ou772CelrLiZRQAA0UY"]
[Mon Jul 20 06:30:47.869502 2026] [security2:error] [pid 935758:tid 935915] [client 34.74.185.202:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4U97cDxY_mIul-JSGSLgAAASM"]
[Mon Jul 20 06:30:47.991905 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U92V3ou772CelrLiaNgAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.992055 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U92V3ou772CelrLiaNgAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.004974 2026] [security2:error] [pid 935758:tid 935959] [client 57.141.18.118:22578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8rcDxY_mIul-JSGQ8wABT28"]
[Mon Jul 20 06:30:48.106007 2026] [security2:error] [pid 935758:tid 935909] [client 171.61.165.146:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U-LcDxY_mIul-JSGSOgAAAR0"]
[Mon Jul 20 06:30:48.106201 2026] [security2:error] [pid 935758:tid 935909] [client 171.61.165.146:24894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U-LcDxY_mIul-JSGSOgAAAR0"]
[Mon Jul 20 06:30:48.140515 2026] [security2:error] [pid 935758:tid 935939] [client 57.141.18.8:28696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8rcDxY_mIul-JSGQ-gABOzo"]
[Mon Jul 20 06:30:48.154587 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSPQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.154715 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSPQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.251413 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSQAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.251523 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSQAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.579816 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-LcDxY_mIul-JSGSSgAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.580418 2026] [security2:error] [pid 929851:tid 930028] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../.env"] [unique_id "al4U-GV3ou772CelrLiaTgAAALA"], referer: https://www.facebook.com/
[Mon Jul 20 06:30:48.690432 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:64679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U-LcDxY_mIul-JSGSYAAAAU8"]
[Mon Jul 20 06:30:48.728482 2026] [security2:error] [pid 935758:tid 935909] [client 136.112.200.207:48628] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "buildwithbluestem.com"] [uri "/"] [unique_id "al4U-LcDxY_mIul-JSGSawAAAR0"]
[Mon Jul 20 06:30:48.797069 2026] [security2:error] [pid 935758:tid 935911] [client 65.1.132.125:16554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U-LcDxY_mIul-JSGSbwAAAR8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:30:48.797225 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:61690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSLAAAAVY"], referer: http://walkingandtalking.net/old
[Mon Jul 20 06:30:48.983496 2026] [security2:error] [pid 929851:tid 930051] [client 34.74.185.202:52822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4U-GV3ou772CelrLiaXwAAAMc"]
[Mon Jul 20 06:30:49.003148 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.122:47742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8mV3ou772CelrLiZawAA_jg"]
[Mon Jul 20 06:30:49.013140 2026] [security2:error] [pid 929851:tid 930017] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../var/www/html/.env"] [unique_id "al4U-WV3ou772CelrLiaYwAAAKU"], referer: https://www.reddit.com/
[Mon Jul 20 06:30:49.067628 2026] [security2:error] [pid 929851:tid 929985] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../var/www/.env"] [unique_id "al4U-WV3ou772CelrLiaZwAAAIU"], referer: https://t.co/nwtvl8i78z
[Mon Jul 20 06:30:49.098552 2026] [security2:error] [pid 929851:tid 930101] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//....//var/www/html/wp-config.php"] [unique_id "al4U-WV3ou772CelrLiaaAAAAPk"], referer: https://www.google.com/search?q=muy0uo
[Mon Jul 20 06:30:49.245483 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSgQAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.245639 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSgQAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.534401 2026] [security2:error] [pid 929851:tid 930067] [client 34.74.185.202:56717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4U-WV3ou772CelrLiafQAAANc"]
[Mon Jul 20 06:30:49.630399 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSnQAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.630539 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSnQAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.671989 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.8:28712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U82V3ou772CelrLiZjQAAtQM"]
[Mon Jul 20 06:30:49.683411 2026] [security2:error] [pid 929851:tid 930013] [client 14.225.17.146:63346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4U-WV3ou772CelrLiadAAAAKE"], referer: http://grecruit.online/old
[Mon Jul 20 06:30:49.818264 2026] [security2:error] [pid 935758:tid 935845] [remote 188.166.241.141:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U-bcDxY_mIul-JSGSogABflQ"]
[Mon Jul 20 06:30:49.818543 2026] [security2:error] [pid 935758:tid 936006] [client 188.166.241.141:60256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U-bcDxY_mIul-JSGSogABflQ"]
[Mon Jul 20 06:30:49.819072 2026] [security2:error] [pid 935758:tid 935931] [client 14.225.17.146:63182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSoAAAATM"], referer: https://walkingandtalking.net/old
[Mon Jul 20 06:30:49.939861 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSnAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.970146 2026] [security2:error] [pid 935758:tid 935950] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSnwAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.061239 2026] [security2:error] [pid 929851:tid 929989] [client 57.141.18.85:22090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9GV3ou772CelrLiZowAAiUI"]
[Mon Jul 20 06:30:50.110681 2026] [security2:error] [pid 935758:tid 936017] [client 57.141.18.17:37720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9LcDxY_mIul-JSGRYQABiVs"]
[Mon Jul 20 06:30:50.260683 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-rcDxY_mIul-JSGSwAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.260875 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-rcDxY_mIul-JSGSwAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.311942 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-mV3ou772CelrLiamwAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.312125 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-mV3ou772CelrLiamwAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.425755 2026] [security2:error] [pid 935758:tid 935988] [client 104.234.53.51:40077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4U-rcDxY_mIul-JSGS1QAAAWw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:50.532162 2026] [security2:error] [pid 935758:tid 935975] [client 50.116.65.227:26776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U-rcDxY_mIul-JSGS3QAAAV8"]
[Mon Jul 20 06:30:50.544593 2026] [security2:error] [pid 935758:tid 935921] [client 50.116.65.227:26788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U-rcDxY_mIul-JSGS3gAAASk"]
[Mon Jul 20 06:30:50.671181 2026] [security2:error] [pid 935758:tid 935998] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-rcDxY_mIul-JSGS1gAAAXY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.002485 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTJgAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.002610 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTJgAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.053331 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTKAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.053446 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTKAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.240759 2026] [security2:error] [pid 935758:tid 935837] [remote 182.77.62.24:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U-7cDxY_mIul-JSGTLwABJkw"]
[Mon Jul 20 06:30:51.242654 2026] [security2:error] [pid 929851:tid 930020] [client 34.74.185.202:55245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4U-2V3ou772CelrLiawQAAAKg"]
[Mon Jul 20 06:30:51.511252 2026] [security2:error] [pid 935758:tid 935963] [client 14.225.17.146:61824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSsgAAAVM"], referer: http://slutilities.com/old
[Mon Jul 20 06:30:51.558500 2026] [security2:error] [pid 935758:tid 935962] [client 57.141.18.14:40528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9bcDxY_mIul-JSGRvQABUmA"]
[Mon Jul 20 06:30:51.559550 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-2V3ou772CelrLiaxAAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.598996 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-7cDxY_mIul-JSGTOQAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.680852 2026] [proxy:error] [pid 935758:tid 936017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:51.680945 2026] [proxy_http:error] [pid 935758:tid 936017] [client 34.73.38.214:52441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:51.681642 2026] [proxy:error] [pid 935758:tid 936017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:51.681687 2026] [proxy_http:error] [pid 935758:tid 936017] [client 34.73.38.214:52441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:51.762253 2026] [security2:error] [pid 935758:tid 935947] [client 57.141.18.82:26194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9bcDxY_mIul-JSGRxwABQzM"]
[Mon Jul 20 06:30:51.784855 2026] [security2:error] [pid 929851:tid 930077] [client 34.74.185.202:59468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4U-2V3ou772CelrLia2QAAAOE"]
[Mon Jul 20 06:30:52.145153 2026] [proxy:error] [pid 935758:tid 936009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:52.145239 2026] [proxy_http:error] [pid 935758:tid 936009] [client 34.73.38.214:64637] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:52.146166 2026] [proxy:error] [pid 935758:tid 936009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:52.146221 2026] [proxy_http:error] [pid 935758:tid 936009] [client 34.73.38.214:64637] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:52.184806 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-7cDxY_mIul-JSGTXQAAASw"]
[Mon Jul 20 06:30:52.200428 2026] [security2:error] [pid 935758:tid 935829] [remote 182.77.62.24:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U_LcDxY_mIul-JSGTbQABU0Q"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:52.484104 2026] [security2:error] [pid 935758:tid 935969] [client 34.74.185.202:50300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4U_LcDxY_mIul-JSGTgAAAAVk"]
[Mon Jul 20 06:30:52.513224 2026] [security2:error] [pid 935758:tid 935992] [client 104.234.53.66:28285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U_LcDxY_mIul-JSGTgQAAAXA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:52.556186 2026] [security2:error] [pid 935758:tid 936005] [client 57.141.18.1:44016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9rcDxY_mIul-JSGR6gABfQ4"]
[Mon Jul 20 06:30:52.569183 2026] [security2:error] [pid 929851:tid 930034] [client 43.205.139.3:18846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U_GV3ou772CelrLia6gAAALY"]
[Mon Jul 20 06:30:52.891781 2026] [security2:error] [pid 935758:tid 935947] [client 171.60.139.123:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U_LcDxY_mIul-JSGTjAAAAUM"]
[Mon Jul 20 06:30:52.891888 2026] [security2:error] [pid 935758:tid 935947] [client 171.60.139.123:55074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U_LcDxY_mIul-JSGTjAAAAUM"]
[Mon Jul 20 06:30:52.904719 2026] [security2:error] [pid 929851:tid 930033] [client 14.225.17.146:54828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4U-2V3ou772CelrLiazwAAALU"], referer: http://iagdevelopments.com/old
[Mon Jul 20 06:30:52.947602 2026] [security2:error] [pid 929851:tid 929932] [remote 5.252.52.249:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4U_GV3ou772CelrLia_wAAoEw"]
[Mon Jul 20 06:30:53.019864 2026] [security2:error] [pid 935758:tid 935834] [remote 182.77.62.24:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4U_bcDxY_mIul-JSGTkwABF0k"]
[Mon Jul 20 06:30:53.030456 2026] [security2:error] [pid 929851:tid 930002] [client 34.74.185.202:60323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4U_WV3ou772CelrLibBAAAAJY"]
[Mon Jul 20 06:30:53.095775 2026] [security2:error] [pid 929851:tid 930090] [client 103.141.108.143:61838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibBQAAAO4"]
[Mon Jul 20 06:30:53.096902 2026] [security2:error] [pid 929851:tid 930090] [client 103.141.108.143:61838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibBQAAAO4"]
[Mon Jul 20 06:30:53.111896 2026] [security2:error] [pid 929851:tid 929871] [remote 5.252.52.249:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibBgAAjw8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:30:53.212176 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTogAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.212282 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTogAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.263328 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTowAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.263465 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:64655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTowAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.289618 2026] [security2:error] [pid 935758:tid 935980] [client 57.141.18.54:44650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSEAABZDY"]
[Mon Jul 20 06:30:53.316220 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.316361 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.376368 2026] [security2:error] [pid 935758:tid 936013] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_bcDxY_mIul-JSGTmQAAAYU"]
[Mon Jul 20 06:30:53.416843 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:64706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEwAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.416956 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:64706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEwAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.425334 2026] [security2:error] [pid 929851:tid 929963] [remote 192.241.143.148:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibFQAAqms"]
[Mon Jul 20 06:30:53.435828 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_WV3ou772CelrLibCQAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.524427 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.524563 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:64707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.563404 2026] [security2:error] [pid 935758:tid 935968] [client 57.141.18.82:26230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSKQABWEs"]
[Mon Jul 20 06:30:53.568481 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.568563 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.576233 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:64683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHwAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.576349 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:64683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHwAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.600305 2026] [security2:error] [pid 929851:tid 929997] [client 34.74.185.202:61043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4U_WV3ou772CelrLibIwAAAJE"]
[Mon Jul 20 06:30:53.619371 2026] [security2:error] [pid 929851:tid 929863] [remote 192.241.143.148:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibJQAA0Qc"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:30:53.639662 2026] [security2:error] [pid 929851:tid 930077] [client 45.116.69.230:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibJgAAAOE"]
[Mon Jul 20 06:30:53.639790 2026] [security2:error] [pid 929851:tid 930077] [client 45.116.69.230:63893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibJgAAAOE"]
[Mon Jul 20 06:30:53.734499 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibKgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.734649 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:64711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibKgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.745538 2026] [proxy:error] [pid 935758:tid 935947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:53.745613 2026] [proxy_http:error] [pid 935758:tid 935947] [client 34.73.38.214:52487] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:53.746409 2026] [proxy:error] [pid 935758:tid 935947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:53.746446 2026] [proxy_http:error] [pid 935758:tid 935947] [client 34.73.38.214:52487] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:53.788849 2026] [security2:error] [pid 935758:tid 935875] [remote 182.77.62.24:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4U_bcDxY_mIul-JSGTuQABU3I"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:30:53.811354 2026] [security2:error] [pid 929851:tid 930073] [client 65.1.132.125:16562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibLgAAAN0"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:30:53.883518 2026] [security2:error] [pid 935758:tid 935991] [client 39.48.81.23:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U_bcDxY_mIul-JSGTwgAAAW8"]
[Mon Jul 20 06:30:53.883687 2026] [security2:error] [pid 935758:tid 935991] [client 39.48.81.23:61691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U_bcDxY_mIul-JSGTwgAAAW8"]
[Mon Jul 20 06:30:53.939687 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_WV3ou772CelrLibIgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.941566 2026] [security2:error] [pid 929851:tid 930068] [client 14.225.17.146:62056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4U_WV3ou772CelrLibLwAAANg"], referer: https://iagdevelopments.com/old
[Mon Jul 20 06:30:53.967006 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibNQAAAJ4"]
[Mon Jul 20 06:30:53.967114 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibNQAAAJ4"]
[Mon Jul 20 06:30:54.018873 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGTygAAAXc"]
[Mon Jul 20 06:30:54.018972 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGTygAAAXc"]
[Mon Jul 20 06:30:54.146381 2026] [security2:error] [pid 929851:tid 930105] [client 57.141.18.14:40530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U-GV3ou772CelrLiaRgAA_Ro"]
[Mon Jul 20 06:30:54.249398 2026] [security2:error] [pid 935758:tid 935974] [client 34.74.185.202:60410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4U_rcDxY_mIul-JSGT1QAAAV4"]
[Mon Jul 20 06:30:54.348815 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:63986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT0QAAAVY"], referer: http://margaretspeckogawa.com/old
[Mon Jul 20 06:30:54.551349 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT2gAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.689862 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT7wAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.689982 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT7wAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.745451 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT9QAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.745571 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT9QAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.752264 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT5wAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.783991 2026] [security2:error] [pid 935758:tid 935998] [client 34.74.185.202:55021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4U_rcDxY_mIul-JSGT-AAAAXY"]
[Mon Jul 20 06:30:54.864984 2026] [proxy:error] [pid 935758:tid 935928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:54.865033 2026] [proxy_http:error] [pid 935758:tid 935928] [client 34.73.38.214:60816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:54.865944 2026] [proxy:error] [pid 935758:tid 935928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:54.865972 2026] [proxy_http:error] [pid 935758:tid 935928] [client 34.73.38.214:60816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:54.876100 2026] [security2:error] [pid 935758:tid 935847] [remote 8.217.108.67:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U_rcDxY_mIul-JSGUAwABXFY"]
[Mon Jul 20 06:30:54.993110 2026] [security2:error] [pid 935758:tid 935945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT8wAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.018313 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_2V3ou772CelrLibXwAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.018461 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_2V3ou772CelrLibXwAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.039139 2026] [security2:error] [pid 935758:tid 935880] [remote 182.77.62.24:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4U_7cDxY_mIul-JSGUCgABfXc"]
[Mon Jul 20 06:30:55.116418 2026] [security2:error] [pid 935758:tid 935948] [client 14.225.17.146:64028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4U_LcDxY_mIul-JSGTiQAAAUQ"], referer: http://latiendadejorge.com.gt/old
[Mon Jul 20 06:30:55.262090 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGUCQAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.270453 2026] [security2:error] [pid 935758:tid 935960] [client 34.74.185.202:64900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4U_7cDxY_mIul-JSGUEgAAAVA"]
[Mon Jul 20 06:30:55.701969 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:64721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_7cDxY_mIul-JSGUIgAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.702067 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:64721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_7cDxY_mIul-JSGUIgAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.732296 2026] [security2:error] [pid 935758:tid 935843] [remote 182.77.62.24:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4U_7cDxY_mIul-JSGUJgABbVI"], referer: https://giftofgiving-usa.org/wp-login.php
[Mon Jul 20 06:30:55.795858 2026] [security2:error] [pid 935758:tid 935848] [remote 8.217.108.67:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U_7cDxY_mIul-JSGUKgABDlc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:30:55.800797 2026] [security2:error] [pid 935758:tid 936016] [client 103.153.183.69:64094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e%2f%2e%2e%2fetc%2fpasswd"] [unique_id "al4U_7cDxY_mIul-JSGULAAAAYg"], referer: https://www.reddit.com/
[Mon Jul 20 06:30:55.948816 2026] [security2:error] [pid 929851:tid 929970] [remote 72.167.132.114:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4U_2V3ou772CelrLibgwAA13I"]
[Mon Jul 20 06:30:55.964998 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.26:61674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U-mV3ou772CelrLiaogAAn3g"]
[Mon Jul 20 06:30:56.013170 2026] [security2:error] [pid 935758:tid 935936] [client 104.234.53.48:41539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VALcDxY_mIul-JSGUOgAAATg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:56.112699 2026] [security2:error] [pid 929851:tid 930020] [client 34.74.185.202:59590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VAGV3ou772CelrLibjgAAAKg"]
[Mon Jul 20 06:30:56.146287 2026] [security2:error] [pid 929851:tid 929856] [remote 72.167.132.114:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VAGV3ou772CelrLibkAAA0AA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:30:56.340327 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAGV3ou772CelrLibiQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.428969 2026] [security2:error] [pid 929851:tid 930038] [client 57.141.18.32:30096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U-2V3ou772CelrLiauAAAumI"]
[Mon Jul 20 06:30:56.548480 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUSwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.548597 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUSwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.604922 2026] [security2:error] [pid 935758:tid 935952] [client 34.73.38.214:56349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VALcDxY_mIul-JSGUTgAAAUg"]
[Mon Jul 20 06:30:56.819250 2026] [security2:error] [pid 929851:tid 930004] [client 34.74.185.202:62105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VAGV3ou772CelrLibswAAAJg"]
[Mon Jul 20 06:30:56.918257 2026] [security2:error] [pid 935758:tid 935995] [client 34.73.38.214:50705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VALcDxY_mIul-JSGUWgAAAXM"]
[Mon Jul 20 06:30:56.942154 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUWwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.942247 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUWwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.131611 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUZgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.135586 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUZgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.224800 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUbQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.224976 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUbQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.299444 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUcQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.299554 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUcQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.382617 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUgAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.382764 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUgAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.492152 2026] [security2:error] [pid 935758:tid 935948] [client 112.208.70.94:45859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUkwAAAUQ"]
[Mon Jul 20 06:30:57.492233 2026] [security2:error] [pid 935758:tid 935948] [client 112.208.70.94:45859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUkwAAAUQ"]
[Mon Jul 20 06:30:57.516573 2026] [security2:error] [pid 935758:tid 935986] [client 57.141.18.65:54110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_LcDxY_mIul-JSGTcAABakI"]
[Mon Jul 20 06:30:57.520185 2026] [security2:error] [pid 935758:tid 935898] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUeAAAARI"]
[Mon Jul 20 06:30:57.533327 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUmgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.533441 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUmgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.684717 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib0QAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.684840 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib0QAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.736622 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUiwAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.766074 2026] [security2:error] [pid 935758:tid 935945] [client 106.219.188.178:40968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUqwAAAUE"]
[Mon Jul 20 06:30:57.766397 2026] [security2:error] [pid 935758:tid 935945] [client 106.219.188.178:40968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUqwAAAUE"]
[Mon Jul 20 06:30:57.777801 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAWV3ou772CelrLibyQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.826658 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUlAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.835452 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib1gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.835589 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib1gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.895263 2026] [security2:error] [pid 935758:tid 935969] [client 103.153.183.69:64094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/etc/passwd"] [unique_id "al4VAbcDxY_mIul-JSGUtQAAAVk"], referer: https://twitter.com/
[Mon Jul 20 06:30:57.909285 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUtwAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.909407 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUtwAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.947829 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUuAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.947989 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUuAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.070786 2026] [security2:error] [pid 935758:tid 935950] [client 57.141.18.3:64518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_LcDxY_mIul-JSGTigABRlA"]
[Mon Jul 20 06:30:58.110037 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:64747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUxQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.110150 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:64747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUxQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.142635 2026] [security2:error] [pid 935758:tid 936006] [client 34.73.38.214:59057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VArcDxY_mIul-JSGUxwAAAX4"]
[Mon Jul 20 06:30:58.263242 2026] [security2:error] [pid 935758:tid 935911] [client 77.110.127.138:64748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUzQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.263452 2026] [security2:error] [pid 935758:tid 935911] [client 77.110.127.138:64748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUzQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.314879 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAmV3ou772CelrLib6AAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.315005 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAmV3ou772CelrLib6AAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.342754 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUtAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.448525 2026] [security2:error] [pid 929851:tid 929987] [client 104.234.53.82:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VAmV3ou772CelrLib7gAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:58.521398 2026] [security2:error] [pid 935758:tid 935926] [client 158.101.99.182:53026] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGU1AAAAS4"]
[Mon Jul 20 06:30:58.521509 2026] [security2:error] [pid 935758:tid 935926] [client 158.101.99.182:53026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGU1AAAAS4"]
[Mon Jul 20 06:30:58.554698 2026] [security2:error] [pid 935758:tid 935891] [client 212.47.238.7:59156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail-box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4VArcDxY_mIul-JSGU4QAAAQs"]
[Mon Jul 20 06:30:58.625974 2026] [security2:error] [pid 929851:tid 930073] [client 197.186.66.42:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VAmV3ou772CelrLib9QAAAN0"]
[Mon Jul 20 06:30:58.664405 2026] [security2:error] [pid 929851:tid 930073] [client 197.186.66.42:56194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VAmV3ou772CelrLib9QAAAN0"]
[Mon Jul 20 06:30:58.684346 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.66:35190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_bcDxY_mIul-JSGTtAABY2Y"]
[Mon Jul 20 06:30:58.789256 2026] [security2:error] [pid 935758:tid 936013] [client 14.225.17.146:63340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4VArcDxY_mIul-JSGU5QAAAYU"], referer: http://alrowad-hub.net/old
[Mon Jul 20 06:30:58.915713 2026] [security2:error] [pid 935758:tid 935948] [client 103.153.183.69:64094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/.env"] [unique_id "al4VArcDxY_mIul-JSGU8gAAAUQ"], referer: https://t.co/hxzrsygf44
[Mon Jul 20 06:30:58.989187 2026] [security2:error] [pid 935758:tid 935933] [client 171.61.165.146:6247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VArcDxY_mIul-JSGU9QAAATU"]
[Mon Jul 20 06:30:58.989301 2026] [security2:error] [pid 935758:tid 935933] [client 171.61.165.146:6247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VArcDxY_mIul-JSGU9QAAATU"]
[Mon Jul 20 06:30:59.021351 2026] [security2:error] [pid 935758:tid 935983] [client 158.101.99.182:53034] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGU9gAAAWc"]
[Mon Jul 20 06:30:59.021453 2026] [security2:error] [pid 935758:tid 935983] [client 158.101.99.182:53034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGU9gAAAWc"]
[Mon Jul 20 06:30:59.154902 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA2V3ou772CelrLicDQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.155018 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA2V3ou772CelrLicDQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.306312 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cowl/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4VA2V3ou772CelrLicFwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.364347 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:64750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGU_AAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.463991 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVCQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.464115 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVCQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.503655 2026] [security2:error] [pid 935758:tid 935958] [client 57.141.18.95:64110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT5gABThI"]
[Mon Jul 20 06:30:59.521032 2026] [security2:error] [pid 935758:tid 935903] [client 158.101.99.182:53040] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVDgAAARc"]
[Mon Jul 20 06:30:59.521116 2026] [security2:error] [pid 935758:tid 935903] [client 158.101.99.182:53040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVDgAAARc"]
[Mon Jul 20 06:30:59.617934 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGAAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.618105 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGAAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.692088 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA2V3ou772CelrLicGwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.769686 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.769803 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.771421 2026] [security2:error] [pid 935758:tid 935891] [client 158.173.166.181:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VA7cDxY_mIul-JSGVHQAAAQs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:59.811146 2026] [security2:error] [pid 935758:tid 935967] [client 57.141.18.85:45284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT_wABV0g"]
[Mon Jul 20 06:30:59.843271 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVJQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.843372 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVJQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.857193 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGVFgAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.905335 2026] [security2:error] [pid 935758:tid 935897] [client 77.110.127.138:64734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cowl/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4VA7cDxY_mIul-JSGVKwAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.023736 2026] [security2:error] [pid 935758:tid 935981] [client 223.185.13.213:24949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VBLcDxY_mIul-JSGVNAAAAWU"]
[Mon Jul 20 06:31:00.023887 2026] [security2:error] [pid 935758:tid 935981] [client 223.185.13.213:24949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VBLcDxY_mIul-JSGVNAAAAWU"]
[Mon Jul 20 06:31:00.092584 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGVKgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.138810 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVPwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.141130 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVPwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.277505 2026] [security2:error] [pid 935758:tid 935968] [client 57.141.18.22:28090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_7cDxY_mIul-JSGUEAABWAM"]
[Mon Jul 20 06:31:00.293352 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVRAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.293433 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVRAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.322025 2026] [security2:error] [pid 929851:tid 929890] [remote 20.153.140.50:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4VBGV3ou772CelrLicPAAAvSI"]
[Mon Jul 20 06:31:00.399223 2026] [security2:error] [pid 935758:tid 935982] [client 34.73.38.214:61600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VBLcDxY_mIul-JSGVSAAAAWY"]
[Mon Jul 20 06:31:00.447239 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicQgAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.447393 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicQgAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.503112 2026] [security2:error] [pid 935758:tid 936003] [client 185.122.141.230:46572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVQwABewo"]
[Mon Jul 20 06:31:00.612828 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVVQAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.612953 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVVQAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.666398 2026] [security2:error] [pid 935758:tid 935963] [client 77.110.127.138:64743] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cowl/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4VBLcDxY_mIul-JSGVXAAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.711562 2026] [security2:error] [pid 929851:tid 929955] [remote 20.153.140.50:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4VBGV3ou772CelrLicUgABA2M"], referer: https://crimargroup.com/wp-login.php
[Mon Jul 20 06:31:00.822912 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicWgAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.823023 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicWgAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.843469 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVVgAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.897669 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVXQAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.988452 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVbgAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.988539 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVbgAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.256195 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBbcDxY_mIul-JSGVcQAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.453815 2026] [security2:error] [pid 929851:tid 930068] [client 34.73.38.214:56029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VBWV3ou772CelrLiccAAAANg"]
[Mon Jul 20 06:31:01.525929 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLicYwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.555779 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiceQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.555883 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:64753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiceQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.562252 2026] [security2:error] [pid 935758:tid 936003] [client 104.234.53.74:25141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VBbcDxY_mIul-JSGViwAAAXs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:01.608732 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLicewAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.608904 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLicewAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.870806 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLiccwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.956664 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiciwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.956849 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:64781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiciwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.007843 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVpAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.007953 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVpAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.029701 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBbcDxY_mIul-JSGVmgAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.092115 2026] [security2:error] [pid 935758:tid 935984] [client 176.171.59.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGVIQAAAWg"], referer: https://worbals.com
[Mon Jul 20 06:31:02.210324 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:64734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBrcDxY_mIul-JSGVoQAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.456484 2026] [security2:error] [pid 929851:tid 930058] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicoQAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.638802 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBmV3ou772CelrLicvAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.638920 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBmV3ou772CelrLicvAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.689408 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVtAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.689523 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVtAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.691903 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicrQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.907796 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicwAAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.916617 2026] [core:error] [pid 935758:tid 935992] [client 103.153.183.69:64094] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=6bbhnmb0&v=8z9us), referer: https://t.co/b99irgjw85
[Mon Jul 20 06:31:02.919405 2026] [security2:error] [pid 935758:tid 935937] [client 127.0.0.1:18636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VBrcDxY_mIul-JSGVwQAAATk"], referer: https://t.co/b99irgjw85
[Mon Jul 20 06:31:03.150176 2026] [security2:error] [pid 935758:tid 935979] [client 34.73.38.214:63061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VB7cDxY_mIul-JSGVzgAAAWM"]
[Mon Jul 20 06:31:03.191247 2026] [security2:error] [pid 935758:tid 935972] [client 57.141.18.107:49454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUoQABXCU"]
[Mon Jul 20 06:31:03.193849 2026] [security2:error] [pid 935758:tid 935987] [client 158.101.99.182:53046] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGVzwAAAWs"]
[Mon Jul 20 06:31:03.193950 2026] [security2:error] [pid 935758:tid 935987] [client 158.101.99.182:53046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGVzwAAAWs"]
[Mon Jul 20 06:31:03.255370 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBrcDxY_mIul-JSGVxQAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.448712 2026] [security2:error] [pid 935758:tid 935803] [remote 162.19.86.63:44481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4VB7cDxY_mIul-JSGV3wABTyo"]
[Mon Jul 20 06:31:03.473918 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VB2V3ou772CelrLic0gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.615896 2026] [security2:error] [pid 929851:tid 930103] [client 66.249.65.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amagicbutton.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLickwAAAPs"]
[Mon Jul 20 06:31:03.656867 2026] [security2:error] [pid 935758:tid 935874] [remote 162.19.86.63:44481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4VB7cDxY_mIul-JSGV7QABSHE"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:31:03.691190 2026] [security2:error] [pid 935758:tid 935999] [client 57.141.18.30:34594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VArcDxY_mIul-JSGUyQABdwc"]
[Mon Jul 20 06:31:03.704185 2026] [security2:error] [pid 935758:tid 935985] [client 158.101.99.182:53056] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGV7gAAAWk"]
[Mon Jul 20 06:31:03.704266 2026] [security2:error] [pid 935758:tid 935985] [client 158.101.99.182:53056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGV7gAAAWk"]
[Mon Jul 20 06:31:03.711207 2026] [security2:error] [pid 935758:tid 935994] [client 171.60.139.123:55602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV7wAAAXI"]
[Mon Jul 20 06:31:03.711299 2026] [security2:error] [pid 935758:tid 935994] [client 171.60.139.123:55602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV7wAAAXI"]
[Mon Jul 20 06:31:03.731087 2026] [security2:error] [pid 935758:tid 935916] [client 103.141.108.143:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV8gAAASQ"]
[Mon Jul 20 06:31:03.731198 2026] [security2:error] [pid 935758:tid 935916] [client 103.141.108.143:62394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV8gAAASQ"]
[Mon Jul 20 06:31:03.736807 2026] [security2:error] [pid 935758:tid 935937] [client 34.73.38.214:55321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VB7cDxY_mIul-JSGV9AAAATk"]
[Mon Jul 20 06:31:03.747438 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VB7cDxY_mIul-JSGV5wAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.977780 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGWBQAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.977932 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:64792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGWBQAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.111900 2026] [security2:error] [pid 935758:tid 936008] [client 57.141.18.110:65174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VArcDxY_mIul-JSGU3wABgGw"]
[Mon Jul 20 06:31:04.132568 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWEAAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.132651 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWEAAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.191708 2026] [security2:error] [pid 935758:tid 935972] [client 104.234.53.88:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VCLcDxY_mIul-JSGWEQAAAVw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:04.282459 2026] [security2:error] [pid 935758:tid 935810] [remote 216.73.163.113:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nzfoodstory.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4VCLcDxY_mIul-JSGWGQABcjE"], referer: http://nzfoodstory.com/wp-includes/css/buttons.css
[Mon Jul 20 06:31:04.293467 2026] [security2:error] [pid 935758:tid 935932] [client 39.48.81.23:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWGwAAATQ"]
[Mon Jul 20 06:31:04.293555 2026] [security2:error] [pid 935758:tid 935932] [client 39.48.81.23:62172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWGwAAATQ"]
[Mon Jul 20 06:31:04.302035 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWHAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.302137 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWHAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.383060 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWJQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.383150 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWJQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.447635 2026] [security2:error] [pid 935758:tid 936003] [client 45.116.69.230:64426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWJwAAAXs"]
[Mon Jul 20 06:31:04.447761 2026] [security2:error] [pid 935758:tid 936003] [client 45.116.69.230:64426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWJwAAAXs"]
[Mon Jul 20 06:31:04.569424 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWLwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.569509 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWLwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.616059 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWMAAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.616159 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWMAAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.655215 2026] [security2:error] [pid 935758:tid 936007] [client 194.163.145.123:50932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4VCLcDxY_mIul-JSGWNgAAAX8"]
[Mon Jul 20 06:31:04.671824 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:64778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9QAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.671967 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:64778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9QAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.742519 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9wAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.742664 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9wAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.743262 2026] [security2:error] [pid 929851:tid 930013] [client 34.73.38.214:60282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VCGV3ou772CelrLic-AAAAKE"]
[Mon Jul 20 06:31:04.814280 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWPQAAASk"]
[Mon Jul 20 06:31:04.814402 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWPQAAASk"]
[Mon Jul 20 06:31:04.989012 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWSQAAAXI"]
[Mon Jul 20 06:31:04.989125 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWSQAAAXI"]
[Mon Jul 20 06:31:05.127395 2026] [security2:error] [pid 935758:tid 935905] [client 194.163.145.123:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4VCbcDxY_mIul-JSGWVgAAARk"]
[Mon Jul 20 06:31:05.243327 2026] [security2:error] [pid 935758:tid 935980] [client 158.101.99.182:53058] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCbcDxY_mIul-JSGWYAAAAWQ"]
[Mon Jul 20 06:31:05.243437 2026] [security2:error] [pid 935758:tid 935980] [client 158.101.99.182:53058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCbcDxY_mIul-JSGWYAAAAWQ"]
[Mon Jul 20 06:31:05.412432 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.79:28912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VA2V3ou772CelrLicKAAA_ko"]
[Mon Jul 20 06:31:05.614997 2026] [security2:error] [pid 929851:tid 930037] [client 194.163.145.123:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4VCWV3ou772CelrLidHAAAALk"]
[Mon Jul 20 06:31:05.638842 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/charity/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4VCbcDxY_mIul-JSGWcAAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:05.650094 2026] [security2:error] [pid 935758:tid 935965] [client 34.73.38.214:54592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VCbcDxY_mIul-JSGWcgAAAVU"]
[Mon Jul 20 06:31:05.738332 2026] [security2:error] [pid 929851:tid 930082] [client 158.101.99.182:53068] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCWV3ou772CelrLidIgAAAOY"]
[Mon Jul 20 06:31:05.738438 2026] [security2:error] [pid 929851:tid 930082] [client 158.101.99.182:53068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCWV3ou772CelrLidIgAAAOY"]
[Mon Jul 20 06:31:05.796084 2026] [security2:error] [pid 935758:tid 935900] [client 14.225.17.146:50830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4VCLcDxY_mIul-JSGWJgAAARQ"], referer: http://alchemygroup.ca/old
[Mon Jul 20 06:31:05.929729 2026] [security2:error] [pid 935758:tid 935935] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWdAAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.140546 2026] [security2:error] [pid 929851:tid 930009] [client 40.77.167.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4VCWV3ou772CelrLidKwAAAJ0"]
[Mon Jul 20 06:31:06.152152 2026] [autoindex:error] [pid 929851:tid 930084] [client 44.201.152.248:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:31:06.283552 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.70:25114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBGV3ou772CelrLicRAAA12c"]
[Mon Jul 20 06:31:06.327293 2026] [security2:error] [pid 935758:tid 935860] [remote 57.141.18.72:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4VCrcDxY_mIul-JSGWjAABG2M"]
[Mon Jul 20 06:31:06.444713 2026] [security2:error] [pid 929851:tid 930013] [client 158.101.99.182:53078] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidQQAAAKE"]
[Mon Jul 20 06:31:06.444822 2026] [security2:error] [pid 929851:tid 930013] [client 158.101.99.182:53078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidQQAAAKE"]
[Mon Jul 20 06:31:06.468969 2026] [security2:error] [pid 929851:tid 930073] [client 45.157.112.60:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VCmV3ou772CelrLidRAAAAN0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:06.780729 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.56:38650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVawABhX8"]
[Mon Jul 20 06:31:06.812191 2026] [security2:error] [pid 935758:tid 935984] [client 34.73.38.214:62635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VCrcDxY_mIul-JSGWqwAAAWg"]
[Mon Jul 20 06:31:06.875161 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWrAAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.875287 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWrAAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.911642 2026] [security2:error] [pid 935758:tid 935893] [client 14.225.17.146:56559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4VCrcDxY_mIul-JSGWqgAAAQ0"], referer: http://soloceos.com/old
[Mon Jul 20 06:31:06.929738 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidWwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.929892 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidWwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.981264 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWswAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.981432 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWswAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:07.413200 2026] [security2:error] [pid 935758:tid 935937] [client 103.125.179.95:63645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VC7cDxY_mIul-JSGWxAAAATk"]
[Mon Jul 20 06:31:07.413377 2026] [security2:error] [pid 935758:tid 935937] [client 103.125.179.95:63645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VC7cDxY_mIul-JSGWxAAAATk"]
[Mon Jul 20 06:31:07.444139 2026] [security2:error] [pid 935758:tid 935907] [client 158.173.241.141:51511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGWvgABGws"]
[Mon Jul 20 06:31:07.499830 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.76:45168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLicdgAAzwA"]
[Mon Jul 20 06:31:07.503410 2026] [security2:error] [pid 935758:tid 935915] [client 77.110.127.138:64679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VC7cDxY_mIul-JSGWzQAAASM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:07.503549 2026] [security2:error] [pid 935758:tid 935915] [client 77.110.127.138:64679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VC7cDxY_mIul-JSGWzQAAASM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:07.547916 2026] [security2:error] [pid 929851:tid 929992] [client 57.141.18.24:38368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLicgAAAjBM"]
[Mon Jul 20 06:31:07.581252 2026] [security2:error] [pid 935758:tid 935955] [client 34.73.38.214:65423] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VC7cDxY_mIul-JSGW1QAAAUs"]
[Mon Jul 20 06:31:07.587308 2026] [security2:error] [pid 929851:tid 930062] [client 14.225.17.146:56099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VC2V3ou772CelrLidagAAANI"], referer: http://fkconstructionfunding.com/old
[Mon Jul 20 06:31:07.609494 2026] [security2:error] [pid 935758:tid 936008] [client 14.225.17.146:56400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGWxwAAAYA"], referer: http://thesoloceos.com/old
[Mon Jul 20 06:31:07.703920 2026] [security2:error] [pid 929851:tid 930065] [client 74.125.215.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4VCmV3ou772CelrLidMwAAANU"]
[Mon Jul 20 06:31:07.728444 2026] [security2:error] [pid 935758:tid 935982] [client 14.225.17.146:51508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4VCrcDxY_mIul-JSGWiQAAAWY"], referer: http://alexsandbergmusic.com/old
[Mon Jul 20 06:31:07.892341 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGW2wAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:08.006430 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/charity/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4VDGV3ou772CelrLidfwAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:08.024732 2026] [security2:error] [pid 935758:tid 935808] [remote 57.141.18.108:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600520"] [unique_id "al4VDLcDxY_mIul-JSGW6gABaS8"]
[Mon Jul 20 06:31:08.124930 2026] [security2:error] [pid 935758:tid 935950] [client 50.116.65.227:51358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4VDLcDxY_mIul-JSGW8wAAAUY"]
[Mon Jul 20 06:31:08.139516 2026] [security2:error] [pid 935758:tid 935951] [client 50.116.65.227:40616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4VDLcDxY_mIul-JSGW9QAAAUc"]
[Mon Jul 20 06:31:08.148186 2026] [security2:error] [pid 935758:tid 935999] [client 158.101.99.182:51892] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGW9gAAAXc"]
[Mon Jul 20 06:31:08.148321 2026] [security2:error] [pid 935758:tid 935999] [client 158.101.99.182:51892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGW9gAAAXc"]
[Mon Jul 20 06:31:08.455851 2026] [security2:error] [pid 929851:tid 930097] [client 103.153.183.69:8542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../app/.env"] [unique_id "al4VDGV3ou772CelrLidkAAAAPU"], referer: https://t.co/hzyflcs9ty
[Mon Jul 20 06:31:08.633125 2026] [security2:error] [pid 929851:tid 930035] [client 103.153.183.69:8542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../srv/.env"] [unique_id "al4VDGV3ou772CelrLidlwAAALc"], referer: https://www.reddit.com/
[Mon Jul 20 06:31:08.649515 2026] [security2:error] [pid 929851:tid 930087] [client 14.225.17.146:56517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4VDGV3ou772CelrLidkgAAAOs"], referer: https://thesoloceos.com/old
[Mon Jul 20 06:31:08.743535 2026] [security2:error] [pid 935758:tid 935973] [client 216.73.216.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4VDLcDxY_mIul-JSGXBwABXUw"]
[Mon Jul 20 06:31:08.754704 2026] [security2:error] [pid 929851:tid 930040] [client 57.141.18.99:23770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicygAAvHc"]
[Mon Jul 20 06:31:08.754781 2026] [security2:error] [pid 935758:tid 935910] [client 216.73.216.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "giftsurprizo.com"] [uri "/index.php"] [unique_id "al4VDLcDxY_mIul-JSGXBQAAAR4"], referer: https://giftsurprizo.com/wp-sitemap.xml
[Mon Jul 20 06:31:08.845930 2026] [security2:error] [pid 935758:tid 935966] [client 158.101.99.182:51906] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGXEgAAAVY"]
[Mon Jul 20 06:31:08.846019 2026] [security2:error] [pid 935758:tid 935966] [client 158.101.99.182:51906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGXEgAAAVY"]
[Mon Jul 20 06:31:08.860169 2026] [security2:error] [pid 929851:tid 929999] [client 14.225.17.146:56116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4VDGV3ou772CelrLidmQAAAJM"], referer: http://carolinapressurewashers.com/old
[Mon Jul 20 06:31:09.193201 2026] [security2:error] [pid 929851:tid 929862] [remote 152.228.213.32:60080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VDWV3ou772CelrLidqgAA7AY"]
[Mon Jul 20 06:31:09.220135 2026] [security2:error] [pid 929851:tid 930068] [client 197.186.66.42:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLidrAAAANg"]
[Mon Jul 20 06:31:09.224765 2026] [security2:error] [pid 929851:tid 930068] [client 197.186.66.42:56682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLidrAAAANg"]
[Mon Jul 20 06:31:09.260480 2026] [security2:error] [pid 935758:tid 936013] [client 113.186.25.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VDbcDxY_mIul-JSGXIAAAAYU"]
[Mon Jul 20 06:31:09.336922 2026] [security2:error] [pid 935758:tid 935932] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VDbcDxY_mIul-JSGXJAAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:09.513972 2026] [security2:error] [pid 929851:tid 930044] [client 103.153.183.69:8542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/.env"] [unique_id "al4VDWV3ou772CelrLidtwAAAMA"], referer: https://t.co/cs3knd3dtk
[Mon Jul 20 06:31:09.534266 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:42287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLiduAAAAM8"]
[Mon Jul 20 06:31:09.534398 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:42287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLiduAAAAM8"]
[Mon Jul 20 06:31:09.560055 2026] [security2:error] [pid 929851:tid 929921] [remote 152.228.213.32:60080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VDWV3ou772CelrLidugAAikE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:09.564885 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDbcDxY_mIul-JSGXPgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:09.564964 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDbcDxY_mIul-JSGXPgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:09.990145 2026] [security2:error] [pid 929851:tid 929953] [remote 192.241.143.148:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VDWV3ou772CelrLidywAA9mE"]
[Mon Jul 20 06:31:10.050273 2026] [security2:error] [pid 929851:tid 930051] [client 171.61.165.146:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VDmV3ou772CelrLidzAAAAMc"]
[Mon Jul 20 06:31:10.050390 2026] [security2:error] [pid 929851:tid 930051] [client 171.61.165.146:6584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VDmV3ou772CelrLidzAAAAMc"]
[Mon Jul 20 06:31:10.163473 2026] [security2:error] [pid 929851:tid 929915] [remote 192.241.143.148:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VDmV3ou772CelrLidzgAA5Ds"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:31:10.225713 2026] [fcgid:warn] [pid 929851:tid 930023] (70014)End of file found: [client 167.94.146.52:35242] mod_fcgid: can't get data from http client
[Mon Jul 20 06:31:10.384396 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXYAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.384529 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXYAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.502909 2026] [security2:error] [pid 935758:tid 935925] [client 57.141.18.62:31784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCLcDxY_mIul-JSGWNwABLXc"]
[Mon Jul 20 06:31:10.531929 2026] [proxy:error] [pid 929851:tid 930039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:10.531986 2026] [proxy_http:error] [pid 929851:tid 930039] [client 34.73.38.214:56123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:10.532434 2026] [proxy:error] [pid 929851:tid 930039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:10.532457 2026] [proxy_http:error] [pid 929851:tid 930039] [client 34.73.38.214:56123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:10.543089 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:64827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXbwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.543163 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:64827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXbwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.752711 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXdgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.752846 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXdgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.887977 2026] [security2:error] [pid 929851:tid 930012] [client 50.116.65.227:48052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VDmV3ou772CelrLid7AAAAKA"]
[Mon Jul 20 06:31:10.898331 2026] [security2:error] [pid 929851:tid 930105] [client 50.116.65.227:48068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VDmV3ou772CelrLid7QAAAP0"]
[Mon Jul 20 06:31:11.014966 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXfAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.015108 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXfAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.078603 2026] [security2:error] [pid 935758:tid 935944] [client 57.141.18.22:61110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWWwABQHk"]
[Mon Jul 20 06:31:11.155443 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:64831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXigAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.155536 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:64831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXigAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.309551 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/charity/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4VD7cDxY_mIul-JSGXjQAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.309833 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.309909 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.344958 2026] [security2:error] [pid 929851:tid 930016] [client 77.110.127.138:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9wAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.345059 2026] [security2:error] [pid 929851:tid 930016] [client 77.110.127.138:64834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9wAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.355084 2026] [security2:error] [pid 935758:tid 935930] [client 57.141.18.3:39612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWZQABMlI"]
[Mon Jul 20 06:31:11.500880 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid_AAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.501034 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid_AAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.646985 2026] [security2:error] [pid 935758:tid 935914] [client 57.141.18.71:41572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWbQABIlc"]
[Mon Jul 20 06:31:11.655772 2026] [security2:error] [pid 935758:tid 935929] [client 77.110.127.138:64837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXpAAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.655897 2026] [security2:error] [pid 935758:tid 935929] [client 77.110.127.138:64837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXpAAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.694271 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:64835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VD7cDxY_mIul-JSGXlQAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.802721 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXqQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.802846 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXqQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.823635 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLieBQAAAPY"]
[Mon Jul 20 06:31:11.823784 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLieBQAAAPY"]
[Mon Jul 20 06:31:12.008153 2026] [security2:error] [pid 935758:tid 936008] [client 223.185.13.213:16035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VELcDxY_mIul-JSGXsQAAAYA"]
[Mon Jul 20 06:31:12.008271 2026] [security2:error] [pid 935758:tid 936008] [client 223.185.13.213:16035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VELcDxY_mIul-JSGXsQAAAYA"]
[Mon Jul 20 06:31:12.131267 2026] [security2:error] [pid 935758:tid 935941] [client 104.234.53.74:22843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VELcDxY_mIul-JSGXuQAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:12.173711 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXvgAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.173881 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXvgAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.216145 2026] [security2:error] [pid 929851:tid 929978] [remote 173.249.4.11:29882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4VEGV3ou772CelrLieDgAA5Ho"]
[Mon Jul 20 06:31:12.244725 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXxgAAAT4"]
[Mon Jul 20 06:31:12.244829 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXxgAAAT4"]
[Mon Jul 20 06:31:12.398661 2026] [security2:error] [pid 929851:tid 930054] [client 77.110.127.138:64844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieEQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.398837 2026] [security2:error] [pid 929851:tid 930054] [client 77.110.127.138:64844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieEQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.440407 2026] [proxy:error] [pid 929851:tid 930040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:12.440491 2026] [proxy_http:error] [pid 929851:tid 930040] [client 34.73.38.214:56260] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:12.441236 2026] [proxy:error] [pid 929851:tid 930040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:12.441281 2026] [proxy_http:error] [pid 929851:tid 930040] [client 34.73.38.214:56260] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:12.612253 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieHAAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.612367 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieHAAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.793407 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VEGV3ou772CelrLieGQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.825508 2026] [security2:error] [pid 935758:tid 935932] [client 14.225.17.146:51612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4VDrcDxY_mIul-JSGXZAAAATQ"], referer: http://onewingpictures.com/old
[Mon Jul 20 06:31:13.006670 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEWV3ou772CelrLieKAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.006786 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEWV3ou772CelrLieKAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.064240 2026] [security2:error] [pid 929851:tid 929885] [remote 173.249.4.11:29882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4VEWV3ou772CelrLieLQAArR0"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 06:31:13.293931 2026] [security2:error] [pid 935758:tid 935946] [client 54.224.22.173:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.224.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VEbcDxY_mIul-JSGYCgAAAUI"]
[Mon Jul 20 06:31:13.515371 2026] [security2:error] [pid 935758:tid 935907] [client 34.74.185.202:50683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VEbcDxY_mIul-JSGYFgAAARs"]
[Mon Jul 20 06:31:13.560249 2026] [security2:error] [pid 935758:tid 935911] [client 57.141.18.125:64890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGW2gABH1E"]
[Mon Jul 20 06:31:13.774593 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEbcDxY_mIul-JSGYLgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.774698 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEbcDxY_mIul-JSGYLgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.805352 2026] [security2:error] [pid 935758:tid 935905] [client 34.207.130.29:32426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VEbcDxY_mIul-JSGYMAAAARk"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:31:13.842643 2026] [security2:error] [pid 935758:tid 935992] [client 34.74.185.202:54320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VEbcDxY_mIul-JSGYMwAAAXA"]
[Mon Jul 20 06:31:13.979058 2026] [security2:error] [pid 935758:tid 935772] [remote 122.154.60.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.60.154.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "beauacoustics.com"] [uri "/xmlrpc.php"] [unique_id "al4VEbcDxY_mIul-JSGYOgABbws"]
[Mon Jul 20 06:31:13.979239 2026] [security2:error] [pid 935758:tid 935991] [client 122.154.60.154:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "beauacoustics.com"] [uri "/xmlrpc.php"] [unique_id "al4VEbcDxY_mIul-JSGYOgABbws"]
[Mon Jul 20 06:31:14.152920 2026] [security2:error] [pid 929851:tid 930013] [client 57.141.18.116:57572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDGV3ou772CelrLidhQAAoVo"]
[Mon Jul 20 06:31:14.184706 2026] [security2:error] [pid 929851:tid 930035] [client 34.74.185.202:57958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VEmV3ou772CelrLieTAAAALc"]
[Mon Jul 20 06:31:14.401283 2026] [security2:error] [pid 935758:tid 935995] [client 57.141.18.78:37914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDLcDxY_mIul-JSGXAwABcxE"]
[Mon Jul 20 06:31:14.427073 2026] [security2:error] [pid 935758:tid 935993] [client 171.60.139.123:56133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYUwAAAXE"]
[Mon Jul 20 06:31:14.427234 2026] [security2:error] [pid 935758:tid 935993] [client 171.60.139.123:56133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYUwAAAXE"]
[Mon Jul 20 06:31:14.460020 2026] [core:error] [pid 929851:tid 930030] [client 14.225.17.146:62208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/old
[Mon Jul 20 06:31:14.460056 2026] [core:error] [pid 929851:tid 930030] [client 14.225.17.146:62208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/old
[Mon Jul 20 06:31:14.477667 2026] [security2:error] [pid 929851:tid 930068] [client 34.74.185.202:53432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VEmV3ou772CelrLieUwAAANg"]
[Mon Jul 20 06:31:14.483408 2026] [proxy:error] [pid 929851:tid 929987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:14.483486 2026] [proxy_http:error] [pid 929851:tid 929987] [client 34.73.38.214:60053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:14.484361 2026] [proxy:error] [pid 929851:tid 929987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:14.484412 2026] [proxy_http:error] [pid 929851:tid 929987] [client 34.73.38.214:60053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:14.502190 2026] [security2:error] [pid 929851:tid 930082] [client 103.141.108.143:62877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieVQAAAOY"]
[Mon Jul 20 06:31:14.502623 2026] [security2:error] [pid 929851:tid 930082] [client 103.141.108.143:62877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieVQAAAOY"]
[Mon Jul 20 06:31:14.519439 2026] [security2:error] [pid 935758:tid 935912] [client 14.225.17.146:50627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4VEbcDxY_mIul-JSGYDwAAASA"], referer: http://mazzucelli.com/old
[Mon Jul 20 06:31:14.841890 2026] [security2:error] [pid 935758:tid 935982] [client 34.74.185.202:62786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VErcDxY_mIul-JSGYdgAAAWY"]
[Mon Jul 20 06:31:14.856207 2026] [security2:error] [pid 929851:tid 930088] [client 39.48.81.23:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieWAAAAOw"]
[Mon Jul 20 06:31:14.856372 2026] [security2:error] [pid 929851:tid 930088] [client 39.48.81.23:62662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieWAAAAOw"]
[Mon Jul 20 06:31:14.993091 2026] [security2:error] [pid 935758:tid 935905] [client 45.116.69.230:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYgwAAARk"]
[Mon Jul 20 06:31:14.993230 2026] [security2:error] [pid 935758:tid 935905] [client 45.116.69.230:64968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYgwAAARk"]
[Mon Jul 20 06:31:15.053823 2026] [security2:error] [pid 935758:tid 935954] [client 14.225.17.146:62704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4VEbcDxY_mIul-JSGX-QAAAUo"], referer: http://itdynamix.com/old
[Mon Jul 20 06:31:15.071441 2026] [security2:error] [pid 935758:tid 935893] [client 34.74.185.202:55508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGYigAAAQ0"]
[Mon Jul 20 06:31:15.084683 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGYjQAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.084806 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGYjQAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.351771 2026] [security2:error] [pid 935758:tid 935942] [client 34.74.185.202:51388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGYowAAAT4"]
[Mon Jul 20 06:31:15.488551 2026] [security2:error] [pid 935758:tid 935995] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtQAAAXM"]
[Mon Jul 20 06:31:15.488551 2026] [security2:error] [pid 935758:tid 935896] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtAAAARA"]
[Mon Jul 20 06:31:15.490078 2026] [security2:error] [pid 935758:tid 935983] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYuAAAAWc"]
[Mon Jul 20 06:31:15.490977 2026] [security2:error] [pid 935758:tid 935917] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtgAAASU"]
[Mon Jul 20 06:31:15.491071 2026] [security2:error] [pid 935758:tid 935993] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYuQAAAXE"]
[Mon Jul 20 06:31:15.512588 2026] [security2:error] [pid 935758:tid 935905] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtwAAARk"]
[Mon Jul 20 06:31:15.570019 2026] [security2:error] [pid 935758:tid 936017] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYxwABiXk"]
[Mon Jul 20 06:31:15.581231 2026] [security2:error] [pid 935758:tid 935890] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYzAAAAQo"]
[Mon Jul 20 06:31:15.584956 2026] [security2:error] [pid 935758:tid 935985] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYywAAAWk"]
[Mon Jul 20 06:31:15.604694 2026] [security2:error] [pid 935758:tid 935987] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYzwAAAWs"]
[Mon Jul 20 06:31:15.618911 2026] [security2:error] [pid 935758:tid 935986] [client 34.74.185.202:64068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGY2QAAAWo"]
[Mon Jul 20 06:31:15.623778 2026] [security2:error] [pid 935758:tid 935913] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYzgAAASE"]
[Mon Jul 20 06:31:15.665998 2026] [security2:error] [pid 929851:tid 929943] [remote 57.141.18.13:55710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDWV3ou772CelrLidxQAAlFc"]
[Mon Jul 20 06:31:15.785421 2026] [security2:error] [pid 935758:tid 935766] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env"] [unique_id "al4VE7cDxY_mIul-JSGY7AABdwU"]
[Mon Jul 20 06:31:15.788158 2026] [proxy:error] [pid 935758:tid 935969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:15.788200 2026] [proxy_http:error] [pid 935758:tid 935969] [client 34.73.38.214:49334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:15.788627 2026] [proxy:error] [pid 935758:tid 935969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:15.788653 2026] [proxy_http:error] [pid 935758:tid 935969] [client 34.73.38.214:49334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:15.875019 2026] [security2:error] [pid 935758:tid 936009] [client 34.74.185.202:56479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGZBAAAAYE"]
[Mon Jul 20 06:31:15.896565 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGZCwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.896646 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGZCwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.954835 2026] [security2:error] [pid 935758:tid 935763] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env.backup"] [unique_id "al4VE7cDxY_mIul-JSGZEAABXgI"]
[Mon Jul 20 06:31:15.956401 2026] [security2:error] [pid 935758:tid 935890] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZCgAAAQo"]
[Mon Jul 20 06:31:15.975640 2026] [security2:error] [pid 935758:tid 935939] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZBwAAATs"]
[Mon Jul 20 06:31:15.992504 2026] [security2:error] [pid 935758:tid 935786] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/.env.old"] [unique_id "al4VE7cDxY_mIul-JSGZFgABXhk"]
[Mon Jul 20 06:31:16.000636 2026] [security2:error] [pid 935758:tid 935770] [remote 84.247.172.23:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VE7cDxY_mIul-JSGZFQABGwk"]
[Mon Jul 20 06:31:16.000834 2026] [security2:error] [pid 935758:tid 935907] [client 84.247.172.23:59706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VE7cDxY_mIul-JSGZFQABGwk"]
[Mon Jul 20 06:31:16.010149 2026] [security2:error] [pid 935758:tid 935826] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tadlarsen.com"] [uri "/graphql"] [unique_id "al4VFLcDxY_mIul-JSGZHAABXkE"]
[Mon Jul 20 06:31:16.011105 2026] [security2:error] [pid 935758:tid 935828] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env.bak"] [unique_id "al4VFLcDxY_mIul-JSGZGwABXkM"]
[Mon Jul 20 06:31:16.029709 2026] [security2:error] [pid 935758:tid 935860] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/api/.env"] [unique_id "al4VFLcDxY_mIul-JSGZHgABXmM"]
[Mon Jul 20 06:31:16.029858 2026] [security2:error] [pid 935758:tid 935974] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/api/.env"] [unique_id "al4VFLcDxY_mIul-JSGZHgABXmM"]
[Mon Jul 20 06:31:16.055821 2026] [security2:error] [pid 935758:tid 935952] [client 14.225.17.146:62859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZCAAAAUg"], referer: https://itdynamix.com/old
[Mon Jul 20 06:31:16.069342 2026] [security2:error] [pid 935758:tid 935807] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/admin/.env"] [unique_id "al4VFLcDxY_mIul-JSGZJgABXi4"]
[Mon Jul 20 06:31:16.069486 2026] [security2:error] [pid 935758:tid 935974] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/admin/.env"] [unique_id "al4VFLcDxY_mIul-JSGZJgABXi4"]
[Mon Jul 20 06:31:16.090303 2026] [security2:error] [pid 935758:tid 935913] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZFwAAASE"]
[Mon Jul 20 06:31:16.094379 2026] [security2:error] [pid 935758:tid 935761] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/backend/.env"] [unique_id "al4VFLcDxY_mIul-JSGZLgABRgA"]
[Mon Jul 20 06:31:16.158654 2026] [security2:error] [pid 935758:tid 935918] [client 34.74.185.202:50867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VFLcDxY_mIul-JSGZMgAAASY"]
[Mon Jul 20 06:31:16.194594 2026] [autoindex:error] [pid 935758:tid 935993] [client 14.225.17.146:62843] AH01276: Cannot serve directory /home2/blaizeac/public_html/old/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://blaizeaccountingservices.com/old
[Mon Jul 20 06:31:16.195986 2026] [security2:error] [pid 935758:tid 935888] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/config/.env"] [unique_id "al4VFLcDxY_mIul-JSGZNQABS38"]
[Mon Jul 20 06:31:16.196699 2026] [security2:error] [pid 929851:tid 929910] [remote 57.141.18.102:25450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDmV3ou772CelrLid1AAAlTY"]
[Mon Jul 20 06:31:16.278069 2026] [security2:error] [pid 935758:tid 935920] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZKAAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.284594 2026] [security2:error] [pid 935758:tid 935804] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tadlarsen.com"] [uri "/api/graphql"] [unique_id "al4VFLcDxY_mIul-JSGZQQABVCs"]
[Mon Jul 20 06:31:16.389997 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZSwABOHs"]
[Mon Jul 20 06:31:16.390806 2026] [security2:error] [pid 935758:tid 935792] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.s3cfg"] [unique_id "al4VFLcDxY_mIul-JSGZYwABOB8"]
[Mon Jul 20 06:31:16.390974 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.s3cfg"] [unique_id "al4VFLcDxY_mIul-JSGZYwABOB8"]
[Mon Jul 20 06:31:16.392398 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZSgABOCg"]
[Mon Jul 20 06:31:16.396681 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZRAABOF4"]
[Mon Jul 20 06:31:16.411341 2026] [security2:error] [pid 935758:tid 935998] [client 34.74.185.202:59823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VFLcDxY_mIul-JSGZawAAAXY"]
[Mon Jul 20 06:31:16.413157 2026] [security2:error] [pid 935758:tid 935930] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZTgAAATI"]
[Mon Jul 20 06:31:16.421362 2026] [authz_core:error] [pid 935758:tid 935897] [client 34.129.173.120:0] AH01630: client denied by server configuration: /home1/tadlarse/public_html/.htpasswd
[Mon Jul 20 06:31:16.431123 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZUgAAAXA"]
[Mon Jul 20 06:31:16.440234 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVAABOGQ"]
[Mon Jul 20 06:31:16.448616 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVwABOAw"]
[Mon Jul 20 06:31:16.449155 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVgABOBE"]
[Mon Jul 20 06:31:16.450215 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVQABOGY"]
[Mon Jul 20 06:31:16.458069 2026] [security2:error] [pid 935758:tid 935851] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tadlarsen.com"] [uri "/v1/graphql"] [unique_id "al4VFLcDxY_mIul-JSGZdAABOFo"]
[Mon Jul 20 06:31:16.490512 2026] [security2:error] [pid 935758:tid 935967] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZbwAAAVc"]
[Mon Jul 20 06:31:16.503830 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZdQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.503946 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZdQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.518768 2026] [security2:error] [pid 935758:tid 935960] [client 57.141.18.41:51110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDrcDxY_mIul-JSGXcQABUA4"]
[Mon Jul 20 06:31:16.607991 2026] [security2:error] [pid 935758:tid 935764] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.ssh/id_rsa"] [unique_id "al4VFLcDxY_mIul-JSGZggABcgM"]
[Mon Jul 20 06:31:16.624268 2026] [security2:error] [pid 935758:tid 935942] [client 14.225.17.146:62122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZWwAAAT4"], referer: http://talknutritionwithlesley.com/old
[Mon Jul 20 06:31:16.632070 2026] [security2:error] [pid 935758:tid 935857] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.ssh/id_dsa"] [unique_id "al4VFLcDxY_mIul-JSGZjAABcmA"]
[Mon Jul 20 06:31:16.680205 2026] [security2:error] [pid 935758:tid 935994] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZfAABchg"]
[Mon Jul 20 06:31:16.685456 2026] [security2:error] [pid 935758:tid 935961] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZiAAAAVE"]
[Mon Jul 20 06:31:16.686568 2026] [security2:error] [pid 935758:tid 935962] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZiQAAAVI"]
[Mon Jul 20 06:31:16.696779 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZoQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.696878 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZoQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.705639 2026] [security2:error] [pid 935758:tid 936013] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZiwAAAYU"]
[Mon Jul 20 06:31:16.709176 2026] [security2:error] [pid 935758:tid 935952] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZjQAAAUg"]
[Mon Jul 20 06:31:16.734897 2026] [security2:error] [pid 935758:tid 935880] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/id_rsa"] [unique_id "al4VFLcDxY_mIul-JSGZpwABcnc"]
[Mon Jul 20 06:31:16.746553 2026] [security2:error] [pid 935758:tid 935900] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZnwAAARQ"]
[Mon Jul 20 06:31:16.748191 2026] [security2:error] [pid 935758:tid 935897] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZoAAAARE"]
[Mon Jul 20 06:31:16.749126 2026] [security2:error] [pid 935758:tid 935958] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZngAAAU4"]
[Mon Jul 20 06:31:16.766756 2026] [security2:error] [pid 935758:tid 935932] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZowAAATQ"]
[Mon Jul 20 06:31:16.862187 2026] [security2:error] [pid 929851:tid 929906] [remote 57.141.18.117:33008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VD2V3ou772CelrLid9QAAmDI"]
[Mon Jul 20 06:31:16.862913 2026] [security2:error] [pid 935758:tid 935831] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/id_dsa"] [unique_id "al4VFLcDxY_mIul-JSGZuwABVEY"]
[Mon Jul 20 06:31:16.900633 2026] [security2:error] [pid 935758:tid 935901] [client 34.74.185.202:63002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VFLcDxY_mIul-JSGZ6wAAARU"]
[Mon Jul 20 06:31:16.908973 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZ1gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.909074 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZ1gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.934680 2026] [security2:error] [pid 935758:tid 935782] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/key.pem"] [unique_id "al4VFLcDxY_mIul-JSGZ8QABeBU"]
[Mon Jul 20 06:31:16.959449 2026] [security2:error] [pid 935758:tid 935823] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/localhost.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9AABeD4"]
[Mon Jul 20 06:31:16.959638 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/localhost.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9AABeD4"]
[Mon Jul 20 06:31:16.960142 2026] [security2:error] [pid 935758:tid 935797] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/ssl/server.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9gABeCQ"]
[Mon Jul 20 06:31:16.960254 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/ssl/server.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9gABeCQ"]
[Mon Jul 20 06:31:16.961223 2026] [security2:error] [pid 935758:tid 935761] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/privatekey.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9QABeAA"]
[Mon Jul 20 06:31:16.969300 2026] [security2:error] [pid 935758:tid 936007] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ7QAAAX8"]
[Mon Jul 20 06:31:16.974392 2026] [security2:error] [pid 935758:tid 935895] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ4wAAAQ8"]
[Mon Jul 20 06:31:17.024474 2026] [security2:error] [pid 935758:tid 935896] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ-AAAARA"]
[Mon Jul 20 06:31:17.048532 2026] [security2:error] [pid 935758:tid 935963] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ_QAAAVM"]
[Mon Jul 20 06:31:17.048793 2026] [security2:error] [pid 935758:tid 935894] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ_gAAAQ4"]
[Mon Jul 20 06:31:17.065616 2026] [security2:error] [pid 935758:tid 935924] [client 57.141.18.84:43064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VD7cDxY_mIul-JSGXjAABLDY"]
[Mon Jul 20 06:31:17.069224 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:64869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaCAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.069321 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:64869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaCAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.128697 2026] [security2:error] [pid 935758:tid 935978] [client 74.208.214.194:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VFbcDxY_mIul-JSGaDgAAAWI"]
[Mon Jul 20 06:31:17.132674 2026] [security2:error] [pid 935758:tid 935884] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.openclaw/.env"] [unique_id "al4VFbcDxY_mIul-JSGaDwABeHs"]
[Mon Jul 20 06:31:17.165357 2026] [security2:error] [pid 935758:tid 935932] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaBwAAATQ"]
[Mon Jul 20 06:31:17.177063 2026] [security2:error] [pid 935758:tid 935949] [client 145.223.130.17:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.130.223.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-rahudsongallery-com/order-buy-geodon-online-clinic-uk/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaFwAAAUU"]
[Mon Jul 20 06:31:17.193703 2026] [security2:error] [pid 935758:tid 935778] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.hermes/.env"] [unique_id "al4VFbcDxY_mIul-JSGaHAABeBE"]
[Mon Jul 20 06:31:17.195543 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaEAABeB8"]
[Mon Jul 20 06:31:17.214672 2026] [security2:error] [pid 929851:tid 929979] [remote 57.141.18.115:33018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VD2V3ou772CelrLid-wAA-3s"]
[Mon Jul 20 06:31:17.257285 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaGgABeGQ"]
[Mon Jul 20 06:31:17.276649 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaGQABeDk"]
[Mon Jul 20 06:31:17.302904 2026] [security2:error] [pid 935758:tid 935908] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaKQAAARw"]
[Mon Jul 20 06:31:17.307481 2026] [security2:error] [pid 935758:tid 935915] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaLAAAASM"]
[Mon Jul 20 06:31:17.327133 2026] [security2:error] [pid 935758:tid 935795] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.claude.json"] [unique_id "al4VFbcDxY_mIul-JSGaOAABeCI"]
[Mon Jul 20 06:31:17.327267 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.claude.json"] [unique_id "al4VFbcDxY_mIul-JSGaOAABeCI"]
[Mon Jul 20 06:31:17.332221 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaPQAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.332311 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaPQAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.340213 2026] [security2:error] [pid 935758:tid 935906] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaNAAAARo"]
[Mon Jul 20 06:31:17.354828 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaQAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.354904 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaQAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.365245 2026] [security2:error] [pid 935758:tid 935865] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.hermes/auth.json"] [unique_id "al4VFbcDxY_mIul-JSGaQQABeGg"]
[Mon Jul 20 06:31:17.365435 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.hermes/auth.json"] [unique_id "al4VFbcDxY_mIul-JSGaQQABeGg"]
[Mon Jul 20 06:31:17.365777 2026] [security2:error] [pid 935758:tid 935812] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al4VFbcDxY_mIul-JSGaQgABeDM"]
[Mon Jul 20 06:31:17.365873 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al4VFbcDxY_mIul-JSGaQgABeDM"]
[Mon Jul 20 06:31:17.526265 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaWQAAAYc"]
[Mon Jul 20 06:31:17.527131 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaYwAAAYk"]
[Mon Jul 20 06:31:17.527241 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaYwAAAYk"]
[Mon Jul 20 06:31:17.530942 2026] [security2:error] [pid 935758:tid 935943] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaUgABP08"]
[Mon Jul 20 06:31:17.533248 2026] [security2:error] [pid 935758:tid 935938] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaWgAAATo"]
[Mon Jul 20 06:31:17.550969 2026] [security2:error] [pid 935758:tid 935943] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaWwABP0Q"]
[Mon Jul 20 06:31:17.561315 2026] [security2:error] [pid 935758:tid 935882] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tadlarsen.com"] [uri "/wp-config.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGaaQABY3k"]
[Mon Jul 20 06:31:17.563461 2026] [security2:error] [pid 935758:tid 935798] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tadlarsen.com"] [uri "/wp-config.php.old"] [unique_id "al4VFbcDxY_mIul-JSGaagABgCU"]
[Mon Jul 20 06:31:17.564928 2026] [security2:error] [pid 935758:tid 935856] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/laravel/.env"] [unique_id "al4VFbcDxY_mIul-JSGabAABgF8"]
[Mon Jul 20 06:31:17.575255 2026] [security2:error] [pid 935758:tid 935831] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/config/.env.php"] [unique_id "al4VFbcDxY_mIul-JSGabgABgEY"]
[Mon Jul 20 06:31:17.631437 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaggAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.631525 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaggAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.655100 2026] [security2:error] [pid 935758:tid 936008] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaawABgDA"]
[Mon Jul 20 06:31:17.682492 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:64877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGahwAAAV0"]
[Mon Jul 20 06:31:17.682648 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:64877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGahwAAAV0"]
[Mon Jul 20 06:31:17.685980 2026] [security2:error] [pid 935758:tid 936004] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGafQAAAXw"]
[Mon Jul 20 06:31:17.687539 2026] [security2:error] [pid 935758:tid 935996] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaewAAAXQ"]
[Mon Jul 20 06:31:17.694952 2026] [security2:error] [pid 935758:tid 935791] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/.env.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGaiAABWB4"]
[Mon Jul 20 06:31:17.743473 2026] [security2:error] [pid 935758:tid 935784] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/configuration.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGakQABhxc"]
[Mon Jul 20 06:31:17.744681 2026] [security2:error] [pid 935758:tid 935875] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env.swp"] [unique_id "al4VFbcDxY_mIul-JSGakgABh3I"]
[Mon Jul 20 06:31:17.746693 2026] [security2:error] [pid 935758:tid 935816] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/auth.json"] [unique_id "al4VFbcDxY_mIul-JSGalQABhzc"]
[Mon Jul 20 06:31:17.747138 2026] [security2:error] [pid 935758:tid 935763] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/config.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGalgABhwI"]
[Mon Jul 20 06:31:17.747334 2026] [security2:error] [pid 935758:tid 935794] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/core/.env"] [unique_id "al4VFbcDxY_mIul-JSGalAABhyE"]
[Mon Jul 20 06:31:17.789002 2026] [security2:error] [pid 935758:tid 935871] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/web/.env"] [unique_id "al4VFbcDxY_mIul-JSGanAABh24"]
[Mon Jul 20 06:31:17.799239 2026] [security2:error] [pid 935758:tid 935839] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/public/.env"] [unique_id "al4VFbcDxY_mIul-JSGanwABh04"]
[Mon Jul 20 06:31:17.814191 2026] [security2:error] [pid 935758:tid 935966] [client 103.125.179.95:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VFbcDxY_mIul-JSGaowAAAVY"]
[Mon Jul 20 06:31:17.817303 2026] [security2:error] [pid 935758:tid 935966] [client 103.125.179.95:64137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VFbcDxY_mIul-JSGaowAAAVY"]
[Mon Jul 20 06:31:17.858727 2026] [security2:error] [pid 935758:tid 935906] [client 34.73.38.214:56320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VFbcDxY_mIul-JSGasAAAARo"]
[Mon Jul 20 06:31:17.876576 2026] [security2:error] [pid 929851:tid 929965] [remote 57.141.18.27:46906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VEGV3ou772CelrLieCQABAm0"]
[Mon Jul 20 06:31:17.880890 2026] [security2:error] [pid 935758:tid 935948] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGamwAAAUQ"]
[Mon Jul 20 06:31:17.914592 2026] [security2:error] [pid 935758:tid 935967] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGarAAAAVc"]
[Mon Jul 20 06:31:17.951106 2026] [security2:error] [pid 935758:tid 935761] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/api/config"] [unique_id "al4VFbcDxY_mIul-JSGawQABhwA"]
[Mon Jul 20 06:31:17.959616 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaxgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.959760 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaxgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.968555 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGatgABhwQ"]
[Mon Jul 20 06:31:17.971022 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGatwABhzw"]
[Mon Jul 20 06:31:17.992262 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGauAABh30"]
[Mon Jul 20 06:31:18.020472 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGawgABhw8"]
[Mon Jul 20 06:31:18.025825 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGawAABhyQ"]
[Mon Jul 20 06:31:18.044432 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGayQAAARc"]
[Mon Jul 20 06:31:18.044923 2026] [security2:error] [pid 935758:tid 935891] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGayAAAAQs"]
[Mon Jul 20 06:31:18.156515 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa0AABhzY"]
[Mon Jul 20 06:31:18.156662 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGazwABh1M"]
[Mon Jul 20 06:31:18.178914 2026] [security2:error] [pid 935758:tid 935813] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/runtime-config.js"] [unique_id "al4VFrcDxY_mIul-JSGa5QABhzQ"]
[Mon Jul 20 06:31:18.179069 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/runtime-config.js"] [unique_id "al4VFrcDxY_mIul-JSGa5QABhzQ"]
[Mon Jul 20 06:31:18.188682 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGawwAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.202426 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa2wABhzs"]
[Mon Jul 20 06:31:18.244709 2026] [security2:error] [pid 935758:tid 935982] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa5gAAAWY"]
[Mon Jul 20 06:31:18.245981 2026] [security2:error] [pid 935758:tid 936016] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa5wAAAYg"]
[Mon Jul 20 06:31:18.269110 2026] [security2:error] [pid 935758:tid 935948] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa4wAAAUQ"]
[Mon Jul 20 06:31:18.274098 2026] [security2:error] [pid 935758:tid 935962] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa6QAAAVI"]
[Mon Jul 20 06:31:18.284525 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa6gABh1Q"]
[Mon Jul 20 06:31:18.305559 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa6wABh0M"]
[Mon Jul 20 06:31:18.307415 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa7AABhys"]
[Mon Jul 20 06:31:18.418776 2026] [security2:error] [pid 935758:tid 935899] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa9gAAARM"]
[Mon Jul 20 06:31:18.429819 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbBwAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.429935 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbBwAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.447210 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa-AABhyg"]
[Mon Jul 20 06:31:18.466026 2026] [security2:error] [pid 935758:tid 935971] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbBAAAAVs"]
[Mon Jul 20 06:31:18.469195 2026] [security2:error] [pid 935758:tid 935954] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbAQAAAUo"]
[Mon Jul 20 06:31:18.480594 2026] [security2:error] [pid 935758:tid 935818] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/service-worker.js"] [unique_id "al4VFrcDxY_mIul-JSGbDgABhzk"]
[Mon Jul 20 06:31:18.492714 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbBgABhx8"]
[Mon Jul 20 06:31:18.529188 2026] [core:error] [pid 935758:tid 935973] [client 14.225.17.146:49663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/old
[Mon Jul 20 06:31:18.529210 2026] [core:error] [pid 935758:tid 935973] [client 14.225.17.146:49663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/old
[Mon Jul 20 06:31:18.536603 2026] [security2:error] [pid 935758:tid 935961] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbDQAAAVE"]
[Mon Jul 20 06:31:18.546184 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbDwABh1s"]
[Mon Jul 20 06:31:18.559459 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbDAABh1o"]
[Mon Jul 20 06:31:18.569294 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbEQABhww"]
[Mon Jul 20 06:31:18.596906 2026] [security2:error] [pid 935758:tid 935953] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbGAAAAUk"]
[Mon Jul 20 06:31:18.627184 2026] [security2:error] [pid 935758:tid 936008] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbHQAAAYA"]
[Mon Jul 20 06:31:18.679711 2026] [security2:error] [pid 935758:tid 935779] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/actuator/mappings"] [unique_id "al4VFrcDxY_mIul-JSGbLwABhxI"]
[Mon Jul 20 06:31:18.699648 2026] [security2:error] [pid 935758:tid 935800] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/phpinfo.php"] [unique_id "al4VFrcDxY_mIul-JSGbNQABhyc"]
[Mon Jul 20 06:31:18.718475 2026] [security2:error] [pid 935758:tid 935933] [client 57.141.18.30:46046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VELcDxY_mIul-JSGX7gABNSw"]
[Mon Jul 20 06:31:18.745621 2026] [security2:error] [pid 935758:tid 935771] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/test.php"] [unique_id "al4VFrcDxY_mIul-JSGbPQABhwo"]
[Mon Jul 20 06:31:18.745827 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/test.php"] [unique_id "al4VFrcDxY_mIul-JSGbPQABhwo"]
[Mon Jul 20 06:31:18.745985 2026] [security2:error] [pid 935758:tid 935858] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/pi.php"] [unique_id "al4VFrcDxY_mIul-JSGbPgABh2E"]
[Mon Jul 20 06:31:18.746069 2026] [security2:error] [pid 935758:tid 935841] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/info.php"] [unique_id "al4VFrcDxY_mIul-JSGbPwABh1A"]
[Mon Jul 20 06:31:18.771701 2026] [security2:error] [pid 935758:tid 935981] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbNwAAAWU"]
[Mon Jul 20 06:31:18.772206 2026] [security2:error] [pid 935758:tid 935905] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbMwAAARk"]
[Mon Jul 20 06:31:18.775301 2026] [security2:error] [pid 935758:tid 935943] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbOQAAAT8"]
[Mon Jul 20 06:31:18.777792 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbRQAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.777895 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbRQAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.780387 2026] [security2:error] [pid 935758:tid 935793] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/i.php"] [unique_id "al4VFrcDxY_mIul-JSGbRwABhyA"]
[Mon Jul 20 06:31:18.814427 2026] [security2:error] [pid 935758:tid 935976] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbQAAAAWA"]
[Mon Jul 20 06:31:18.840511 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbVwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.840610 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbVwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.877888 2026] [security2:error] [pid 935758:tid 935876] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/app_dev.php"] [unique_id "al4VFrcDxY_mIul-JSGbXQABh3M"]
[Mon Jul 20 06:31:18.897584 2026] [security2:error] [pid 935758:tid 935787] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/app_dev.php/_profiler"] [unique_id "al4VFrcDxY_mIul-JSGbYQABhxo"]
[Mon Jul 20 06:31:18.958854 2026] [security2:error] [pid 935758:tid 935768] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/_ignition/health-check"] [unique_id "al4VFrcDxY_mIul-JSGbdwABhwc"]
[Mon Jul 20 06:31:18.959069 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/_ignition/health-check"] [unique_id "al4VFrcDxY_mIul-JSGbdwABhwc"]
[Mon Jul 20 06:31:19.010355 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkQAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.010442 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkQAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.020714 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:64889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkgAAAU8"]
[Mon Jul 20 06:31:19.020841 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:64889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkgAAAU8"]
[Mon Jul 20 06:31:19.029171 2026] [access_compat:error] [pid 935758:tid 935860] [remote 34.129.173.120:52974] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Mon Jul 20 06:31:19.029641 2026] [security2:error] [pid 935758:tid 935886] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/server-info"] [unique_id "al4VF7cDxY_mIul-JSGbkwABh30"]
[Mon Jul 20 06:31:19.135811 2026] [security2:error] [pid 935758:tid 935942] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbVgAAAT4"]
[Mon Jul 20 06:31:19.169007 2026] [security2:error] [pid 935758:tid 936008] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbXgAAAYA"]
[Mon Jul 20 06:31:19.189866 2026] [security2:error] [pid 935758:tid 936011] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbfAAAAYM"]
[Mon Jul 20 06:31:19.197215 2026] [security2:error] [pid 935758:tid 935983] [client 34.73.38.214:64012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VF7cDxY_mIul-JSGbtwAAAWc"]
[Mon Jul 20 06:31:19.199849 2026] [security2:error] [pid 935758:tid 935950] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbrgAAAUY"]
[Mon Jul 20 06:31:19.201331 2026] [security2:error] [pid 935758:tid 935897] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbggAAARE"]
[Mon Jul 20 06:31:19.204199 2026] [security2:error] [pid 935758:tid 935920] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbgAAAASg"]
[Mon Jul 20 06:31:19.204309 2026] [security2:error] [pid 935758:tid 935944] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbfwAAAUA"]
[Mon Jul 20 06:31:19.205899 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbqAABhzs"]
[Mon Jul 20 06:31:19.206680 2026] [security2:error] [pid 935758:tid 935931] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbgQAAATM"]
[Mon Jul 20 06:31:19.251715 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbugAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.251832 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbugAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.252790 2026] [security2:error] [pid 935758:tid 935901] [client 77.110.127.138:64891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbuwAAARU"]
[Mon Jul 20 06:31:19.252896 2026] [security2:error] [pid 935758:tid 935901] [client 77.110.127.138:64891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbuwAAARU"]
[Mon Jul 20 06:31:19.286501 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbtgABh1Q"]
[Mon Jul 20 06:31:19.287247 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbuAABh0M"]
[Mon Jul 20 06:31:19.334629 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbvgABh3s"]
[Mon Jul 20 06:31:19.407293 2026] [security2:error] [pid 935758:tid 935964] [client 14.225.17.146:62902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbvQAAAVQ"], referer: http://alaraycreative.com/old
[Mon Jul 20 06:31:19.442512 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbygABcEw"]
[Mon Jul 20 06:31:19.448693 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbyQABcAs"]
[Mon Jul 20 06:31:19.459717 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb1wAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.459901 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb1wAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.465306 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbzgABcDk"]
[Mon Jul 20 06:31:19.568966 2026] [security2:error] [pid 935758:tid 935911] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb3gABHw4"]
[Mon Jul 20 06:31:19.591211 2026] [security2:error] [pid 935758:tid 935911] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb2gABH1o"]
[Mon Jul 20 06:31:19.595152 2026] [security2:error] [pid 935758:tid 935911] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb3wABHww"]
[Mon Jul 20 06:31:19.626435 2026] [security2:error] [pid 935758:tid 935985] [client 77.110.127.138:64893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb7QAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.626591 2026] [security2:error] [pid 935758:tid 935985] [client 77.110.127.138:64893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb7QAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.693520 2026] [security2:error] [pid 935758:tid 935849] [remote 194.164.192.228:43700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VF7cDxY_mIul-JSGb9QABg1g"]
[Mon Jul 20 06:31:19.711735 2026] [security2:error] [pid 935758:tid 936006] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb8AABfhI"]
[Mon Jul 20 06:31:19.728425 2026] [security2:error] [pid 935758:tid 936006] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb8wABfmo"]
[Mon Jul 20 06:31:19.730433 2026] [security2:error] [pid 935758:tid 936006] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb7wABflE"]
[Mon Jul 20 06:31:19.788866 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcAAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.788998 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcAAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.809727 2026] [security2:error] [pid 935758:tid 935923] [client 77.110.127.138:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcBgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.809867 2026] [security2:error] [pid 935758:tid 935923] [client 77.110.127.138:64896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcBgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.901039 2026] [http2:info] [pid 940476:tid 940476] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:31:19.902359 2026] [security2:error] [pid 935758:tid 935887] [remote 194.164.192.228:43700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VF7cDxY_mIul-JSGcDAABeH4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:19.937011 2026] [security2:error] [pid 935758:tid 935999] [client 197.186.66.42:57169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VF7cDxY_mIul-JSGcEwAAAXc"]
[Mon Jul 20 06:31:19.950210 2026] [security2:error] [pid 935758:tid 935999] [client 197.186.66.42:57169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VF7cDxY_mIul-JSGcEwAAAXc"]
[Mon Jul 20 06:31:20.072216 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGLcDxY_mIul-JSGcHQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.072351 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGLcDxY_mIul-JSGcHQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.126513 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb_QABF2E"]
[Mon Jul 20 06:31:20.141850 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGcAQABF0k"]
[Mon Jul 20 06:31:20.147831 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGcAgABF2g"]
[Mon Jul 20 06:31:20.153273 2026] [fcgid:warn] [pid 935758:tid 935940] (70014)End of file found: [client 66.132.172.223:34248] mod_fcgid: can't get data from http client
[Mon Jul 20 06:31:20.155520 2026] [security2:error] [pid 935758:tid 935919] [client 57.141.18.89:35622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VErcDxY_mIul-JSGYRAABJy8"]
[Mon Jul 20 06:31:20.202489 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGcFwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.361373 2026] [security2:error] [pid 935758:tid 935909] [client 157.52.92.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amazonservices.xp-design.co"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbcQAAAR0"]
[Mon Jul 20 06:31:20.361858 2026] [security2:error] [pid 935758:tid 935913] [client 157.52.92.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amazonservices.xp-design.co"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbXAAAASE"]
[Mon Jul 20 06:31:20.473350 2026] [security2:error] [pid 940476:tid 940631] [client 114.119.155.81:31733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hilltopnurseryinc.com"] [uri "/robots.txt"] [unique_id "al4VGBjVYcQxwGpYwZmZ3gAAABk"], referer: https://hilltopnurseryinc.com/robots.txt
[Mon Jul 20 06:31:20.495258 2026] [security2:error] [pid 935758:tid 936002] [client 57.141.18.52:56834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VErcDxY_mIul-JSGYXwABemI"]
[Mon Jul 20 06:31:20.731737 2026] [security2:error] [pid 940476:tid 940679] [client 34.73.38.214:64845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VGBjVYcQxwGpYwZmZ8wAAAEk"]
[Mon Jul 20 06:31:20.790227 2026] [security2:error] [pid 935758:tid 936015] [client 52.187.75.220:19457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4VGLcDxY_mIul-JSGcUQAAAYc"]
[Mon Jul 20 06:31:20.825720 2026] [security2:error] [pid 935758:tid 935974] [client 14.225.17.146:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb0gAAAV4"], referer: http://dereckcastellon.com/old
[Mon Jul 20 06:31:20.967019 2026] [security2:error] [pid 940476:tid 940677] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGBjVYcQxwGpYwZmZ8QAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.979636 2026] [security2:error] [pid 935758:tid 935952] [client 14.225.17.146:62952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb4gAAAUg"], referer: http://sarahsnyder.net/old
[Mon Jul 20 06:31:20.990233 2026] [security2:error] [pid 935758:tid 935913] [client 52.187.75.220:19457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4VGLcDxY_mIul-JSGcXwAAASE"]
[Mon Jul 20 06:31:20.997250 2026] [security2:error] [pid 935758:tid 935904] [client 57.141.18.38:36480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYnAABGBA"]
[Mon Jul 20 06:31:21.003772 2026] [security2:error] [pid 935758:tid 935914] [client 34.73.38.214:50118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VGbcDxY_mIul-JSGcYQAAASI"]
[Mon Jul 20 06:31:21.167337 2026] [security2:error] [pid 940476:tid 940660] [client 171.61.165.146:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VGRjVYcQxwGpYwZmaBgAAADY"]
[Mon Jul 20 06:31:21.168391 2026] [security2:error] [pid 940476:tid 940660] [client 171.61.165.146:16214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VGRjVYcQxwGpYwZmaBgAAADY"]
[Mon Jul 20 06:31:21.188964 2026] [security2:error] [pid 940476:tid 940712] [client 50.116.65.227:12742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VGRjVYcQxwGpYwZmaCAAAAGo"]
[Mon Jul 20 06:31:21.203200 2026] [security2:error] [pid 940476:tid 940715] [client 50.116.65.227:12752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VGRjVYcQxwGpYwZmaCQAAAG0"]
[Mon Jul 20 06:31:21.206304 2026] [security2:error] [pid 935758:tid 935906] [client 14.225.17.146:62200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb-wAAARo"], referer: http://phillipbloch.com/old
[Mon Jul 20 06:31:21.240954 2026] [security2:error] [pid 935758:tid 935957] [client 104.234.53.50:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VGbcDxY_mIul-JSGccAAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:21.267106 2026] [security2:error] [pid 940476:tid 940686] [client 14.225.17.146:49663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4VGRjVYcQxwGpYwZmZ_wAAAFA"], referer: http://adirondackengineering.com/old
[Mon Jul 20 06:31:21.467014 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGRjVYcQxwGpYwZmaDgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:21.821626 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGbcDxY_mIul-JSGcjQAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:21.937187 2026] [security2:error] [pid 940476:tid 940629] [client 14.225.17.146:62811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4VGRjVYcQxwGpYwZmaHgAAABc"], referer: https://sarahsnyder.net/old
[Mon Jul 20 06:31:21.968933 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGbcDxY_mIul-JSGcnQAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:22.080942 2026] [security2:error] [pid 935758:tid 935932] [client 104.234.53.73:44683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VGrcDxY_mIul-JSGcsAAAATQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:22.154165 2026] [security2:error] [pid 935758:tid 935913] [client 223.185.13.213:13020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VGrcDxY_mIul-JSGcswAAASE"]
[Mon Jul 20 06:31:22.154343 2026] [security2:error] [pid 935758:tid 935913] [client 223.185.13.213:13020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VGrcDxY_mIul-JSGcswAAASE"]
[Mon Jul 20 06:31:22.181094 2026] [proxy:error] [pid 935758:tid 935958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:22.181169 2026] [proxy_http:error] [pid 935758:tid 935958] [client 165.154.182.53:37834] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:22.181798 2026] [proxy:error] [pid 935758:tid 935958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:22.181862 2026] [proxy_http:error] [pid 935758:tid 935958] [client 165.154.182.53:37834] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:22.194348 2026] [security2:error] [pid 935758:tid 935907] [client 57.141.18.46:63580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZUAABGwE"]
[Mon Jul 20 06:31:22.397857 2026] [security2:error] [pid 935758:tid 935936] [client 34.73.38.214:65134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VGrcDxY_mIul-JSGcxQAAATg"]
[Mon Jul 20 06:31:22.425930 2026] [security2:error] [pid 940476:tid 940667] [client 114.119.143.104:55713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.itdynamix.com"] [uri "/why-is-customer-relationship-management-so-important"] [unique_id "al4VGhjVYcQxwGpYwZmaMwAAAD0"], referer: https://www.itdynamix.com/why-is-customer-relationship-management-so-important
[Mon Jul 20 06:31:22.434738 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGrcDxY_mIul-JSGcvAAAASo"]
[Mon Jul 20 06:31:22.604657 2026] [security2:error] [pid 935758:tid 935984] [client 57.141.18.123:28974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZqwABaA0"]
[Mon Jul 20 06:31:22.836405 2026] [security2:error] [pid 940476:tid 940712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGhjVYcQxwGpYwZmaPAAAAGo"]
[Mon Jul 20 06:31:22.899944 2026] [security2:error] [pid 940476:tid 940683] [client 112.208.70.94:42768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VGhjVYcQxwGpYwZmaQwAAAE0"]
[Mon Jul 20 06:31:22.900091 2026] [security2:error] [pid 940476:tid 940683] [client 112.208.70.94:42768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VGhjVYcQxwGpYwZmaQwAAAE0"]
[Mon Jul 20 06:31:22.933773 2026] [security2:error] [pid 935758:tid 935858] [remote 91.142.222.105:60826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4VGrcDxY_mIul-JSGc4wABaWE"]
[Mon Jul 20 06:31:22.941109 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGhjVYcQxwGpYwZmaRAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:22.941210 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:64927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGhjVYcQxwGpYwZmaRAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.253972 2026] [security2:error] [pid 940476:tid 940609] [client 45.3.42.229:65169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VGxjVYcQxwGpYwZmaVgAAAAM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:23.303461 2026] [security2:error] [pid 935758:tid 935794] [remote 91.142.222.105:60826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4VG7cDxY_mIul-JSGc-wABLSE"], referer: https://omrobuildingcenter.com/wp-login.php
[Mon Jul 20 06:31:23.309250 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.61:42782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaSwABEhg"]
[Mon Jul 20 06:31:23.442150 2026] [security2:error] [pid 940476:tid 940642] [client 34.73.38.214:63189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VGxjVYcQxwGpYwZmaXQAAACQ"]
[Mon Jul 20 06:31:23.468683 2026] [security2:error] [pid 935758:tid 935915] [client 57.141.18.106:20100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGadQABIyM"]
[Mon Jul 20 06:31:23.541352 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VG7cDxY_mIul-JSGc_AAAARA"], referer: 1'"3000
[Mon Jul 20 06:31:23.648032 2026] [security2:error] [pid 940476:tid 940666] [client 14.225.17.146:49523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VGhjVYcQxwGpYwZmaMAAAADw"], referer: http://effingweirdmuseums.com/old
[Mon Jul 20 06:31:23.691123 2026] [security2:error] [pid 940476:tid 940661] [client 34.74.185.202:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VGxjVYcQxwGpYwZmaZgAAADc"]
[Mon Jul 20 06:31:23.735771 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VG7cDxY_mIul-JSGdGAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.735917 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VG7cDxY_mIul-JSGdGAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.747297 2026] [security2:error] [pid 940476:tid 940688] [client 165.154.182.53:38064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/favicon.ico"] [unique_id "al4VGxjVYcQxwGpYwZmaaAAAAFI"]
[Mon Jul 20 06:31:23.823341 2026] [security2:error] [pid 935758:tid 935874] [remote 152.228.213.32:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4VG7cDxY_mIul-JSGdHgABVnE"]
[Mon Jul 20 06:31:23.842350 2026] [security2:error] [pid 940476:tid 940677] [client 165.154.182.53:38068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/sitemap.xml"] [unique_id "al4VGxjVYcQxwGpYwZmaawAAAEc"]
[Mon Jul 20 06:31:23.842350 2026] [security2:error] [pid 935758:tid 935998] [client 165.154.182.53:38070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/robots.txt"] [unique_id "al4VG7cDxY_mIul-JSGdIQAAAXY"]
[Mon Jul 20 06:31:23.851204 2026] [security2:error] [pid 935758:tid 935972] [client 104.207.52.225:20583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VG7cDxY_mIul-JSGdHwAAAVw"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:23.893164 2026] [security2:error] [pid 940476:tid 940669] [client 77.110.127.138:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGxjVYcQxwGpYwZmacAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.893282 2026] [security2:error] [pid 940476:tid 940669] [client 77.110.127.138:64940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGxjVYcQxwGpYwZmacAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.967720 2026] [security2:error] [pid 940476:tid 940507] [remote 47.86.33.52:25874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VGxjVYcQxwGpYwZmacQAAFh4"]
[Mon Jul 20 06:31:24.039983 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGxjVYcQxwGpYwZmaaQAAADs"], referer: 1'"3000
[Mon Jul 20 06:31:24.162695 2026] [security2:error] [pid 940476:tid 940710] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaeQAAAGg"]
[Mon Jul 20 06:31:24.179237 2026] [security2:error] [pid 940476:tid 940729] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmahQAAAHs"]
[Mon Jul 20 06:31:24.181122 2026] [security2:error] [pid 940476:tid 940720] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaggAAAHI"]
[Mon Jul 20 06:31:24.183122 2026] [security2:error] [pid 940476:tid 940683] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmagwAAAE0"]
[Mon Jul 20 06:31:24.184920 2026] [security2:error] [pid 935758:tid 935980] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHLcDxY_mIul-JSGdNwAAAWQ"]
[Mon Jul 20 06:31:24.194219 2026] [security2:error] [pid 935758:tid 935943] [client 34.73.38.214:55867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VHLcDxY_mIul-JSGdPAAAAT8"]
[Mon Jul 20 06:31:24.200072 2026] [security2:error] [pid 940476:tid 940730] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmahgAAAHw"]
[Mon Jul 20 06:31:24.207415 2026] [security2:error] [pid 935758:tid 935824] [remote 152.228.213.32:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdPQABGj8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:31:24.387346 2026] [security2:error] [pid 935758:tid 935997] [client 57.141.18.65:57438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbGQABdSI"]
[Mon Jul 20 06:31:24.443370 2026] [security2:error] [pid 935758:tid 935840] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdRwABO08"], referer: https://tadlarsen.com/login
[Mon Jul 20 06:31:24.465586 2026] [security2:error] [pid 935758:tid 935915] [client 104.207.62.94:48223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdSwAAASM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:24.506139 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.23:59312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbJgABiAM"]
[Mon Jul 20 06:31:24.580803 2026] [security2:error] [pid 940476:tid 940610] [client 14.225.17.146:59648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmajgAAAAQ"], referer: https://effingweirdmuseums.com/old
[Mon Jul 20 06:31:24.622993 2026] [security2:error] [pid 940476:tid 940620] [client 34.74.185.202:57827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VHBjVYcQxwGpYwZmalAAAAA4"]
[Mon Jul 20 06:31:24.746331 2026] [security2:error] [pid 940476:tid 940652] [client 104.234.53.73:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VHBjVYcQxwGpYwZmanQAAAC4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:24.865122 2026] [security2:error] [pid 935758:tid 935828] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdZQABC0M"], referer: https://tadlarsen.com/wp-admin/
[Mon Jul 20 06:31:24.865874 2026] [security2:error] [pid 935758:tid 935884] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdZgABC3s"], referer: https://tadlarsen.com/wp-admin/
[Mon Jul 20 06:31:24.897811 2026] [security2:error] [pid 935758:tid 935989] [client 57.141.18.24:25774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbrQABbXQ"]
[Mon Jul 20 06:31:24.922272 2026] [security2:error] [pid 935758:tid 935898] [client 34.73.38.214:56089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VHLcDxY_mIul-JSGdbQAAARI"]
[Mon Jul 20 06:31:25.079613 2026] [security2:error] [pid 935758:tid 935976] [client 171.60.139.123:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdewAAAWA"]
[Mon Jul 20 06:31:25.079704 2026] [security2:error] [pid 935758:tid 935976] [client 171.60.139.123:56668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdewAAAWA"]
[Mon Jul 20 06:31:25.087721 2026] [security2:error] [pid 935758:tid 936008] [client 65.111.20.90:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VHbcDxY_mIul-JSGdegAAAYA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:25.207247 2026] [security2:error] [pid 935758:tid 935990] [client 34.74.185.202:63333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VHbcDxY_mIul-JSGdhQAAAW4"]
[Mon Jul 20 06:31:25.217395 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VHRjVYcQxwGpYwZmaqgAAAFo"]
[Mon Jul 20 06:31:25.217842 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:63362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VHRjVYcQxwGpYwZmaqgAAAFo"]
[Mon Jul 20 06:31:25.436447 2026] [security2:error] [pid 940476:tid 940712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VHRjVYcQxwGpYwZmarAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:25.691458 2026] [security2:error] [pid 935758:tid 935938] [client 45.116.69.230:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdnQAAATo"]
[Mon Jul 20 06:31:25.691620 2026] [security2:error] [pid 935758:tid 935938] [client 45.116.69.230:65525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdnQAAATo"]
[Mon Jul 20 06:31:25.772490 2026] [security2:error] [pid 940476:tid 940630] [client 34.73.38.214:57245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VHRjVYcQxwGpYwZmawgAAABg"]
[Mon Jul 20 06:31:25.903227 2026] [security2:error] [pid 940476:tid 940657] [client 34.74.185.202:59392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VHRjVYcQxwGpYwZmaxwAAADM"]
[Mon Jul 20 06:31:26.134028 2026] [security2:error] [pid 940476:tid 940695] [client 39.48.81.23:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VHhjVYcQxwGpYwZma1wAAAFk"]
[Mon Jul 20 06:31:26.134207 2026] [security2:error] [pid 940476:tid 940695] [client 39.48.81.23:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VHhjVYcQxwGpYwZma1wAAAFk"]
[Mon Jul 20 06:31:26.514628 2026] [security2:error] [pid 940476:tid 940706] [client 34.73.38.214:63747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VHhjVYcQxwGpYwZma5wAAAGQ"]
[Mon Jul 20 06:31:26.528410 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma6AAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.528503 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:64952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma6AAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.529437 2026] [security2:error] [pid 940476:tid 940535] [remote 162.19.86.63:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4VHhjVYcQxwGpYwZma6QAAZjo"]
[Mon Jul 20 06:31:26.579076 2026] [security2:error] [pid 940476:tid 940718] [client 34.74.185.202:50602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VHhjVYcQxwGpYwZma7AAAAHA"]
[Mon Jul 20 06:31:26.581682 2026] [security2:error] [pid 940476:tid 940616] [client 104.234.53.55:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VHhjVYcQxwGpYwZma7QAAAAo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:26.642719 2026] [security2:error] [pid 940476:tid 940717] [client 66.249.70.4:57839] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.gitec.org"] [uri "/robots.txt"] [unique_id "al4VHhjVYcQxwGpYwZma9AAAAG8"]
[Mon Jul 20 06:31:26.714787 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma-QAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.714884 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:64954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma-QAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.752827 2026] [security2:error] [pid 940476:tid 940541] [remote 162.19.86.63:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4VHhjVYcQxwGpYwZma-wAAXUA"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:31:26.887158 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:64955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZmbAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.887276 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:64955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZmbAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.948146 2026] [security2:error] [pid 935758:tid 935944] [client 14.225.17.146:59506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4VHLcDxY_mIul-JSGdcQAAAUA"], referer: http://webgardensbypaula.com/old
[Mon Jul 20 06:31:27.048562 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbDAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.048710 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbDAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.214622 2026] [security2:error] [pid 940476:tid 940608] [client 34.74.185.202:63017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VHxjVYcQxwGpYwZmbFgAAAAI"]
[Mon Jul 20 06:31:27.269377 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbGgAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.269489 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:64958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbGgAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.315011 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VH7cDxY_mIul-JSGdwgAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.315147 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VH7cDxY_mIul-JSGdwgAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.473117 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbIQAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.473205 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:64961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbIQAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.502009 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.39:62343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VGbcDxY_mIul-JSGcjwABYxE"]
[Mon Jul 20 06:31:27.551723 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbJwAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.551854 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:64962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbJwAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.565854 2026] [security2:error] [pid 935758:tid 935923] [client 34.73.38.214:60956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VH7cDxY_mIul-JSGdxwAAASs"]
[Mon Jul 20 06:31:27.758707 2026] [security2:error] [pid 940476:tid 940687] [client 78.188.32.111:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.32.188.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bandsir.com"] [uri "/xmlrpc.php"] [unique_id "al4VHxjVYcQxwGpYwZmbLAAAAFE"]
[Mon Jul 20 06:31:27.758861 2026] [security2:error] [pid 940476:tid 940687] [client 78.188.32.111:60312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bandsir.com"] [uri "/xmlrpc.php"] [unique_id "al4VHxjVYcQxwGpYwZmbLAAAAFE"]
[Mon Jul 20 06:31:27.894056 2026] [security2:error] [pid 940476:tid 940649] [client 77.110.127.138:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbMAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.894174 2026] [security2:error] [pid 940476:tid 940649] [client 77.110.127.138:64964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbMAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:28.413198 2026] [security2:error] [pid 940476:tid 940618] [client 34.73.38.214:50828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VIBjVYcQxwGpYwZmbSAAAAAw"]
[Mon Jul 20 06:31:28.489565 2026] [security2:error] [pid 940476:tid 940678] [client 104.234.53.93:28241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VIBjVYcQxwGpYwZmbSwAAAEg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:28.737305 2026] [security2:error] [pid 940476:tid 940717] [client 34.74.185.202:65123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VIBjVYcQxwGpYwZmbYgAAAG8"]
[Mon Jul 20 06:31:28.797905 2026] [security2:error] [pid 935758:tid 936011] [client 103.125.179.95:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VILcDxY_mIul-JSGd8QAAAYM"]
[Mon Jul 20 06:31:28.798054 2026] [security2:error] [pid 935758:tid 936011] [client 103.125.179.95:64765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VILcDxY_mIul-JSGd8QAAAYM"]
[Mon Jul 20 06:31:28.867914 2026] [security2:error] [pid 940476:tid 940705] [client 57.141.18.23:58248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VGhjVYcQxwGpYwZmaQAAAYxc"]
[Mon Jul 20 06:31:28.946627 2026] [security2:error] [pid 940476:tid 940580] [remote 47.86.33.52:25874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VIBjVYcQxwGpYwZmbbAAAXmc"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:31:29.022343 2026] [security2:error] [pid 940476:tid 940716] [client 14.225.17.146:58627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4VIBjVYcQxwGpYwZmbagAAAG4"], referer: http://dnsplumbing.com/old
[Mon Jul 20 06:31:29.251729 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VIRjVYcQxwGpYwZmbcgAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:29.589797 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:62727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4VIbcDxY_mIul-JSGd9wAAAWo"], referer: http://partnerselectricalllc.com/old
[Mon Jul 20 06:31:30.474337 2026] [security2:error] [pid 940476:tid 940704] [client 57.141.18.113:64016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaiQAAYiM"]
[Mon Jul 20 06:31:30.493173 2026] [security2:error] [pid 935758:tid 935964] [client 34.74.185.202:57403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VIrcDxY_mIul-JSGeGwAAAVQ"]
[Mon Jul 20 06:31:30.571246 2026] [security2:error] [pid 940476:tid 940609] [client 57.141.18.100:59772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaiwAAAyU"]
[Mon Jul 20 06:31:30.651418 2026] [security2:error] [pid 935758:tid 935924] [client 63.177.52.239:54086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VIrcDxY_mIul-JSGeHQAAASw"]
[Mon Jul 20 06:31:30.651551 2026] [security2:error] [pid 935758:tid 935924] [client 63.177.52.239:54086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VIrcDxY_mIul-JSGeHQAAASw"]
[Mon Jul 20 06:31:30.886487 2026] [security2:error] [pid 935758:tid 936010] [client 104.234.53.70:61167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VIrcDxY_mIul-JSGeJQAAAYI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:30.933487 2026] [security2:error] [pid 940476:tid 940698] [client 197.186.66.42:57671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VIhjVYcQxwGpYwZmbwwAAAFw"]
[Mon Jul 20 06:31:30.949544 2026] [security2:error] [pid 940476:tid 940698] [client 197.186.66.42:57671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VIhjVYcQxwGpYwZmbwwAAAFw"]
[Mon Jul 20 06:31:30.983316 2026] [security2:error] [pid 940476:tid 940493] [remote 100.42.189.89:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4VIhjVYcQxwGpYwZmbxgAAexA"]
[Mon Jul 20 06:31:30.994138 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIrcDxY_mIul-JSGeLQAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:30.994232 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIrcDxY_mIul-JSGeLQAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.151975 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:64982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIxjVYcQxwGpYwZmb1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.152082 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:64982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIxjVYcQxwGpYwZmb1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.266955 2026] [security2:error] [pid 940476:tid 940628] [client 50.116.65.227:54866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VIxjVYcQxwGpYwZmb2wAAABY"]
[Mon Jul 20 06:31:31.279008 2026] [security2:error] [pid 935758:tid 935907] [client 50.116.65.227:54872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VI7cDxY_mIul-JSGePgAAARs"]
[Mon Jul 20 06:31:31.421076 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VI7cDxY_mIul-JSGePwAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.421172 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VI7cDxY_mIul-JSGePwAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.706144 2026] [security2:error] [pid 940476:tid 940645] [client 34.74.185.202:58281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VIxjVYcQxwGpYwZmb8AAAACc"]
[Mon Jul 20 06:31:31.717900 2026] [security2:error] [pid 940476:tid 940508] [remote 100.42.189.89:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4VIxjVYcQxwGpYwZmb8QAAdR8"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:31:31.817141 2026] [security2:error] [pid 935758:tid 935894] [client 50.116.65.227:54898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VI7cDxY_mIul-JSGeSQAAAQ4"]
[Mon Jul 20 06:31:31.833647 2026] [security2:error] [pid 935758:tid 935885] [remote 173.249.4.11:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4VI7cDxY_mIul-JSGeUwABPXw"]
[Mon Jul 20 06:31:32.021381 2026] [security2:error] [pid 935758:tid 936006] [client 50.116.65.227:54912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VI7cDxY_mIul-JSGeVAAAAX4"]
[Mon Jul 20 06:31:32.145544 2026] [security2:error] [pid 940476:tid 940524] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4VJBjVYcQxwGpYwZmcCwAAey8"]
[Mon Jul 20 06:31:32.145871 2026] [security2:error] [pid 940476:tid 940729] [client 47.86.33.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4VJBjVYcQxwGpYwZmcCwAAey8"]
[Mon Jul 20 06:31:32.272716 2026] [security2:error] [pid 935758:tid 936008] [client 171.61.165.146:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VJLcDxY_mIul-JSGeYwAAAYA"]
[Mon Jul 20 06:31:32.272835 2026] [security2:error] [pid 935758:tid 936008] [client 171.61.165.146:7872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VJLcDxY_mIul-JSGeYwAAAYA"]
[Mon Jul 20 06:31:32.395222 2026] [security2:error] [pid 940476:tid 940681] [client 98.159.234.160:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VJBjVYcQxwGpYwZmcHAAAAEs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:32.415334 2026] [security2:error] [pid 940476:tid 940697] [client 57.141.18.4:33228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VHhjVYcQxwGpYwZma1AAAWzI"]
[Mon Jul 20 06:31:32.679301 2026] [security2:error] [pid 935758:tid 935918] [client 5.189.184.113:50732] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel-box5020.bluehost.com"] [uri "/"] [unique_id "al4VJLcDxY_mIul-JSGeagAAASY"]
[Mon Jul 20 06:31:32.694127 2026] [security2:error] [pid 940476:tid 940640] [client 158.173.89.95:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VJBjVYcQxwGpYwZmcMwAAACI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:32.718059 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJBjVYcQxwGpYwZmcJAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:32.778501 2026] [security2:error] [pid 935758:tid 935955] [client 34.74.185.202:59483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VJLcDxY_mIul-JSGecAAAAUs"]
[Mon Jul 20 06:31:33.228568 2026] [security2:error] [pid 940476:tid 940649] [client 50.116.65.227:45470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4VJRjVYcQxwGpYwZmcQwAAACs"]
[Mon Jul 20 06:31:33.351327 2026] [security2:error] [pid 935758:tid 935923] [client 223.185.13.213:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VJbcDxY_mIul-JSGeiAAAASs"]
[Mon Jul 20 06:31:33.352950 2026] [security2:error] [pid 935758:tid 935923] [client 223.185.13.213:3031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VJbcDxY_mIul-JSGeiAAAASs"]
[Mon Jul 20 06:31:33.776927 2026] [security2:error] [pid 935758:tid 935899] [client 34.74.185.202:63263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VJbcDxY_mIul-JSGengAAARM"]
[Mon Jul 20 06:31:33.808328 2026] [security2:error] [pid 935758:tid 935969] [client 57.141.18.53:28216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VH7cDxY_mIul-JSGdzAABWUk"]
[Mon Jul 20 06:31:34.414633 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:65001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJhjVYcQxwGpYwZmcdwAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.441873 2026] [security2:error] [pid 940476:tid 940617] [client 34.74.185.202:65128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VJhjVYcQxwGpYwZmcgAAAAAs"]
[Mon Jul 20 06:31:34.456926 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:65003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmcggAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.457010 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:65003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmcggAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.615352 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmciAAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.616943 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:65004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmciAAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.767952 2026] [security2:error] [pid 940476:tid 940639] [client 77.110.127.138:65006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmckAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.768056 2026] [security2:error] [pid 940476:tid 940639] [client 77.110.127.138:65006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmckAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.969797 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:65005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJhjVYcQxwGpYwZmcjwAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:35.085606 2026] [core:error] [pid 940476:tid 940670] [client 198.235.24.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:35.085632 2026] [core:error] [pid 940476:tid 940670] [client 198.235.24.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:35.151848 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJhjVYcQxwGpYwZmcmwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:35.400635 2026] [security2:error] [pid 940476:tid 940642] [client 77.110.127.138:65012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJxjVYcQxwGpYwZmcswAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:35.563508 2026] [security2:error] [pid 935758:tid 935779] [remote 162.19.86.63:38461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VJ7cDxY_mIul-JSGexQABKxI"]
[Mon Jul 20 06:31:35.563659 2026] [security2:error] [pid 935758:tid 935923] [client 162.19.86.63:38461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VJ7cDxY_mIul-JSGexQABKxI"]
[Mon Jul 20 06:31:35.654924 2026] [security2:error] [pid 940476:tid 940733] [client 74.208.214.194:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VJxjVYcQxwGpYwZmczQAAAH8"]
[Mon Jul 20 06:31:35.718684 2026] [security2:error] [pid 940476:tid 940616] [client 171.60.139.123:57194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VJxjVYcQxwGpYwZmc0AAAAAo"]
[Mon Jul 20 06:31:35.718843 2026] [security2:error] [pid 940476:tid 940616] [client 171.60.139.123:57194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VJxjVYcQxwGpYwZmc0AAAAAo"]
[Mon Jul 20 06:31:35.720905 2026] [security2:error] [pid 935758:tid 935944] [client 82.135.202.97:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.202.135.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/forecast/covers.php"] [unique_id "al4VJ7cDxY_mIul-JSGe0AAAAUA"]
[Mon Jul 20 06:31:35.761235 2026] [security2:error] [pid 940476:tid 940654] [client 57.141.18.68:57488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VIRjVYcQxwGpYwZmbdQAAMGs"]
[Mon Jul 20 06:31:35.958796 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:65017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJ7cDxY_mIul-JSGezQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.016084 2026] [security2:error] [pid 940476:tid 940697] [client 103.141.108.143:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc2QAAAFs"]
[Mon Jul 20 06:31:36.016188 2026] [security2:error] [pid 940476:tid 940697] [client 103.141.108.143:63846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc2QAAAFs"]
[Mon Jul 20 06:31:36.105583 2026] [security2:error] [pid 935758:tid 935948] [client 39.48.81.23:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe2QAAAUQ"]
[Mon Jul 20 06:31:36.105679 2026] [security2:error] [pid 935758:tid 935948] [client 39.48.81.23:63641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe2QAAAUQ"]
[Mon Jul 20 06:31:36.156779 2026] [security2:error] [pid 940476:tid 940597] [remote 20.173.88.122:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VKBjVYcQxwGpYwZmc4QAARng"]
[Mon Jul 20 06:31:36.297296 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKBjVYcQxwGpYwZmc3wAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.404114 2026] [security2:error] [pid 935758:tid 935805] [remote 47.86.33.52:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4VKLcDxY_mIul-JSGe4wABKCw"]
[Mon Jul 20 06:31:36.426420 2026] [security2:error] [pid 935758:tid 935995] [client 45.116.69.230:49692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe5AAAAXM"]
[Mon Jul 20 06:31:36.426566 2026] [security2:error] [pid 935758:tid 935995] [client 45.116.69.230:49692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe5AAAAXM"]
[Mon Jul 20 06:31:36.455635 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:65026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKBjVYcQxwGpYwZmc6gAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.506350 2026] [security2:error] [pid 940476:tid 940604] [remote 20.173.88.122:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VKBjVYcQxwGpYwZmc9QAAdH8"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:36.533762 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:65029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-AAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.533864 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:65029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-AAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.556433 2026] [proxy:error] [pid 935758:tid 935912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.556512 2026] [proxy_http:error] [pid 935758:tid 935912] [client 165.232.42.95:53624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:36.557217 2026] [proxy:error] [pid 935758:tid 935912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.557247 2026] [proxy_http:error] [pid 935758:tid 935912] [client 165.232.42.95:53624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:36.589267 2026] [security2:error] [pid 940476:tid 940648] [client 112.208.70.94:43232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-gAAACo"]
[Mon Jul 20 06:31:36.589436 2026] [security2:error] [pid 940476:tid 940648] [client 112.208.70.94:43232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-gAAACo"]
[Mon Jul 20 06:31:36.723050 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdBQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.723156 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdBQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.773560 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:64990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdCAAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.773679 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:64990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdCAAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.820203 2026] [security2:error] [pid 940476:tid 940677] [client 104.234.53.80:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VKBjVYcQxwGpYwZmdCwAAAEc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:36.835992 2026] [proxy:error] [pid 940476:tid 940658] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.836030 2026] [proxy_http:error] [pid 940476:tid 940658] [client 165.232.42.95:53640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.msandreaadams.net/
[Mon Jul 20 06:31:36.836470 2026] [proxy:error] [pid 940476:tid 940658] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.836491 2026] [proxy_http:error] [pid 940476:tid 940658] [client 165.232.42.95:53640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.msandreaadams.net/
[Mon Jul 20 06:31:36.893165 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:64989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKBjVYcQxwGpYwZmdAgAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:37.078997 2026] [security2:error] [pid 935758:tid 935870] [remote 47.86.33.52:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4VKbcDxY_mIul-JSGe9gABb20"], referer: https://claysharecon.com/wp-login.php
[Mon Jul 20 06:31:37.148633 2026] [proxy:error] [pid 935758:tid 935896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:37.148675 2026] [proxy_http:error] [pid 935758:tid 935896] [client 107.175.132.21:40000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:37.149297 2026] [proxy:error] [pid 935758:tid 935896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:37.149321 2026] [proxy_http:error] [pid 935758:tid 935896] [client 107.175.132.21:40000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:37.171165 2026] [security2:error] [pid 935758:tid 935957] [client 57.141.18.52:63472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VIrcDxY_mIul-JSGeFQABTRs"]
[Mon Jul 20 06:31:37.348539 2026] [security2:error] [pid 940476:tid 940690] [client 77.110.127.138:65040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdGQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:37.434121 2026] [core:error] [pid 940476:tid 940680] [client 165.232.42.95:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:37.434140 2026] [core:error] [pid 940476:tid 940680] [client 165.232.42.95:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:37.468578 2026] [security2:error] [pid 935758:tid 935937] [client 114.119.152.130:64121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bluedoorbar.co.nz"] [uri "/pagine/460428-HIDRKYBFAH.html"] [unique_id "al4VKbcDxY_mIul-JSGfAwAAATk"], referer: http://bluedoorbar.co.nz/pagine/460428-HIDRKYBFAH.html
[Mon Jul 20 06:31:37.616507 2026] [security2:error] [pid 940476:tid 940689] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdLAAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:37.836654 2026] [security2:error] [pid 935758:tid 935871] [remote 81.173.115.7:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4VKbcDxY_mIul-JSGfDQABfm4"]
[Mon Jul 20 06:31:37.891947 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:65047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKbcDxY_mIul-JSGfBwAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.058163 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdPgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.101956 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdRQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.200471 2026] [security2:error] [pid 935758:tid 935785] [remote 81.173.115.7:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4VKrcDxY_mIul-JSGfGgABGxg"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:31:38.246471 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKhjVYcQxwGpYwZmdTwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.246602 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:65056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKhjVYcQxwGpYwZmdTwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.261216 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.84:65128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VI7cDxY_mIul-JSGeQQABEj8"]
[Mon Jul 20 06:31:38.351182 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:65055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKhjVYcQxwGpYwZmdTQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.039391 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKrcDxY_mIul-JSGfMgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.114981 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:65060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKhjVYcQxwGpYwZmdbAAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.314885 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:65065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfOwAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.314986 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:65065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfOwAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.459598 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VK7cDxY_mIul-JSGfOQAAAVI"]
[Mon Jul 20 06:31:39.512144 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:65070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfQgAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.512264 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:65070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfQgAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.567880 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:65066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VK7cDxY_mIul-JSGfPgAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.746290 2026] [security2:error] [pid 940476:tid 940706] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKxjVYcQxwGpYwZmdhwAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.747232 2026] [security2:error] [pid 940476:tid 940720] [client 103.125.179.95:65240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VKxjVYcQxwGpYwZmdjAAAAHI"]
[Mon Jul 20 06:31:39.747368 2026] [security2:error] [pid 940476:tid 940720] [client 103.125.179.95:65240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VKxjVYcQxwGpYwZmdjAAAAHI"]
[Mon Jul 20 06:31:39.779847 2026] [security2:error] [pid 940476:tid 940694] [client 50.116.65.227:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4VKxjVYcQxwGpYwZmdjwAAAFg"]
[Mon Jul 20 06:31:39.791015 2026] [security2:error] [pid 940476:tid 940622] [client 50.116.65.227:21308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4VKxjVYcQxwGpYwZmdkAAAADk"]
[Mon Jul 20 06:31:39.935334 2026] [security2:error] [pid 940476:tid 940698] [client 74.249.245.134:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VKxjVYcQxwGpYwZmdngAAAFw"]
[Mon Jul 20 06:31:39.935451 2026] [security2:error] [pid 940476:tid 940698] [client 74.249.245.134:52774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VKxjVYcQxwGpYwZmdngAAAFw"]
[Mon Jul 20 06:31:40.016599 2026] [security2:error] [pid 940476:tid 940682] [client 77.110.127.138:65073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKxjVYcQxwGpYwZmdkwAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:40.075598 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKxjVYcQxwGpYwZmdmAAAAEM"]
[Mon Jul 20 06:31:40.218855 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLLcDxY_mIul-JSGfTgAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:40.283570 2026] [security2:error] [pid 940476:tid 940703] [client 77.110.127.138:65042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLBjVYcQxwGpYwZmdqgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:40.313140 2026] [security2:error] [pid 940476:tid 940730] [client 57.141.18.18:24174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VJRjVYcQxwGpYwZmcTAAAfEQ"]
[Mon Jul 20 06:31:41.167151 2026] [security2:error] [pid 940476:tid 940632] [client 104.234.53.64:41203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VLRjVYcQxwGpYwZmd2wAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:41.570530 2026] [security2:error] [pid 935758:tid 935947] [client 57.141.18.41:37594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VJrcDxY_mIul-JSGerQABQ0g"]
[Mon Jul 20 06:31:41.732960 2026] [security2:error] [pid 935758:tid 935910] [client 195.2.67.184:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-content/plugins/si-captcha-for-wordpress/captcha/securimage_show.php"] [unique_id "al4VLbcDxY_mIul-JSGfgQAAAR4"], referer: https://suretybonds-california.com/new-wage-liability-for-general-contractors/
[Mon Jul 20 06:31:41.842626 2026] [security2:error] [pid 940476:tid 940671] [client 197.186.66.42:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VLRjVYcQxwGpYwZmeAAAAAEE"]
[Mon Jul 20 06:31:41.854090 2026] [security2:error] [pid 940476:tid 940671] [client 197.186.66.42:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VLRjVYcQxwGpYwZmeAAAAAEE"]
[Mon Jul 20 06:31:41.891263 2026] [security2:error] [pid 935758:tid 935966] [client 104.234.53.82:23557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VLbcDxY_mIul-JSGfhQAAAVY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:42.088804 2026] [security2:error] [pid 940476:tid 940733] [client 74.249.245.134:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4VLhjVYcQxwGpYwZmeCwAAAH8"]
[Mon Jul 20 06:31:42.088900 2026] [security2:error] [pid 940476:tid 940733] [client 74.249.245.134:52770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4VLhjVYcQxwGpYwZmeCwAAAH8"]
[Mon Jul 20 06:31:42.230739 2026] [security2:error] [pid 940476:tid 940624] [client 20.245.75.247:38560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4VLhjVYcQxwGpYwZmeDwAAABI"]
[Mon Jul 20 06:31:42.236344 2026] [security2:error] [pid 940476:tid 940614] [client 77.110.127.138:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeEgAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.236439 2026] [security2:error] [pid 940476:tid 940614] [client 77.110.127.138:65091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeEgAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.250566 2026] [security2:error] [pid 940476:tid 940700] [client 20.245.75.247:38560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4VLhjVYcQxwGpYwZmeFwAAAF4"]
[Mon Jul 20 06:31:42.373316 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:65043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLhjVYcQxwGpYwZmeDQAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.457255 2026] [security2:error] [pid 940476:tid 940713] [client 57.141.18.57:60126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VJxjVYcQxwGpYwZmcxAAAa2o"]
[Mon Jul 20 06:31:42.489192 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLrcDxY_mIul-JSGfkwAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.698745 2026] [security2:error] [pid 940476:tid 940676] [client 195.2.67.184:61329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeLgAAAEY"], referer: https://suretybonds-california.com/new-wage-liability-for-general-contractors/
[Mon Jul 20 06:31:42.698853 2026] [security2:error] [pid 940476:tid 940676] [client 195.2.67.184:61329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeLgAAAEY"], referer: https://suretybonds-california.com/new-wage-liability-for-general-contractors/
[Mon Jul 20 06:31:42.746960 2026] [security2:error] [pid 940476:tid 940621] [client 47.128.21.147:14616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "itekphonerepair.com"] [uri "/robots.txt"] [unique_id "al4VLhjVYcQxwGpYwZmeNQAAAA8"]
[Mon Jul 20 06:31:42.804974 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:65095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLhjVYcQxwGpYwZmeKAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.840688 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLrcDxY_mIul-JSGfpAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.840786 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:65097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLrcDxY_mIul-JSGfpAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.847822 2026] [security2:error] [pid 940476:tid 940634] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLhjVYcQxwGpYwZmeLQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.991171 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmePwAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.991279 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:65099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmePwAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:43.002551 2026] [security2:error] [pid 940476:tid 940606] [client 171.61.165.146:17750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeQAAAAAA"]
[Mon Jul 20 06:31:43.002709 2026] [security2:error] [pid 940476:tid 940606] [client 171.61.165.146:17750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeQAAAAAA"]
[Mon Jul 20 06:31:43.159476 2026] [security2:error] [pid 940476:tid 940716] [client 106.219.188.178:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeSAAAAG4"]
[Mon Jul 20 06:31:43.159679 2026] [security2:error] [pid 940476:tid 940716] [client 106.219.188.178:58750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeSAAAAG4"]
[Mon Jul 20 06:31:43.287423 2026] [security2:error] [pid 935758:tid 935932] [client 77.110.127.138:65017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VL7cDxY_mIul-JSGfpwAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:43.942329 2026] [proxy:error] [pid 935758:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:43.942430 2026] [proxy_http:error] [pid 935758:tid 935995] [client 34.73.38.214:57441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:43.943503 2026] [proxy:error] [pid 935758:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:43.943552 2026] [proxy_http:error] [pid 935758:tid 935995] [client 34.73.38.214:57441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:44.216206 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMLcDxY_mIul-JSGfzAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.368681 2026] [security2:error] [pid 935758:tid 935978] [client 223.185.13.213:23766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VMLcDxY_mIul-JSGf2AAAAWI"]
[Mon Jul 20 06:31:44.368809 2026] [security2:error] [pid 935758:tid 935978] [client 223.185.13.213:23766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VMLcDxY_mIul-JSGf2AAAAWI"]
[Mon Jul 20 06:31:44.537521 2026] [security2:error] [pid 940476:tid 940652] [client 216.73.216.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.waterproofgoods.com"] [uri "/index.php"] [unique_id "al4VMBjVYcQxwGpYwZmedQAAAC4"]
[Mon Jul 20 06:31:44.642982 2026] [security2:error] [pid 940476:tid 940675] [client 77.110.127.138:65107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMBjVYcQxwGpYwZmegwAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.805020 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:65108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMLcDxY_mIul-JSGf6AAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.805154 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:65108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMLcDxY_mIul-JSGf6AAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.840743 2026] [proxy:error] [pid 935758:tid 935974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:44.840847 2026] [proxy_http:error] [pid 935758:tid 935974] [client 34.73.38.214:54308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:44.841324 2026] [proxy:error] [pid 935758:tid 935974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:44.841348 2026] [proxy_http:error] [pid 935758:tid 935974] [client 34.73.38.214:54308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:45.074290 2026] [security2:error] [pid 935758:tid 935924] [client 176.57.150.156:53280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4VMbcDxY_mIul-JSGf9AAAASw"]
[Mon Jul 20 06:31:45.193876 2026] [security2:error] [pid 940476:tid 940688] [client 104.234.53.92:36231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VMRjVYcQxwGpYwZmemgAAAFI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:45.288802 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMRjVYcQxwGpYwZmelwAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:45.419534 2026] [security2:error] [pid 940476:tid 940677] [client 34.24.137.199:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.137.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casabella.aasgroup.online"] [uri "/xmlrpc.php"] [unique_id "al4VMRjVYcQxwGpYwZmeqQAAAEc"]
[Mon Jul 20 06:31:45.426934 2026] [security2:error] [pid 940476:tid 940733] [client 74.7.227.179:43334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VMRjVYcQxwGpYwZmeogAAfxE"], referer: https://tejasenvironmental.com/p=955081
[Mon Jul 20 06:31:45.478458 2026] [security2:error] [pid 940476:tid 940714] [client 158.173.166.181:35153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VMRjVYcQxwGpYwZmesAAAAGw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:45.517400 2026] [security2:error] [pid 935758:tid 935903] [client 176.57.150.156:53290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4VMbcDxY_mIul-JSGgCQAAARc"]
[Mon Jul 20 06:31:45.607590 2026] [security2:error] [pid 940476:tid 940671] [client 14.225.17.146:64773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4VMRjVYcQxwGpYwZmesgAAAEE"], referer: http://nikkidesigns.net/Old
[Mon Jul 20 06:31:45.659089 2026] [security2:error] [pid 935758:tid 935949] [client 74.249.245.134:10945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/wp.php"] [unique_id "al4VMbcDxY_mIul-JSGgEAAAAUU"]
[Mon Jul 20 06:31:45.659228 2026] [security2:error] [pid 935758:tid 935949] [client 74.249.245.134:10945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/wp.php"] [unique_id "al4VMbcDxY_mIul-JSGgEAAAAUU"]
[Mon Jul 20 06:31:45.772740 2026] [security2:error] [pid 935758:tid 935897] [client 57.141.18.125:27450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VKrcDxY_mIul-JSGfJAABEVI"]
[Mon Jul 20 06:31:45.948538 2026] [security2:error] [pid 940476:tid 940709] [client 176.57.150.156:53300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4VMRjVYcQxwGpYwZmevAAAAGc"]
[Mon Jul 20 06:31:45.959906 2026] [proxy:error] [pid 935758:tid 935901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:45.959984 2026] [proxy_http:error] [pid 935758:tid 935901] [client 34.73.38.214:54283] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:45.960705 2026] [proxy:error] [pid 935758:tid 935901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:45.960739 2026] [proxy_http:error] [pid 935758:tid 935901] [client 34.73.38.214:54283] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:46.078726 2026] [security2:error] [pid 940476:tid 940630] [client 34.24.137.199:52092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VMhjVYcQxwGpYwZmevgAAABg"]
[Mon Jul 20 06:31:46.134606 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:65114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMbcDxY_mIul-JSGgCAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.168306 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMbcDxY_mIul-JSGgGgAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.271051 2026] [security2:error] [pid 935758:tid 935978] [client 171.60.139.123:57723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VMrcDxY_mIul-JSGgNgAAAWI"]
[Mon Jul 20 06:31:46.271158 2026] [security2:error] [pid 935758:tid 935978] [client 171.60.139.123:57723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VMrcDxY_mIul-JSGgNgAAAWI"]
[Mon Jul 20 06:31:46.452582 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme3gAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.452686 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme3gAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.459112 2026] [security2:error] [pid 940476:tid 940732] [client 164.52.11.194:39498] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme2QAAAH4"]
[Mon Jul 20 06:31:46.459243 2026] [security2:error] [pid 940476:tid 940732] [client 164.52.11.194:39498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme2QAAAH4"]
[Mon Jul 20 06:31:46.459275 2026] [security2:error] [pid 940476:tid 940732] [client 164.52.11.194:39498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme2QAAAH4"]
[Mon Jul 20 06:31:46.613794 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme5QAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.613932 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme5QAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.641495 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VMhjVYcQxwGpYwZme5gAAAFo"]
[Mon Jul 20 06:31:46.641888 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:64328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VMhjVYcQxwGpYwZme5gAAAFo"]
[Mon Jul 20 06:31:46.713936 2026] [security2:error] [pid 940476:tid 940627] [client 34.24.137.199:51693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VMhjVYcQxwGpYwZme7AAAABU"]
[Mon Jul 20 06:31:46.748959 2026] [security2:error] [pid 940476:tid 940682] [client 14.225.17.146:51285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZme4AAAAEw"], referer: http://nomorewetsheets.net/Old
[Mon Jul 20 06:31:46.787230 2026] [security2:error] [pid 935758:tid 935988] [client 74.249.245.134:52757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/new.php"] [unique_id "al4VMrcDxY_mIul-JSGgRgAAAWw"]
[Mon Jul 20 06:31:46.787322 2026] [security2:error] [pid 935758:tid 935988] [client 74.249.245.134:52757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/new.php"] [unique_id "al4VMrcDxY_mIul-JSGgRgAAAWw"]
[Mon Jul 20 06:31:46.857873 2026] [security2:error] [pid 940476:tid 940697] [client 14.225.17.146:51430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZme6QAAAFs"], referer: http://xp-design.co/Old
[Mon Jul 20 06:31:46.984821 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:65120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZme7wAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.014027 2026] [security2:error] [pid 935758:tid 935978] [client 39.48.81.23:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgUQAAAWI"]
[Mon Jul 20 06:31:47.014187 2026] [security2:error] [pid 935758:tid 935978] [client 39.48.81.23:64143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgUQAAAWI"]
[Mon Jul 20 06:31:47.198560 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:65123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMxjVYcQxwGpYwZmfCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.198696 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:65123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMxjVYcQxwGpYwZmfCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.213651 2026] [security2:error] [pid 935758:tid 935859] [remote 103.28.36.106:47574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VM7cDxY_mIul-JSGgVwABWWI"]
[Mon Jul 20 06:31:47.251821 2026] [security2:error] [pid 935758:tid 936005] [client 57.141.18.19:49134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLLcDxY_mIul-JSGfVAABfQA"]
[Mon Jul 20 06:31:47.257280 2026] [security2:error] [pid 935758:tid 935907] [client 45.116.69.230:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgWgAAARs"]
[Mon Jul 20 06:31:47.257398 2026] [security2:error] [pid 935758:tid 935907] [client 45.116.69.230:50238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgWgAAARs"]
[Mon Jul 20 06:31:47.286697 2026] [proxy:error] [pid 940476:tid 940628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:47.286774 2026] [proxy_http:error] [pid 940476:tid 940628] [client 34.73.38.214:55274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:47.287459 2026] [proxy:error] [pid 940476:tid 940628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:47.287493 2026] [proxy_http:error] [pid 940476:tid 940628] [client 34.73.38.214:55274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:47.361534 2026] [security2:error] [pid 940476:tid 940624] [client 34.24.137.199:52028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VMxjVYcQxwGpYwZmfFQAAABI"]
[Mon Jul 20 06:31:47.380866 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:65121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgVgAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.456080 2026] [security2:error] [pid 940476:tid 940694] [client 57.141.18.96:21426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLBjVYcQxwGpYwZmdvAAAWEk"]
[Mon Jul 20 06:31:47.633558 2026] [security2:error] [pid 935758:tid 935766] [remote 103.28.36.106:47574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VM7cDxY_mIul-JSGgbgABTgU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:31:47.729152 2026] [security2:error] [pid 940476:tid 940709] [client 46.110.96.34:59854] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4VMxjVYcQxwGpYwZmfKAAAAGc"]
[Mon Jul 20 06:31:47.734089 2026] [security2:error] [pid 940476:tid 940530] [remote 72.167.132.114:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4VMxjVYcQxwGpYwZmfJwAASTU"]
[Mon Jul 20 06:31:47.877167 2026] [security2:error] [pid 935758:tid 935962] [client 34.73.38.214:58316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VM7cDxY_mIul-JSGgewAAAVI"]
[Mon Jul 20 06:31:47.880284 2026] [security2:error] [pid 935758:tid 935952] [client 14.225.17.146:56779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgcgAAAUg"], referer: http://taskidsvirginia.com/Old
[Mon Jul 20 06:31:47.887449 2026] [security2:error] [pid 935758:tid 935947] [client 34.24.137.199:59297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VM7cDxY_mIul-JSGgfQAAAUM"]
[Mon Jul 20 06:31:47.921363 2026] [security2:error] [pid 940476:tid 940642] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rentorangegrove.com"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZmeyAAAACQ"]
[Mon Jul 20 06:31:47.927824 2026] [security2:error] [pid 940476:tid 940612] [client 74.7.175.158:36718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rentorangegrove.com"] [uri "/robots.txt"] [unique_id "al4VMhjVYcQxwGpYwZmewgAABik"]
[Mon Jul 20 06:31:47.947785 2026] [security2:error] [pid 940476:tid 940526] [remote 72.167.132.114:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4VMxjVYcQxwGpYwZmfMQAADzE"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:31:48.014969 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:65126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgeAAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:48.285740 2026] [security2:error] [pid 935758:tid 935960] [client 14.225.17.146:57934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGggAAAAVA"], referer: http://tacticaltreeoperations.com/Old
[Mon Jul 20 06:31:48.294441 2026] [security2:error] [pid 940476:tid 940699] [client 34.73.38.214:58714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VNBjVYcQxwGpYwZmfQAAAAF0"]
[Mon Jul 20 06:31:48.332977 2026] [security2:error] [pid 935758:tid 935931] [client 164.52.11.194:39942] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VNLcDxY_mIul-JSGgkAAAATM"]
[Mon Jul 20 06:31:48.333190 2026] [security2:error] [pid 935758:tid 935931] [client 164.52.11.194:39942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VNLcDxY_mIul-JSGgkAAAATM"]
[Mon Jul 20 06:31:48.333245 2026] [security2:error] [pid 935758:tid 935931] [client 164.52.11.194:39942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VNLcDxY_mIul-JSGgkAAAATM"]
[Mon Jul 20 06:31:48.473531 2026] [security2:error] [pid 935758:tid 935911] [client 34.24.137.199:60186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VNLcDxY_mIul-JSGgmQAAAR8"]
[Mon Jul 20 06:31:48.571785 2026] [security2:error] [pid 940476:tid 940675] [client 14.251.3.155:58424] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4VNBjVYcQxwGpYwZmfTgAAAEU"]
[Mon Jul 20 06:31:48.659458 2026] [security2:error] [pid 940476:tid 940536] [remote 160.187.68.132:37342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VNBjVYcQxwGpYwZmfUQAAbDs"]
[Mon Jul 20 06:31:48.689112 2026] [security2:error] [pid 940476:tid 940689] [client 74.249.245.134:10996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/wpls.php"] [unique_id "al4VNBjVYcQxwGpYwZmfVAAAAFM"]
[Mon Jul 20 06:31:48.689212 2026] [security2:error] [pid 940476:tid 940689] [client 74.249.245.134:10996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/wpls.php"] [unique_id "al4VNBjVYcQxwGpYwZmfVAAAAFM"]
[Mon Jul 20 06:31:48.866983 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:65129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNLcDxY_mIul-JSGgnAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:48.890300 2026] [security2:error] [pid 940476:tid 940678] [client 57.141.18.22:32520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLRjVYcQxwGpYwZmd-AAASGE"]
[Mon Jul 20 06:31:48.970483 2026] [security2:error] [pid 940476:tid 940717] [client 34.24.137.199:50730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VNBjVYcQxwGpYwZmfYwAAAG8"]
[Mon Jul 20 06:31:49.004298 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:65131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNBjVYcQxwGpYwZmfVgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.060712 2026] [security2:error] [pid 940476:tid 940718] [client 57.141.18.60:27394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLRjVYcQxwGpYwZmeAQAAcGI"]
[Mon Jul 20 06:31:49.089281 2026] [security2:error] [pid 940476:tid 940730] [client 77.110.127.138:65135] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/contact-me/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4VNRjVYcQxwGpYwZmfaAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.129608 2026] [security2:error] [pid 935758:tid 936017] [client 14.225.17.146:55545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgZgAAAYk"], referer: http://swafforddetailing.com/Old
[Mon Jul 20 06:31:49.138313 2026] [security2:error] [pid 940476:tid 940537] [remote 160.187.68.132:37342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VNRjVYcQxwGpYwZmfagAAIjw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:49.220999 2026] [security2:error] [pid 935758:tid 935891] [client 34.73.38.214:55660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VNbcDxY_mIul-JSGgrQAAAQs"]
[Mon Jul 20 06:31:49.240834 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:65141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNbcDxY_mIul-JSGgrwAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.240939 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:65141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNbcDxY_mIul-JSGgrwAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.264986 2026] [security2:error] [pid 940476:tid 940731] [client 114.119.134.231:47123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.danwolfe.us"] [uri "/on-the-closure-of-valley-forge-military-academy/"] [unique_id "al4VNRjVYcQxwGpYwZmfbQAAAH0"], referer: https://blog.danwolfe.us/
[Mon Jul 20 06:31:49.391931 2026] [security2:error] [pid 940476:tid 940728] [client 34.24.137.199:54867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VNRjVYcQxwGpYwZmfdgAAAHo"]
[Mon Jul 20 06:31:49.453784 2026] [security2:error] [pid 940476:tid 940668] [client 77.110.127.138:65144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNRjVYcQxwGpYwZmfeAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.453949 2026] [security2:error] [pid 940476:tid 940668] [client 77.110.127.138:65144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNRjVYcQxwGpYwZmfeAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.563450 2026] [security2:error] [pid 940476:tid 940619] [client 77.110.127.138:65143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNRjVYcQxwGpYwZmfdQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.749857 2026] [security2:error] [pid 940476:tid 940700] [client 50.116.65.227:24456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VNRjVYcQxwGpYwZmfiAAAAF4"]
[Mon Jul 20 06:31:49.760546 2026] [security2:error] [pid 940476:tid 940643] [client 50.116.65.227:24462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VNRjVYcQxwGpYwZmfiQAAACU"]
[Mon Jul 20 06:31:49.848653 2026] [security2:error] [pid 940476:tid 940651] [client 34.24.137.199:54658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VNRjVYcQxwGpYwZmfjQAAAC0"]
[Mon Jul 20 06:31:49.891557 2026] [security2:error] [pid 940476:tid 940623] [client 14.225.17.146:56861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4VMxjVYcQxwGpYwZmfKgAAABE"], referer: http://dollpassionista.com/Old
[Mon Jul 20 06:31:50.005897 2026] [security2:error] [pid 940476:tid 940615] [client 34.73.38.214:53398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VNhjVYcQxwGpYwZmflAAAAAk"]
[Mon Jul 20 06:31:50.227134 2026] [security2:error] [pid 940476:tid 940646] [client 34.24.137.199:52183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VNhjVYcQxwGpYwZmfnwAAACg"]
[Mon Jul 20 06:31:50.295276 2026] [security2:error] [pid 940476:tid 940663] [client 74.249.245.134:52772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/mjq.php"] [unique_id "al4VNhjVYcQxwGpYwZmfpAAAADk"]
[Mon Jul 20 06:31:50.295387 2026] [security2:error] [pid 940476:tid 940663] [client 74.249.245.134:52772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/mjq.php"] [unique_id "al4VNhjVYcQxwGpYwZmfpAAAADk"]
[Mon Jul 20 06:31:50.328233 2026] [security2:error] [pid 935758:tid 935896] [client 14.225.17.146:55577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VNrcDxY_mIul-JSGgyAAAARA"], referer: http://sesamegreenbeans.com/Old
[Mon Jul 20 06:31:50.371001 2026] [security2:error] [pid 940476:tid 940680] [client 78.176.96.33:62814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLxjVYcQxwGpYwZmeagAASgU"], referer: https://toddnielsen.com
[Mon Jul 20 06:31:50.447854 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:65147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNhjVYcQxwGpYwZmfowAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.564413 2026] [security2:error] [pid 940476:tid 940699] [client 103.125.179.95:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VNhjVYcQxwGpYwZmfrAAAAF0"]
[Mon Jul 20 06:31:50.564685 2026] [security2:error] [pid 940476:tid 940699] [client 103.125.179.95:49305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VNhjVYcQxwGpYwZmfrAAAAF0"]
[Mon Jul 20 06:31:50.608094 2026] [security2:error] [pid 935758:tid 935957] [client 34.24.137.199:56965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VNrcDxY_mIul-JSGg3AAAAU0"]
[Mon Jul 20 06:31:50.652305 2026] [proxy:error] [pid 935758:tid 936004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:50.652397 2026] [proxy_http:error] [pid 935758:tid 936004] [client 34.73.38.214:63969] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:50.653382 2026] [proxy:error] [pid 935758:tid 936004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:50.653431 2026] [proxy_http:error] [pid 935758:tid 936004] [client 34.73.38.214:63969] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:50.678063 2026] [security2:error] [pid 940476:tid 940724] [client 57.141.18.60:27418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VMBjVYcQxwGpYwZmedAAAdhI"]
[Mon Jul 20 06:31:50.693604 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:65150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNhjVYcQxwGpYwZmfqAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.906298 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:65154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNrcDxY_mIul-JSGg3wAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.922889 2026] [security2:error] [pid 940476:tid 940621] [client 14.225.17.146:59289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4VNhjVYcQxwGpYwZmfswAAAA8"], referer: https://dollpassionista.com/Old
[Mon Jul 20 06:31:50.926389 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNhjVYcQxwGpYwZmfuQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.926466 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNhjVYcQxwGpYwZmfuQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:51.102888 2026] [security2:error] [pid 940476:tid 940549] [remote 167.71.218.184:48614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VNxjVYcQxwGpYwZmfwQAAHEg"]
[Mon Jul 20 06:31:51.203379 2026] [security2:error] [pid 935758:tid 936006] [client 104.234.53.53:51697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VN7cDxY_mIul-JSGg7wAAAX4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:51.375156 2026] [security2:error] [pid 940476:tid 940722] [client 34.24.137.199:52157] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VNxjVYcQxwGpYwZmfzQAAAHQ"]
[Mon Jul 20 06:31:51.377416 2026] [security2:error] [pid 940476:tid 940612] [client 14.225.17.146:59308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmfxQAAAAY"], referer: https://sesamegreenbeans.com/Old
[Mon Jul 20 06:31:51.497164 2026] [security2:error] [pid 940476:tid 940552] [remote 167.71.218.184:48614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VNxjVYcQxwGpYwZmf0AAAR0s"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:31:51.763502 2026] [security2:error] [pid 940476:tid 940673] [client 104.234.53.75:55023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VNxjVYcQxwGpYwZmf3gAAAEM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:51.831390 2026] [security2:error] [pid 940476:tid 940701] [client 14.225.17.146:53241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmf1QAAAF8"], referer: http://709fx.com/Old
[Mon Jul 20 06:31:51.850793 2026] [security2:error] [pid 940476:tid 940624] [client 14.225.17.146:59348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmf3AAAABI"], referer: http://alaraycreative.com/Old
[Mon Jul 20 06:31:51.912429 2026] [proxy:error] [pid 940476:tid 940711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:51.912512 2026] [proxy_http:error] [pid 940476:tid 940711] [client 34.73.38.214:61948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:51.913072 2026] [proxy:error] [pid 940476:tid 940711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:51.913103 2026] [proxy_http:error] [pid 940476:tid 940711] [client 34.73.38.214:61948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:51.961114 2026] [security2:error] [pid 935758:tid 935958] [client 74.249.245.134:10955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/class-t.api.php"] [unique_id "al4VN7cDxY_mIul-JSGhDAAAAU4"]
[Mon Jul 20 06:31:51.961221 2026] [security2:error] [pid 935758:tid 935958] [client 74.249.245.134:10955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/class-t.api.php"] [unique_id "al4VN7cDxY_mIul-JSGhDAAAAU4"]
[Mon Jul 20 06:31:52.064800 2026] [security2:error] [pid 935758:tid 935925] [client 34.73.38.214:61873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VOLcDxY_mIul-JSGhFQAAAS0"]
[Mon Jul 20 06:31:52.167475 2026] [security2:error] [pid 940476:tid 940690] [client 34.24.137.199:52161] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VOBjVYcQxwGpYwZmf9QAAAFQ"]
[Mon Jul 20 06:31:52.243699 2026] [security2:error] [pid 935758:tid 935956] [client 57.141.18.108:38436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VMbcDxY_mIul-JSGgJgABTHc"]
[Mon Jul 20 06:31:52.299862 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:65161] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/contact-me/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4VOLcDxY_mIul-JSGhIgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.451264 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgBgAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.451373 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgBgAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.606446 2026] [security2:error] [pid 940476:tid 940618] [client 77.110.127.138:65168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgCgAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.606583 2026] [security2:error] [pid 940476:tid 940618] [client 77.110.127.138:65168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgCgAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.611320 2026] [proxy:error] [pid 935758:tid 935919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:52.611377 2026] [proxy_http:error] [pid 935758:tid 935919] [client 34.73.38.214:64406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:52.611936 2026] [proxy:error] [pid 935758:tid 935919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:52.611962 2026] [proxy_http:error] [pid 935758:tid 935919] [client 34.73.38.214:64406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:52.622302 2026] [security2:error] [pid 935758:tid 935911] [client 197.186.66.42:58656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhLwAAAR8"]
[Mon Jul 20 06:31:52.622403 2026] [security2:error] [pid 935758:tid 935911] [client 197.186.66.42:58656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhLwAAAR8"]
[Mon Jul 20 06:31:52.827342 2026] [security2:error] [pid 940476:tid 940623] [client 14.225.17.146:57454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4VOBjVYcQxwGpYwZmgEgAAABE"], referer: http://betterbonddogtraining.com/Old
[Mon Jul 20 06:31:52.836697 2026] [security2:error] [pid 935758:tid 935898] [client 104.234.53.50:48667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VOLcDxY_mIul-JSGhNwAAARI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:52.934091 2026] [security2:error] [pid 935758:tid 935963] [client 15.237.142.234:23356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhOQAAAVM"]
[Mon Jul 20 06:31:52.934189 2026] [security2:error] [pid 935758:tid 935963] [client 15.237.142.234:23356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhOQAAAVM"]
[Mon Jul 20 06:31:52.987418 2026] [security2:error] [pid 940476:tid 940675] [client 112.208.70.94:43694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VOBjVYcQxwGpYwZmgIQAAAEU"]
[Mon Jul 20 06:31:52.987547 2026] [security2:error] [pid 940476:tid 940675] [client 112.208.70.94:43694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VOBjVYcQxwGpYwZmgIQAAAEU"]
[Mon Jul 20 06:31:53.152171 2026] [security2:error] [pid 935758:tid 935942] [client 14.225.17.146:58999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4VOLcDxY_mIul-JSGhPAAAAT4"], referer: http://bbwipartnerconference.com/Old
[Mon Jul 20 06:31:53.177349 2026] [proxy:error] [pid 935758:tid 935984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:53.177397 2026] [proxy_http:error] [pid 935758:tid 935984] [client 34.73.38.214:58867] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:53.177961 2026] [proxy:error] [pid 935758:tid 935984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:53.177994 2026] [proxy_http:error] [pid 935758:tid 935984] [client 34.73.38.214:58867] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:53.316743 2026] [security2:error] [pid 940476:tid 940658] [client 106.219.188.178:10276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgKQAAADQ"]
[Mon Jul 20 06:31:53.316909 2026] [security2:error] [pid 940476:tid 940658] [client 106.219.188.178:10276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgKQAAADQ"]
[Mon Jul 20 06:31:53.353366 2026] [security2:error] [pid 935758:tid 936000] [client 34.73.38.214:63071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VObcDxY_mIul-JSGhTgAAAXg"]
[Mon Jul 20 06:31:53.359415 2026] [security2:error] [pid 940476:tid 940651] [client 14.225.17.146:57972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4VORjVYcQxwGpYwZmgJwAAAC0"], referer: http://alexsandbergmusic.com/Old
[Mon Jul 20 06:31:53.436885 2026] [security2:error] [pid 935758:tid 935932] [client 45.157.112.60:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VObcDxY_mIul-JSGhUQAAATQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:53.701346 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VORjVYcQxwGpYwZmgNAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:53.702107 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VORjVYcQxwGpYwZmgNAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:53.837884 2026] [security2:error] [pid 940476:tid 940721] [client 171.61.165.146:23232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgOgAAAHM"]
[Mon Jul 20 06:31:53.838023 2026] [security2:error] [pid 940476:tid 940721] [client 171.61.165.146:23232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgOgAAAHM"]
[Mon Jul 20 06:31:53.884512 2026] [security2:error] [pid 935758:tid 935954] [client 34.73.38.214:56604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VObcDxY_mIul-JSGhagAAAUo"]
[Mon Jul 20 06:31:53.978408 2026] [security2:error] [pid 935758:tid 935938] [client 14.225.17.146:57408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4VObcDxY_mIul-JSGhaAAAATo"]
[Mon Jul 20 06:31:53.982798 2026] [security2:error] [pid 940476:tid 940713] [client 34.73.38.214:56403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VORjVYcQxwGpYwZmgQgAAAGs"]
[Mon Jul 20 06:31:54.356443 2026] [security2:error] [pid 940476:tid 940708] [client 82.102.27.163:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVQAAAGY"]
[Mon Jul 20 06:31:54.356561 2026] [security2:error] [pid 940476:tid 940708] [client 82.102.27.163:35234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVQAAAGY"]
[Mon Jul 20 06:31:54.374758 2026] [security2:error] [pid 940476:tid 940644] [client 223.185.13.213:20529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVgAAACY"]
[Mon Jul 20 06:31:54.374845 2026] [security2:error] [pid 940476:tid 940644] [client 223.185.13.213:20529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVgAAACY"]
[Mon Jul 20 06:31:54.617960 2026] [security2:error] [pid 940476:tid 940667] [client 34.73.38.214:50875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VOhjVYcQxwGpYwZmgXQAAAD0"]
[Mon Jul 20 06:31:54.714174 2026] [security2:error] [pid 940476:tid 940588] [remote 47.86.33.52:17168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4VOhjVYcQxwGpYwZmgbAAAPG8"]
[Mon Jul 20 06:31:54.985328 2026] [security2:error] [pid 940476:tid 940625] [client 34.73.38.214:50348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VOhjVYcQxwGpYwZmgfgAAABM"]
[Mon Jul 20 06:31:55.110053 2026] [security2:error] [pid 935758:tid 935968] [client 164.52.11.194:41806] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhjwAAAVg"]
[Mon Jul 20 06:31:55.110729 2026] [security2:error] [pid 935758:tid 935968] [client 164.52.11.194:41806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhjwAAAVg"]
[Mon Jul 20 06:31:55.110775 2026] [security2:error] [pid 935758:tid 935968] [client 164.52.11.194:41806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhjwAAAVg"]
[Mon Jul 20 06:31:55.123437 2026] [security2:error] [pid 940476:tid 940659] [client 57.141.18.42:54494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNBjVYcQxwGpYwZmfXQAANTo"]
[Mon Jul 20 06:31:55.435814 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:65184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/contact-me/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4VOxjVYcQxwGpYwZmglAAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.450269 2026] [security2:error] [pid 940476:tid 940676] [client 114.119.131.253:34583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elevator-data.com"] [uri "/robots.txt"] [unique_id "al4VOxjVYcQxwGpYwZmglQAAAEY"], referer: http://elevator-data.com/robots.txt
[Mon Jul 20 06:31:55.515648 2026] [security2:error] [pid 940476:tid 940643] [client 34.73.38.214:56632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VOxjVYcQxwGpYwZmgmAAAACU"]
[Mon Jul 20 06:31:55.540783 2026] [security2:error] [pid 940476:tid 940715] [client 104.234.53.75:22739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VOxjVYcQxwGpYwZmgmgAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:55.546417 2026] [security2:error] [pid 940476:tid 940621] [client 74.249.245.134:10965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/plugins.php"] [unique_id "al4VOxjVYcQxwGpYwZmgmwAAAA8"]
[Mon Jul 20 06:31:55.546501 2026] [security2:error] [pid 940476:tid 940621] [client 74.249.245.134:10965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/plugins.php"] [unique_id "al4VOxjVYcQxwGpYwZmgmwAAAA8"]
[Mon Jul 20 06:31:55.587963 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhoQAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.588065 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhoQAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.738367 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:65187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOxjVYcQxwGpYwZmgogAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.738469 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:65187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOxjVYcQxwGpYwZmgogAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.791081 2026] [security2:error] [pid 935758:tid 935895] [client 57.141.18.75:60946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNbcDxY_mIul-JSGgvwABD0k"]
[Mon Jul 20 06:31:55.865946 2026] [security2:error] [pid 940476:tid 940733] [client 34.73.38.214:50347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VOxjVYcQxwGpYwZmgqAAAAH8"]
[Mon Jul 20 06:31:55.911445 2026] [security2:error] [pid 940476:tid 940481] [remote 5.161.225.162:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VOxjVYcQxwGpYwZmgrQAAawQ"]
[Mon Jul 20 06:31:56.224166 2026] [security2:error] [pid 940476:tid 940601] [remote 5.161.225.162:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VPBjVYcQxwGpYwZmgvAAAOnw"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:31:56.239308 2026] [security2:error] [pid 940476:tid 940514] [remote 47.86.33.52:17168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4VPBjVYcQxwGpYwZmgvQAASSU"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:31:56.313182 2026] [security2:error] [pid 940476:tid 940614] [client 34.73.38.214:54764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VPBjVYcQxwGpYwZmgwQAAAAg"]
[Mon Jul 20 06:31:56.560552 2026] [security2:error] [pid 935758:tid 935762] [remote 152.228.213.32:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VPLcDxY_mIul-JSGhzQABQwE"]
[Mon Jul 20 06:31:56.560710 2026] [security2:error] [pid 935758:tid 935947] [client 152.228.213.32:46466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VPLcDxY_mIul-JSGhzQABQwE"]
[Mon Jul 20 06:31:56.670255 2026] [security2:error] [pid 935758:tid 935965] [client 57.141.18.122:30870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNrcDxY_mIul-JSGg4gABVSc"]
[Mon Jul 20 06:31:56.872795 2026] [security2:error] [pid 940476:tid 940655] [client 34.73.38.214:53769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VPBjVYcQxwGpYwZmg2AAAADE"]
[Mon Jul 20 06:31:56.882797 2026] [security2:error] [pid 940476:tid 940678] [client 172.232.181.107:16162] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VPBjVYcQxwGpYwZmg2QAAAEg"]
[Mon Jul 20 06:31:56.998274 2026] [security2:error] [pid 940476:tid 940702] [client 171.60.139.123:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VPBjVYcQxwGpYwZmg5AAAAGA"]
[Mon Jul 20 06:31:56.998401 2026] [security2:error] [pid 940476:tid 940702] [client 171.60.139.123:58239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VPBjVYcQxwGpYwZmg5AAAAGA"]
[Mon Jul 20 06:31:57.010512 2026] [security2:error] [pid 940476:tid 940489] [remote 20.153.140.50:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4VPBjVYcQxwGpYwZmg4wAAMww"]
[Mon Jul 20 06:31:57.015883 2026] [security2:error] [pid 940476:tid 940710] [client 57.141.18.22:48268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmfxAAAaEI"]
[Mon Jul 20 06:31:57.097858 2026] [security2:error] [pid 940476:tid 940728] [client 114.119.133.35:60713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "windowtx.com"] [uri "/news/"] [unique_id "al4VPRjVYcQxwGpYwZmg5wAAAHo"], referer: https://www.1stoncology.com/blog/category/uncategorized/page/10703/
[Mon Jul 20 06:31:57.201429 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:65202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmg9wAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.201523 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:65202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmg9wAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.254854 2026] [security2:error] [pid 940476:tid 940716] [client 103.141.108.143:64806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmg-wAAAG4"]
[Mon Jul 20 06:31:57.255374 2026] [security2:error] [pid 940476:tid 940716] [client 103.141.108.143:64806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmg-wAAAG4"]
[Mon Jul 20 06:31:57.280835 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:65161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPbcDxY_mIul-JSGh5gAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.280969 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:65161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPbcDxY_mIul-JSGh5gAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.424161 2026] [security2:error] [pid 940476:tid 940700] [client 39.48.81.23:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAgAAAF4"]
[Mon Jul 20 06:31:57.424279 2026] [security2:error] [pid 940476:tid 940700] [client 39.48.81.23:64641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAgAAAF4"]
[Mon Jul 20 06:31:57.424593 2026] [security2:error] [pid 940476:tid 940486] [remote 20.153.140.50:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAQAAKwk"], referer: https://fansarogroup.com/wp-login.php
[Mon Jul 20 06:31:57.456262 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.456383 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.580409 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VPRjVYcQxwGpYwZmg_QAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.635871 2026] [security2:error] [pid 940476:tid 940640] [client 57.141.18.0:36808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmf6QAAIkw"]
[Mon Jul 20 06:31:57.669909 2026] [security2:error] [pid 935758:tid 935857] [remote 154.66.198.148:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VPbcDxY_mIul-JSGh9wABYGA"]
[Mon Jul 20 06:31:57.765535 2026] [security2:error] [pid 935758:tid 935963] [client 45.116.69.230:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VPbcDxY_mIul-JSGh-wAAAVM"]
[Mon Jul 20 06:31:57.765671 2026] [security2:error] [pid 935758:tid 935963] [client 45.116.69.230:50778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VPbcDxY_mIul-JSGh-wAAAVM"]
[Mon Jul 20 06:31:57.855167 2026] [security2:error] [pid 940476:tid 940694] [client 34.73.38.214:62123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VPRjVYcQxwGpYwZmhGAAAAFg"]
[Mon Jul 20 06:31:57.956857 2026] [security2:error] [pid 940476:tid 940615] [client 77.110.127.138:65208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhHAAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.956955 2026] [security2:error] [pid 940476:tid 940615] [client 77.110.127.138:65208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhHAAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.199287 2026] [security2:error] [pid 935758:tid 935880] [remote 154.66.198.148:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VPrcDxY_mIul-JSGiCwABf3c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:31:58.234891 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:65181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhKwAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.235047 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:65181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhKwAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.259195 2026] [security2:error] [pid 940476:tid 940706] [client 14.225.17.146:59375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4VPRjVYcQxwGpYwZmg-gAAAGQ"], referer: http://ancestralidadytrance.space/Old
[Mon Jul 20 06:31:58.375940 2026] [security2:error] [pid 935758:tid 935926] [client 57.141.18.5:56096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOLcDxY_mIul-JSGhKwABLgI"]
[Mon Jul 20 06:31:58.390136 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOgAAABo"]
[Mon Jul 20 06:31:58.390232 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOgAAABo"]
[Mon Jul 20 06:31:58.392130 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:65214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.392275 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:65214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.576718 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhRAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.576844 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:65217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhRAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.626214 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPrcDxY_mIul-JSGiFwAAAUU"]
[Mon Jul 20 06:31:58.626308 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPrcDxY_mIul-JSGiFwAAAUU"]
[Mon Jul 20 06:31:58.691585 2026] [security2:error] [pid 940476:tid 940708] [client 34.73.38.214:56649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VPhjVYcQxwGpYwZmhSwAAAGY"]
[Mon Jul 20 06:31:58.754803 2026] [security2:error] [pid 940476:tid 940609] [client 57.141.18.43:59310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOBjVYcQxwGpYwZmgGwAAA1w"]
[Mon Jul 20 06:31:58.811539 2026] [security2:error] [pid 940476:tid 940641] [client 34.73.38.214:54453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VPhjVYcQxwGpYwZmhUAAAACM"]
[Mon Jul 20 06:31:58.849100 2026] [security2:error] [pid 940476:tid 940519] [remote 154.61.75.100:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4VPhjVYcQxwGpYwZmhUQAAcyo"]
[Mon Jul 20 06:31:59.008870 2026] [security2:error] [pid 935758:tid 936006] [client 74.249.245.134:10969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/jp.php"] [unique_id "al4VP7cDxY_mIul-JSGiLwAAAX4"]
[Mon Jul 20 06:31:59.008994 2026] [security2:error] [pid 935758:tid 936006] [client 74.249.245.134:10969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/jp.php"] [unique_id "al4VP7cDxY_mIul-JSGiLwAAAX4"]
[Mon Jul 20 06:31:59.042241 2026] [security2:error] [pid 940476:tid 940633] [client 34.73.38.214:57151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VPxjVYcQxwGpYwZmhWgAAABs"]
[Mon Jul 20 06:31:59.265349 2026] [security2:error] [pid 940476:tid 940692] [client 50.116.65.227:43982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VPxjVYcQxwGpYwZmhYgAAAFY"]
[Mon Jul 20 06:31:59.275210 2026] [security2:error] [pid 940476:tid 940632] [client 50.116.65.227:43988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VPxjVYcQxwGpYwZmhYwAAABo"]
[Mon Jul 20 06:31:59.333141 2026] [security2:error] [pid 940476:tid 940522] [remote 154.61.75.100:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4VPxjVYcQxwGpYwZmhZAAAYi0"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:31:59.389720 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:65220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VPxjVYcQxwGpYwZmhXgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:59.605973 2026] [security2:error] [pid 940476:tid 940638] [client 57.141.18.101:21894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VORjVYcQxwGpYwZmgMQAAIFo"]
[Mon Jul 20 06:31:59.803119 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VPxjVYcQxwGpYwZmhcwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:59.949165 2026] [security2:error] [pid 940476:tid 940697] [client 34.73.38.214:61973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VPxjVYcQxwGpYwZmhfAAAAFs"]
[Mon Jul 20 06:31:59.978633 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPxjVYcQxwGpYwZmhfQAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:59.978763 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:65223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPxjVYcQxwGpYwZmhfQAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.120311 2026] [security2:error] [pid 935758:tid 936009] [client 57.141.18.13:51876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOrcDxY_mIul-JSGhegABgUg"]
[Mon Jul 20 06:32:00.432951 2026] [security2:error] [pid 940476:tid 940610] [client 34.74.185.202:59599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VQBjVYcQxwGpYwZmhlAAAAAQ"]
[Mon Jul 20 06:32:00.441397 2026] [security2:error] [pid 940476:tid 940676] [client 45.131.194.10:42881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "generationloveproject.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4VQBjVYcQxwGpYwZmhlgAAAEY"]
[Mon Jul 20 06:32:00.537943 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:65206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhmgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.538121 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:65206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhmgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.646785 2026] [security2:error] [pid 935758:tid 935930] [client 14.225.17.146:55886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4VP7cDxY_mIul-JSGiQQAAATI"], referer: http://intelligentengineeringsolutions.com/Old
[Mon Jul 20 06:32:00.759378 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQLcDxY_mIul-JSGiagAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.759469 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:65229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQLcDxY_mIul-JSGiagAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.898537 2026] [security2:error] [pid 940476:tid 940650] [client 82.102.27.163:57490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrgAAACw"]
[Mon Jul 20 06:32:00.898632 2026] [security2:error] [pid 940476:tid 940650] [client 82.102.27.163:57490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrgAAACw"]
[Mon Jul 20 06:32:00.918527 2026] [security2:error] [pid 940476:tid 940629] [client 164.52.11.194:43530] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrwAAABc"]
[Mon Jul 20 06:32:00.918684 2026] [security2:error] [pid 940476:tid 940629] [client 164.52.11.194:43530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrwAAABc"]
[Mon Jul 20 06:32:00.918732 2026] [security2:error] [pid 940476:tid 940629] [client 164.52.11.194:43530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrwAAABc"]
[Mon Jul 20 06:32:00.985143 2026] [security2:error] [pid 940476:tid 940674] [client 172.232.181.107:20174] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VQBjVYcQxwGpYwZmhtQAAAEQ"]
[Mon Jul 20 06:32:01.186990 2026] [security2:error] [pid 940476:tid 940618] [client 103.125.179.95:49764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmhxAAAAAw"]
[Mon Jul 20 06:32:01.187604 2026] [security2:error] [pid 940476:tid 940618] [client 103.125.179.95:49764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmhxAAAAAw"]
[Mon Jul 20 06:32:01.338528 2026] [security2:error] [pid 935758:tid 935968] [client 14.225.17.146:58830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4VQbcDxY_mIul-JSGicAAAAVg"], referer: http://hilltopnurseryinc.com/Old
[Mon Jul 20 06:32:01.389311 2026] [security2:error] [pid 940476:tid 940678] [client 34.74.185.202:52805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VQRjVYcQxwGpYwZmhzAAAAEg"]
[Mon Jul 20 06:32:01.468389 2026] [security2:error] [pid 940476:tid 940717] [client 104.234.53.58:38491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VQRjVYcQxwGpYwZmhzQAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:01.585143 2026] [security2:error] [pid 935758:tid 935971] [client 34.73.38.214:63401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VQbcDxY_mIul-JSGihAAAAVs"]
[Mon Jul 20 06:32:01.697974 2026] [security2:error] [pid 935758:tid 935837] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VQbcDxY_mIul-JSGiiAABJkw"]
[Mon Jul 20 06:32:01.713630 2026] [security2:error] [pid 940476:tid 940656] [client 57.141.18.69:26668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOxjVYcQxwGpYwZmgqQAAMiM"]
[Mon Jul 20 06:32:01.847103 2026] [security2:error] [pid 940476:tid 940714] [client 106.219.188.178:47756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmh1wAAAGw"]
[Mon Jul 20 06:32:01.848585 2026] [security2:error] [pid 940476:tid 940714] [client 106.219.188.178:47756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmh1wAAAGw"]
[Mon Jul 20 06:32:02.155626 2026] [security2:error] [pid 935758:tid 935959] [client 34.74.185.202:50852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VQrcDxY_mIul-JSGinQAAAU8"]
[Mon Jul 20 06:32:02.202214 2026] [security2:error] [pid 935758:tid 935987] [client 104.207.58.248:41203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VQrcDxY_mIul-JSGinwAAAWs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:02.599019 2026] [security2:error] [pid 940476:tid 940687] [client 74.249.245.134:10953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/pu9.php"] [unique_id "al4VQhjVYcQxwGpYwZmh8AAAAFE"]
[Mon Jul 20 06:32:02.599118 2026] [security2:error] [pid 940476:tid 940687] [client 74.249.245.134:10953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/pu9.php"] [unique_id "al4VQhjVYcQxwGpYwZmh8AAAAFE"]
[Mon Jul 20 06:32:02.794400 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VQrcDxY_mIul-JSGirwAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:02.800571 2026] [security2:error] [pid 940476:tid 940729] [client 34.73.38.214:54028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VQhjVYcQxwGpYwZmh-wAAAHs"]
[Mon Jul 20 06:32:02.839916 2026] [security2:error] [pid 940476:tid 940647] [client 104.28.156.112:13519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.156.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmh_QAAACk"]
[Mon Jul 20 06:32:02.850378 2026] [security2:error] [pid 940476:tid 940651] [client 65.111.26.68:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmh_wAAAC0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:02.861904 2026] [security2:error] [pid 940476:tid 940541] [remote 202.51.202.242:44632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmiAAAAC0A"]
[Mon Jul 20 06:32:02.869050 2026] [security2:error] [pid 940476:tid 940646] [client 104.28.156.112:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.156.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kgsnsteel.com"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmiBAAAACg"]
[Mon Jul 20 06:32:02.924352 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:56094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4VQrcDxY_mIul-JSGiqgAAAWo"]
[Mon Jul 20 06:32:02.984540 2026] [security2:error] [pid 940476:tid 940690] [client 34.74.185.202:59064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VQhjVYcQxwGpYwZmiCwAAAFQ"]
[Mon Jul 20 06:32:03.033054 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiDQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.033168 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiDQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.247391 2026] [security2:error] [pid 935758:tid 935783] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VQ7cDxY_mIul-JSGixAABeBY"]
[Mon Jul 20 06:32:03.357102 2026] [security2:error] [pid 940476:tid 940702] [client 177.215.119.206:59192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4VQxjVYcQxwGpYwZmiHQAAAGA"]
[Mon Jul 20 06:32:03.383700 2026] [security2:error] [pid 935758:tid 935897] [client 14.225.17.146:58881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4VQbcDxY_mIul-JSGilwAAARE"], referer: http://balticsteelmgmt.com/Old
[Mon Jul 20 06:32:03.446530 2026] [security2:error] [pid 940476:tid 940640] [client 34.73.38.214:64062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VQxjVYcQxwGpYwZmiIwAAACI"]
[Mon Jul 20 06:32:03.450058 2026] [security2:error] [pid 935758:tid 935793] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VQ7cDxY_mIul-JSGi0gABJCA"]
[Mon Jul 20 06:32:03.481771 2026] [security2:error] [pid 935758:tid 935946] [client 45.3.45.198:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VQ7cDxY_mIul-JSGi0AAAAUI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:03.501845 2026] [security2:error] [pid 940476:tid 940682] [client 57.141.18.48:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VPRjVYcQxwGpYwZmhCAAATA4"]
[Mon Jul 20 06:32:03.621300 2026] [security2:error] [pid 935758:tid 935944] [client 197.186.66.42:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VQ7cDxY_mIul-JSGi2AAAAUA"]
[Mon Jul 20 06:32:03.621415 2026] [security2:error] [pid 935758:tid 935944] [client 197.186.66.42:59147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VQ7cDxY_mIul-JSGi2AAAAUA"]
[Mon Jul 20 06:32:03.670072 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiLwAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.670183 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiLwAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.858311 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:65256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi4QAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.858435 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:65256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi4QAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.910360 2026] [security2:error] [pid 935758:tid 935972] [client 77.110.127.138:65194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VQ7cDxY_mIul-JSGi5QAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.971534 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi5wAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.971685 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:65257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi5wAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.989797 2026] [security2:error] [pid 940476:tid 940552] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VQxjVYcQxwGpYwZmiOgAAH0s"]
[Mon Jul 20 06:32:04.009288 2026] [security2:error] [pid 940476:tid 940613] [client 103.87.64.56:36200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4VRBjVYcQxwGpYwZmiOwAAAAc"]
[Mon Jul 20 06:32:04.044788 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiPAAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.044903 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiPAAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.060132 2026] [security2:error] [pid 940476:tid 940719] [client 91.51.137.234:51168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VPhjVYcQxwGpYwZmhQwAAcSY"], referer: https://toddnielsen.com
[Mon Jul 20 06:32:04.065909 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi7AAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.066011 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi7AAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.218453 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQAAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.218554 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQAAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.219148 2026] [security2:error] [pid 935758:tid 936008] [client 34.74.185.202:55854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VRLcDxY_mIul-JSGi8QAAAYA"]
[Mon Jul 20 06:32:04.288837 2026] [security2:error] [pid 940476:tid 940660] [client 77.110.127.138:65264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQgAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.288961 2026] [security2:error] [pid 940476:tid 940660] [client 77.110.127.138:65264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQgAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.341070 2026] [security2:error] [pid 935758:tid 935778] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRLcDxY_mIul-JSGi-QABXhE"]
[Mon Jul 20 06:32:04.424513 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi_AAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.424602 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:65224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi_AAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.444896 2026] [security2:error] [pid 935758:tid 935950] [client 69.160.102.45:36410] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4VRLcDxY_mIul-JSGi_QAAAUY"]
[Mon Jul 20 06:32:04.474830 2026] [security2:error] [pid 940476:tid 940712] [client 54.166.194.245:48160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.194.166.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VRBjVYcQxwGpYwZmiSQAAAGo"]
[Mon Jul 20 06:32:04.584353 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:65266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiVgAAAH0"]
[Mon Jul 20 06:32:04.584449 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:65266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiVgAAAH0"]
[Mon Jul 20 06:32:04.621204 2026] [security2:error] [pid 940476:tid 940611] [client 34.73.38.214:56951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VRBjVYcQxwGpYwZmiWAAAAAU"]
[Mon Jul 20 06:32:04.639167 2026] [security2:error] [pid 940476:tid 940650] [client 74.249.245.134:10977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/error.php"] [unique_id "al4VRBjVYcQxwGpYwZmiWgAAACw"]
[Mon Jul 20 06:32:04.639264 2026] [security2:error] [pid 940476:tid 940650] [client 74.249.245.134:10977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/error.php"] [unique_id "al4VRBjVYcQxwGpYwZmiWgAAACw"]
[Mon Jul 20 06:32:04.650385 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:65268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiXAAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.650503 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:65268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiXAAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.656236 2026] [security2:error] [pid 940476:tid 940547] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRBjVYcQxwGpYwZmiXQAAKEY"]
[Mon Jul 20 06:32:04.677967 2026] [security2:error] [pid 940476:tid 940693] [client 136.158.62.28:26840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4VRBjVYcQxwGpYwZmiXgAAAFc"]
[Mon Jul 20 06:32:04.696153 2026] [security2:error] [pid 940476:tid 940609] [client 34.74.185.202:59358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VRBjVYcQxwGpYwZmiYQAAAAM"]
[Mon Jul 20 06:32:04.704608 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:65236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiZAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.704738 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:65236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiZAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.708037 2026] [security2:error] [pid 935758:tid 935894] [client 78.182.129.136:2726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4VRLcDxY_mIul-JSGjCgAAAQ4"]
[Mon Jul 20 06:32:04.748209 2026] [security2:error] [pid 935758:tid 935912] [client 223.185.13.213:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VRLcDxY_mIul-JSGjCwAAASA"]
[Mon Jul 20 06:32:04.748383 2026] [security2:error] [pid 935758:tid 935912] [client 223.185.13.213:4240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VRLcDxY_mIul-JSGjCwAAASA"]
[Mon Jul 20 06:32:04.749071 2026] [security2:error] [pid 940476:tid 940616] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VRBjVYcQxwGpYwZmiVQAAAAo"]
[Mon Jul 20 06:32:04.757290 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiawAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.757401 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiawAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.798504 2026] [security2:error] [pid 940476:tid 940711] [client 57.141.18.77:40994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VPxjVYcQxwGpYwZmhXwAAaSs"]
[Mon Jul 20 06:32:04.798875 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmibwAAACo"]
[Mon Jul 20 06:32:04.798974 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmibwAAACo"]
[Mon Jul 20 06:32:04.799139 2026] [security2:error] [pid 940476:tid 940637] [client 52.207.32.99:26306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VRBjVYcQxwGpYwZmibAAAAB8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:04.808490 2026] [security2:error] [pid 935758:tid 935900] [client 199.27.99.213:43328] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4VRLcDxY_mIul-JSGjDgAAARQ"]
[Mon Jul 20 06:32:04.811683 2026] [security2:error] [pid 935758:tid 935978] [client 200.112.80.245:36856] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4VRLcDxY_mIul-JSGjDwAAAWI"]
[Mon Jul 20 06:32:04.822009 2026] [security2:error] [pid 940476:tid 940715] [client 171.61.165.146:25453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VRBjVYcQxwGpYwZmicAAAAG0"]
[Mon Jul 20 06:32:04.822134 2026] [security2:error] [pid 940476:tid 940715] [client 171.61.165.146:25453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VRBjVYcQxwGpYwZmicAAAAG0"]
[Mon Jul 20 06:32:04.879514 2026] [security2:error] [pid 935758:tid 935969] [client 45.165.207.57:42742] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4VRLcDxY_mIul-JSGjEQAAAVk"]
[Mon Jul 20 06:32:04.882514 2026] [security2:error] [pid 935758:tid 935913] [client 172.232.181.107:20180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VRLcDxY_mIul-JSGjEwAAASE"]
[Mon Jul 20 06:32:04.909980 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmicgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.910092 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmicgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.972652 2026] [security2:error] [pid 935758:tid 935933] [client 181.163.102.84:39316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4VRLcDxY_mIul-JSGjGQAAATU"]
[Mon Jul 20 06:32:04.988418 2026] [security2:error] [pid 935758:tid 935930] [client 121.121.56.114:3664] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4VRLcDxY_mIul-JSGjGgAAATI"]
[Mon Jul 20 06:32:05.102573 2026] [security2:error] [pid 940476:tid 940664] [client 203.211.104.148:8840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4VRRjVYcQxwGpYwZmieAAAADo"]
[Mon Jul 20 06:32:05.211930 2026] [security2:error] [pid 940476:tid 940713] [client 70.29.144.67:36424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4VRRjVYcQxwGpYwZmigAAAAGs"]
[Mon Jul 20 06:32:05.327604 2026] [security2:error] [pid 935758:tid 936003] [client 37.202.72.176:62457] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjJgAAAXs"]
[Mon Jul 20 06:32:05.328292 2026] [security2:error] [pid 940476:tid 940685] [client 14.225.17.146:52996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4VRRjVYcQxwGpYwZmifAAAAE8"], referer: http://kromosenergy.com/Old
[Mon Jul 20 06:32:05.336308 2026] [security2:error] [pid 940476:tid 940661] [client 141.126.4.26:48030] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf"] [unique_id "al4VRRjVYcQxwGpYwZmihgAAADc"]
[Mon Jul 20 06:32:05.362466 2026] [security2:error] [pid 940476:tid 940622] [client 92.63.112.224:35026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmihwAAABA"]
[Mon Jul 20 06:32:05.362914 2026] [security2:error] [pid 940476:tid 940499] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRRjVYcQxwGpYwZmiiAAAKBY"]
[Mon Jul 20 06:32:05.393183 2026] [security2:error] [pid 935758:tid 935957] [client 144.91.117.173:57258] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4VRbcDxY_mIul-JSGjKAAAAU0"]
[Mon Jul 20 06:32:05.395531 2026] [security2:error] [pid 940476:tid 940642] [client 177.53.145.13:25569] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmiigAAACQ"]
[Mon Jul 20 06:32:05.398514 2026] [security2:error] [pid 935758:tid 936004] [client 112.203.171.97:62158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4VRbcDxY_mIul-JSGjKQAAAXw"]
[Mon Jul 20 06:32:05.404801 2026] [security2:error] [pid 940476:tid 940641] [client 14.225.17.146:54249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4VRRjVYcQxwGpYwZmifgAAACM"]
[Mon Jul 20 06:32:05.418663 2026] [security2:error] [pid 940476:tid 940690] [client 88.181.188.87:34546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmiiwAAAFQ"]
[Mon Jul 20 06:32:05.441059 2026] [security2:error] [pid 940476:tid 940659] [client 109.243.71.120:14520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4VRRjVYcQxwGpYwZmijAAAADU"]
[Mon Jul 20 06:32:05.485871 2026] [security2:error] [pid 940476:tid 940669] [client 49.151.135.136:11691] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4VRRjVYcQxwGpYwZmikgAAAD8"]
[Mon Jul 20 06:32:05.505871 2026] [security2:error] [pid 940476:tid 940677] [client 51.36.227.236:1710] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmilAAAAEc"]
[Mon Jul 20 06:32:05.507472 2026] [security2:error] [pid 940476:tid 940663] [client 189.110.175.226:38078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4VRRjVYcQxwGpYwZmilQAAADk"]
[Mon Jul 20 06:32:05.508550 2026] [security2:error] [pid 940476:tid 940676] [client 186.189.89.122:31700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4VRRjVYcQxwGpYwZmilgAAAEY"]
[Mon Jul 20 06:32:05.553802 2026] [security2:error] [pid 940476:tid 940665] [client 45.169.175.159:41933] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmimAAAADs"]
[Mon Jul 20 06:32:05.573548 2026] [security2:error] [pid 940476:tid 940653] [client 80.30.118.242:51864] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmimQAAAC8"]
[Mon Jul 20 06:32:05.598214 2026] [security2:error] [pid 935758:tid 935903] [client 186.194.20.193:2160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4VRbcDxY_mIul-JSGjMQAAARc"]
[Mon Jul 20 06:32:05.635112 2026] [security2:error] [pid 940476:tid 940683] [client 84.238.252.86:35272] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4VRRjVYcQxwGpYwZmimgAAAE0"]
[Mon Jul 20 06:32:05.655547 2026] [security2:error] [pid 940476:tid 940639] [client 23.17.128.7:49092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4VRRjVYcQxwGpYwZminQAAACE"]
[Mon Jul 20 06:32:05.679680 2026] [security2:error] [pid 940476:tid 940546] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRRjVYcQxwGpYwZmioAAAYUU"]
[Mon Jul 20 06:32:05.686480 2026] [security2:error] [pid 940476:tid 940607] [client 131.0.198.61:55624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4VRRjVYcQxwGpYwZmioQAAAAE"]
[Mon Jul 20 06:32:05.723757 2026] [security2:error] [pid 935758:tid 935939] [client 125.99.232.55:41132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjNQAAATs"]
[Mon Jul 20 06:32:05.747210 2026] [security2:error] [pid 940476:tid 940729] [client 188.3.178.90:15422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff"] [unique_id "al4VRRjVYcQxwGpYwZmipgAAAHs"]
[Mon Jul 20 06:32:05.772058 2026] [security2:error] [pid 935758:tid 935924] [client 103.148.213.80:37368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjNwAAASw"]
[Mon Jul 20 06:32:05.845539 2026] [security2:error] [pid 935758:tid 936009] [client 45.124.5.137:35296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjOwAAAYE"]
[Mon Jul 20 06:32:05.845539 2026] [security2:error] [pid 940476:tid 940706] [client 80.94.250.34:51476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4VRRjVYcQxwGpYwZmiswAAAGQ"]
[Mon Jul 20 06:32:05.877506 2026] [security2:error] [pid 935758:tid 936002] [client 171.229.249.99:56234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4VRbcDxY_mIul-JSGjPQAAAXo"]
[Mon Jul 20 06:32:05.896779 2026] [security2:error] [pid 940476:tid 940570] [remote 160.187.68.132:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VRRjVYcQxwGpYwZmitAAAb10"]
[Mon Jul 20 06:32:05.990990 2026] [security2:error] [pid 935758:tid 935943] [client 103.190.40.137:14046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4VRbcDxY_mIul-JSGjRQAAAT8"]
[Mon Jul 20 06:32:05.991323 2026] [security2:error] [pid 935758:tid 935959] [client 177.21.78.46:8260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4VRbcDxY_mIul-JSGjRAAAAU8"]
[Mon Jul 20 06:32:06.009293 2026] [security2:error] [pid 935758:tid 935886] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VRrcDxY_mIul-JSGjRwABXn0"]
[Mon Jul 20 06:32:06.015954 2026] [security2:error] [pid 935758:tid 935932] [client 186.189.90.48:23784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff"] [unique_id "al4VRrcDxY_mIul-JSGjSAAAATQ"]
[Mon Jul 20 06:32:06.024799 2026] [security2:error] [pid 940476:tid 940658] [client 77.239.165.93:65128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4VRhjVYcQxwGpYwZmiwwAAADQ"]
[Mon Jul 20 06:32:06.040107 2026] [security2:error] [pid 940476:tid 940579] [remote 202.51.202.242:44632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmixAAATmY"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:32:06.048571 2026] [security2:error] [pid 935758:tid 935937] [client 34.74.185.202:52380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VRrcDxY_mIul-JSGjSgAAATk"]
[Mon Jul 20 06:32:06.066946 2026] [security2:error] [pid 935758:tid 935935] [client 181.123.89.110:55266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4VRrcDxY_mIul-JSGjSwAAATc"]
[Mon Jul 20 06:32:06.100280 2026] [security2:error] [pid 940476:tid 940577] [remote 113.160.142.119:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmixgAAd2Q"]
[Mon Jul 20 06:32:06.115908 2026] [security2:error] [pid 940476:tid 940719] [client 49.156.84.178:45652] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4VRhjVYcQxwGpYwZmiyQAAAHE"]
[Mon Jul 20 06:32:06.117054 2026] [security2:error] [pid 940476:tid 940647] [client 119.30.119.166:10478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4VRhjVYcQxwGpYwZmiygAAACk"]
[Mon Jul 20 06:32:06.142550 2026] [security2:error] [pid 940476:tid 940666] [client 112.208.70.94:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VRhjVYcQxwGpYwZmizQAAADw"]
[Mon Jul 20 06:32:06.142667 2026] [security2:error] [pid 940476:tid 940666] [client 112.208.70.94:44159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VRhjVYcQxwGpYwZmizQAAADw"]
[Mon Jul 20 06:32:06.142826 2026] [security2:error] [pid 940476:tid 940708] [client 90.238.19.133:24763] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmizAAAAGY"]
[Mon Jul 20 06:32:06.185580 2026] [security2:error] [pid 940476:tid 940611] [client 113.199.244.176:43468] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmizwAAAAU"]
[Mon Jul 20 06:32:06.206541 2026] [security2:error] [pid 940476:tid 940655] [client 190.80.34.72:39476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi0gAAADE"]
[Mon Jul 20 06:32:06.206640 2026] [security2:error] [pid 935758:tid 935987] [client 1.52.89.105:52966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4VRrcDxY_mIul-JSGjWQAAAWs"]
[Mon Jul 20 06:32:06.230945 2026] [security2:error] [pid 940476:tid 940695] [client 79.106.125.131:54780] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi0wAAAFk"]
[Mon Jul 20 06:32:06.244123 2026] [security2:error] [pid 935758:tid 935925] [client 153.67.107.135:17086] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4VRrcDxY_mIul-JSGjWgAAAS0"]
[Mon Jul 20 06:32:06.293210 2026] [security2:error] [pid 940476:tid 940606] [client 45.41.165.152:6672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmixQAAAGg"]
[Mon Jul 20 06:32:06.329543 2026] [security2:error] [pid 940476:tid 940711] [client 192.223.105.252:57732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi1gAAAGk"]
[Mon Jul 20 06:32:06.363948 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjUgAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.386299 2026] [security2:error] [pid 935758:tid 936005] [client 91.73.227.1:36832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4VRrcDxY_mIul-JSGjXgAAAX0"]
[Mon Jul 20 06:32:06.395707 2026] [security2:error] [pid 935758:tid 936007] [client 49.147.194.213:5397] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.ttf"] [unique_id "al4VRrcDxY_mIul-JSGjXwAAAX8"]
[Mon Jul 20 06:32:06.400870 2026] [security2:error] [pid 940476:tid 940673] [client 114.119.130.251:61197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.maxenengineering.com"] [uri "/wp-content/uploads/2016/07/20160120_110949.jpg"] [unique_id "al4VRhjVYcQxwGpYwZmi2gAAAEM"], referer: https://www.maxenengineering.com/gallery/page/2
[Mon Jul 20 06:32:06.402429 2026] [security2:error] [pid 940476:tid 940500] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRhjVYcQxwGpYwZmi2QAAVhc"]
[Mon Jul 20 06:32:06.402785 2026] [security2:error] [pid 940476:tid 940580] [remote 160.187.68.132:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmi2AAAbmc"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:32:06.415643 2026] [security2:error] [pid 935758:tid 935953] [client 212.47.149.30:2649] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4VRrcDxY_mIul-JSGjYAAAAUk"]
[Mon Jul 20 06:32:06.423573 2026] [security2:error] [pid 935758:tid 935973] [client 34.73.38.214:64281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VRrcDxY_mIul-JSGjYgAAAV0"]
[Mon Jul 20 06:32:06.431143 2026] [security2:error] [pid 935758:tid 935909] [client 103.159.167.42:37806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4VRrcDxY_mIul-JSGjYwAAAR0"]
[Mon Jul 20 06:32:06.434872 2026] [security2:error] [pid 935758:tid 935980] [client 14.225.17.146:53343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4VRbcDxY_mIul-JSGjIQAAAWQ"], referer: http://getgarrison.com/Old
[Mon Jul 20 06:32:06.482036 2026] [security2:error] [pid 940476:tid 940616] [client 176.236.157.150:57284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi2wAAAAo"]
[Mon Jul 20 06:32:06.568148 2026] [security2:error] [pid 940476:tid 940641] [client 2.89.151.80:49822] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi3gAAACM"]
[Mon Jul 20 06:32:06.620988 2026] [security2:error] [pid 940476:tid 940668] [client 78.161.242.177:58626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4VRhjVYcQxwGpYwZmi5QAAAD4"]
[Mon Jul 20 06:32:06.681868 2026] [security2:error] [pid 940476:tid 940649] [client 89.246.100.230:20425] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi5gAAACs"]
[Mon Jul 20 06:32:06.686918 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRrcDxY_mIul-JSGjcwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.687037 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRrcDxY_mIul-JSGjcwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.701516 2026] [security2:error] [pid 940476:tid 940702] [client 164.52.11.194:44796] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VRhjVYcQxwGpYwZmi6AAAAGA"]
[Mon Jul 20 06:32:06.701971 2026] [security2:error] [pid 940476:tid 940702] [client 164.52.11.194:44796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VRhjVYcQxwGpYwZmi6AAAAGA"]
[Mon Jul 20 06:32:06.702018 2026] [security2:error] [pid 940476:tid 940702] [client 164.52.11.194:44796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VRhjVYcQxwGpYwZmi6AAAAGA"]
[Mon Jul 20 06:32:06.734928 2026] [security2:error] [pid 940476:tid 940728] [client 14.225.17.146:50370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi3wAAAHo"], referer: http://dnsplumbing.com/Old
[Mon Jul 20 06:32:06.760101 2026] [security2:error] [pid 935758:tid 935950] [client 45.165.207.66:1766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4VRrcDxY_mIul-JSGjeQAAAUY"]
[Mon Jul 20 06:32:06.801776 2026] [security2:error] [pid 940476:tid 940679] [client 14.225.17.146:50369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi4gAAAEk"], referer: http://windowtx.com/Old
[Mon Jul 20 06:32:06.816602 2026] [security2:error] [pid 940476:tid 940583] [remote 113.160.142.119:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmi7gAATmo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:06.843595 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:65287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VRrcDxY_mIul-JSGjfQAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.852095 2026] [security2:error] [pid 940476:tid 940614] [client 88.227.93.193:34920] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi7wAAAAg"]
[Mon Jul 20 06:32:06.857310 2026] [security2:error] [pid 935758:tid 935839] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VRrcDxY_mIul-JSGjfgABDE4"]
[Mon Jul 20 06:32:06.860142 2026] [security2:error] [pid 940476:tid 940637] [client 187.109.135.18:1623] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4VRhjVYcQxwGpYwZmi8AAAAB8"]
[Mon Jul 20 06:32:06.862244 2026] [security2:error] [pid 935758:tid 935995] [client 52.190.138.124:44676] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scarlettshirt.com"] [uri "/"] [unique_id "al4VRrcDxY_mIul-JSGjgAAAAXM"]
[Mon Jul 20 06:32:06.917723 2026] [security2:error] [pid 935758:tid 935964] [client 213.152.162.79:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VRrcDxY_mIul-JSGjgwAAAVQ"]
[Mon Jul 20 06:32:06.917859 2026] [security2:error] [pid 935758:tid 935964] [client 213.152.162.79:54508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VRrcDxY_mIul-JSGjgwAAAVQ"]
[Mon Jul 20 06:32:06.939556 2026] [security2:error] [pid 935758:tid 935924] [client 66.249.73.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjewAAASw"]
[Mon Jul 20 06:32:06.994036 2026] [security2:error] [pid 940476:tid 940648] [client 187.62.186.117:21380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4VRhjVYcQxwGpYwZmi9QAAACo"]
[Mon Jul 20 06:32:07.018140 2026] [security2:error] [pid 940476:tid 940633] [client 103.134.219.130:16405] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmi-AAAABs"]
[Mon Jul 20 06:32:07.234783 2026] [security2:error] [pid 935758:tid 935933] [client 34.74.185.202:59056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VR7cDxY_mIul-JSGjmQAAATU"]
[Mon Jul 20 06:32:07.401536 2026] [security2:error] [pid 940476:tid 940638] [client 172.59.215.204:28477] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjAwAAACA"]
[Mon Jul 20 06:32:07.408498 2026] [security2:error] [pid 935758:tid 935789] [remote 157.85.212.221:51721] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mtlegnews.gov"] [uri "/wp-json/batch/v1"] [unique_id "al4VR7cDxY_mIul-JSGjpwABcBw"]
[Mon Jul 20 06:32:07.415175 2026] [security2:error] [pid 940476:tid 940721] [client 125.162.26.230:48182] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjBAAAAHM"]
[Mon Jul 20 06:32:07.486186 2026] [security2:error] [pid 935758:tid 935939] [client 178.27.54.222:56872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufc5qw54a.woff2"] [unique_id "al4VR7cDxY_mIul-JSGjwAAAATs"]
[Mon Jul 20 06:32:07.534832 2026] [security2:error] [pid 940476:tid 940708] [client 46.248.208.100:37466] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjCgAAAGY"]
[Mon Jul 20 06:32:07.537429 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:65194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VR7cDxY_mIul-JSGj0AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.537514 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:65194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VR7cDxY_mIul-JSGj0AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.588371 2026] [security2:error] [pid 935758:tid 935955] [client 102.66.149.122:48990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4VR7cDxY_mIul-JSGj2wAAAUs"]
[Mon Jul 20 06:32:07.687362 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:65297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRxjVYcQxwGpYwZmjEQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.687457 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:65297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRxjVYcQxwGpYwZmjEQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.689413 2026] [security2:error] [pid 935758:tid 935915] [client 171.60.139.123:58761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VR7cDxY_mIul-JSGj4QAAASM"]
[Mon Jul 20 06:32:07.689565 2026] [security2:error] [pid 935758:tid 935915] [client 171.60.139.123:58761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VR7cDxY_mIul-JSGj4QAAASM"]
[Mon Jul 20 06:32:07.690307 2026] [security2:error] [pid 935758:tid 935871] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VR7cDxY_mIul-JSGj4AABe24"]
[Mon Jul 20 06:32:07.888637 2026] [security2:error] [pid 940476:tid 940611] [client 139.135.241.3:34100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjGwAAAAU"]
[Mon Jul 20 06:32:07.912138 2026] [security2:error] [pid 940476:tid 940616] [client 14.225.17.146:60859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4VRxjVYcQxwGpYwZmjGQAAAAo"], referer: http://backandneckpainrelieflaceychiropractor.com/Old
[Mon Jul 20 06:32:08.128759 2026] [security2:error] [pid 940476:tid 940694] [client 14.225.17.146:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4VSBjVYcQxwGpYwZmjIQAAAFg"], referer: http://mazzucelli.com/Old
[Mon Jul 20 06:32:08.231316 2026] [security2:error] [pid 940476:tid 940700] [client 180.191.208.151:35296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4VSBjVYcQxwGpYwZmjMQAAAF4"]
[Mon Jul 20 06:32:08.315306 2026] [security2:error] [pid 935758:tid 936011] [client 50.116.65.227:44090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VSLcDxY_mIul-JSGj_QAAAYM"]
[Mon Jul 20 06:32:08.325925 2026] [security2:error] [pid 935758:tid 935942] [client 50.116.65.227:44100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VSLcDxY_mIul-JSGj_gAAAT4"]
[Mon Jul 20 06:32:08.327682 2026] [security2:error] [pid 935758:tid 935794] [remote 157.85.212.221:30679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mtlegnews.gov"] [uri "/wp-json/batch/v1"] [unique_id "al4VSLcDxY_mIul-JSGj_wABhSE"]
[Mon Jul 20 06:32:08.341499 2026] [security2:error] [pid 935758:tid 935916] [client 177.44.177.215:28950] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4VSLcDxY_mIul-JSGkAQAAASQ"]
[Mon Jul 20 06:32:08.385354 2026] [security2:error] [pid 935758:tid 935951] [client 45.116.69.230:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VSLcDxY_mIul-JSGkAwAAAUc"]
[Mon Jul 20 06:32:08.385456 2026] [security2:error] [pid 935758:tid 935951] [client 45.116.69.230:51308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VSLcDxY_mIul-JSGkAwAAAUc"]
[Mon Jul 20 06:32:08.386220 2026] [security2:error] [pid 940476:tid 940674] [client 14.225.17.146:50410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmiwAAAAEQ"], referer: http://adastra.love/Old
[Mon Jul 20 06:32:08.489932 2026] [security2:error] [pid 935758:tid 935969] [client 102.100.89.214:60796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4VSLcDxY_mIul-JSGkCQAAAVk"]
[Mon Jul 20 06:32:08.498587 2026] [security2:error] [pid 935758:tid 935921] [client 104.234.53.62:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VSLcDxY_mIul-JSGkCgAAASk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:08.516354 2026] [security2:error] [pid 940476:tid 940598] [remote 5.182.209.54:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VSBjVYcQxwGpYwZmjPQAAQ3k"]
[Mon Jul 20 06:32:08.529514 2026] [security2:error] [pid 940476:tid 940699] [client 57.141.18.12:39052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VQxjVYcQxwGpYwZmiDAAAXXE"]
[Mon Jul 20 06:32:08.531150 2026] [security2:error] [pid 940476:tid 940613] [client 14.225.17.146:64273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4VSBjVYcQxwGpYwZmjNwAAAAc"], referer: http://mourgroup.com/Old
[Mon Jul 20 06:32:08.532954 2026] [security2:error] [pid 940476:tid 940538] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VSBjVYcQxwGpYwZmjPwAAWz0"]
[Mon Jul 20 06:32:08.570009 2026] [security2:error] [pid 940476:tid 940621] [client 34.74.185.202:59698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VSBjVYcQxwGpYwZmjQAAAAA8"]
[Mon Jul 20 06:32:08.689577 2026] [security2:error] [pid 940476:tid 940481] [remote 5.182.209.54:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VSBjVYcQxwGpYwZmjRgAAfAQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:08.766037 2026] [security2:error] [pid 940476:tid 940722] [client 57.141.18.71:50048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VQxjVYcQxwGpYwZmiFgAAdEQ"]
[Mon Jul 20 06:32:08.869327 2026] [security2:error] [pid 940476:tid 940693] [client 39.48.81.23:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VSBjVYcQxwGpYwZmjTQAAAFc"]
[Mon Jul 20 06:32:08.869435 2026] [security2:error] [pid 940476:tid 940693] [client 39.48.81.23:65137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VSBjVYcQxwGpYwZmjTQAAAFc"]
[Mon Jul 20 06:32:08.882833 2026] [security2:error] [pid 940476:tid 940694] [client 172.232.181.107:20184] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VSBjVYcQxwGpYwZmjTgAAAFg"]
[Mon Jul 20 06:32:09.295609 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:65311] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VSRjVYcQxwGpYwZmjVgAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:09.402458 2026] [security2:error] [pid 940476:tid 940688] [client 74.249.245.134:52769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/bdshell.php"] [unique_id "al4VSRjVYcQxwGpYwZmjWQAAAFI"]
[Mon Jul 20 06:32:09.402586 2026] [security2:error] [pid 940476:tid 940688] [client 74.249.245.134:52769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/bdshell.php"] [unique_id "al4VSRjVYcQxwGpYwZmjWQAAAFI"]
[Mon Jul 20 06:32:09.437371 2026] [security2:error] [pid 935758:tid 935840] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VSbcDxY_mIul-JSGkMgABSk8"]
[Mon Jul 20 06:32:09.482532 2026] [security2:error] [pid 940476:tid 940642] [client 95.177.87.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VRxjVYcQxwGpYwZmjHQAAACQ"]
[Mon Jul 20 06:32:09.532625 2026] [security2:error] [pid 935758:tid 935999] [client 95.177.87.42:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VR7cDxY_mIul-JSGj6gABdz8"]
[Mon Jul 20 06:32:09.539034 2026] [security2:error] [pid 935758:tid 935999] [client 95.177.87.42:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VR7cDxY_mIul-JSGj6wABdzA"]
[Mon Jul 20 06:32:09.763168 2026] [security2:error] [pid 940476:tid 940712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VSRjVYcQxwGpYwZmjYQAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:09.811540 2026] [security2:error] [pid 940476:tid 940682] [client 57.141.18.13:50748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRBjVYcQxwGpYwZmiUQAATE8"]
[Mon Jul 20 06:32:09.857734 2026] [security2:error] [pid 935758:tid 935907] [client 112.204.205.62:41160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4VSbcDxY_mIul-JSGkSwAAARs"]
[Mon Jul 20 06:32:09.928886 2026] [security2:error] [pid 940476:tid 940704] [client 52.190.138.124:56576] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scarlettshirt.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi8gAAAGI"]
[Mon Jul 20 06:32:09.929160 2026] [security2:error] [pid 935758:tid 935952] [client 52.190.138.124:56586] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scarlettshirt.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjhQAAAUg"]
[Mon Jul 20 06:32:09.989169 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSbcDxY_mIul-JSGkUQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:09.989295 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:65316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSbcDxY_mIul-JSGkUQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.049067 2026] [security2:error] [pid 940476:tid 940663] [client 52.190.138.124:56608] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "scarlettshirt.com"] [uri "/cgi-sys/404.html"] [unique_id "al4VShjVYcQxwGpYwZmjewAAADk"]
[Mon Jul 20 06:32:10.102353 2026] [security2:error] [pid 940476:tid 940720] [client 34.74.185.202:53353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VShjVYcQxwGpYwZmjfQAAAHI"]
[Mon Jul 20 06:32:10.139876 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:65317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkXAAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.139983 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:65317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkXAAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.277687 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjigAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.277862 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:65320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjigAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.294275 2026] [security2:error] [pid 940476:tid 940486] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VShjVYcQxwGpYwZmjiwAAKgk"]
[Mon Jul 20 06:32:10.314337 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjjgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.314512 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:65322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjjgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.536197 2026] [security2:error] [pid 940476:tid 940695] [client 34.74.185.202:52106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VShjVYcQxwGpYwZmjmgAAAFk"]
[Mon Jul 20 06:32:10.696684 2026] [security2:error] [pid 940476:tid 940686] [client 52.190.138.124:56608] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scarlettshirt.com"] [uri "/wp-login.php"] [unique_id "al4VShjVYcQxwGpYwZmjggAAAFA"]
[Mon Jul 20 06:32:10.720241 2026] [security2:error] [pid 940476:tid 940652] [client 57.141.18.114:49616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRRjVYcQxwGpYwZmingAALl8"]
[Mon Jul 20 06:32:10.727970 2026] [security2:error] [pid 940476:tid 940728] [client 52.190.138.124:56608] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "scarlettshirt.com"] [uri "/ads.txt"] [unique_id "al4VShjVYcQxwGpYwZmjoAAAAHo"]
[Mon Jul 20 06:32:10.757817 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjowAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.757910 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:65327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjowAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.764883 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:65326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjpAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.764950 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:65326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjpAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.766285 2026] [security2:error] [pid 935758:tid 935996] [client 63.177.52.239:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VSrcDxY_mIul-JSGkdgAAAXQ"]
[Mon Jul 20 06:32:10.955251 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkfgAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.955335 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkfgAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.103111 2026] [security2:error] [pid 935758:tid 935825] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VS7cDxY_mIul-JSGkgwABSUA"]
[Mon Jul 20 06:32:11.141001 2026] [security2:error] [pid 935758:tid 935894] [client 34.74.185.202:54411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VS7cDxY_mIul-JSGkhQAAAQ4"]
[Mon Jul 20 06:32:11.193072 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.193191 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:65333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.200484 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.200608 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.341772 2026] [security2:error] [pid 935758:tid 935972] [client 63.177.52.239:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VS7cDxY_mIul-JSGkjwAAAVw"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:11.877600 2026] [security2:error] [pid 940476:tid 940646] [client 57.141.18.37:65402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi5AAAKGk"]
[Mon Jul 20 06:32:11.878320 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.45:36536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjcgABiGs"]
[Mon Jul 20 06:32:11.993511 2026] [security2:error] [pid 935758:tid 935917] [client 57.141.18.34:58562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjdwABJSk"]
[Mon Jul 20 06:32:12.031051 2026] [security2:error] [pid 935758:tid 936008] [client 103.125.179.95:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VTLcDxY_mIul-JSGktAAAAYA"]
[Mon Jul 20 06:32:12.031529 2026] [security2:error] [pid 935758:tid 936008] [client 103.125.179.95:50227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VTLcDxY_mIul-JSGktAAAAYA"]
[Mon Jul 20 06:32:12.105379 2026] [security2:error] [pid 935758:tid 935973] [client 14.225.17.146:54794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4VS7cDxY_mIul-JSGkhAAAAV0"]
[Mon Jul 20 06:32:12.274108 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:65338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkvQAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.274216 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:65338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkvQAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.304143 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkwQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.304285 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:65339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkwQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.488835 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:65340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VTBjVYcQxwGpYwZmj_gAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.777050 2026] [ssl:error] [pid 940476:tid 940613] [client 54.86.115.253:25406] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname webmail.ambarmdesign.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:32:12.796500 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VTBjVYcQxwGpYwZmkAwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.883408 2026] [security2:error] [pid 940476:tid 940637] [client 172.232.181.107:61016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VTBjVYcQxwGpYwZmkDgAAAB8"]
[Mon Jul 20 06:32:12.970448 2026] [security2:error] [pid 940476:tid 940699] [client 14.225.17.146:60440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4VSxjVYcQxwGpYwZmj1QAAAF0"], referer: http://daseighty.net/Old
[Mon Jul 20 06:32:12.978337 2026] [security2:error] [pid 935758:tid 935991] [client 57.141.18.60:61532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VR7cDxY_mIul-JSGj5wABbxg"]
[Mon Jul 20 06:32:13.005275 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk4wAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.005434 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:65343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk4wAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.007944 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:65344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk5AAAAWw"]
[Mon Jul 20 06:32:13.008037 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:65344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk5AAAAWw"]
[Mon Jul 20 06:32:13.010605 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkGAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.010678 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkGAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.427881 2026] [security2:error] [pid 940476:tid 940512] [remote 81.173.115.7:52380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTRjVYcQxwGpYwZmkJAAAGiM"]
[Mon Jul 20 06:32:13.428015 2026] [security2:error] [pid 940476:tid 940632] [client 81.173.115.7:52380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTRjVYcQxwGpYwZmkJAAAGiM"]
[Mon Jul 20 06:32:13.695237 2026] [security2:error] [pid 935758:tid 935907] [client 77.110.127.138:65357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGlBAAAARs"]
[Mon Jul 20 06:32:13.695380 2026] [security2:error] [pid 935758:tid 935907] [client 77.110.127.138:65357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGlBAAAARs"]
[Mon Jul 20 06:32:13.699502 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:65358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkKQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.699611 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:65358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkKQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.976822 2026] [security2:error] [pid 940476:tid 940672] [client 164.52.11.194:46376] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkNQAAAEI"]
[Mon Jul 20 06:32:13.977001 2026] [security2:error] [pid 940476:tid 940672] [client 164.52.11.194:46376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkNQAAAEI"]
[Mon Jul 20 06:32:13.977057 2026] [security2:error] [pid 940476:tid 940672] [client 164.52.11.194:46376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkNQAAAEI"]
[Mon Jul 20 06:32:14.132056 2026] [security2:error] [pid 940476:tid 940593] [remote 57.141.18.23:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4VThjVYcQxwGpYwZmkPQAACHQ"]
[Mon Jul 20 06:32:14.135859 2026] [security2:error] [pid 940476:tid 940624] [client 82.102.27.163:56782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VThjVYcQxwGpYwZmkPgAAABI"]
[Mon Jul 20 06:32:14.135948 2026] [security2:error] [pid 940476:tid 940624] [client 82.102.27.163:56782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VThjVYcQxwGpYwZmkPgAAABI"]
[Mon Jul 20 06:32:14.173606 2026] [security2:error] [pid 935758:tid 935981] [client 151.123.177.234:58357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VTrcDxY_mIul-JSGlIwAAAWU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:14.192981 2026] [security2:error] [pid 935758:tid 935997] [client 216.73.216.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rywventures.com"] [uri "/index.php"] [unique_id "al4VTrcDxY_mIul-JSGlHQAAAXU"]
[Mon Jul 20 06:32:14.465981 2026] [security2:error] [pid 935758:tid 936009] [client 197.186.66.42:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlNgAAAYE"]
[Mon Jul 20 06:32:14.473927 2026] [security2:error] [pid 935758:tid 936009] [client 197.186.66.42:59643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlNgAAAYE"]
[Mon Jul 20 06:32:14.498405 2026] [security2:error] [pid 935758:tid 935811] [remote 162.19.86.63:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlOQABJzI"]
[Mon Jul 20 06:32:14.498584 2026] [security2:error] [pid 935758:tid 935919] [client 162.19.86.63:59383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlOQABJzI"]
[Mon Jul 20 06:32:14.599251 2026] [security2:error] [pid 935758:tid 935960] [client 57.141.18.9:53612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VSbcDxY_mIul-JSGkQAABUCI"]
[Mon Jul 20 06:32:14.704467 2026] [security2:error] [pid 935758:tid 935931] [client 14.225.17.146:56027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4VTrcDxY_mIul-JSGlPAAAATM"], referer: http://lifeisbetterlakeside.com/Old
[Mon Jul 20 06:32:14.737554 2026] [security2:error] [pid 935758:tid 935996] [client 164.52.11.194:46832] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTrcDxY_mIul-JSGlRgAAAXQ"]
[Mon Jul 20 06:32:14.737735 2026] [security2:error] [pid 935758:tid 935996] [client 164.52.11.194:46832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTrcDxY_mIul-JSGlRgAAAXQ"]
[Mon Jul 20 06:32:14.737785 2026] [security2:error] [pid 935758:tid 935996] [client 164.52.11.194:46832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTrcDxY_mIul-JSGlRgAAAXQ"]
[Mon Jul 20 06:32:14.890903 2026] [security2:error] [pid 935758:tid 936000] [client 5.161.187.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4VTbcDxY_mIul-JSGk_gAAAXg"]
[Mon Jul 20 06:32:15.150984 2026] [security2:error] [pid 940476:tid 940491] [remote 100.42.189.89:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VTxjVYcQxwGpYwZmkWAAAXw4"]
[Mon Jul 20 06:32:15.159873 2026] [security2:error] [pid 935758:tid 935999] [client 5.161.76.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4VTrcDxY_mIul-JSGlMAAAAXc"]
[Mon Jul 20 06:32:15.378516 2026] [security2:error] [pid 940476:tid 940540] [remote 100.42.189.89:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VTxjVYcQxwGpYwZmkZQAAcj8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:15.440846 2026] [security2:error] [pid 935758:tid 935963] [client 57.141.18.2:41642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VSrcDxY_mIul-JSGkaAABUxw"]
[Mon Jul 20 06:32:16.011298 2026] [security2:error] [pid 940476:tid 940714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VTxjVYcQxwGpYwZmkbQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:16.026115 2026] [security2:error] [pid 940476:tid 940666] [client 171.61.165.146:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkeQAAADw"]
[Mon Jul 20 06:32:16.026223 2026] [security2:error] [pid 940476:tid 940666] [client 171.61.165.146:9507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkeQAAADw"]
[Mon Jul 20 06:32:16.045450 2026] [security2:error] [pid 935758:tid 935827] [remote 81.173.115.7:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VULcDxY_mIul-JSGlfQABbUI"]
[Mon Jul 20 06:32:16.291113 2026] [security2:error] [pid 940476:tid 940722] [client 114.119.150.49:39913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtlegnews.gov"] [uri "/robots.txt"] [unique_id "al4VUBjVYcQxwGpYwZmkhAAAAHQ"], referer: https://mtlegnews.gov/robots.txt
[Mon Jul 20 06:32:16.302334 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:65373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:16.302455 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:65373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:16.333295 2026] [security2:error] [pid 940476:tid 940673] [client 223.185.13.213:21534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhwAAAEM"]
[Mon Jul 20 06:32:16.333449 2026] [security2:error] [pid 940476:tid 940673] [client 223.185.13.213:21534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhwAAAEM"]
[Mon Jul 20 06:32:16.354606 2026] [security2:error] [pid 940476:tid 940547] [remote 57.141.18.77:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2535740"] [unique_id "al4VUBjVYcQxwGpYwZmkigAAUUY"]
[Mon Jul 20 06:32:16.780112 2026] [security2:error] [pid 935758:tid 935892] [client 50.116.65.227:16304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4VULcDxY_mIul-JSGlnQAAAQw"]
[Mon Jul 20 06:32:16.794555 2026] [security2:error] [pid 940476:tid 940638] [client 50.116.65.227:58284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4VUBjVYcQxwGpYwZmkowAAACA"]
[Mon Jul 20 06:32:17.113884 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:65383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUbcDxY_mIul-JSGlqAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.113985 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:65383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUbcDxY_mIul-JSGlqAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.278758 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VURjVYcQxwGpYwZmktgAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.278854 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VURjVYcQxwGpYwZmktgAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.524585 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmkuQAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.646407 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:65387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmkwwAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.752103 2026] [security2:error] [pid 935758:tid 935987] [client 50.116.65.227:58310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VUbcDxY_mIul-JSGlwQAAAWs"]
[Mon Jul 20 06:32:17.756784 2026] [security2:error] [pid 935758:tid 935993] [client 98.159.234.160:43047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VUbcDxY_mIul-JSGlwgAAAXE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:32:17.763759 2026] [security2:error] [pid 940476:tid 940714] [client 50.116.65.227:58316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VURjVYcQxwGpYwZmkzwAAAGw"]
[Mon Jul 20 06:32:18.233784 2026] [security2:error] [pid 940476:tid 940650] [client 104.234.53.79:25633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VUhjVYcQxwGpYwZmk3QAAACw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:18.460521 2026] [security2:error] [pid 940476:tid 940643] [client 171.60.139.123:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk6wAAACU"]
[Mon Jul 20 06:32:18.460649 2026] [security2:error] [pid 940476:tid 940643] [client 171.60.139.123:59281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk6wAAACU"]
[Mon Jul 20 06:32:18.597124 2026] [security2:error] [pid 940476:tid 940613] [client 39.48.81.23:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk8wAAAAc"]
[Mon Jul 20 06:32:18.597266 2026] [security2:error] [pid 940476:tid 940613] [client 39.48.81.23:49370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk8wAAAAc"]
[Mon Jul 20 06:32:18.621365 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VUrcDxY_mIul-JSGl3gAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:18.958372 2026] [security2:error] [pid 940476:tid 940706] [client 14.225.17.146:54445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmkzgAAAGQ"], referer: http://lutheranphilosopher.com/Old
[Mon Jul 20 06:32:18.985187 2026] [security2:error] [pid 940476:tid 940615] [client 45.116.69.230:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmlCgAAAAk"]
[Mon Jul 20 06:32:18.985353 2026] [security2:error] [pid 940476:tid 940615] [client 45.116.69.230:51864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmlCgAAAAk"]
[Mon Jul 20 06:32:19.099664 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VUhjVYcQxwGpYwZmlBgAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.195167 2026] [security2:error] [pid 940476:tid 940674] [client 14.225.17.146:49282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmk2gAAAEQ"], referer: http://momheadquarters.com/Old
[Mon Jul 20 06:32:19.277256 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:19.277322 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:19.277836 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:19.277860 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:19.361347 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUxjVYcQxwGpYwZmlGAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.361439 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUxjVYcQxwGpYwZmlGAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.440007 2026] [security2:error] [pid 935758:tid 935782] [remote 81.173.115.7:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VU7cDxY_mIul-JSGmAwABFxU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:32:19.517651 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:65400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmCAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.517777 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:65400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmCAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.705652 2026] [security2:error] [pid 935758:tid 935988] [client 13.201.64.214:16936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VU7cDxY_mIul-JSGmEwAAAWw"]
[Mon Jul 20 06:32:19.744573 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:65403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmFAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.744711 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:65403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmFAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.854068 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VU7cDxY_mIul-JSGmDgAAAW4"]
[Mon Jul 20 06:32:19.858272 2026] [security2:error] [pid 940476:tid 940703] [client 57.141.18.83:28978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VTxjVYcQxwGpYwZmkVgAAYRo"]
[Mon Jul 20 06:32:20.057334 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:65404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlMwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.057456 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:65404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlMwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.143162 2026] [security2:error] [pid 935758:tid 935969] [client 14.225.17.146:54773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VVLcDxY_mIul-JSGmIQAAAVk"], referer: http://ksands.co.uk/Old
[Mon Jul 20 06:32:20.222618 2026] [security2:error] [pid 940476:tid 940632] [client 104.234.53.79:25633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlRAAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:20.229297 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlSAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.229473 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:65368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlSAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.358726 2026] [security2:error] [pid 935758:tid 935971] [client 112.208.70.94:44597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VVLcDxY_mIul-JSGmKQAAAVs"]
[Mon Jul 20 06:32:20.358899 2026] [security2:error] [pid 935758:tid 935971] [client 112.208.70.94:44597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VVLcDxY_mIul-JSGmKQAAAVs"]
[Mon Jul 20 06:32:20.362561 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:65406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlTAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.362648 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:65406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlTAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.406796 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVBjVYcQxwGpYwZmlOwAAABU"]
[Mon Jul 20 06:32:20.440796 2026] [security2:error] [pid 935758:tid 935999] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-5ab144f7.uritems.net"] [uri "/index.php"] [unique_id "al4VUrcDxY_mIul-JSGl1gAAAXc"]
[Mon Jul 20 06:32:20.645539 2026] [security2:error] [pid 940476:tid 940596] [remote 217.61.143.92:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlXAAABXc"]
[Mon Jul 20 06:32:20.758163 2026] [security2:error] [pid 940476:tid 940591] [remote 167.233.114.32:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlXQAAAHI"]
[Mon Jul 20 06:32:20.760561 2026] [security2:error] [pid 940476:tid 940730] [client 77.110.127.138:65407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVBjVYcQxwGpYwZmlWAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.801779 2026] [security2:error] [pid 940476:tid 940684] [client 103.174.5.160:42862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VUBjVYcQxwGpYwZmkjQAATis"], referer: https://toddnielsen.com
[Mon Jul 20 06:32:20.879255 2026] [security2:error] [pid 940476:tid 940542] [remote 217.61.143.92:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlYQAARkE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:32:20.944731 2026] [security2:error] [pid 940476:tid 940602] [remote 167.233.114.32:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlZwAAVn0"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 06:32:21.077182 2026] [security2:error] [pid 940476:tid 940631] [client 57.141.18.12:59660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VUBjVYcQxwGpYwZmklQAAGVM"]
[Mon Jul 20 06:32:21.189934 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmlbgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.190026 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmlbgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.222573 2026] [security2:error] [pid 940476:tid 940720] [client 14.225.17.146:63901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4VVRjVYcQxwGpYwZmlawAAAHI"], referer: http://ironcitywellness.com/Old
[Mon Jul 20 06:32:21.307475 2026] [proxy:error] [pid 940476:tid 940647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:21.307540 2026] [proxy_http:error] [pid 940476:tid 940647] [client 34.73.38.214:54488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:21.308165 2026] [proxy:error] [pid 940476:tid 940647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:21.308199 2026] [proxy_http:error] [pid 940476:tid 940647] [client 34.73.38.214:54488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:21.519534 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmligAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.519673 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:65413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmligAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.748923 2026] [security2:error] [pid 940476:tid 940481] [remote 100.42.189.89:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4VVRjVYcQxwGpYwZmljAAAWAQ"]
[Mon Jul 20 06:32:21.763008 2026] [security2:error] [pid 940476:tid 940690] [client 77.110.127.138:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmljQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.763134 2026] [security2:error] [pid 940476:tid 940690] [client 77.110.127.138:65414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmljQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.014619 2026] [security2:error] [pid 940476:tid 940514] [remote 100.42.189.89:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4VVhjVYcQxwGpYwZmlmQAAPyU"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:32:22.026419 2026] [security2:error] [pid 935758:tid 935890] [client 87.199.196.160:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.musichaven.info"] [uri "/wp-comments-post.php"] [unique_id "al4VVbcDxY_mIul-JSGmYQAAAQo"], referer: https://www.musichaven.info/how-songwriting-improves-mental-health/
[Mon Jul 20 06:32:22.026569 2026] [security2:error] [pid 935758:tid 935890] [client 87.199.196.160:60669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.musichaven.info"] [uri "/wp-comments-post.php"] [unique_id "al4VVbcDxY_mIul-JSGmYQAAAQo"], referer: https://www.musichaven.info/how-songwriting-improves-mental-health/
[Mon Jul 20 06:32:22.174685 2026] [security2:error] [pid 940476:tid 940703] [client 158.173.89.95:20717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VVhjVYcQxwGpYwZmlogAAAGE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:32:22.191760 2026] [security2:error] [pid 940476:tid 940665] [client 14.225.17.146:49494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VVhjVYcQxwGpYwZmlngAAADs"], referer: http://effingweirdmuseums.com/Old
[Mon Jul 20 06:32:22.195317 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:65391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVrcDxY_mIul-JSGmaQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.195438 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:65391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVrcDxY_mIul-JSGmaQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.246504 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVhjVYcQxwGpYwZmlmwAAAEA"], referer: 1'"3000
[Mon Jul 20 06:32:22.392303 2026] [security2:error] [pid 940476:tid 940624] [client 57.141.18.94:57972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmk2QAAElg"]
[Mon Jul 20 06:32:22.400480 2026] [security2:error] [pid 935758:tid 935950] [client 77.110.127.138:65416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampJEqIeGln' OR 664. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 664 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VVrcDxY_mIul-JSGmcgAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.597788 2026] [security2:error] [pid 940476:tid 940625] [client 57.141.18.75:21894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VUhjVYcQxwGpYwZmk4QAAE2M"]
[Mon Jul 20 06:32:22.791300 2026] [security2:error] [pid 940476:tid 940728] [client 103.125.179.95:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmluwAAAHo"]
[Mon Jul 20 06:32:22.791426 2026] [security2:error] [pid 940476:tid 940728] [client 103.125.179.95:50697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmluwAAAHo"]
[Mon Jul 20 06:32:22.816491 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:22.816556 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:52508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:22.817125 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:22.817164 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:52508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:22.916232 2026] [security2:error] [pid 935758:tid 935976] [client 57.141.18.109:62544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmjQABYAY"]
[Mon Jul 20 06:32:22.988300 2026] [security2:error] [pid 940476:tid 940722] [client 106.219.188.178:40165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmlxAAAAHQ"]
[Mon Jul 20 06:32:22.998629 2026] [security2:error] [pid 940476:tid 940722] [client 106.219.188.178:40165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmlxAAAAHQ"]
[Mon Jul 20 06:32:23.072205 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmjAAAATY"], referer: 1'"3000
[Mon Jul 20 06:32:23.126062 2026] [security2:error] [pid 940476:tid 940730] [client 14.225.17.146:64141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VVxjVYcQxwGpYwZmlxgAAAHw"], referer: https://effingweirdmuseums.com/Old
[Mon Jul 20 06:32:23.361129 2026] [security2:error] [pid 940476:tid 940724] [client 114.119.130.57:49085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/why-is-screen-printing-so-expensive/"] [unique_id "al4VVxjVYcQxwGpYwZmlzQAAAHY"], referer: https://sustaintheart.com/how-long-does-it-take-to-do-a-screen-print/
[Mon Jul 20 06:32:23.487012 2026] [security2:error] [pid 935758:tid 935994] [client 104.234.53.54:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VV7cDxY_mIul-JSGmrwAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:23.767508 2026] [security2:error] [pid 940476:tid 940659] [client 187.108.85.186:63848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVxjVYcQxwGpYwZml3wAAADU"]
[Mon Jul 20 06:32:23.767758 2026] [security2:error] [pid 940476:tid 940659] [client 187.108.85.186:63848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVxjVYcQxwGpYwZml3wAAADU"]
[Mon Jul 20 06:32:23.851517 2026] [security2:error] [pid 940476:tid 940617] [client 65.111.26.25:65377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VVxjVYcQxwGpYwZml5QAAAAs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:23.906725 2026] [security2:error] [pid 940476:tid 940647] [client 43.205.139.3:63722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VVxjVYcQxwGpYwZml7QAAACk"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:23.966595 2026] [proxy:error] [pid 940476:tid 940690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:23.966643 2026] [proxy_http:error] [pid 940476:tid 940690] [client 34.73.38.214:64295] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:23.967287 2026] [proxy:error] [pid 940476:tid 940690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:23.967312 2026] [proxy_http:error] [pid 940476:tid 940690] [client 34.73.38.214:64295] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:24.009120 2026] [security2:error] [pid 940476:tid 940631] [client 14.225.17.146:52440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4VVxjVYcQxwGpYwZml3gAAABk"], referer: http://mcg.homes/Old
[Mon Jul 20 06:32:24.261110 2026] [security2:error] [pid 935758:tid 936012] [client 57.141.18.76:53226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VU7cDxY_mIul-JSGmFwABhAg"]
[Mon Jul 20 06:32:24.330244 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWBjVYcQxwGpYwZml_AAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:24.330352 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWBjVYcQxwGpYwZml_AAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:24.502933 2026] [security2:error] [pid 935758:tid 935923] [client 65.111.26.132:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VWLcDxY_mIul-JSGmzAAAASs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:24.998221 2026] [security2:error] [pid 935758:tid 935803] [remote 85.204.69.248:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4VWLcDxY_mIul-JSGm4gABcyo"]
[Mon Jul 20 06:32:25.037877 2026] [security2:error] [pid 935758:tid 935947] [client 17.241.75.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.willowbranchequines.org"] [uri "/index.php"] [unique_id "al4VV7cDxY_mIul-JSGmrQAAAUM"]
[Mon Jul 20 06:32:25.256840 2026] [security2:error] [pid 935758:tid 935795] [remote 85.204.69.248:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4VWbcDxY_mIul-JSGm7QABaiI"], referer: https://website-e4de5cd0.epu.kzx.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:32:25.493657 2026] [security2:error] [pid 935758:tid 935929] [client 197.186.66.42:60143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VWbcDxY_mIul-JSGm8wAAATE"]
[Mon Jul 20 06:32:25.493774 2026] [security2:error] [pid 935758:tid 935929] [client 197.186.66.42:60143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VWbcDxY_mIul-JSGm8wAAATE"]
[Mon Jul 20 06:32:25.505772 2026] [security2:error] [pid 935758:tid 935964] [client 34.73.38.214:54035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VWbcDxY_mIul-JSGm9QAAAVQ"]
[Mon Jul 20 06:32:25.577871 2026] [security2:error] [pid 940476:tid 940723] [client 57.141.18.112:52458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVRjVYcQxwGpYwZmlaQAAdWs"]
[Mon Jul 20 06:32:25.610395 2026] [security2:error] [pid 935758:tid 935993] [client 104.234.53.59:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VWbcDxY_mIul-JSGm-QAAAXE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:25.673353 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWRjVYcQxwGpYwZmmKgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:25.673450 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWRjVYcQxwGpYwZmmKgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.067603 2026] [security2:error] [pid 940476:tid 940639] [client 223.185.13.213:22868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VWhjVYcQxwGpYwZmmOAAAACE"]
[Mon Jul 20 06:32:26.067719 2026] [security2:error] [pid 940476:tid 940639] [client 223.185.13.213:22868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VWhjVYcQxwGpYwZmmOAAAACE"]
[Mon Jul 20 06:32:26.220396 2026] [security2:error] [pid 940476:tid 940509] [remote 152.228.213.32:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4VWhjVYcQxwGpYwZmmQgAAdyA"]
[Mon Jul 20 06:32:26.294223 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:65438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampLR0ntXZF') OR 198. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 198 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VWhjVYcQxwGpYwZmmRgAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.430251 2026] [security2:error] [pid 940476:tid 940508] [remote 152.228.213.32:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4VWhjVYcQxwGpYwZmmTAAAMB8"], referer: https://daseighty.net/wp-login.php
[Mon Jul 20 06:32:26.460588 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWrcDxY_mIul-JSGnHAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.464452 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:65441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWrcDxY_mIul-JSGnHAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.469046 2026] [security2:error] [pid 935758:tid 935891] [client 57.141.18.67:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVbcDxY_mIul-JSGmXAABCy0"]
[Mon Jul 20 06:32:26.663682 2026] [security2:error] [pid 935758:tid 936005] [client 171.61.165.146:33195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VWrcDxY_mIul-JSGnKQAAAX0"]
[Mon Jul 20 06:32:26.721342 2026] [security2:error] [pid 935758:tid 936005] [client 171.61.165.146:33195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VWrcDxY_mIul-JSGnKQAAAX0"]
[Mon Jul 20 06:32:26.836348 2026] [security2:error] [pid 940476:tid 940684] [client 104.234.53.69:25281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VWhjVYcQxwGpYwZmmXQAAAE4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:27.224847 2026] [security2:error] [pid 940476:tid 940689] [client 34.73.38.214:64805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VWxjVYcQxwGpYwZmmbAAAAFM"]
[Mon Jul 20 06:32:27.255034 2026] [security2:error] [pid 935758:tid 935898] [client 50.116.65.227:54796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VW7cDxY_mIul-JSGnQwAAARI"]
[Mon Jul 20 06:32:27.265732 2026] [security2:error] [pid 940476:tid 940613] [client 50.116.65.227:54810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VWxjVYcQxwGpYwZmmbwAAAAc"]
[Mon Jul 20 06:32:27.662109 2026] [security2:error] [pid 935758:tid 935957] [client 57.141.18.31:64732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmiwABTVA"]
[Mon Jul 20 06:32:27.761841 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWxjVYcQxwGpYwZmmjAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:27.761927 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWxjVYcQxwGpYwZmmjAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:27.821146 2026] [security2:error] [pid 935758:tid 935972] [client 57.141.18.112:52468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmlAABXGU"]
[Mon Jul 20 06:32:28.108136 2026] [security2:error] [pid 940476:tid 940626] [client 34.73.38.214:64187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VXBjVYcQxwGpYwZmmlAAAABQ"]
[Mon Jul 20 06:32:28.428871 2026] [security2:error] [pid 940476:tid 940642] [client 20.15.133.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4VXBjVYcQxwGpYwZmmnwAAACQ"]
[Mon Jul 20 06:32:28.433719 2026] [security2:error] [pid 935758:tid 935995] [client 57.141.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VXLcDxY_mIul-JSGnawAAAXM"]
[Mon Jul 20 06:32:28.905922 2026] [security2:error] [pid 940476:tid 940714] [client 171.60.139.123:59788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VXBjVYcQxwGpYwZmmugAAAGw"]
[Mon Jul 20 06:32:28.906044 2026] [security2:error] [pid 940476:tid 940714] [client 171.60.139.123:59788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VXBjVYcQxwGpYwZmmugAAAGw"]
[Mon Jul 20 06:32:28.949667 2026] [security2:error] [pid 940476:tid 940675] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VXBjVYcQxwGpYwZmmtwAAAEU"], referer: 1'"3000
[Mon Jul 20 06:32:29.020373 2026] [security2:error] [pid 940476:tid 940661] [client 77.110.127.138:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmmyAAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.020468 2026] [security2:error] [pid 940476:tid 940661] [client 77.110.127.138:65452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmmyAAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.141975 2026] [security2:error] [pid 940476:tid 940689] [client 34.73.38.214:59646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VXRjVYcQxwGpYwZmmygAAAFM"]
[Mon Jul 20 06:32:29.243977 2026] [security2:error] [pid 940476:tid 940687] [client 77.110.127.138:65453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:amp9aGghcWq')) OR 199. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "select 199 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VXRjVYcQxwGpYwZmmzwAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.393600 2026] [security2:error] [pid 940476:tid 940708] [client 43.129.235.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4VWxjVYcQxwGpYwZmmhwAAZnQ"], referer: https://www.aleishapenny.ca/listing/page/193?view=map&paged=193
[Mon Jul 20 06:32:29.395035 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmm0wAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.395153 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:65454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmm0wAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.563827 2026] [security2:error] [pid 940476:tid 940679] [client 104.234.53.85:20133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VXRjVYcQxwGpYwZmm3gAAAEk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:29.620381 2026] [security2:error] [pid 940476:tid 940494] [remote 100.42.189.89:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4VXRjVYcQxwGpYwZmm4AAADRE"]
[Mon Jul 20 06:32:29.638526 2026] [security2:error] [pid 940476:tid 940625] [client 45.116.69.230:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VXRjVYcQxwGpYwZmm4QAAABM"]
[Mon Jul 20 06:32:29.638639 2026] [security2:error] [pid 940476:tid 940625] [client 45.116.69.230:52394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VXRjVYcQxwGpYwZmm4QAAABM"]
[Mon Jul 20 06:32:29.680863 2026] [security2:error] [pid 940476:tid 940630] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VXRjVYcQxwGpYwZmm3AAAABg"], referer: 1'"3000
[Mon Jul 20 06:32:29.828856 2026] [security2:error] [pid 940476:tid 940561] [remote 100.42.189.89:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4VXRjVYcQxwGpYwZmm6QAAOVQ"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:32:29.989297 2026] [security2:error] [pid 940476:tid 940717] [client 173.239.224.236:22593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "